Bandoo Datamngr

By CagedTech in Browser Hijackers

Threat Scorecard

Popularity Rank: 2,957
Threat Level: 50 % (Medium)
Infected Computers: 47,180
First Seen: September 20, 2010
Last Seen: February 3, 2026
OS(es) Affected: Windows

Aliases

1 security vendors flagged this file as malicious.

Antivirus Vendor Detection
NOD32 a variant of Win32/Toolbar.SearchSuite

SpyHunter Detects & Remove Bandoo Datamngr

File System Details

Bandoo Datamngr may create the following file(s):
# File Name MD5 Detections
1. installhelper.dll.vir 46baa11b87c127ad9386d91e844c7351 3,661
2. $RRZCM50.dll 2304bf0ff7b559373be4645a09f34f3e 877
3. installhelper.dll 4b8c528b795b0d872774205aea3fe116 645
4. DatamngrCoordinator.exe 21e549a289662f116d7b3398c43654c7 571
5. del_DM_EXE_49.dll 82e9093b9404d44d56e89c7a2c29a149 454
6. del_DM_EXE_83.dll 122a47b49993422f29b2a20d439e15ca 118
7. datamngr.dll 9c7ba5358dc5ec4f66716d395fc2a7ab 12
8. DatamngrUI.exe db2cd06abb5d7c7a6e4d71969a78e52f 2
9. BrowserConnection.dll 5b95ebbb44e8b8160c8903387697d11c 2
More files

Registry Details

Bandoo Datamngr may create the following registry entry or registry entries:
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\DATAMNGR

Directories

Bandoo Datamngr may create the following directory or directories:

%PROGRAMFILES%\SearchCore for Browsers
%PROGRAMFILES(x86)%\SearchCore for Browsers

Analysis Report

General information

Family Name: Bandoo Datamngr
Signature status: Self Signed

Known Samples

MD5: 458706d3b83bb0ed0dd2f5751d4dfacf
SHA1: 9a9fcc69efa9663cef9cfcf5824bc1dafa38c46d
File Size: 8.06 MB, 8062368 bytes
MD5: 442a139475bc38425c683f1569e342ff
SHA1: c8e295eaa481004abff9764a55614267d82ccf91
SHA256: BC81054C9DAB108378819E3FA6DDB8C9650682B9179AB2A2B2D23670E76AF46E
File Size: 119.81 KB, 119808 bytes
MD5: 46323601e689ca0e7db1eebe32de686a
SHA1: 706add146f83a6793a2441df938a70fc7d04178d
SHA256: 99329775C3B9955F322E4C24BEF391567CDCBEB04F0DAC12A03105FED5E0E4FA
File Size: 156.23 KB, 156230 bytes
MD5: 97e1f8521dbc7b14c98c0f6e6a69451e
SHA1: 6ee82d78af4728169bffc41cb95cd95a5b79f60c
SHA256: 9276F8757A18A392B3AB3B81ABE7A687982935B956C9CD6EC5124309B1A08FC9
File Size: 230.24 KB, 230240 bytes
MD5: 574166a7a811b1f71232345da17251e4
SHA1: f8d9497cf37f96ad5538ae2f1dc3fcbff3d0722e
SHA256: 58C9C7097D24801B1C9166C3ABFE8C1E29CF9B5F9A528D1A5BE6BCC0B4AFCA0D
File Size: 440.85 KB, 440848 bytes
Show More
MD5: 2c2ff7642499a567cb93bf7b6325ffb4
SHA1: f270ddf32f0769868bf0ab6b9a19dc2e31600e93
SHA256: 10C98BC272CEF5FF86AA981651E34272642913549556A1938FB1A6982C706001
File Size: 7.91 MB, 7913472 bytes
MD5: 571375e0e59e6a114ca0a9b771df8bf4
SHA1: f2dfc4be5a242e843876bc3f5d79705b78224e54
SHA256: 1E8B11520B4EC045907FB9456FEAFA415A4915B2AF9BA7C5EA4DA3DDA417008C
File Size: 1.32 MB, 1318592 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Bandoo Media Inc
  • Bandoo Media Inc.
  • Igor Pavlov
  • iMesh Inc
  • Koyote-Lab Inc
File Description
  • 7z Console SFX
  • Bandoo
  • Free iPod video Converter Install
  • Free MP3 Cutter Install
  • iLivid Download Manager
  • iMesh Install
  • Movies Toolbar Install
File Version
  • 12.5.0.135176
  • 9.20
  • 5.0.2.4595
  • 5.0.0.12349
  • 1.0.0.135585
  • 1.0.0.0
Internal Name
  • 7z.sfx
  • iLivid
Legal Copyright
  • Copyright (c) 1999-2010 Igor Pavlov
  • Copyright (c) 2005 - 2014
  • Copyright (c) 2011
  • Copyright (C) 2013
  • Copyright (C) 2014 Bandoo Media Inc. All Rights Reserved.
  • Copyright (c) 2015
Original Filename
  • 7z.sfx.exe
  • iLivid.exe
Product Name
  • 7-Zip
  • Free iPod video Converter
  • Free MP3 Cutter
  • iLivid Download Manager
  • iMesh
  • Koyote
Product Version
  • 12.5.0.135176
  • 9.20
  • 5.0.2.4595
  • 5.0.0.12349
  • 1.0.0.135585
  • 1.0.0.115982

Digital Signatures

Signer Root Status
Bandoo Media, Inc Thawte Code Signing CA - G2 Hash Mismatch
Koyote-Lab Inc. Thawte Code Signing CA - G2 Self Signed
Bandoo Media, Inc Thawte Premium Server CA Root Not Trusted
Koyote-Lab Inc. thawte Primary Root CA Root Not Trusted

File Traits

  • big overlay
  • HighEntropy
  • Installer Manifest
  • Installer Version
  • nosig nsis
  • x86

Block Information

Similar Families

  • AdGazelle.A
  • Downloader.Agent.TJ
  • Mobogenie
  • SearchSuite.C
  • Zusy.CA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\glcae1c.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nseb934.tmp\apphelp.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\license.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\registry.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\soffer.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\uac.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\uninstall.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nseb934.tmp\userinfo.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsfbba5.tmp\helper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsfbba5.tmp\license.txt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsfbba5.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsfbba5.tmp\nsdialogs.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsfbba5.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsfbba5.tmp\uac.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nspe13b.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsue15b.tmp\helper.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsue15b.tmp\helper.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsue15b.tmp\helper.dll Generic Write,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsue15b.tmp\helper.dll Generic Write,Read Attributes,LEFT 262144
c:\users\user\appdata\local\temp\nsue15b.tmp\helper.dll Generic Write,Read Data,Read Attributes,Delete,LEFT 262144
c:\users\user\appdata\local\temp\nsue15b.tmp\helper.dll Generic Write,Read Data,Read Attributes,LEFT 262144
c:\users\user\appdata\local\temp\nsue15b.tmp\registry.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsue15b.tmp\starter.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsue15b.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsue15b.tmp\userinfo.dll Generic Write,Read Attributes

Windows API Usage

Category API
User Data Access
  • GetUserName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
Other Suspicious
  • AdjustTokenPrivileges

Trending

Most Viewed

Loading...