PUA

What is “PUADlManager:Win32/Avarus”?

Malware Removal

The PUADlManager:Win32/Avarus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/Avarus virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Checks the version of Bios, possibly for anti-virtualization
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Suspicious wmic.exe use was detected

How to determine PUADlManager:Win32/Avarus?


File Info:

name: 8F1696A206D0A6B22DEF.mlw
path: /opt/CAPEv2/storage/binaries/5fd2f85001b359045f60ac7e07b59045f883df79a14155c0fbf0a361c42f1772
crc32: 3885EDCD
md5: 8f1696a206d0a6b22deffa0c1a9543d1
sha1: 592fece72dd218517478f2be3653dbcf8b106c02
sha256: 5fd2f85001b359045f60ac7e07b59045f883df79a14155c0fbf0a361c42f1772
sha512: 965542487ad22c7beb8140d8d52cb43595081c67831eb0736d098b2e58f938a25f0977b4765b8dca14e0e3f2bf23ada5cbf4f6ca93ed763dfcdab03dd79d5994
ssdeep: 24576:69bZn113GiwllQiK1UBEZF7NWxwntNOpdZTW:ubv12LlMUBENWxwntwp/TW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12125332B59B4546BF4270BF205327C6EC0F7CACE60A546434BB47DDBC5B1F81896AAD0
sha3_384: b9ecdbe903209e6bd1931c492c61c9ddbde173db3f119453f2485bc1f62ec3491ebac7da3257137c8c9f3aa3fe2c2558
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

Comments: 7-Zip
CompanyName: 7-Zip
FileDescription: Extract and compress your files
LegalCopyright:
LegalTrademarks: 7-Zip
ProductName: 7-Zip
ProductVersion: 3.0
Translation: 0x0000 0x04e4

PUADlManager:Win32/Avarus also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.OutBrowse.m1jN
MicroWorld-eScanMemScan:Application.Bundler.Outbrowse.K
FireEyeGeneric.mg.8f1696a206d0a6b2
CAT-QuickHealTrojan.Agent
SkyhighBehavesLike.Win32.Suspicious.dc
ALYacMemScan:Application.Bundler.Outbrowse.K
Cylanceunsafe
VIPREMemScan:Application.Bundler.Outbrowse.K
SangforSuspicious.Win32.Save.ins
AlibabaAdWare:Win32/OutBrowse.6d173b6b
K7GWTrojan ( 0049cb321 )
K7AntiVirusTrojan ( 0049cb321 )
ArcabitApplication.Bundler.Outbrowse.K
BaiduNSIS.Adware.Generic.a
VirITAdware.Win32.Downware.IQV
Elasticmalicious (high confidence)
ESET-NOD32Win32/OutBrowse.X potentially unwanted
APEXMalicious
TrendMicro-HouseCallTROJ_SPNR.0BIN14
McAfeeArtemis!8F1696A206D0
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.OutBrowse.aau
BitDefenderMemScan:Application.Bundler.Outbrowse.K
NANO-AntivirusTrojan.Win32.OutBrowse.deinil
AvastNSIS:OutBrowse-E [PUP]
TencentWin32.Trojan.Outbrowse.Kajl
EmsisoftMemScan:Application.Bundler.Outbrowse.K (B)
F-SecurePotentialRisk.PUA/Outbrowse.Gen
DrWebAdware.Downware.5845
ZillyaAdware.OutBrowse.Win32.6039
TrendMicroTROJ_SPNR.0BIN14
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusPUA.OutBrowse
MAXmalware (ai score=99)
JiangminAdWare.OutBrowse.jdk
WebrootW32.Malware.Heur
GoogleDetected
AviraPUA/Outbrowse.Gen
VaristW32/Outbrowse.B2.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.ConvertAd.yy
Kingsoftmalware.kb.a.890
XcitiumApplicUnwnt@#1xjzo2yihie48
MicrosoftPUADlManager:Win32/Avarus
ViRobotAdware.Outbrowse.999698.E
ZoneAlarmnot-a-virus:AdWare.Win32.OutBrowse.aau
GDataMemScan:Application.Bundler.Outbrowse.K
CynetMalicious (score: 100)
TACHYONTrojan/W32.PornoAsset.999698
VBA32Adware.OutBrowse
MalwarebytesPUP.Optional.OutBrowse
RisingTrojan.Generic@AI.97 (RDML:CB8ruLRJX5MeQUZ0fseWIA)
YandexPUA.OutBrowse!P0w9AcuTDJw
AVGNSIS:OutBrowse-E [PUP]
DeepInstinctMALICIOUS
alibabacloudAdWare:Win/OutBrowse.aau

How to remove PUADlManager:Win32/Avarus?

PUADlManager:Win32/Avarus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment