Threat Database Adware PayLessWizard Ads

PayLessWizard Ads

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 8,510
Threat Level: 80 % (High)
Infected Computers: 43
First Seen: June 26, 2014
Last Seen: July 27, 2026
OS(es) Affected: Windows

PayLessWizard Ads are pop-up advertisements that may try to offer various coupon deals or online savings. Many times the PayLessWizard Ads will redirect you to other sites where some of them are unwanted and could offer additional so-called savings and coupon deals. PayLessWizard Ads may be loaded on your system automatically due to installing various freeware programs or bundled software apps. In such an event, PayLessWizard Ads may load at startup of Windows where it will continually display ads while you are surfing the internet. In some cases PayLessWizard Ads could reduce the performance of your web browser preventing normal usage of certain web sites. Removal of the PayLessWizard Ads and its related files may be done manually through finding each component and deleting it. In other cases, PayLessWizard Ads may be automatically removed using an antispyware tool.

Analysis Report

General information

Family Name: Trojan.Dapato.G
Signature status: No Signature

Known Samples

MD5: 1daaab6a16595a05263cd6fc023f42f6
SHA1: 81c255d769d78e9be4196c2b0b14961bb0951401
SHA256: 67332F3C77AF36896BC36E8252ADFB583F006CD71436104E9D1093B3B2D10EF3
File Size: 2.77 MB, 2765312 bytes
MD5: 16acfd6be9d0ae39043cd020113259b7
SHA1: 98431ac71078e7bd01309e60f702d03846707751
SHA256: 0F85708D2ED53346C0B9BBE668581082D24AB7998999DBD4257F998F65533717
File Size: 1.42 MB, 1419102 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Officeverse Inc
  • Synaptics
File Description
  • Loudtalks
  • Synaptics Pointing Device Driver
File Version
  • 1.0.0.4
  • 0.9.0.56
Internal Name Loudtalks
Legal Copyright Copyright © 2008 Officeverse Inc
Product Name
  • Loudtalks
  • Synaptics Pointing Device Driver
Product Version
  • 1.0.0.0
  • 0.9.0.56

File Traits

  • dll
  • VirtualQueryEx
  • WriteProcessMemory
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\programdata\synaptics Synchronize,Write Attributes
c:\programdata\synaptics\rcxadee.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\synaptics\synaptics.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\synaptics\synaptics.exe Synchronize,Write Attributes
c:\programdata\synaptics\synaptics.exe Synchronize,Write Data
c:\users\user\appdata\local\temp\nsc42bf.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc42bf.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsc42bf.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc42bf.tmp\ltnsis.dll Generic Write,Read Attributes
Show More
c:\users\user\appdata\local\temp\nsc42bf.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc42bf.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsc42bf.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn42af.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\pwqmmt1.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\roaming\winsl Synchronize,Write Attributes
c:\users\user\appdata\roaming\winsl\l2\26\2026 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_81c255d769d78e9be4196c2b0b14961bb0951401_0002765312 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\._cache_81c255d769d78e9be4196c2b0b14961bb0951401_0002765312 Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 (k�8��8tX��B �� �6 �v 5� �Z xy ��T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::synaptics pointing device driver C:\ProgramData\Synaptics\Synaptics.exe RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 )k�8��8tX��B �� �6 �v 5� �Z xy ��T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�05�G RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 ~� % xy* �/��Y�d�kP~� ��ރ�p��^�o���zee,Vs} kP~ ��1���7 ���ﺃee����1��fe��h�n RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 *k�8��8tX��B �� �6 �v 5� �Z xy ����T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 +k8��8tX��B �� �6 �v 5� �Z xy ����T���B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey

Windows API Usage

Category API
Service Control
  • OpenSCManager
Process Shell Execute
  • ShellExecuteEx
Process Manipulation Evasion
  • NtUnmapViewOfSection
Network Winsock2
  • WSAStartup
  • WSAttemptAutodialName
User Data Access
  • GetUserObjectInformation
Network Winhttp
  • WinHttpOpen
Network Wininet
  • InternetOpen
  • InternetOpenUrl
  • InternetReadFile
Network Winsock
  • bind
  • closesocket
  • gethostbyname
  • getsockname
  • socket

Shell Command Execution

runas c:\users\user\downloads\._cache_81c255d769d78e9be4196c2b0b14961bb0951401_0002765312
runas C:\ProgramData\Synaptics\Synaptics.exe InjUpdate