Home Malware Programs Adware Adware.OfferBox

Adware.OfferBox

Posted: May 10, 2011

Threat Metric

Ranking: 4,304
Threat Level: 2/10
Infected PCs: 292,177
First Seen: May 10, 2011
Last Seen: March 10, 2025
OS(es) Affected: Windows


Adware.OfferBox Screenshot 1OfferBox, or OfferBox.com, is an online shopping assistant website and application that offers coupons for online shopping. OfferBox is used as delivery system which tracks Internet user's surfing habits and sends this data to a third party for analysis and marketing purposes. OfferBox primarly uses the collected data to display relevant advertisements to Internet users based on their Web-browsing interests. If you're not comfortable with Offerbox on you PC and wish to uninstall OfferBox, go to your Add/Remove Programs tool, search for OfferBox, and click OfferBox to remove it from the list.

Aliases

Adware:Win32/OfferBoxBrowser [Microsoft]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Qoobox\Quarantine\C\Program Files (x86)\OfferBox\OfferBoxUpdateService.exe.vir File name: OfferBoxUpdateService.exe.vir
Size: 336.7 KB (336704 bytes)
MD5: aa6143151975ddcd59e5097ec95fa084
Detection count: 17,711
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\Qoobox\Quarantine\C\Program Files (x86)\OfferBox\OfferBoxUpdateService.exe.vir
Group: Malware file
Last Updated: October 5, 2024
C:\System Volume Information\_restore{5E4640FE-E1D1-471B-9517-C56274E98931}\RP171\A0047434.exe File name: A0047434.exe
Size: 4.88 MB (4880232 bytes)
MD5: 8ac88dcac5fe730b128beab8d6873a8f
Detection count: 1,827
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{5E4640FE-E1D1-471B-9517-C56274E98931}\RP171\A0047434.exe
Group: Malware file
Last Updated: May 26, 2023
C:\System Volume Information\_restore{5E4640FE-E1D1-471B-9517-C56274E98931}\RP171\A0047435.exe File name: A0047435.exe
Size: 177.51 KB (177512 bytes)
MD5: 7dc9799b627ad83caf81732d5d7e7c76
Detection count: 1,529
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\_restore{5E4640FE-E1D1-471B-9517-C56274E98931}\RP171\A0047435.exe
Group: Malware file
Last Updated: May 26, 2023
C:\Qoobox\Quarantine\C\Program Files (x86)\OfferBox\OfferBoxBHO.dll.vir File name: OfferBoxBHO.dll.vir
Size: 135 KB (135000 bytes)
MD5: 17731c1a77174801b5bce82109658b51
Detection count: 560
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\Program Files (x86)\OfferBox\OfferBoxBHO.dll.vir
Group: Malware file
Last Updated: March 25, 2022
C:\Program Files (x86)\OfferBox\OfferBoxBHO.dll File name: OfferBoxBHO.dll
Size: 135 KB (135000 bytes)
MD5: 2a512fd5e465b4fe04d15899d7d23949
Detection count: 499
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\OfferBox\OfferBoxBHO.dll
Group: Malware file
Last Updated: February 26, 2024
%PROGRAMFILES%\OfferBox\OfferBoxUpdateService.exe File name: OfferBoxUpdateService.exe
Size: 334.18 KB (334184 bytes)
MD5: 0270e88fa89a49190198a062a99b5b3d
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\OfferBox
Group: Malware file
Last Updated: February 25, 2014
F:\COPIAS\BACKUP RAFA\System Volume Information\_restore{DA9293F7-8C3E-43F6-B8EC-901639D66148}\RP1627\A0191597.exe File name: A0191597.exe
Size: 175.97 KB (175976 bytes)
MD5: 6041c582215df89c10b61810535db733
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: F:\COPIAS\BACKUP RAFA\System Volume Information\_restore{DA9293F7-8C3E-43F6-B8EC-901639D66148}\RP1627\A0191597.exe
Group: Malware file
Last Updated: March 15, 2023
%PROGRAMFILES(x86)%\OfferBox\OfferBoxHTTPProxy.exe File name: OfferBoxHTTPProxy.exe
Size: 177.51 KB (177512 bytes)
MD5: 19e3f9fd4ea2a617cf3aaeca627f47ec
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\OfferBox
Group: Malware file
Last Updated: February 25, 2014
%AppData%\OfferBox File name: %AppData%\OfferBox
Group: Malware file
%AppData%\OfferBox\config.dat File name: %AppData%\OfferBox\config.dat
File type: Data file
Mime Type: unknown/dat
Group: Malware file
%AppData%\OfferBox\config.xml File name: %AppData%\OfferBox\config.xml
Mime Type: unknown/xml
Group: Malware file
%CommonPrograms%\OfferBox Browser.lnk File name: %CommonPrograms%\OfferBox Browser.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%ProgramFiles%\OfferBox\OfferBoxChromeExtension.crx File name: %ProgramFiles%\OfferBox\OfferBoxChromeExtension.crx
Mime Type: unknown/crx
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com
File type: Command, executable file
Mime Type: unknown/com
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome
Mime Type: unknown/com\chrome
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome.manifest File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome.manifest
Mime Type: unknown/manifest
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome\content File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome\content
Mime Type: unknown/com\chrome\content
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome\content\events.js File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome\content\events.js
File type: JavaScript file
Mime Type: unknown/js
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome\content\overlay.xul File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\chrome\content\overlay.xul
Mime Type: unknown/xul
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\components File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\components
Mime Type: unknown/com\components
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.dll File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.xpt File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\components\OfferBoxXpCom.xpt
Mime Type: unknown/xpt
Group: Malware file
%ProgramFiles%\OfferBox\offerboxffx@offerbox.com\install.rdf File name: %ProgramFiles%\OfferBox\offerboxffx@offerbox.com\install.rdf
Mime Type: unknown/rdf
Group: Malware file
%ProgramFiles%\OfferBox\OfferBoxLauncher.exe File name: %ProgramFiles%\OfferBox\OfferBoxLauncher.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\OfferBox\res File name: %ProgramFiles%\OfferBox\res
Group: Malware file
%ProgramFiles%\OfferBox\res\language.xml File name: %ProgramFiles%\OfferBox\res\language.xml
Mime Type: unknown/xml
Group: Malware file
%ProgramFiles%\OfferBox\res\loader.gif File name: %ProgramFiles%\OfferBox\res\loader.gif
Mime Type: unknown/gif
Group: Malware file
%ProgramFiles%\OfferBox\uninst.exe File name: %ProgramFiles%\OfferBox\uninst.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%Temp%\OB.exe File name: %Temp%\OB.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\OfferBox\OfferBoxEngine.dll File name: %ProgramFiles%\OfferBox\OfferBoxEngine.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0EE02110-967B-4256-ACA6-BC8AC7CB7E61}{8216BD4A-4DC2-4DCE-9AFF-C86C5ACC6757}{8ABB9FA2-0740-4AD9-8F54-1192254B3CF4}{AF0C0AA7-AFBA-46a0-A394-B1E1345FD936}{D4D390BE-98E6-4633-AD1B-B18B54BE5E76}File name without pathOfferBox.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\Applications\OfferBox.exeSOFTWARE\Classes\OfferBoxUI.TheBoxCtrlSOFTWARE\Classes\OfferBoxUI.TheBoxCtrl.1Software\OfferBoxSOFTWARE\Wow6432Node\OfferBoxSYSTEM\ControlSet001\services\OfferBox update serviceSYSTEM\ControlSet002\services\OfferBox update serviceSYSTEM\CurrentControlSet\services\OfferBox update serviceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}OfferBox

Additional Information

The following directories were created:
%AppData%\OfferBox%PROGRAMFILES%\OfferBox%PROGRAMFILES(x86)%\OfferBox
Loading...