Deal Spy

By Domesticus in Adware

Threat Scorecard

Ranking: 13,061
Threat Level: 20 % (Normal)
Infected Computers: 295
First Seen: April 2, 2013
Last Seen: August 22, 2023
OS(es) Affected: Windows

ScreenshotDeal Spy is a potentially unwanted program/adware, which is generated by 215 Apps. Deal Spy will show pop-up ads, savings coupon, and deals on the screen of the compromised PC while the computer user is browsing the web. Deal Spy will emerge as a small box on upper right corner of the hacked web browser when the Internet users visits online shopping websites. Deal Spy emerges as a small button that, if clicked, will reveal the contents showing links for a variety of offers. Deal Spy usually installs a browser add-on on Internet Explorer, Google Chrome, and Mozilla Firefox. Deal Spy may come packaged with free programs that web users have downloaded from various websites. When the computer user is installing the particular tool, he/she also unknowingly loads Deal Spy or other types of adware without consent.

SpyHunter Detects & Remove Deal Spy

Registry Details

Deal Spy may create the following registry entry or registry entries:
CLSID
{11111111-1111-1111-1111-110211621176}
{22222222-2222-2222-2222-220222622276}
{55555555-5555-5555-5555-550255625576}
{66666666-6666-6666-6666-660266626676}
Software\AppDataLow\Software\Deal Spy
SOFTWARE\Classes\CrossriderApp0026276.Sandbox
SOFTWARE\Classes\CrossriderApp0026276.Sandbox.1
Software\Cr_Installer\26276
Software\InstalledBrowserExtensions\215 Apps\26276
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Deal Spy-updater.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Deal Spy-updater.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater26276.exe
SOFTWARE\Wow6432Node\Deal Spy
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211621176}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211621176}
SOFTWARE\Wow6432Node\Microsoft\Tracing\Deal Spy_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Deal Spy_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\Updater26276_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\Updater26276_RASMANCS

Directories

Deal Spy may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Deal Spy
%LOCALAPPDATA%\Deal Spy
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd
%LOCALAPPDATA%\Updater26276
%PROGRAMFILES%\Deal Spy
%PROGRAMFILES(x86)%\Deal Spy
%USERPROFILE%\AppData\LocalLow\Deal Spy
%UserProfile%\Local Settings\Application Data\Updater26276

URLs

Deal Spy may call the following URLs:

https://www.dealspy.com/

Trending

Most Viewed

Loading...