PUA

OfferB (PUA) removal guide

Malware Removal

The OfferB (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What OfferB (PUA) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
stat.offerbox.io
a.tomx.xyz

How to determine OfferB (PUA)?


File Info:

crc32: B74213D5
md5: ecceda526dddad833dd943465ea32d20
name: ____________.exe
sha1: 2e1ce77be8b349b86f08e168db056ae2cd00b26b
sha256: eb3e2d5f177f87c7b8321a481cb53f58f0482aaaa51dd1d48777b999bd0557b5
sha512: 2b414bdfc7a76e7398691ee8c1c2af57c32d0155c370ab8da205d0d4e98b5bdef5977d81074408c2740c994b4a0545e72f94b32e626d2b6ced286dec1be66c46
ssdeep: 24576:uBWRYKfF07Erfe31UhHoEX3pwHVa3zQUIx5Lf4ltCOqCMCdM9x7VNrxaDKUw9Yja:bn07Eze3C0mExxSvzMPjrwA/b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Offerbox
Comments: This installation was built with Inno Setup.
ProductName: x41fx435x43ax430x440x44c
ProductVersion: 0.0.0.1
FileDescription: x41fx435x43ax430x440x44c Setup
Translation: 0x0000 0x04b0

OfferB (PUA) also known as:

MicroWorld-eScanGen:Variant.Midie.68215
FireEyeGeneric.mg.ecceda526dddad83
Qihoo-360HEUR/QVM06.1.2539.Malware.Gen
McAfeeArtemis!ECCEDA526DDD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusAdware ( 0053dc471 )
BitDefenderGen:Variant.Midie.68215
K7GWAdware ( 0053dc471 )
Invinceaheuristic
APEXMalicious
AvastWin32:UnwantedSig [PUP]
GDataNSIS.Application.Offerbox.A
Kasperskynot-a-virus:HEUR:Downloader.Win32.OfferInstall.gen
NANO-AntivirusTrojan.Win32.Magala.flpthi
RisingAdware.AppsetOffer!1.B831 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftApplication.Agent (A)
ComodoApplication.Win32.Appster.CB@7yjsvh
F-SecureHeuristic.HEUR/AGEN.1031226
DrWebProgram.Appset.14
TrendMicroTROJ_GEN.R01FC0OB920
McAfee-GW-EditionArtemis!PUP
SophosOfferB (PUA)
CyrenW32/S-70232f14!Eldorado
WebrootW32.Adware.Gen
AviraHEUR/AGEN.1031226
MAXmalware (ai score=89)
Antiy-AVLGrayWare[AdWare]/Win32.Appster.a
ArcabitTrojan.Midie.D10A77
SUPERAntiSpywareAdware.AppsetOffer/Variant
ZoneAlarmnot-a-virus:HEUR:Downloader.Win32.OfferInstall.gen
MicrosoftPUA:Win32/Offerbox
AhnLab-V3PUP/Win32.OfferInstaller.R249693
MalwarebytesPUP.Optional.AppsetOffer
PandaPUP/Multitoolbar
ESET-NOD32a variant of Win32/Appster.D potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R01FC0OB920
FortinetRiskware/OfferInstall
AVGWin32:UnwantedSig [PUP]
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecurenot.a.virus.Downloader.OfferInstall.GEN

How to remove OfferB (PUA)?

OfferB (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment