PUA

PUADlManager:Win32/OfferCore removal tips

Malware Removal

The PUADlManager:Win32/OfferCore is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/OfferCore virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk

How to determine PUADlManager:Win32/OfferCore?


File Info:

name: DE54AA12119682DE4FF6.mlw
path: /opt/CAPEv2/storage/binaries/30d9fbfb0eb4b7f51e8330f7bf032e55ca52236278781738fe2967bc50971e0a
crc32: DB0C92DC
md5: de54aa12119682de4ff649b9e9e2e723
sha1: b35246680157f7076b95921ff2fe8f59f9612518
sha256: 30d9fbfb0eb4b7f51e8330f7bf032e55ca52236278781738fe2967bc50971e0a
sha512: 95643d94324bb82e7a065904da2ef87aacaa29c4db5c55f5ef444b7c1e59123edb94444e6eaa4ddd01e2b1a4f3ed4b889a83644616b0ca08d8cee94bffba4f0e
ssdeep: 196608:jDXxuqr0huyO2KywxpKJCz2tLJu+2TDFcTu:jDE1+yOKJCzmmleu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E476335A36702433C73EFA704FA527F1FA9EF3A045D57F1A1E6DAAE214160985C213B8
sha3_384: 1be160cb8b83299bb22fac1de718aae2fab8fb6901644e692159e2676433aac91540bbe7c7c69d6aeec497468328b434
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:52

Version Info:

0: [No Data]

PUADlManager:Win32/OfferCore also known as:

BkavW32.AIDetectMalware
AVGNSIS:AdwareX-gen [Adw]
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Nemesis.31305
FireEyeGen:Variant.Nemesis.31305
SkyhighBehavesLike.Win32.Suspicious.wc
MalwarebytesMalware.AI.1973343411
K7AntiVirusRiskware ( 005add141 )
K7GWRiskware ( 005add141 )
CrowdStrikewin/grayware_confidence_70% (D)
VirITDeceptor.FileHippoDM.DWH
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/OfferCore.E potentially unwanted
CynetMalicious (score: 100)
Kasperskynot-a-virus:UDS:AdWare.Win32.Convagent.gen
BitDefenderGen:Variant.Nemesis.31305
NANO-AntivirusRiskware.Win32.Convagent.kjlbzz
AvastNSIS:AdwareX-gen [Adw]
EmsisoftGen:Variant.Nemesis.31305 (B)
DrWebAdware.Downware.20416
VIPREGen:Variant.Nemesis.31305
Trapminemalicious.moderate.ml.score
IkarusTrojan-Downloader.NSIS.Adload
GDataGen:Variant.Nemesis.31305
VaristW32/OfferCore.Q.gen!Eldorado
Antiy-AVLGrayWare/Win32.Wacapew
XcitiumApplicUnwnt@#13l86jehq5a2j
ArcabitTrojan.Nemesis.D7A49
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Convagent.gen
MicrosoftPUADlManager:Win32/OfferCore
GoogleDetected
AhnLab-V3PUP/Win.Softonic.C5570269
VBA32Adware.Convagent
ALYacGen:Variant.Nemesis.31305
MAXmalware (ai score=89)
Cylanceunsafe
MaxSecureTrojan.Malware.121218.susgen
FortinetNSIS/Adload.DS!tr
Cybereasonmalicious.211968

How to remove PUADlManager:Win32/OfferCore?

PUADlManager:Win32/OfferCore removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment