Malware

Downloader.Win32.InnoBundle.apfp removal instruction

Malware Removal

The Downloader.Win32.InnoBundle.apfp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.InnoBundle.apfp virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Deletes executed files from disk
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Downloader.Win32.InnoBundle.apfp?


File Info:

name: BE84E62C5B84470FA5C4.mlw
path: /opt/CAPEv2/storage/binaries/4f2bbc87450ff7b3e9a2697ef9f6de3934dd4726e819c71bac2bec2462c9a9bf
crc32: 75B76BFE
md5: be84e62c5b84470fa5c4dea9e20b9216
sha1: 3d8b8904e79f98b138c0c9f157296da228c91356
sha256: 4f2bbc87450ff7b3e9a2697ef9f6de3934dd4726e819c71bac2bec2462c9a9bf
sha512: 0518c97b670e3c96e707fe0134671f7cb4987bf80f0cb14edafb367b03fb26b6e9fee670c8d9994a9c9671f8fe0757fa7f64e87413f3566cb0e7a51c5bce7376
ssdeep: 196608:UUNyKvSBNTBPlv0skiSYglmG9C5z9bpFzqUVgyZuZXdKZa4wt9xT0CvGFKzVMFyP:rLwDNcskflmWC5dZetbTqFGZqA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18ED63326B7828178F0418ABD887194046D29BD8E79F210207FB0D91DC4FAADB9D7E75F
sha3_384: 19d3d3bf8549298c80876140158993a6dca9b519fb5f7226d28458d4d3c63398f86ce4ca78ddc3d70f03949ece96d8f1
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2018-06-14 13:27:46

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: WinRAR Setup (r2401180500)
FileVersion:
LegalCopyright:
ProductName: WinRAR
ProductVersion:
Translation: 0x0000 0x04b0

Downloader.Win32.InnoBundle.apfp also known as:

BkavW32.Common.4693DABE
DrWebAdware.Downware.20475
CAT-QuickHealTrojan.Riskware
SkyhighArtemis!PUP
McAfeeArtemis!BE84E62C5B84
Cylanceunsafe
CrowdStrikewin/grayware_confidence_60% (W)
AlibabaDownloader:Win32/InnoBundle.fe7e410a
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecPUA.Gen.2
Elasticmalicious (high confidence)
Kasperskynot-a-virus:Downloader.Win32.InnoBundle.apfp
NANO-AntivirusTrojan.Win32.InnoBundle.khpqim
AvastWin32:Malware-gen
SophosGeneric Reputation PUA (PUA)
VaristW32/ABRisk.LQOM-1107
ZoneAlarmnot-a-virus:Downloader.Win32.InnoBundle.apfp
GoogleDetected
MalwarebytesGeneric.Malware/Suspicious
MaxSecureTrojan.Malware.226587122.susgen
FortinetRiskware/Application
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Downloader.Win32.InnoBundle.apfp?

Downloader.Win32.InnoBundle.apfp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment