Malware

SoftwareBundler:Win32/SBInstaller removal guide

Malware Removal

The SoftwareBundler:Win32/SBInstaller is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What SoftwareBundler:Win32/SBInstaller virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (7 unique times)
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Network anomalies occured during the analysis.
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Attempts to modify Internet Explorer’s start page
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Collects information about installed applications
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Uses suspicious command line tools or Windows utilities

Related domains:

d1cfk8e4o0c4u2.cloudfront.net
d1vw44q53d84jx.cloudfront.net
d11sfnc01fj8ag.cloudfront.net
s.symcd.com
ocsp.digicert.com
dyd9qf154h76q.cloudfront.net
d1y2jryd6u59ns.cloudfront.net
www-searching.com

How to determine SoftwareBundler:Win32/SBInstaller?


File Info:

crc32: AB7E2419
md5: 9f4bee88a88b7604a112a7364f0c9f5e
name: imytd.exe
sha1: eb7cacfa3321559afed81b1b87192d240a445738
sha256: 6647ebcef93251330c94bd7affbbe4c3ec3331706ab593d665cff60c81c0aeb6
sha512: c36b5c71003809648d983f94000878e8155b87a6d10d94ee1750489ddd7fb66ecc020d56c8f471f078407bfcb6c2827b1a13438a9b8a2821aad847d0b20f4519
ssdeep: 24576:Rb/nMCNj7J77nQDTlJq40/kXPd1bDezo+WMvjTtLXlvGMkbioq:BNj7J77nQDpt0/C1uU+JvPtLXNGMkbi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014
FileVersion: 2.13.0.999
ProductVersion: 2.13.0.999
Translation: 0x0009 0x04b0

SoftwareBundler:Win32/SBInstaller also known as:

MicroWorld-eScanTrojan.GenericKD.40831159
FireEyeGeneric.mg.9f4bee88a88b7604
CAT-QuickHealTrojan.Sbinstaller
McAfeeGenericRXGA-HV!9F4BEE88A88B
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.40831159
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.8a88b7
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Adware-gen [Adw]
GDataTrojan.GenericKD.40831159
KasperskyTrojan-Dropper.Win32.Agent.bjpybi
NANO-AntivirusRiskware.Win32.Adw.dyziyx
Endgamemalicious (high confidence)
SophosGeneric PUA OL (PUA)
F-SecureAdware.ADWARE/CrossRider.Gen
DrWebWin32.HLLW.Unjap.952
ZillyaTrojan.GenericKD.Win32.142229
Invinceaheuristic
McAfee-GW-EditionGenericRXGA-HV!9F4BEE88A88B
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.40831159 (B)
IkarusPUA.Wajam
JiangminVariant.Zusy.it
MaxSecureTrojan.Malware.73692564.susgen
AviraADWARE/CrossRider.Gen
WebrootPua.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Generic.D26F08B7
SUPERAntiSpywarePUP.Goobzo/Variant
ZoneAlarmTrojan-Dropper.Win32.Agent.bjpybi
MicrosoftSoftwareBundler:Win32/SBInstaller
AhnLab-V3Malware/Gen.Generic.C1252052
VBA32TrojanDropper.Agent
ALYacTrojan.GenericKD.40831159
Ad-AwareTrojan.GenericKD.40831159
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/SpeedBit.T potentially unwanted
RisingTrojan.Generic!8.C3 (CLOUD)
YandexPUA.Downware!
eGambitGeneric.Malware
FortinetW32/Agent.BJPYBI!tr
BitDefenderThetaGen:NN.ZexaF.34106.@u0@a0bw3meO
AVGWin32:Adware-gen [Adw]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Dropper.26b

How to remove SoftwareBundler:Win32/SBInstaller?

SoftwareBundler:Win32/SBInstaller removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment