Bonanza Deals

Bonanza Deals Description

Bonanza Deals is an adware program that may be installed onto Google Chrome, Mozilla Firefox and Internet Explorer. Bonanza Deals may embed a browser plug-in that shows a variety of messages while the affected web user is browsing the webt. Bonanza Deals may also show a variety of irritating pop-up advertisements that carry coupons with discounts and other offers. Bonanza Deals expects Internet users to click on these pop-up ads. Bonanza Deals tries to increase traffic of advertising websites and benefit from associated links. Bonanza Deals may reroute target computer users to doubtful commercial websites and disturb the web user's work with continuous pop-up ads and messages. Bonanza Deals may also threaten the target computer user's privacy and security. Bonanza Deals may trace the affected web user's surfing activities, that is what websites he is visiting, what information he enters while surfing on the net and other details. Then, Bonanza Deals may transmit this data to remote cybercriminals.
Aliases: Adware.BL [Symantec], Adware.DealPly (fs) [VIPRE], Adware.Shopper.363 [DrWeb], Application.Win32.Bonanza.gr [Comodo], Hoax.Mbro [VBA32], PE:Trojan.GenericKDV!6.B5C [Rising], PUP.Optional.BonanzaDeals.A [Malwarebytes], Riskware.Agent! [Agnitum], Trojan.Win32.Shopper.cquvgh [NANO-Antivirus] and Win32/DealPly.L [ESET-NOD32].

Infected with Bonanza Deals? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect Bonanza Deals

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of Bonanza Deals outbreaks and other threats from global to local level.

File System Details

Bonanza Deals creates the following file(s):
# File Name Size MD5 Detection Count
1 %LocalAppData%\Google\Chrome\User Data\Default\Extensions\ieadcoanfjloocmfafkebdnfefmohngj 63
2 %AppData%\Microsoft\Windows\Start Menu\Programs\BonanzaDeals 61
3 %AllUsersProfile%\BonanzaDealsLive 60
4 %ProgramFiles(x86)%\BonanzaDealsLive 56
5 %WINDIR%\Bonanza Baby.scr 2,379,776 f2c4e56bb5aaf4ea01ee8ea4af7a26f3 37
6 %PROGRAMFILES%\Cooperweb\BackUpBonanza\BAT\JimBakUp.bat 6,637 7dbd136597004df276d615ad71938017 29
7 %PROGRAMFILES%\BonanzaDeals\BonanzaDealsIE.dll 100,336 bacaf8bccaa20e52eb48054ee54266a3 14
8 %PROGRAMFILES(x86)%\BonanzaDeals\BonanzaDealsUpdate.exe 78,384 5826462e5834594a81e0397a097b5d3e 6
9 %LOCALAPPDATA%\Microsoft\Windows\Temporary Internet Files\Content.IE5\J15RFMLQ\uninstall.exe 821,760 b52c9369cfd0b07290aa3deba1599ab6 4,784
10 %TEMP%\{10E78180-78B7-4A78-BB5C-46BFAAFED8F5}\files\uninst.exe 892,416 c1b47e8d875b63f5dabd81331833b15f 4,373
11 %PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe 218,608 94c2354808fc7b7c2c22ab8375f44cc9 2
12 %PROGRAMFILES%\WindowsApps\Infiapps.SlotBonanza_1.0.0.61_x64__kjw77hz2at8sa\SlotBonanza.exe 171,008 a5b7df6a53c1d440804de9483f9f7406 2
13 %APPDATA%\Bonanza\UpdateProc\UpdateTask.exe 129,024 0338d3a024fb2c2259bf2da77ebee6ee 2
14 %PROGRAMFILES(x86)%\500,000 Games\Game Collection 500,000\4500 Vegas Slots Bonus Bonanza\VegasBonusSlots.exe 3,366,967 5455684f1d75091f5ddef8e0a97dca49 2
15 %PROGRAMFILES%\Selectsoft\Business Card Bonanza\printgenerator.exe 4,440,064 8a78b12c248f64edbec6b5d9ffd4680f 2

More files

Registry Details

Bonanza Deals creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
Local\Application Data\BonanzaDealsLive
SYSTEM\CurrentControlSet\services\bonanzadealslivem
SYSTEM\CurrentControlSet\services\bonanzadealslive
SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Bonanza Deals
Software\Microsoft\Internet Explorer\Approved Extensions, value: {fe063412-bea4-4d76-8ed3-183be6220d17}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdate
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUA
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCore
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{234D7CED-4E3D-472B-9D7D-0FBC1F9BFE15}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{234D7CED-4E3D-472B-9D7D-0FBC1F9BFE15}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00A5E545-94F6-42CD-A4CA-9298A0E6D361}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{00A5E545-94F6-42CD-A4CA-9298A0E6D361}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E5179844-F468-4274-BA4F-69F7FAFA1243}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E5179844-F468-4274-BA4F-69F7FAFA1243}
SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine
SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService
SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher
SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine
SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0
SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine
SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass.1
SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass
SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass.1
SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass
SOFTWARE\Classes\BonanzaDealsLive.Update3WebControl.3
SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0
SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine
SOFTWARE\Classes\BonanzaDealsLive.OneClickCtrl.9
BonanzaDealsLiveUpdate.Update3WebSvc.1.0
BonanzaDealsLiveUpdate.Update3WebSvc
BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0
BonanzaDealsLiveUpdate.Update3WebMachineFallback
BonanzaDealsLiveUpdate.Update3COMClassService.1.0
BonanzaDealsLiveUpdate.Update3COMClassService
BonanzaDealsLiveUpdate.ProcessLauncher.1.0
BonanzaDealsLiveUpdate.ProcessLauncher
BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0
BonanzaDealsLiveUpdate.OnDemandCOMClassSvc
BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0
BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback
BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0
BonanzaDealsLiveUpdate.CredentialDialogMachine
BonanzaDealsLiveUpdate.CoreMachineClass.1
BonanzaDealsLiveUpdate.CoreMachineClass
BonanzaDealsLiveUpdate.CoreClass.1
BonanzaDealsLiveUpdate.CoreClass
BonanzaDealsLiveUpdate.CoCreateAsync.1.0
BonanzaDealsLiveUpdate.CoCreateAsync
BonanzaDealsLive.OneClickProcessLauncherMachine
BonanzaDealsLive.OneClickCtrl.9
SOFTWARE\Classes\Wow6432Node\AppID\BonanzaDealsLive.exe
SOFTWARE\Wow6432Node\Classes\AppID\BonanzaDealsLive.exe
Wow6432Node\AppID\BonanzaDealsLive.exe
SOFTWARE\Classes\AppID\BonanzaDealsLive.exe
AppID\BonanzaDealsLive.exe
SOFTWARE\Wow6432Node\BonanzaDealsLive
Software\BonanzaDeals
MIME\Database\Content Type\application/x-vnd.bdliveupdate.oneclickctrl.9
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17}
MIME\Database\Content Type\application/x-vnd.bdliveupdate.update3webcontrol.3
SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.update3webcontrol.3
SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.oneclickctrl.9
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CFE8F751-C1B4-46AA-A590-37C372154FA0}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{57485504-98BB-4756-890C-2B79F201E362}
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CFE8F751-C1B4-46AA-A590-37C372154FA0}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}
SOFTWARE\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9
SOFTWARE\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9
SOFTWARE\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3
SOFTWARE\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3
SYSTEM\ControlSet002\Services\bonanzadealslive
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
Bonanza Deals
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{118E1BF6-6279-432F-A285-373A77B90C7A}
{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}
{1CC8D970-F626-4F19-815F-890032BB6606}
{29494049-211F-4F5C-8545-7DA8BF7A6CF8}
{806785D0-375F-4C2C-92E3-B8EE65D28E83}
{944661E7-67B9-4DF7-BFF2-05388C166D34}
{9EA8702C-EEDB-4731-BE68-E9A167DD3597}
{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}
{B71934E5-6B93-448D-9D32-CBAA5150C5D8}
{C4BEF720-313C-420A-ACF6-77DD95D8F553}
{D34F391D-4CB7-467F-A543-F583857C63B0}
{E970727E-0508-4BEB-8B72-BBA9D0D047C7}
{fe063412-bea4-4d76-8ed3-183be6220d17}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 3 + 7 ?