Malware

Downloader.Win32.OfferInstall.caa information

Malware Removal

The Downloader.Win32.OfferInstall.caa is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.OfferInstall.caa virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

stat.offerbox.io

How to determine Downloader.Win32.OfferInstall.caa?


File Info:

crc32: 7F8C7193
md5: 36ceb8543c8cfe3f28be3671503a285b
name: igra_troyki_i_pyaterki_domino_solo.exe
sha1: 50c03f992f9561847390e90ce76e07ecc71cc7fc
sha256: 66b824995e7f626637be44e3917cca796d72c30957dfb100a9948ca57d2eccb6
sha512: 51804150adc3123666d7452bf5c79b878d8ad6b02978c65ab89e94fdbbba8ec14569776942552555f9424a0b04f5149f4b21dd0395f88f369b5739dbd02859ad
ssdeep: 24576:MBWRYqfFXBUuXsQH/0tMwE5RujJaJg0TIq9HNQUIx1ZLf4ltCOqCMCdM9x7VNrxW:pPXBUu8QmMj8jJATvtExvSvzMPjrwA/o
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Offerbox
Comments: This installation was built with Inno Setup.
ProductName: igra_troyki_i_pyaterki_domino_solo
ProductVersion: 0.0.0.1
FileDescription: igra_troyki_i_pyaterki_domino_solo Setup
Translation: 0x0000 0x04b0

Downloader.Win32.OfferInstall.caa also known as:

FireEyeGeneric.mg.36ceb8543c8cfe3f
McAfeeArtemis!36CEB8543C8C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 0053dc471 )
K7GWAdware ( 0053dc471 )
TrendMicroTROJ_GEN.R002C0OGJ20
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Appster.D potentially unwanted
APEXMalicious
AvastWin32:UnwantedSig [PUP]
GDataNSIS.Application.Offerbox.A
Kasperskynot-a-virus:Downloader.Win32.OfferInstall.caa
AlibabaDownloader:Win32/OfferInstall.579e621c
NANO-AntivirusTrojan.Win32.Magala.flpthi
Endgamemalicious (high confidence)
SophosOfferB (PUA)
ComodoApplicUnwnt@#1m9qa018j9v4a
F-SecureHeuristic.HEUR/AGEN.1109570
DrWebProgram.Appset.14
Invinceaheuristic
EmsisoftApplication.Agent (A)
CyrenW32/S-70232f14!Eldorado
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1109570
Antiy-AVLGrayWare[AdWare]/Win32.Appster.a
MicrosoftPUA:Win32/Offerbox
SUPERAntiSpywareAdware.AppsetOffer/Variant
AhnLab-V3PUP/Win32.OfferInstaller.R249693
ZoneAlarmnot-a-virus:Downloader.Win32.OfferInstall.caa
CynetMalicious (score: 85)
VBA32Adware.Downware
MalwarebytesPUP.Optional.AppsetOffer
PandaPUP/Multitoolbar
TrendMicro-HouseCallTROJ_GEN.R002C0OGJ20
RisingAdware.AppsetOffer!1.B831 (CLASSIC)
FortinetRiskware/OfferInstall
AVGWin32:UnwantedSig [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM42.2.4655.Malware.Gen

How to remove Downloader.Win32.OfferInstall.caa?

Downloader.Win32.OfferInstall.caa removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment