Malware

Downloader.Win32.OfferInstall.ddi removal

Malware Removal

The Downloader.Win32.OfferInstall.ddi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Downloader.Win32.OfferInstall.ddi virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
stat.offerbox.io
redirector.gvt1.com
r4—sn-4g5ednss.gvt1.com

How to determine Downloader.Win32.OfferInstall.ddi?


File Info:

crc32: D0C4E0EC
md5: 7f04d610ec1abb3a6fb2feac0017b707
name: igra_koleso_fortuny.exe
sha1: 034d0d6dae9cabb0ba9eba56b96dc289f6b7143c
sha256: b467edd10f05c3bf4e2f9b2bc488d5d6939d82d40e9fcefb549d0e7465764fa7
sha512: 530ac06e352d3ce76ae41e432d9cb5c8cdf05516d1c8c9b51780eb2953b457afdc4e30b89ca8fe50b684400c3e329f58f1b92b29e5fab20df65643adf4ca3072
ssdeep: 24576:1BWRYsfFZAL5ydvm7QWIQpyWtYHCLJKOSQUIxzX7Lf4ltCOqCMCdM9x7VNrxaDKn:+5ZX9m7FIQHYHCLnSExzvSvzMPjrwA/d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Offerbox
Comments: This installation was built with Inno Setup.
ProductName: igra_koleso_fortuny
ProductVersion: 0.0.0.1
FileDescription: igra_koleso_fortuny Setup
Translation: 0x0000 0x04b0

Downloader.Win32.OfferInstall.ddi also known as:

DrWebProgram.Appset.14
FireEyeGeneric.mg.7f04d610ec1abb3a
MalwarebytesPUP.Optional.AppsetOffer
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 0053dc471 )
K7GWAdware ( 0053dc471 )
Invinceaheuristic
CyrenW32/S-70232f14!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:UnwantedSig [PUP]
Kasperskynot-a-virus:Downloader.Win32.OfferInstall.ddi
AlibabaDownloader:Win32/OfferInstall.28a28108
NANO-AntivirusTrojan.Win32.Magala.flpthi
RisingAdware.AppsetOffer!1.B831 (CLASSIC)
SophosOfferB (PUA)
ComodoApplication.Win32.Appster.CB@7yjsvh
F-SecureHeuristic.HEUR/AGEN.1109570
TrendMicroTROJ_GEN.R002C0OGJ20
EmsisoftApplication.Agent (A)
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1109570
FortinetRiskware/OfferInstall
Antiy-AVLGrayWare[AdWare]/Win32.Appster.a
Endgamemalicious (high confidence)
SUPERAntiSpywareAdware.AppsetOffer/Variant
ZoneAlarmnot-a-virus:Downloader.Win32.OfferInstall.ddi
MicrosoftPUA:Win32/Offerbox
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.OfferInstaller.R249693
McAfeeArtemis!7F04D610EC1A
VBA32Downloader.OfferInstall
CylanceUnsafe
PandaPUP/Multitoolbar
ESET-NOD32a variant of Win32/Appster.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0OGJ20
GDataNSIS.Application.Offerbox.A
AVGWin32:UnwantedSig [PUP]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.1ea

How to remove Downloader.Win32.OfferInstall.ddi?

Downloader.Win32.OfferInstall.ddi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment