Home Malware Programs Adware Adware.DealsFinderPro

Adware.DealsFinderPro

Posted: February 25, 2014

Threat Metric

Ranking: 12,365
Threat Level: 2/10
Infected PCs: 3,576
First Seen: February 25, 2014
Last Seen: September 23, 2023
OS(es) Affected: Windows


DealsFinderPro is an ad-supported web-browser extension delivered by InstalleRex (WebPick) download and install manager. Users may find DealsFinderPro bundled with many free applications as this is a common adware distribution technique. DealsFinderPro installs itself to run automatically on system startup and adds a Browser Helper Object (BHO) to users' main browsers. Afterwards, users might start experiencing difficulties in normal web-browsing activities and crashes of the browser. DealsFinderPro adware may inject browsers with endless advertisements that are relevant to users browsing preferences. What is more, DealsFinderPro ads can be completely unrelated to the underlying webpage and in large quantities, and that can be annoying.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\DeealsFFindderPro\e.x64.dll File name: e.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: e73cfe037991b684de7fab63531686fd
Detection count: 429
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DeealsFFindderPro
Group: Malware file
Last Updated: August 6, 2014
%ALLUSERSPROFILE%\DDeAlsaFiinderPro\iqGXJ.x64.dll File name: iqGXJ.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 60065dad57953f3c15df134cbe5747db
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DDeAlsaFiinderPro
Group: Malware file
Last Updated: February 25, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{7875EC88-66DF-579A-1D31-E327E1BCCD08}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\dealsfinderpro.dealsfinderproSOFTWARE\Google\Chrome\Extensions\bhneakpjjpieipoanceahhhdhdhbknenSoftware\Microsoft\Internet Explorer\Approved Extensions\{7875EC88-66DF-579A-1D31-E327E1BCCD08}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7875EC88-66DF-579A-1D31-E327E1BCCD08}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{ADA5408B-1BF2-A302-38F2-CD4E3F87F81A}SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bhneakpjjpieipoanceahhhdhdhbknenSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{7875EC88-66DF-579A-1D31-E327E1BCCD08}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\DDeAlsaFiinderPro%ALLUSERSPROFILE%\dealsfinderpro%LocalAppData%\Google\Chrome\User Data\Default\Extensions\apkjfbgjdonhkeedopiobcjboaillghg%LocalAppData%\Google\Chrome\User Data\Default\Extensions\bhneakpjjpieipoanceahhhdhdhbknen%PROGRAMFILES%\DDeAlsaFiinderPro%PROGRAMFILES%\dealsfinderpro%PROGRAMFILES(x86)%\DDeAlsaFiinderPro%PROGRAMFILES(x86)%\dealsfinderpro%USERPROFILE%\AppData\LocalLow\{ADA5408B-1BF2-A302-38F2-CD4E3F87F81A}%appdata%\{ADA5408B-1BF2-A302-38F2-CD4E3F87F81A}
The following URL's were detected:
dealsfinderpro
Loading...