PennyBee

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 8,399
Threat Level: 20 % (Normal)
Infected Computers: 45,296
First Seen: July 1, 2014
Last Seen: August 21, 2026
OS(es) Affected: Windows

PennyBee is an adware program that renders advertisements that may attempt to offer various discounts or coupon deals for shopping online. The PennyBee Ads may come as pop-up ads when you are surfing the internet. Some of the PennyBee Ads may redirect you to various unwanted sites or pages that try to advertise other products and services. The PennyBee Ads may also reduce the performance of your web browser making it difficult or aggravating for surfing the web. The PennyBee program may have several associated files that load with the installation of random freeware programs or bundled applications. Removing the PennyBee files and add-ons may require using an antispyware tool designed to eliminate adware and browser hijacker files.

SpyHunter Detects & Remove PennyBee

File System Details

PennyBee may create the following file(s):
# File Name MD5 Detections
1. PennyBee.exe.vir f7181e6df93cb6123363915fe97079a3 3,828
2. A0058046.exe 3e01a07597677e78805a1947e0b52a8e 1,639
3. PennyBee.exe 68090de5d41ec985fc6de24a578308f0 1,519
4. wpennybeed.exe fa8f5a2775273a35fffb8157a5ecf449 1,006
5. wpennybeed.exe47122 2c1611c7d509dd1c19f011c7a91a38a1 923
6. lyricsgizmL32.exe 3fb6073eb13c7203053393398494ec98 17
7. wlyricsgizmd.exe 4909e8769c6f39726240772e2c508213 16
8. lyricsgizm.exe e1b69a2a405ed4f7c70291872858725a 16
9. bkup.dat 59dea63ada82c0785a0f0198e4b27c27 16
10. UpdateTask.exe 7297a1d8001a2de6462126f394d2e4c4 14
11. PennyBeeW.exe 02418c3533493e0ac6df342d64186d4d 6
12. pennybeepro.exe 43dacdf4ee757f16230c585db0ebad4d 5
13. pennybeeproD32.exe 102701e0a5ad26f1ac4340e9d9743f4c 4
14. pennybeeprol64.exe dd6d5b2ae17a7b0ae4cfdff39a90bfa9 1
15. Ipygi120.sys dc1633d35a8468f7b59cdf01832ac250 1
16. Jefdad120.sys 0758fb8fa82c1c60b51e9881dda66e94 1
17. wpennybeeprod.exe 91f82effca8f74a894d48b10ea21b37a 1
18. 988adae5538c14759e6e6ed4e52d2fdd 988adae5538c14759e6e6ed4e52d2fdd 1
More files

Registry Details

PennyBee may create the following registry entry or registry entries:
CLSID
{903260FE-C27C-4585-AC5C-2BB4AAB6C019}
{A983DCA3-7CCD-4C76-B894-57ADEE66AFDC}
{ECCD8756-E877-457F-8C44-4EC20055DDB5}
Regexp file mask
%windir%\System32\Tasks\pennybee Runner[RANDOM CHARACTERS]
%windir%\System32\Tasks\pennybee[RANDOM CHARACTERS]
%windir%\Tasks\pennybee Runner[RANDOM CHARACTERS]
%windir%\Tasks\pennybee[RANDOM CHARACTERS]
Software\AppDataLow\Software\pennybee
SOFTWARE\Microsoft\Tracing\PennyBeeW_RASAPI32
SOFTWARE\Microsoft\Tracing\PennyBeeW_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\pennybee Runner.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\pennybee Runner.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\PennyBee.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\PennyBee.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\pennybeepro Runner.job
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\pennybeepro Runner.job.fp
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PennyBee
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pennybee Runner
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pennybeepro Runner
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PennyBee.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PennyBee
Software\PennyBee
SOFTWARE\pennybeepro
SOFTWARE\Wow6432Node\Microsoft\Tracing\PennyBeeW_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\PennyBeeW_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\PennyBee.exe
SOFTWARE\Wow6432Node\pennybeepro
SYSTEM\ControlSet001\services\pennybee
SYSTEM\ControlSet001\services\pennybeepro
SYSTEM\ControlSet001\services\wpennybeed
SYSTEM\CurrentControlSet\services\pennybee
SYSTEM\CurrentControlSet\services\pennybeepro
SYSTEM\CurrentControlSet\services\wpennybeed

Directories

PennyBee may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\pennybee
%ALLUSERSPROFILE%\lyricsgizm
%ALLUSERSPROFILE%\lyricsgizm2
%ALLUSERSPROFILE%\mhvixutt
%ALLUSERSPROFILE%\pennybee
%ALLUSERSPROFILE%\pennybeepro
%ALLUSERSPROFILE%\pennybeepro2
%APPDATA%\tifro
%LOCALAPPDATA%\PennyBee
%PROGRAMFILES%\PennyBee
%PROGRAMFILES(x86)%\PennyBee
%USERPROFILE%\AppData\LocalLow\pennybee
%USERPROFILE%\AppData\LocalLow\pennybeepro
%UserProfile%\Local Settings\Application Data\PennyBee
%appdata%\Hemkajdoa
%appdata%\OyijLya
%appdata%\Rikfootov
%appdata%\Vyhliwe
%appdata%\pennybee
%appdata%\pennybeepro

Analysis Report

General information

Family Name: Adware.PennyBee
Signature status: No Signature

Known Samples

MD5: 99241e660fb9c4cd00652935e99f1b9a
SHA1: 5ed334a8dfb6f7623538e19631fb77436f64d2f4
SHA256: 00515EC31C383A45BAF866D9012D3BDF003AA63B1535A8A975B2738C67A225FA
File Size: 3.02 MB, 3023404 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Version 1.1.0.31
Product Version 1.1.0.31

File Traits

  • dll
  • x86