Should I block it?

60%
60% of PCs block this file from running.
Possible reason:
Performance resource utilization

VersionsAdditional versions

18b74 20.00%
6d35a 20.00%
72ef4 20.00%
b85c1 20.00%
4e89a 20.00%
(Note, iMesh Inc. publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
LookupAccountNameW, IsValidSid, ConvertSidToStringSidW, GetTokenInformation, GetLengthSid, InitializeAcl, AddAce, GetSecurityInfo, GetAclInformation, GetAce, DeleteAce, SetSecurityInfo, OpenThreadToken, OpenProcessToken, SetKernelObjectSecurity, RegEnumValueW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegEnumKeyW, RegNotifyChangeKeyValue, RegQueryValueExW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegOpenKeyExW
comctl32.dll
InitCommonControlsEx, _TrackMouseEvent
gdi32.dll
GetTextExtentPoint32W, SetTextColor, DeleteDC, CreateCompatibleBitmap, BitBlt, CreateFontIndirectW, CreateCompatibleDC, GetObjectW, SetBkMode, CreatePatternBrush, CreateSolidBrush, DeleteObject, GetTextMetricsW, SelectObject, GetStockObject
kernel32.dll
DllMain
ole32.dll
CoTaskMemAlloc, CoCreateInstance, CoTaskMemFree, CoUninitialize, CoInitialize, CLSIDFromString, StringFromGUID2, CoTaskMemRealloc
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
SHDeleteKeyW, SHCopyKeyW, UrlIsW, PathAddBackslashW, PathRemoveFileSpecW
user32.dll
MessageBoxW, FindWindowW, MsgWaitForMultipleObjects, PostQuitMessage, SetPropW, MsgWaitForMultipleObjectsEx, PeekMessageW, IsWindowUnicode, GetMessageW, GetMessageA, TranslateMessage, DispatchMessageW, DispatchMessageA, SetCursor, CreateWindowExW, RegisterClassExW, GetSysColor, ReleaseDC, GetDC, BeginPaint, PtInRect, LoadCursorW, GetClassInfoExW, IsWindow, GetParent, RedrawWindow, InvalidateRect, SetWindowPos, DrawTextW, GetActiveWindow, GetWindowLongW, SetLayeredWindowAttributes, SystemParametersInfoW, GetClientRect, GetWindowRect, MoveWindow, FillRect, GetCursorPos, TrackMouseEvent, ChildWindowFromPoint, KillTimer, SetTimer, ScreenToClient, DialogBoxParamW, LoadBitmapW, GetTopWindow, ShowWindow, SetWindowLongW, LoadStringW, GetDlgItem, SetWindowTextW, SendMessageW, EndDialog, DefWindowProcW, DestroyWindow, CharNextW, EndPaint, UnregisterClassA, LoadStringA, CallWindowProcW
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
wininet.dll
InternetCloseHandle, HttpSendRequestW, InternetSetOptionW, HttpOpenRequestW, InternetConnectW, InternetOpenW

datamngrui.exe

By iMesh Inc. (Signed)

Remove datamngrui.exe
MD5:   b85c1fe14a28ff2a75c6ee440af23968
SHA1:   d9ddfeb6b41c8397bcc74612bae9204739890ed4
SHA256:   6d7f73c5b0919f9bbdc0b14616be36889dbc3c91a958bbdcf914a077f8c2b5ab

Overview

datamngrui.exe executes as a process with the local user's privileges. It is set to be start when the PC boots and any user logs into Windows (added to the Run registry key for the all users under the local machine). This is typically installed with the program iMesh published by iMesh Inc.. The file is digitally signed by iMesh Inc. which was issued by the Thawte certificate authority (CA). Note, some antivirus scanners have flagged this file, however it is not necessarily considered malware (see below for details).

DetailsDetails

File name:datamngrui.exe
Typical file path:C:\Program Files\imesh applications\mediabar\datamngr\datamngrui.exe
Size:1.61 MB (1,684,696 bytes)
Certificate
Issued to:iMesh Inc.
Authority (CA):Thawte
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
iMesh Inc.
24% remove
iMesh is a media and file sharing client that's available in 9 languages. It uses a proprietary, centralized, P2P network (IM2Net) operating on ports 80, 443 and 1863. iMesh operates the first "RIAA-approved" P2P service, allowing users residing in United States and Canada to download music content of choice for a monthly fee in the form of either a Premium subscription or a "ToGo" subscription. This subscription based approach is advoc...

BehaviorsBehaviors

Startup files (all users) run
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'DATAMNGR' → C:\Program Files1\IMESHA~1\Mediabar\Datamngr\DATAMN~1.EXE

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 40.00%
Windows Vista Home Premium 20.00%
Windows 8 Pro with Media Center 20.00%
Windows 7 Home Premium 20.00%

Distribution by countryDistribution by country

Australia installs about 20.00% of datamngrui.exe.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE