Threat Database Adware Awesome Dealers

Awesome Dealers

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 10 % (Normal)
Infected Computers: 77,068
First Seen: October 12, 2020
Last Seen: October 24, 2025
OS(es) Affected: Windows

The Awesome Dealers software may be promoted to users as a shopping enhancer. The Awesome Dealers software can be found in free software packages and on hxxp://awesomedealers.com/index.html. You should note that the developers of the Awesome Dealers do not take responsibility for any content provided through their software. Additionally, PC users are not given the opportunity to specify the way how they would like to receive updates and notifications from the Awesome Dealers program. We have received complaints regarding the Awesome Dealers app in the first weeks of November 2017.

It appears that the behavior of the Awesome Dealers became somewhat aggressive and PC users were subjected to waves of spam messages, notifications, browser redirects, and notifications with marketing materials. There are cybersecurity researchers who classify the Awesome Dealers program as adware and a Potentially Unwanted Program (PUP). Lab tests have shown that the Awesome Dealers adware communicates with the following IP addresses:

162.255.119.250
52.84.64.153
54.230.0.159
54.230.0.224
54.230.0.234
54.230.0.30
54.230.0.80

As mentioned above, the Awesome Dealers adware is designed to deliver content from third parties to your screen. We have detected that the Awesome Dealers adware loads images, video, and text from the following URLs:

hxxp://artafric[.]com/boxd/renew.php?rand=13InboxLightaspxn.1774256418
hxxp://awesomesoftstohavealways[.]website/
hxxp://freshupdatestoinstallsafely[.]online/
hxxp://getnewadsforawesomsoft[.]online/
hxxp://setupupgrade45678safesystems[.]download/
hxxp://updatestoget4freealwaystoday[.]website/
hxxp://workingupdate247safesystems4you[.]download/

The data downloaded by the Awesome Dealers adware includes tracking cookies and persistent Web beacons. The resources loaded by the Awesome Dealers adware may be insecure and lead users to download riskware. The Awesome Dealers adware is reported to display pages colored in black that feature a button colored in green and suggest the user proceed with the download of promotional content. The files and pages presented by the Awesome Dealers are likely to be tagged by AV scanners as:

  • HTML:Redirector-HQ [Trj]
  • JS.Z.Agent.13385.Q
  • JS/Techbrolo.A!Eldorado
  • JS:Trojan.Cryxos.D461
  • SupportScam:JS/TechBrolo.F
  • Suspicious_GEN.F47V1109
  • Trojan.HTML.FakeAlert

SpyHunter Detects & Remove Awesome Dealers

File System Details

Awesome Dealers may create the following file(s):
# File Name MD5 Detections
1. rlvknlg64.ex_ 68d7324ba0773b18853916efcffce529 2,225
2. rkinstaller.exe cf8361bd4360c31db7ed331a3e855576 1,407
3. rkverify.exe 60db193bce83f05363c874fec9b310c5 676
4. spt_setup.exe 89c8796cd6169d14531791b7388bc0e9 292
5. rlls.dll b4a262f7a440a830de2fabc16327b5c4 60
6. rlls64.dll 5417f1ec92429ef41ed17eb5bbb4f249 59
7. rlservice.exe 34aff57d6f2f1c074573b7aaa573092a 50
8. rlvknlg32.exe 3f128ed69207decf2fc07526f8dc656c 50
9. rlvknlg64.exe fc1b0b7cd09b3f88a759f3b9a9ac3023 49
10. rlvknlg.exe 969ae0fb8d881fa7876f0ec3e7ce7178 41
11. 3e632d7f0392251dd0b3049734163f5c_RKInstall_050620.exe 3e632d7f0392251dd0b3049734163f5c 35
12. FreeOCRtoWord.exe 57595cf8580c67962475d19518572d49 25
13. PowerSoundEditorFree.exe eed30fdf147ff30a24f2279d13e3bbe5 25
14. RKInstall_052919.exe 76d1bc443d9a01e017783b9a96b6079b 23
15. uprkset.exe 6a38c053466eab3656074f81ddc00d77 5
More files

Related Posts

Trending

Most Viewed

Loading...