Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

64eb5 3.51%
e202a 7.02%
1b34b 10.53%
af529 1.75%
952ec 1.75%
67873 3.51%
7e109 10.53%
0e4fd 8.77%
26b5c 1.75%
6870e 1.75%
c9eb9 1.75%
332a7 7.02%
6ec14 5.26%
a5584 1.75%
3cda2 3.51%
94ca1 1.75%
62e62 1.75%
40a32 1.75%
2e0f2 3.51%
d4c00 3.51%
b5f86 1.75%
d86f9 3.51%
3ccdd 1.75%
fb2d4 1.75%
87ecf 5.26%
View more
(Note, Bandoo Media publishes each variation of this file with the same version, but the hashes are unique.)

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
ConvertSidToStringSidW, IsValidSid, GetTokenInformation, GetLengthSid, InitializeAcl, AddAce, GetSecurityInfo, GetAclInformation, GetAce, DeleteAce, SetSecurityInfo, OpenThreadToken, OpenProcessToken, RegEnumKeyW, ConvertStringSecurityDescriptorToSecurityDescriptorW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegNotifyChangeKeyValue, RegEnumValueW, RegQueryValueExW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegOpenKeyExW, RegCloseKey, SetKernelObjectSecurity, LookupAccountNameW, SaferCreateLevel, SaferCloseLevel, SetTokenInformation, CreateProcessAsUserW, GetSidSubAuthorityCount, GetUserNameW, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, CopySid, SaferComputeTokenFromLevel
comctl32.dll
InitCommonControlsEx, _TrackMouseEvent
gdi32.dll
GetTextExtentPoint32W, SetTextColor, DeleteDC, CreateCompatibleBitmap, BitBlt, CreateFontIndirectW, CreateCompatibleDC, GetObjectW, SetBkMode, CreatePatternBrush, CreateSolidBrush, DeleteObject, GetTextMetricsW, SelectObject, GetStockObject
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain
netapi32.dll
Netbios
ole32.dll
CoTaskMemRealloc, CoCreateInstance, CoTaskMemFree, CoUninitialize, CoInitialize, CLSIDFromString, StringFromGUID2, CoTaskMemAlloc, StringFromIID, CoCreateGuid, CoSetProxyBlanket
sensapi.dll
IsNetworkAlive
shell32.dll
SHGetSpecialFolderPathW, SHFileOperationW, ShellExecuteExW
shlwapi.dll
PathRemoveFileSpecW, UrlIsW, PathAddBackslashW, SHDeleteKeyW, SHCopyKeyW, StrStrIW
user32.dll
PeekMessageW, MsgWaitForMultipleObjectsEx, SetPropW, MessageBoxW, FindWindowW, MsgWaitForMultipleObjects, IsWindowUnicode, GetMessageA, DispatchMessageA, SetCursor, GetSysColor, ReleaseDC, GetDC, EndPaint, BeginPaint, PtInRect, IsWindow, RedrawWindow, SetWindowPos, DrawTextW, GetActiveWindow, SetLayeredWindowAttributes, SystemParametersInfoW, GetClientRect, GetWindowRect, MoveWindow, FillRect, DialogBoxParamW, LoadBitmapW, GetCursorPos, TrackMouseEvent, GetTopWindow, ChildWindowFromPoint, ShowWindow, ScreenToClient, GetMessageW, TranslateMessage, DispatchMessageW, CreateWindowExW, RegisterClassExW, PostQuitMessage, LoadCursorW, GetClassInfoExW, KillTimer, SetTimer, PostMessageW, LoadStringW, GetDlgItem, SetWindowTextW, SendMessageW, EndDialog, GetWindowLongW, SetWindowLongW, CallWindowProcW, DestroyWindow, CharNextW, DefWindowProcW, GetParent, UnregisterClassA, LoadStringA, InvalidateRect, GetGUIThreadInfo
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
wininet.dll
InternetCloseHandle, InternetReadFile, HttpQueryInfoW, HttpSendRequestW, InternetSetOptionW, HttpOpenRequestW, InternetConnectW, InternetOpenW, InternetGetConnectedState

datamngrUI.exe

By Bandoo Media (Signed)

Remove datamngrUI.exe
MD5:   7e10902f4402672bdebb21de707e5fd3
SHA1:   4256b4c8d90df535cbba81dbde0c44afa3510529
SHA256:   047976280fe9b1af7ff32fa8c70ed88be98aeb620b72a9050a7c237938f30712

What is datamngrUI.exe?

