Home Malware Programs Adware InnoApp

InnoApp

Posted: March 31, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 2,532
First Seen: March 31, 2014
Last Seen: October 6, 2024
OS(es) Affected: Windows


InnoApp is considered to be adware that may declare to be able to help computer users save time and money while they are shopping online. InnoApp may proliferate and access the PC through bundled freeware that are available for download to PC users on suspicious download websites. InnoApp may be downloaded and installed on the PC without the computer user's permission. InnoApp may display unwanted pop-up ads and messages that carry discount coupons, sale deals and other offers on the computer system. InnoApp may take over all the Web browser installed on the PC and alter the default browser settings. InnoApp may also substitute the default homepage and search provider or a new tab page with an unreliable website that was created to possibly generate advertising revenue from clicks on advertisements and raised traffic of the website.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



system32\drivers\{3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}Gw64.sys File name: {3c3ae2b4-4a36-40c4-a356-ffc1820b7ece}Gw64.sys
Size: 48.82 KB (48824 bytes)
MD5: 4ef053f2447541b7abf4ca37459b6749
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: system32\drivers
Group: Malware file
Last Updated: September 29, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0E47F4E2-AAEF-4583-9D90-A0BFC1945BC5}{59e47ef9-5163-4e82-9c17-3d6f63dda496}{741227E4-EDAE-443F-A438-64B1E79F5062}{79A7FE5F-BE17-4CF8-91F4-AEBD7ABBF762}HKEY..\..\..\..{RegistryKeys}Software\innoAppSoftware\Microsoft\Internet Explorer\Approved Extensions\{50B63821-88A0-4987-8B85-B46C94C8F39B}Software\Microsoft\Internet Explorer\Approved Extensions\{BD48B836-0F8B-48CA-A603-2DF62DEF07F2}SOFTWARE\Microsoft\Tracing\innoApp_RASAPI32SOFTWARE\Microsoft\Tracing\innoApp_RASMANCSSOFTWARE\Microsoft\Tracing\updateinnoApp_RASAPI32SOFTWARE\Microsoft\Tracing\updateinnoApp_RASMANCSSOFTWARE\Microsoft\Tracing\utilinnoApp_RASAPI32SOFTWARE\Microsoft\Tracing\utilinnoApp_RASMANCSSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{50B63821-88A0-4987-8B85-B46C94C8F39B}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BD48B836-0F8B-48CA-A603-2DF62DEF07F2}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{50B63821-88A0-4987-8B85-B46C94C8F39B}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD48B836-0F8B-48CA-A603-2DF62DEF07F2}SOFTWARE\Wow6432Node\innoAppSOFTWARE\Wow6432Node\Microsoft\Tracing\innoApp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\innoApp_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updateinnoApp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateinnoApp_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilinnoApp_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilinnoApp_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update innoAppSYSTEM\ControlSet002\services\eventlog\Application\Update innoAppSYSTEM\ControlSet002\services\Update innoAppSYSTEM\CurrentControlSet\services\eventlog\Application\Update innoAppSYSTEM\CurrentControlSet\services\Update innoAppHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}innoApp

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\pjbepjpoliboddkljgjphikhegfhelmo%LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\pjbepjpoliboddkljgjphikhegfhelmo%PROGRAMFILES%\innoApp%PROGRAMFILES(x86)%\innoApp%TEMP%\innoApp
The following URL's were detected:
innoApp
Loading...