Trojan Horse Removal

I keep getting a trojan horse named PUP.Datamngr when I open IE (Win7) and do a scan with Malwarebytes Anitmalware. This trojan does not show up when scanning with Avast (free version). Any suggestions how to remove this ‘registry key’ entry? -KS

PUP = Potentially Unwanted Program - See,,sid14_gci1066761,00.html. Not included in this definition are tools which can be used for good or evil, some have been legitimately installed for a specifically good purpose, but could have been unknowing installed for a malicious purpose.

Not all antivirus programs scan for PUPs and avast has it turned off by default (an exception being the boot-time scan). So that would account for it not being detected on a regular avast scan, the boot-time scan and the web shield do scan for PUPs by default.

What is actually detecting this, mbam ?
If it is only mbam, what are the full details of the detection ?

searching on google…this seems to be a Malwarebytes detection
so if malwarebytes detect it…why does you not remove it with malwarebytes?
is malwarebytes updated before you scan?
is the detection marked for removal (a red x to the left of it) … do you click the remove selected button after scan?

I would certainly recommend investigation before removal no matter what application detects it.

I apologize for butting in. I cannot figure out how to post a new topic. I need help urgently. This is my first time on this site.

I have been emailing avast for a few days, but there seems to be a language barrier.

I had a virus detected a few days ago (I have avast internet security pro 7).

I put it in the virus vault and contacted avast tech (I assume they are NOT here in the US).

Avast emailed me and told me to “submit the suspicious file to our FTP server.” I have generated a file over and over, but when I press
what’s next" nothing happens.

When I emailed avast back for help they just ask me if I sent the file yet. I cannot send it. When I go to"" nothing really happens. Some folders come up. I know that I am supposed to load to the “incoming folder” , but when I click on it the headings “Name” “Size” and “File” appear. I can’t click on them. I don’t know what to do from here. I am logged in, so that is not the issue.

I need to have the log anaylized it is pretty serious. (Spyeye) I put it in the vault as I said, but this was days ago and I still cannot send the file. I have no idea if I have actually been effected or if it was a false positive, because I have not been able to send it.

Can someone help?

I apologize for butting in. I cannot figure out how to post a new topic. I need help urgently. This is my first time on this site.
when you enter a forum find a new topic button at top right

if you have a virus sample to send, you can do it here.

I also have this problem. Malwarebytes reports “pup datamngr” in windows full scan. System seems slower than normal so I think I have an infection. The scan log only reports regestry entrys for this trojan with no action taken. Many referances on the net to this but little info here. Here is the log from MWB. What do you advise? Thanks…
Malwarebytes Anti-Malware

Database version: v2013.01.16.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Bill :: BILLS-XPSLAPTOP [administrator]

1/16/2013 9:02:46 AM
mbam-log-2013-01-16 (09-02-46).txt

Scan type: Full scan (C:|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 458255
Time elapsed: 1 hour(s), 58 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 4
HKCR\CLSID{f34c9277-6577-4dff-b2d7-7d58092f272f} (PUP.Datamngr) → No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings{F34C9277-6577-4DFF-B2D7-7D58092F272F} (PUP.Datamngr) → No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{F34C9277-6577-4DFF-B2D7-7D58092F272F} (PUP.Datamngr) → No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy{F34C9277-6577-4DFF-B2D7-7D58092F272F} (PUP.Datamngr) → No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)


PUP datamanager is normally associated with dubious tool bars. AdwCleaner will remove them