Searchqu Toolbar is a browser add-on which adds various shortcuts and other buttons to your Internet browsers such as Internet Explorer, FireFox, Google Chrome. Some PC users may find such shortcuts useful but Searchqu Toolbar can be categorized as an unwanted program because it's deceptive ways of installation and not full uninstall procedures. When installed on your PC this toolbar by default will change your homepage to searchnu.com.

About datamngrUI.exe (from Bandoo Media)

Windows Searchqu Toolbar is an Internet browser toolbar that offers helpful search suggestions as the user types keywords into the search box. Additionally, it catches misspelled words and suggests a

DetailsDetails

File name:datamngrUI.exe
Typical file path:C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe
Size:1.81 MB (1,898,936 bytes)
Certificate
Issued to:Bandoo Media
Authority (CA):Thawte
Expiration date:Friday, November 2, 2012
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'DATAMNGR' → C:\Program Files1\WIA6EB~1\Datamngr\DATAMN~1.EXE
Network connections
  • [TCP] NYC-207-232-22-200.netvision.net.il (207.232.22.200:80)
  • [TCP] ec2-54-243-193-48.compute-1.amazonaws.com (54.243.193.48:80)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.01147985%
    0.028634%
    Kernel CPU:0.01001413%
    0.013761%
    User CPU:0.00146573%
    0.014873%
    Kernel CPU time:176 ms/min
    100,923,805ms/min
    CPU cycles:173,136/sec
    17,470,203/sec
    Memory
    Private memory:2.57 MB
    21.59 MB
    Private (maximum):6.38 MB
    Private (minimum):5.05 MB
    Non-paged memory:2.57 MB
    21.59 MB
    Virtual memory:81.83 MB
    140.96 MB
    Virtual memory (peak):90.84 MB
    169.69 MB
    Working set:5.28 MB
    18.61 MB
    Working set (peak):9.67 MB
    37.95 MB
    Page faults:5,140/min
    2,039/min
    I/O
    I/O read transfer:1.53 KB/sec
    1.02 MB/min
    I/O read operations:2/sec
    343/min
    I/O write transfer:42 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:132 Bytes/sec
    448.09 KB/min
    I/O other operations:32/sec
    1,671/min
    Resource allocations
    Threads:9
    12
    Handles:259
    600
    GUI GDI count:18
    103
    GUI GDI peak:39
    142
    GUI USER count:13
    49
    GUI USER peak:32
    71

    BehaviorsProcess properties

    Integrety level:Medium
    Platform:32-bit
    Command lines:
    • "C:\progra~1\srtool~1\datamngr\datamn~1.exe"
    • "C:\Program Files\srtoolbar\datamngr\datamngrui.exe"
    Owner:User
    Parent process:explorer.exe (Windows Explorer by Microsoft Corporation)

    ResourcesThreads

    Averages
     
    datamngrUI.exe
    Total CPU:0.00224787%
    0.272967%
    Kernel CPU:0.00181925%
    0.107585%
    User CPU:0.00042862%
    0.165382%
    CPU cycles:45,099/sec
    5,741,424/sec
    Memory:1.83 MB
    1.16 MB
    WININET.dll
    Total CPU:0.00142283%
    Kernel CPU:0.00142283%
    User CPU:0.00000000%
    CPU cycles:33,514/sec
    Memory:980 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Ultimate 26.32%
    Windows 7 Ultimate N 24.56%
    Windows 7 Home Premium 15.79%
    Microsoft Windows XP 12.28%
    Windows 8 Pro 5.26%
    Windows 7 Home Basic 3.51%
    Windows 7 Professional 3.51%
    Windows Vista Home Basic 3.51%
    Windows Vista Home Premium 3.51%
    Windows 8 1.75%

    Distribution by countryDistribution by country

    United States installs about 43.64% of datamngrUI.exe.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Acer 20.00%
    Hewlett-Packard 20.00%
    Dell 20.00%
    Lenovo 20.00%
    Sony 10.00%
    Sahara 5.00%
    GIGABYTE 5.00%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE