PUA

PUADlManager:Win32/SoftPuls removal guide

Malware Removal

The PUADlManager:Win32/SoftPuls is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/SoftPuls virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine PUADlManager:Win32/SoftPuls?


File Info:

name: 0019FDB6733B50226C56.mlw
path: /opt/CAPEv2/storage/binaries/eac43d4d682aa7c6f0300c3b0fc0c42d22cb1f2bb72b0d8c3a24f48c4c8e197c
crc32: 8819908F
md5: 0019fdb6733b50226c569c7acab2e1d5
sha1: 15d9c82a61c74edd0810fc233982d22f87eb4c4c
sha256: eac43d4d682aa7c6f0300c3b0fc0c42d22cb1f2bb72b0d8c3a24f48c4c8e197c
sha512: 7a322555205b84a36d11275fe78f0e09b71d71d1f4b8667647cea5df4166a13322cd8a17a44b22fb4f2a3ad05791c88aaee013c5ab217d8159c65da7e9ecd798
ssdeep: 12288:BW1xsqFZeJeJeJeJeJeJdgs4BxjkN2ieWfYgKZ3F8FDZaxSCWKarX73HY04Rzbr:ixpZIB+JSZ3FuZMGrU0IzX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B05F101B885C4F2F877827640E6562294BDFA2647E17BCB57E81FDCBB385C24538BA1
sha3_384: bbe3975842ea675eb79ae78b3146d1975b3609fd3dbe1b012c5c41faf7b0c73f0baefcd7bfbb70fa753ce9390d7cc8e6
ep_bytes: e8d43b0000e939feffffcccccccccccc
timestamp: 2014-07-15 10:40:27

Version Info:

0: [No Data]

PUADlManager:Win32/SoftPuls also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Packed.28257
MicroWorld-eScanApplication.Bundler.SoftPulse.A
ClamAVWin.Trojan.JavaInstaller-1
FireEyeGeneric.mg.0019fdb6733b5022
McAfeeSoftPulse
MalwarebytesMalware.AI.3003441628
ZillyaTool.Bundler.Win32.4005
SangforTrojan.Win32.Save.a
AlibabaMalware:Win32/km_24a83.None
Cybereasonmalicious.6733b5
VirITTrojan.Win32.Packed.BPUV
CyrenW32/S-0ba0feb0!Eldorado
SymantecTrojan.Gen.2
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/SoftPulse.D potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Inject.uosq
BitDefenderApplication.Bundler.SoftPulse.A
NANO-AntivirusTrojan.Win32.Inject.dcnwxu
TencentMalware.Win32.Gencirc.114c164b
EmsisoftApplication.Bundler.SoftPulse.A (B)
VIPREApplication.Bundler.SoftPulse.A
TrendMicroTROJ_GEN.R002C0ODM23
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataApplication.Bundler.SoftPulse.A
JiangminTrojan/Inject.assy
Antiy-AVLTrojan/Win32.AGeneric
XcitiumTrojWare.Win32.Rogue.DCN@5e7dg9
ArcabitApplication.Bundler.SoftPulse.A
ViRobotAdware.Softpulse.811661
ZoneAlarmTrojan.Win32.Inject.uosq
MicrosoftPUADlManager:Win32/SoftPuls
GoogleDetected
AhnLab-V3PUP/Win32.SoftPulse.R121551
ALYacApplication.Bundler.SoftPulse.A
MAXmalware (ai score=71)
VBA32BScope.Adware.SoftPulse
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0ODM23
RisingTrojan.Injector!1.B5EA (CLASSIC)
YandexTrojan.GenAsa!K7I0fPWw5go
IkarusPUA.SoftPulse
FortinetW32/Generic.AC.FA6!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (D)

How to remove PUADlManager:Win32/SoftPuls?

PUADlManager:Win32/SoftPuls removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment