PUA

PUADlManager:Win32/Niguide removal tips

Malware Removal

The PUADlManager:Win32/Niguide is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/Niguide virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUADlManager:Win32/Niguide?


File Info:

name: 48CB38013BBE41E33D5B.mlw
path: /opt/CAPEv2/storage/binaries/c97be242733277fb1ce9ed0c68f5c0efc0f1e1b8400559b083978295be7d3745
crc32: 69649633
md5: 48cb38013bbe41e33d5b6ef13b027205
sha1: 554ba30ee5c12a6c31dacd113006d6045bc5efec
sha256: c97be242733277fb1ce9ed0c68f5c0efc0f1e1b8400559b083978295be7d3745
sha512: fdec21c696c77bdf08a63b25900634cd1d1dbabda17733905ee0742b8a04bcb8c52cd98f769770d143a20d30112ca55d45aa0fe8084f1230e7c5872ba63036ac
ssdeep: 196608:MAA/TBVa9cYZM3VjSv7KJe+I1zKXIEuMwFTe33UW+8VZ/z:2jFoM3VjSTA2KYNFC3n+8V9z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1358633017A54A96FE0038DB2D27304A3FAB86DEA823BCDF1BC4D7C5774D47D05A68A49
sha3_384: 10c3e0f975cd3614564cb5caf2a49958ddf2cc9ab560657cb69fad81bcddd084c65b476e9090be1f29f8f1d2c01d99e7
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

PUADlManager:Win32/Niguide also known as:

LionicRiskware.Win32.Agent.1!c
DrWebTrojan.Adkor.290
MicroWorld-eScanTrojan.Generic.31124286
FireEyeTrojan.Generic.31124286
McAfeeArtemis!48CB38013BBE
CylanceUnsafe
K7AntiVirusAdware ( 004d93a31 )
K7GWAdware ( 004d93a31 )
Cybereasonmalicious.13bbe4
ESET-NOD32multiple detections
Kasperskynot-a-virus:HEUR:Downloader.Win32.Agent.gen
BitDefenderTrojan.Generic.31124286
NANO-AntivirusTrojan.Win32.Adkor.efyazm
AvastWin32:PUP-gen [PUP]
RisingTrojan.Generic@ML.88 (RDML:P9qzHDH66ga8UhGP0GshIw)
Ad-AwareTrojan.Generic.31124286
EmsisoftTrojan.Generic.31124286 (B)
TrendMicroTROJ_GEN.R002C0PL421
McAfee-GW-EditionNSIS/Nieguide.a
SophosMal/Generic-S
GDataTrojan.Generic.31124286
Antiy-AVLTrojan/Generic.ASMalwNS.229
ArcabitTrojan.Generic.D1DAEB3E
MicrosoftPUADlManager:Win32/Niguide
ALYacTrojan.Generic.31124286
MAXmalware (ai score=84)
VBA32BScope.Adware.NSIS.Agent
TrendMicro-HouseCallTROJ_GEN.R002C0PL421
TencentWin32.Trojan.Multiple.Pfjv
YandexTrojan.GenAsa!FDXsMu50vuU
FortinetW32/Generic_PUA_KC.AF
AVGWin32:PUP-gen [PUP]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_60% (D)

How to remove PUADlManager:Win32/Niguide?

PUADlManager:Win32/Niguide removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment