mgrldr.dll

Bandoo Media, Inc

The module mgrldr.dll by Bandoo Media, Inc has been detected as adware by 11 anti-malware scanners.
Publisher:
Bandoo Media, Inc  (signed and verified)

MD5:
bfb22a28bed32910a20be8218bc1a8ef

SHA-1:
489533058c9e869b6431a147d73eec53cfd473e0

SHA-256:
50b2522011d6c0b37211ec561a85ef1e378b424387bbafad47cf5e974050825f

Scanner detections:
11 / 68

Status:
Adware

Analysis date:
4/19/2024 6:42:54 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Toolbar.SearchSuite
2015.0.3405

Baidu Antivirus
Adware.Win64.SearchSuite
4.0.3.14723

ESET NOD32
Win64/Toolbar.SearchSuite (variant)
8.10059

G Data
Win64.Application.Searchsuite
14.7.24

IKARUS anti.virus
PUA.Bandoo
t3scan.1.6.1.0

Kaspersky
not-a-virus:WebToolbar.Win64.SearchSuite
14.0.0.3518

Panda Antivirus
Trj/Chgt.A
14.07.23.11

Qihoo 360 Security
Win32/Virus.WebToolbar.49b
1.0.0.1015

Reason Heuristics
PUP.BandooToolbar.BandooMedia.G
14.7.23.11

Trend Micro House Call
Suspicious_GEN.F47V0630
7.2.204

VIPRE Antivirus
Adware.SearchSuite
31062

File size:
22 KB (22,528 bytes)

File type:
Dynamic link library (Win64 DLL)

Common path:
C:\Program Files\movies toolbar\datamngr\x64\mgrldr.dll

Digital Signature
Authority:
Thawte, Inc.

Valid from:
2/9/2014 8:00:00 AM

Valid to:
11/3/2014 7:59:59 AM

Subject:
CN="Bandoo Media, Inc", O="Bandoo Media, Inc", L=Panama City, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
74B45E4BF603EDCA78C252159948CF7A

File PE Metadata
Compilation timestamp:
6/30/2014 5:33:27 PM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
384:bk2OK5OETq/Tp5st7v3olXkJGnjrSuSPLZl:o2Ol6q7p5i7Ckwjr+

Entry address:
0x2290

Entry point:
4C, 89, 44, 24, 18, 89, 54, 24, 10, 48, 89, 4C, 24, 08, 48, 83, EC, 28, 83, 7C, 24, 38, 01, 75, 4D, 48, 8B, 44, 24, 30, 48, 89, 05, 8B, 2F, 00, 00, E8, A6, 13, 00, 00, 0F, B6, C0, 85, C0, 74, 2B, E8, 5A, EF, FF, FF, E8, 35, 00, 00, 00, E8, 30, ED, FF, FF, E8, 9B, FD, FF, FF, 48, 8B, C8, E8, D3, FD, FF, FF, E8, 4E, FC, FF, FF, 48, 8B, C8, E8, 86, 00, 00, 00, EB, 0A, 48, 8B, 4C, 24, 30, E8, DA, 13, 00, 00, B8, 01, 00, 00, 00, 48, 83, C4, 28, C3, 48, 81, EC, 58, 02, 00, 00, 48, 8D, 15, 32, 20, 00, 00, 48, 8D...
 
[+]

Entropy:
6.0316

Code size:
10 KB (10,240 bytes)

Remove mgrldr.dll - Powered by Reason Core Security