Concrete signature match: PUADlManager for 32-bit Windows platform, family OfferCore
PUADlManager:Win32/OfferCore is a Potentially Unwanted Application (PUA), commonly known as adware or bundleware. This program is typically an installer that uses various system utilities and persistence methods, like scheduled tasks, to download and install additional, unwanted software onto the system without clear user consent.
Relevant strings associated with this threat: - m%1q/ (SNID) Relevant strings associated with this threat: - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT) - rundll32 (PEHSTR_EXT) - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT) - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT) - !#HSTR:ExecutionGuardrails (PEHSTR_EXT) - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT) - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT) - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
dec7a31e7a02838b2097770419336f659334851822d8c369f9e917f8727f0e1999d5190f475f003698b8e5e9f22f6e2479aa400e98bb9ed9fde45faac35b1b3ed8389233fac178c9a539cc3229652c7877570a32e608327e1ccbf4c7664ed8ee888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc17d9094e06d2edcaeb07b72263ee2f12009f98e079daf3e3ca48df5fc5b04586Use Windows Defender to remove the detected threat. Run a full system scan to find any related components it may have installed. Review 'Apps & features' to uninstall any recently added, unrecognized applications. Check browser extensions and system startup items for suspicious entries.