Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

64eb5 3.51%
e202a 7.02%
1b34b 10.53%
af529 1.75%
952ec 1.75%
67873 3.51%
7e109 10.53%
0e4fd 8.77%
26b5c 1.75%
6870e 1.75%
c9eb9 1.75%
332a7 7.02%
6ec14 5.26%
a5584 1.75%
3cda2 3.51%
94ca1 1.75%
62e62 1.75%
40a32 1.75%
2e0f2 3.51%
d4c00 3.51%
b5f86 1.75%
d86f9 3.51%
3ccdd 1.75%
fb2d4 1.75%
87ecf 5.26%
View more
(Note, Bandoo Media publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
ConvertSidToStringSidW, IsValidSid, GetTokenInformation, GetLengthSid, InitializeAcl, AddAce, GetSecurityInfo, GetAclInformation, GetAce, DeleteAce, SetSecurityInfo, OpenThreadToken, OpenProcessToken, RegEnumKeyW, ConvertStringSecurityDescriptorToSecurityDescriptorW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegNotifyChangeKeyValue, RegEnumValueW, RegQueryValueExW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegOpenKeyExW, RegCloseKey, SetKernelObjectSecurity, LookupAccountNameW, SaferCreateLevel, SaferCloseLevel, SetTokenInformation, CreateProcessAsUserW, GetSidSubAuthorityCount, GetUserNameW, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, CopySid, SaferComputeTokenFromLevel
comctl32.dll
InitCommonControlsEx, _TrackMouseEvent
gdi32.dll
GetTextExtentPoint32W, SetTextColor, DeleteDC, CreateCompatibleBitmap, BitBlt, CreateFontIndirectW, CreateCompatibleDC, GetObjectW, SetBkMode, CreatePatternBrush, CreateSolidBrush, DeleteObject, GetTextMetricsW, SelectObject, GetStockObject
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain
netapi32.dll
Netbios
ole32.dll
CoTaskMemRealloc, CoCreateInstance, CoTaskMemFree, CoUninitialize, CoInitialize, CLSIDFromString, StringFromGUID2, CoTaskMemAlloc, StringFromIID, CoCreateGuid, CoSetProxyBlanket
sensapi.dll
IsNetworkAlive
shell32.dll
SHGetSpecialFolderPathW, SHFileOperationW, ShellExecuteExW
shlwapi.dll
PathRemoveFileSpecW, UrlIsW, PathAddBackslashW, SHDeleteKeyW, SHCopyKeyW, StrStrIW
user32.dll
PeekMessageW, MsgWaitForMultipleObjectsEx, SetPropW, MessageBoxW, FindWindowW, MsgWaitForMultipleObjects, IsWindowUnicode, GetMessageA, DispatchMessageA, SetCursor, GetSysColor, ReleaseDC, GetDC, EndPaint, BeginPaint, PtInRect, IsWindow, RedrawWindow, SetWindowPos, DrawTextW, GetActiveWindow, SetLayeredWindowAttributes, SystemParametersInfoW, GetClientRect, GetWindowRect, MoveWindow, FillRect, DialogBoxParamW, LoadBitmapW, GetCursorPos, TrackMouseEvent, GetTopWindow, ChildWindowFromPoint, ShowWindow, ScreenToClient, GetMessageW, TranslateMessage, DispatchMessageW, CreateWindowExW, RegisterClassExW, PostQuitMessage, LoadCursorW, GetClassInfoExW, KillTimer, SetTimer, PostMessageW, LoadStringW, GetDlgItem, SetWindowTextW, SendMessageW, EndDialog, GetWindowLongW, SetWindowLongW, CallWindowProcW, DestroyWindow, CharNextW, DefWindowProcW, GetParent, UnregisterClassA, LoadStringA, InvalidateRect, GetGUIThreadInfo
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
wininet.dll
InternetCloseHandle, InternetReadFile, HttpQueryInfoW, HttpSendRequestW, InternetSetOptionW, HttpOpenRequestW, InternetConnectW, InternetOpenW, InternetGetConnectedState

datamngrUI.exe

By Bandoo Media (Signed)

Remove datamngrUI.exe
MD5:   64eb5ff7bcfdf69ce3a13fa83c84318e
SHA1:   3620f37790a336cafa70eda240e5687bbb13e214
SHA256:   8ccf601521a2a1c027ceac3d68f6120d143f8f1cfa5c4202a061a26f24644202
Warning 5 antivirus scanners has detected malware.

What is datamngrUI.exe?

Searchqu Toolbar is a browser add-on which adds various shortcuts and other buttons to your Internet browsers such as Internet Explorer, FireFox, Google Chrome. Some PC users may find such shortcuts useful but Searchqu Toolbar can be categorized as an unwanted program because it's deceptive ways of installation and not full uninstall procedures. When installed on your PC this toolbar by default will change your homepage to searchnu.com.

About datamngrUI.exe (from Bandoo Media)

Windows Searchqu Toolbar is an Internet browser toolbar that offers helpful search suggestions as the user types keywords into the search box. Additionally, it catches misspelled words and suggests a

DetailsDetails

File name:datamngrUI.exe
Typical file path:C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe
Size:1.74 MB (1,823,160 bytes)
Certificate
Issued to:Bandoo Media
Authority (CA):Thawte
Expiration date:Friday, November 2, 2012
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Bandoo Media Inc
  83% remove
The Searchqu Toolbar is a Bandoo powered toolbar (by Bandoo Media Inc) for Intenet Explorer and Firefox. Searchqu collects and stores information about your web browsing habits and sends this information to Conduit so they can suggest services or provide advertising via the toolbar. The Bandoo Searchqu Toolbar will attempt to change your home page and search provider if you are not careful during installation and provides a search box a...
Bandoo Media Inc
  88% remove
Windows Searchqu Toolbar is an ad-supported program installed into Internet Explorer, Firefox and Chrome. The programs collects and stores information about web browsing habits and sends this information to its remote servers in order to provide injected advertising in search results and various other places. It will also modify the browser's home page and search provider. It displays various pop-up advertisements and tracks and reports...

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'DATAMNGR' → C:\Program Files1\WIA6EB~1\Datamngr\DATAMN~1.EXE

MalwareMalware detections

Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
Antivirus engineEngine versionDetection
Emsisoft Anti-Malware None Riskware.Win32.Toolbar.SearchSuite.AMN (A)
ESET NOD32 7.8018 a variant of Win32/Toolbar.SearchSuite.A
K7 AntiVirus 9.160.8224 Trojan
Trend Micro HouseCall 9.700.0.1001 TROJ_GEN.F47V0902
Vba32 AntiVirus 3.12.20.2 Trojan.Genome.ajleo

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.01609120%
0.028634%
Kernel CPU:0.01436715%
0.013761%
User CPU:0.00172406%
0.014873%
Kernel CPU time:250 ms/min
100,923,805ms/min
Context switches:3/sec
284/sec
Memory
Private memory:2.44 MB
21.59 MB
Private (maximum):1.73 MB
Private (minimum):1.72 MB
Non-paged memory:2.44 MB
21.59 MB
Virtual memory:79.16 MB
140.96 MB
Virtual memory (peak):80.16 MB
169.69 MB
Working set:1.77 MB
18.61 MB
Working set (peak):7.64 MB
37.95 MB
Resource allocations
Threads:12
12
Handles:255
600
GUI GDI count:87
103
GUI GDI peak:90
142
GUI USER count:34
49
GUI USER peak:37
71

BehaviorsProcess properties

Integrety level:Medium
Platform:32-bit
Command line:"C:\progra~1\wia6eb~1\datamngr\datamn~1.exe"
Owner:User

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate 26.32%
Windows 7 Ultimate N 24.56%
Windows 7 Home Premium 15.79%
Microsoft Windows XP 12.28%
Windows 8 Pro 5.26%
Windows 7 Home Basic 3.51%
Windows 7 Professional 3.51%
Windows Vista Home Basic 3.51%
Windows Vista Home Premium 3.51%
Windows 8 1.75%

Distribution by countryDistribution by country

United States installs about 43.64% of datamngrUI.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Acer 20.00%
Hewlett-Packard 20.00%
Dell 20.00%
Lenovo 20.00%
Sony 10.00%
Sahara 5.00%
GIGABYTE 5.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE