datamngrui.exe

Bandoo Media, Inc

The application datamngrui.exe by Bandoo Media, Inc has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘DATAMNGR’. This file is typically installed with the program Windows iLivid Toolbar by Bandoo Media Inc which is a potentially unwanted software program.
Publisher:
Bandoo Media, Inc  (signed and verified)

MD5:
c0909655d4bdf541da23e828b7b05a7a

SHA-1:
99990edfc577aec1951ca93a2d4423dbeab48e77

SHA-256:
45c27057f66a8848fa31c516b7f109958b3ec2d5fbac63b2c24a51944ac1e5e2

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/26/2024 11:47:54 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.BandooToolbar (M)
17.2.14.1

File size:
1.5 MB (1,546,640 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\windows ilivid toolbar\datamngr\datamngrui.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
11/3/2010 1:00:00 AM

Valid to:
11/3/2012 12:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
7AD02DB75E76EA8D8CF4A4D1C2591229

File PE Metadata
Compilation timestamp:
6/1/2011 10:43:04 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xF3148

Entry point:
E8, A5, B6, 00, 00, E9, 79, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 55, 8B, EC, 57, 56, 8B, 75, 0C, 8B, 4D, 10, 8B, 7D, 08, 8B, C1, 8B, D1, 03, C6, 3B, FE, 76, 08, 3B, F8, 0F, 82, A4, 01, 00, 00, 81, F9, 00, 01, 00, 00, 72, 1F, 83, 3D, 48, A8, 54, 00, 00, 74, 16, 57, 56, 83, E7, 0F, 83, E6, 0F, 3B, FE, 5E, 5F, 75, 08, 5E, 5F, 5D, E9, 68, B7, 00, 00, F7, C7, 03, 00, 00, 00, 75, 15, C1, E9, 02, 83, E2, 03, 83, F9, 08, 72, 2A, F3, A5, FF, 24, 95, D4, 32, 4F, 00, 90, 8B, C7, BA, 03...
 
[+]

Packer / compiler:
PEQuake V0.06

Code size:
1.1 MB (1,144,832 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
DATAMNGR

Command:
C:\Program Files2\wi3c8a~1\datamngr\datamn~1.exe


The file datamngrui.exe has been discovered within the following programs.

Windows iLivid Toolbar  by Bandoo Media Inc
This toolbar is typiclaly bundled with the installation of the free iLivid software. Windows iLivid Toolbar by Bandoo for Intenet Explorer collects and stores information about your web browsing habits in order to suggest services or provide advertising via the toolbar.
www.ilivid.com
79% remove it
 
Powered by Should I Remove It?

Remove datamngrui.exe - Powered by Reason Core Security