Dealio Toolbar

Threat Scorecard

Popularity Rank: 7,934
Threat Level: 20 % (Normal)
Infected Computers: 5,700
First Seen: July 24, 2009
Last Seen: January 13, 2026
OS(es) Affected: Windows

Dealio Toolbar is an add-on for popular web browsers that may display repeated and annoying advertisements attempting to offer deals and coupons on online shopping. Dealio Toolbar is known for also changing the default search engine page and default home page of popular web browsers. The installation of Dealio Toolbar may come from various bundled programs downloaded on file sharing sites and those that offer freeware and shareware applications. When loaded, Dealio Toolbar may also attempt to offer other internet services through shortcut buttons. The Dealio Toolbar is not a virus by itself but has the tendency to be a serious annoyance for computer users who want to restore their internet settings to load their preferred home page by default. The removal of Dealio Toolbar and its components may involve using an updated antispyware tool.

Aliases

5 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Sophos Dealio Installer
McAfee Artemis!4AC870C6DA03
NOD32 Win32/Adware.Toolbar.Dealio
McAfee+Artemis Artemis!DF13B8F5A476
Comodo Unclassified Malware

SpyHunter Detects & Remove Dealio Toolbar

File System Details

Dealio Toolbar may create the following file(s):
# File Name MD5 Detections
1. iobitToolbarIE.dll d6e6c591e43f17981cd32eeb792742a3 741
2. WidgiHelper.exe 77b1b2b4bacd122a78bb58ac56f897ed 98
3. file.exe b32ca052601c77a68056c5f342f8f6f2 8
4. Dealio Deskbar.exe df13b8f5a476b1022c5730eec66b4515 2
5. free-msn-emoticons-pack-01-ingles.exe 4ac870c6da035d325b14f8325101ae5b 2

Registry Details

Dealio Toolbar may create the following registry entry or registry entries:
CLSID
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
Software\AppDataLow\Software\Dealio
SOFTWARE\Classes\Installer\Products\31DF8B43BC380E4468DAEEF4766B6F16
Software\Dealio
Software\Microsoft\Internet Explorer\Approved Extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
Software\Microsoft\Internet Explorer\UrlSearchHooks\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
SOFTWARE\Wow6432Node\Dealio
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}
{4F30976E-356B-45F3-A760-66954ED55893}
{B9123641-0094-4C1D-A181-627F725FD122}
{D7BB45D3-1001-431D-A01E-11E407790E9A}

Directories

Dealio Toolbar may create the following directory or directories:

%ProgramFiles%\Dealio Toolbar
%ProgramFiles(x86)%\Dealio Toolbar
%USERPROFILE%\AppData\LocalLow\Dealio
%USERPROFILE%\Application Data\Dealio

Analysis Report

General information

Family Name: Dealio Toolbar
Signature status: No Signature

Known Samples

MD5: 7ab56e258740eb951eae6f28f588bc6a
SHA1: cd01b618616ddb1596bbacf1552be35e9f1d9432
SHA256: B75AD9FC24D8E737C9FB9035C9E5ADD878489EAB3212A2341AC12A484753AEF4
File Size: 2.39 MB, 2391415 bytes
MD5: 5d736ed41ade0080627738865924d35c
SHA1: e0d4ebfd0d27f312ca26ee87054509a21698e79f
SHA256: B5B7EAA3351BF81CEDA43016953B0E6A6834EF02377FCAD9633FC08E3F2A4636
File Size: 9.05 MB, 9049552 bytes
MD5: a0109806f86c0e3e9426493f0222b69f
SHA1: 9606127a39654246e978864eb6a1aecda48c5920
SHA256: A7BD724E73CA6A39128DDDE1C9944AF2B9D5805965FD487D919E72EC71C911AC
File Size: 4.18 MB, 4175089 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • This installation was built with Inno Setup.
Company Name Koyote Soft
File Description
  • Ares Destiny Setup
  • Free Video Converter Setup
File Version 2.5.0.0
Legal Copyright Koyote Soft
Product Name Free Video Converter
Product Version 2.5.0.0

Digital Signatures

Signer Root Status
AVSOFT CORP. VeriSign Class 3 Code Signing 2010 CA Self Signed

File Traits

  • Installer Manifest
  • Installer Version
  • WriteProcessMemory
  • x86

Files Modified

File Attributes
c:\users\user\appdata\local\temp\dealio_install02.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\dealiotoolbar-stub-1.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\dvdmmg.sys Generic Write,Read Attributes
c:\users\user\appdata\local\temp\iod.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsm15d1.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsm15d1.tmp\iod.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsm15d1.tmp\iod.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsm15d1.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsm15d1.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsm15d1.tmp\modern-header.bmp Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsm15d1.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsm15d1.tmp\security.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsm15d1.tmp\security.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsw15c0.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\wizesupp.dll Generic Write,Read Attributes

Related Posts

Trending

Most Viewed

Loading...