Threat Database Potentially Unwanted Programs SoftwareBundler:Win32/Protlerdob

SoftwareBundler:Win32/Protlerdob

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 14
First Seen: October 29, 2012
Last Seen: August 21, 2022
OS(es) Affected: Windows

SoftwareBundler:Win32/Protlerdob is a potentially unwanted program that introduces itself as a free movie download, as an executable file such as 'filme.exe', but instead, it comes bundled with various programs that PC user have to pay for. While being installed on the corrupted machine, SoftwareBundler:Win32/Protlerdob makes system changes by dropping several files and registry entries. SoftwareBundler:Win32/Protlerdob also shows the certain images. PC users may electively download SoftwareBundler:Win32/Protlerdob. SoftwareBundler:Win32/Protlerdob may set an uninstaller in the Add or Remove Programs window. If SoftwareBundler:Win32/Protlerdob is launched, a window will emerge that seems to be it's downloading offers. While the installation cannot be stopped through the GUI (graphical user interface), you can stop it by turning off your PC. Once the offers have been downloaded, the computer user will be introduced with some offers. If the computer users continues with the installation by clicking the 'Avancar' (Advance) button, one of the offers called DealPly, will be installed. The offers may occur in the Manage Add-ons window. One of the offers discovered is a horoscope service, which the PC user could sign up for, that would be sent to the cell phone for the cost of a premium SMS. At last, the computer user may get diverted to a website that pushes movie downloads, which are paid.

File System Details

SoftwareBundler:Win32/Protlerdob may create the following file(s):
# File Name Detections
1. %Documents and Settings%\All Users\Start Menu\Programs\DealPly
2. %Documents and Settings%\All Users\Desktop\Acelerador de Downloads.lnk
3. %ProgramFiles%\Acelerador de Downloads
4. %Documents and Settings%\All Users\Desktop\ CONTA PRIME.lnk
5. %ProgramFiles%\DealPly
6. %Documents and Settings%\All Users\Start Menu\Programs\Acelerador de Downloads

Registry Details

SoftwareBundler:Win32/Protlerdob may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - DealPly CLSID
HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - DealPly BHO
HKEY_CURRENT_USER\Software\DealPly

URLs

SoftwareBundler:Win32/Protlerdob may call the following URLs:

freedevicespeedsmart.cyou

Trending

Most Viewed

Loading...