PUA

PUADlManager:Win32/InstallMate malicious file

Malware Removal

The PUADlManager:Win32/InstallMate is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/InstallMate virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.bbc.com
techine.info

How to determine PUADlManager:Win32/InstallMate?


File Info:

crc32: EFBE4A20
md5: 2667e5c4ce3cb21d22f53660ae2e11a7
name: 2667E5C4CE3CB21D22F53660AE2E11A7.mlw
sha1: 15db2f20083c413ffc00da080af2c67ebf1eebc3
sha256: ac106c6ff60be5370455e9ecfc64df68ebba89e751b7e8eb527877cb07b7e14d
sha512: d2332b4b55199982c23f4cfa60f61c2995ba87d2b89b1524b5323beaf46698a47b601b77db677cab7760f4512a38b731e4e5579a1390b03e5003391d0ff816d9
ssdeep: 49152:Q9GEJP8HZ8PGnPt/NCgafePD1VsGejLYg9rJXTpn44PACifIcYEQEK:4GEJEyQPt/4mLEsg9rHn2V
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PUADlManager:Win32/InstallMate also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Trojan.Crypt.63
CylanceUnsafe
ZillyaAdware.MultiPlug.Win32.317748
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWHacktool ( 700007861 )
Cybereasonmalicious.4ce3cb
BaiduWin32.Adware.Generic.bo
CyrenW32/S-3951c29e!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Adware.MultiPlug.IX
APEXMalicious
AvastFileRepMalware
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Trojan.Crypt.63
NANO-AntivirusRiskware.Win32.MultiPlug.drtjms
ViRobotAdware.Agent.2756096
MicroWorld-eScanGen:Variant.Trojan.Crypt.63
TencentWin32.Adware.Generic.Hqlr
Ad-AwareGen:Variant.Trojan.Crypt.63
SophosGeneric PUA BF (PUA)
ComodoApplicUnwnt@#2ftz9klvgxwqe
BitDefenderThetaGen:NN.ZexaF.34294.OwW@aGvEcCki
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.vc
FireEyeGeneric.mg.2667e5c4ce3cb21d
EmsisoftGen:Variant.Trojan.Crypt.63 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.Generic.mvmc
WebrootPua.Gen
AviraADWARE/MultiPlug.Gen7
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftPUADlManager:Win32/InstallMate
ArcabitTrojan.Trojan.Crypt.63
GDataGen:Variant.Trojan.Crypt.63
AhnLab-V3PUP/Win32.MultiPlug.R148636
Acronissuspicious
McAfeeMultiplug-FXV
MAXmalware (ai score=85)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesPUP.Optional.MultiPlug
PandaTrj/Genetic.gen
YandexPUA.MultiPlug!8/VdfeZxN04
IkarusPUA.Multiplug
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/MultiPlug
AVGFileRepMalware
Paloaltogeneric.ml

How to remove PUADlManager:Win32/InstallMate?

PUADlManager:Win32/InstallMate removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment