Threat Database Adware Adware:Win32/DealsPlugin

Adware:Win32/DealsPlugin

By LoneStar in Adware

Threat Scorecard

Ranking: 3,329
Threat Level: 10 % (Normal)
Infected Computers: 1,555
First Seen: February 1, 2013
Last Seen: September 19, 2023
OS(es) Affected: Windows

Adware:Win32/DealsPlugin is an adware application that delivers offers to the compromised PC, based on the websites visited by attacked Internet users. Adware:Win32/DealsPlugin also embeds unassociated ads into the websites visited by affected PC users. Adware:Win32/DealsPlugin may create an uninstaller that can be accessed by PC users from the Control Panel. The entry name of Adware:Win32/DealsPlugin may show up as 'Deals Plugin'. Adware:Win32/DealsPlugin may be installed on the victimzied PC when the computer user visits the website of the application. Adware:Win32/DealsPlugin will emerge as a BHO (Browser Helper Object) in Internet Explorer. Adware:Win32/DealsPlugin creates a scheduled task to start every day at 13:00, permitting it to update itself. Adware:Win32/DealsPlugin also installs itself as an extension for Google Chrome and Mozilla Firefox. When installed, Adware:Win32/DealsPlugin show deals when the computer user browses the web. If the victim clicks on the 'flag', the application will show a variety of deals. Adware:Win32/DealsPlugin may show a 'flag' on the top right-hand corner of the hacked Internet browser. Adware:Win32/DealsPlugin may create an uninstaller that PC users can found in the Programs and Features window. Adware:Win32/DealsPlugin creates numerous registry keys.

File System Details

Adware:Win32/DealsPlugin may create the following file(s):
# File Name Detections
1. %LOCALAPPDATA%\Updater4637\Updater4637.exe

Registry Details

Adware:Win32/DealsPlugin may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004637.Sandbox.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004637.BHO
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055465537}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011461137}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110011461137}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004637.BHO.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066466637}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110011461137}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220022462237}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CrossriderApp0004637.Sandbox
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440044464437}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110011461137}

Trending

Most Viewed

Loading...