PUA

Should I remove “PUADlManager:Win32/Somoto”?

Malware Removal

The PUADlManager:Win32/Somoto is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PUADlManager:Win32/Somoto virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine PUADlManager:Win32/Somoto?


File Info:

name: 1032A62D8DFE7DA87068.mlw
path: /opt/CAPEv2/storage/binaries/464edf3627014a99f0dd2d0606b720e855fb028c428568cfe78b43307a7679fc
crc32: 05DB9235
md5: 1032a62d8dfe7da87068aebb4f30e2c6
sha1: d2519de9352aa37352670a2de11a3bfbba09af00
sha256: 464edf3627014a99f0dd2d0606b720e855fb028c428568cfe78b43307a7679fc
sha512: ef1734cf0616482ff8fb387f065d0d1ad73c10c20ba82b787565882b0b7400ee206cda74955582c34c98495a239e2c9c3739eccc972fe8cc11c21c736db96fe7
ssdeep: 12288:d4yOFgR8msvyA36z4I/xguB+Ltz2MQnejJNpg2lEDapvRr7twgn2dTh9vSse:dDO1mQyAqksgXt2BejJ8SEDOlp2H9vO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1901501493BB677E3CE908A337D1662B617756DF82905D24B3662F72D3873235CC4AA20
sha3_384: a3b1446f4fca35fedd2585b0584d541dd27536e35c119d8cb962dad4c2017a5f5cf8ad1f4a50b982c083a57eff7c572f
ep_bytes: 81ec8401000053555633db57895c2418
timestamp: 2014-05-11 20:03:36

Version Info:

0: [No Data]

PUADlManager:Win32/Somoto also known as:

LionicTrojan.Win32.Generic.4!c
CylanceUnsafe
SangforPUP.Win32.SkinPack.Gen
K7AntiVirusTrojan ( 0049b0c21 )
AlibabaAdWare:Win32/Somoto.c92b3c2a
K7GWTrojan ( 0049b0c21 )
Cybereasonmalicious.9352aa
ESET-NOD32Win32/Somoto.U potentially unwanted
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:AdWare.Win32.Downware.sc
NANO-AntivirusTrojan.Win32.PUA.euwkyt
SUPERAntiSpywareAdware.PastaLeads/Variant
AvastWin32:Malware-gen
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PUP.dc
WebrootPua.Downloadmanager
AviraPUA/SkinPack.Gen
Antiy-AVLTrojan/Generic.ASMalwNS.A0
MicrosoftPUADlManager:Win32/Somoto
CynetMalicious (score: 99)
McAfeeArtemis!1032A62D8DFE
VBA32Trojan.Wacatac
AVGWin32:Malware-gen
PandaTrj/CI.A

How to remove PUADlManager:Win32/Somoto?

PUADlManager:Win32/Somoto removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment