Malware

Downloader.OfferInstall removal instruction

Malware Removal

The Downloader.OfferInstall is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.OfferInstall virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it

Related domains:

stat.offerbox.io

How to determine Downloader.OfferInstall?


File Info:

crc32: 8E3C74F8
md5: 03e0ed902f642c18a82386aa36f6f91a
name: igra_ostrov_chernoy_borody.exe
sha1: 22d256045e5654ed4ef4fb0f16fc71b691e8588b
sha256: e5a1497378edced0ded2926707dab55acfc99b3a587bcb70a1b79d8a4ea39122
sha512: 3ea1cab215b8975bc5b1072aa716c57b8f1dd4adc6332882699124a0aa79d51bf94490c209833a42e3964edb9708b63c218a3e4bfe7d7ef15d85616565f8cf94
ssdeep: 98304:8zv8nGLqqpMO+D5yU/zx0Wa0vZxPtkq9AauPUuc65zQKVjIW+KX2VSL4PwEk:c8nqLJ+h/FjBrtI+65RIWdmm4Y/
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Offerbox
Comments: This installation was built with Inno Setup.
ProductName: igra_ostrov_chernoy_borody
ProductVersion: 0.0.0.1
FileDescription: igra_ostrov_chernoy_borody Setup
Translation: 0x0000 0x04b0

Downloader.OfferInstall also known as:

DrWebProgram.Appset.14
Qihoo-360Win32/Virus.Downloader.b0e
McAfeeArtemis!03E0ED902F64
CylanceUnsafe
SangforMalware
K7AntiVirusAdware ( 0055782a1 )
K7GWAdware ( 0055782a1 )
TrendMicroTROJ_GEN.R015C0OAC20
CyrenW32/Trojan.GCOD-2430
SymantecSMG.Heur!gen
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Trojan.Agent.I1MU10
Kasperskynot-a-virus:HEUR:Downloader.Win32.OfferInstall.gen
ViRobotAdware.Offerinstall.4826015
ComodoApplication.Win32.Appster.CB@7yjsvh
F-SecureHeuristic.HEUR/AGEN.1031226
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.AdwareAdposhel.rc
EmsisoftApplication.AdOffer (A)
IkarusAdWare.InnoBundle
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1031226
Antiy-AVLGrayWare[AdWare]/Win32.Appster.a
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.OfferInstall.gen
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3PUP/Win32.OfferInstaller.R249693
Acronissuspicious
VBA32Downloader.OfferInstall
MalwarebytesPUP.Optional.BundleInstaller
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Appster.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R015C0OAC20
YandexPUA.Downloader!
FortinetRiskware/OfferInstall
AVGWin32:Malware-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.73928840.susgen

How to remove Downloader.OfferInstall?

Downloader.OfferInstall removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment