PUA

PUADlManager:Win32/OfferCore malicious file

Malware Removal

The PUADlManager:Win32/OfferCore is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/OfferCore virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Deletes executed files from disk
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine PUADlManager:Win32/OfferCore?


File Info:

name: 07AB173DADA33EF6E1D7.mlw
path: /opt/CAPEv2/storage/binaries/f3428c86014dd8b20b161cdb3ae912d8e7f253380cdfcbcc52365ee234b8b46a
crc32: D6615B8C
md5: 07ab173dada33ef6e1d7a701f5a74a6e
sha1: 7ab357d767b2abc7a0cdc54c8b3ff08003e87e3e
sha256: f3428c86014dd8b20b161cdb3ae912d8e7f253380cdfcbcc52365ee234b8b46a
sha512: 85d5fcf339df152a77861881859801946f5e6e6465f7012c76dc4e4d1d17452e22e04d7b0ec2d492343abeb1918f85346ead264c6272b608706578bfddaef770
ssdeep: 49152:nqe3f6hSi/P6QkO6U6HP6Rbtpv/UEvsL/BTp8:qSihSi/P6Qk/U6iRbtpvs7TS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12BC5E13FB268A13ED46A0B324573D250597B7E25A91A8C2F1BF0790CCF765601E3FA16
sha3_384: 419468bb3ae52ab192d0040feb193f6b7944d49fdc144310de221b1614fb06131385c49cb0acb201ff3c553824f63dd4
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-11-15 09:48:30

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Frostwire Installer
FileVersion: 6.9.2
LegalCopyright:
OriginalFileName:
ProductName: Frostwire
ProductVersion: 6.9.2
Translation: 0x0000 0x04b0

PUADlManager:Win32/OfferCore also known as:

Elasticmalicious (high confidence)
SkyhighArtemis!PUP
McAfeeArtemis!07AB173DADA3
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/grayware_confidence_100% (W)
ESET-NOD32Win32/OfferCore.C potentially unwanted
Kasperskynot-a-virus:HEUR:Downloader.Win32.Bundler.gen
NANO-AntivirusTrojan.Win32.Bundler.jrgwwd
AvastFileRepMalware [Trj]
SophosGeneric Reputation PUA (PUA)
DrWebAdware.Downware.19949
WebrootW32.Adware.Gen
GoogleDetected
MicrosoftPUADlManager:Win32/OfferCore
ViRobotAdware.Offercore.2682528.A
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.Bundler.gen
VaristW32/ABRisk.DNUM-2375
VBA32Adware.Downware
MalwarebytesPUP.Optional.OfferCore.DDS
RisingAdware.OfferCore!1.DF2E (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.119177799.susgen
FortinetAdware/OfferCore
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS

How to remove PUADlManager:Win32/OfferCore?

PUADlManager:Win32/OfferCore removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment