PUA

How to remove “PUADlManager:Win32/DomaIQ”?

Malware Removal

The PUADlManager:Win32/DomaIQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/DomaIQ virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUADlManager:Win32/DomaIQ?


File Info:

name: E2EF40FAEFB8265D57C2.mlw
path: /opt/CAPEv2/storage/binaries/410d3d1b9fd44104b59423d93912532b5e25ef27a8982e715c0b7d1c1df4e18f
crc32: F951A914
md5: e2ef40faefb8265d57c2b435ae563c99
sha1: 8d1fbc8ce0a128ac77832557e101c5e5a9ac830a
sha256: 410d3d1b9fd44104b59423d93912532b5e25ef27a8982e715c0b7d1c1df4e18f
sha512: 86eb4dd95babcba2000110f6a30b4a2401c3b0790603f3031a7bf846863665dc2d11519a8a81f2017f5b6c6534fb2aca95cb5dd5eab52d5bd96a0c78a4c3988d
ssdeep: 12288:nGQlIdQ8lIglrNYlPGAHQlmKgGRPcIxWcOAUK:n/IdQ8KglrNYltim/GRJx8AN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161C4236E28C2B437E7222B349C7757BEE332BD081791469753328EA70DF25D84B291D6
sha3_384: 2adb843cd820546098c5e01e424ccad0cfc167224b79b86bef944303468e42bb07ef7a80034de2f5c767a4ad7d0b306d
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:46

Version Info:

0: [No Data]

PUADlManager:Win32/DomaIQ also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.DomaIQ.Q
ClamAVWin.Adware.Domaiq-1
CAT-QuickHealPUA.Lunacomint.Gen
SkyhighArtemis!Trojan
McAfeeArtemis!E2EF40FAEFB8
Cylanceunsafe
ZillyaAdware.Lollipop.Win32.216
K7AntiVirusUnwanted-Program ( 00575d171 )
AlibabaAdWare:Win32/DomaIQ.97c0ab09
K7GWUnwanted-Program ( 00575d171 )
ArcabitApplication.Bundler.DomaIQ.Q
VirITPUP.Win32.Lunacom.A
SymantecTrojan.ADH.2
tehtrisGeneric.Malware
ESET-NOD32Win32/DomaIQ.AH potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.MSIL.DomaIQ.heur
BitDefenderApplication.Bundler.DomaIQ.Q
NANO-AntivirusTrojan.Win32.DomaIQ.csgowf
SUPERAntiSpywarePUP.BundleInstaller/Variant
AvastWin32:DomaIQ-AJ [PUP]
TencentAdware.Win32.Lollipop.f
EmsisoftApplication.InstallMon (A)
BaiduWin32.Adware.DomnIQ.b
F-SecurePotentialRisk.PUA/DomaIQ.Gen
DrWebTrojan.Domaiq.261
VIPREApplication.Bundler.DomaIQ.Q
SophosDomaIQ pay-per install (PUA)
IkarusPUA.DomaIQ
JiangminAdWare/MSIL.aug
GoogleDetected
AviraPUA/DomaIQ.Gen7
Antiy-AVLGrayWare[AdWare]/Win32.DomaIQ.eece
KingsoftWin32.Troj.Unknown.a
XcitiumApplicUnwnt@#2gfirqnpl7zna
MicrosoftPUADlManager:Win32/DomaIQ
ZoneAlarmnot-a-virus:Downloader.NSIS.DomaIQ.a
GDataMSIL.Adware.DomaIQ.F
AhnLab-V3Win-PUP/DomaIQ.Gen
VBA32Adware.MSIL.DomaIQ
MalwarebytesPUP.Optional.BundleInstaller.DDS
PandaPUP/MultiToolbar.A
RisingTrojan.Win32.Generic.180B5577 (C64:YzY0OotyGtmGtTDD)
YandexPUA.DomaIQ!yehgacw/Sn0
SentinelOneStatic AI – Suspicious PE
MaxSecurenot-a-virus:Trojan.DomaIQ
FortinetNSIS/Domaiq.BFA!tr
AVGWin32:DomaIQ-AJ [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove PUADlManager:Win32/DomaIQ?

PUADlManager:Win32/DomaIQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment