Home Malware Programs Adware Bonanza Deals

Bonanza Deals

Posted: September 24, 2013

Threat Metric

Ranking: 2,721
Threat Level: 2/10
Infected PCs: 176,725
First Seen: September 24, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

Bonanza Deals is an adware application that may be installed onto Internet Explorer, Mozilla Firefox and Google Chrome. Bonanza Deals may add a browser extension that displays numerous messages while the target PC user is surfing the Internet. Bonanza Deals may also display numerous annoying pop-up ads that include coupons with discounts and other offers. Bonanza Deals expects computer users to click on these pop-up advertisements. Bonanza Deals attempts to raise traffic of commercial websites and make money from affiliate links. Bonanza Deals may redirect affected web users to dubious advertising websites and disturb the PC user's work with repeated pop-up advertisements and messages. Bonanza Deals may als pose risk to the affected Internet user's privacy and security. Bonanza Deals may keep track of the target PC user's browsing activities, that is what websites he is visiting, what information he enters while browsing on the web and other details. Then, Bonanza Deals may transfer this data to remote attackers.

Aliases

Adware.Shopper.363 [DrWeb]Application.Win32.Bonanza.gr [Comodo]Adware.BL [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: c40e44deaee08c93263b53be589ac409
Detection count: 1,375
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: 6cbeac2c020c5eeb3ac88de3cbd851cf
Detection count: 379
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: 2862ea2ff176263d77949327757f178d
Detection count: 323
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: deb6c34b9e821bec405f4692cae80191
Detection count: 304
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: 6b1dd0217b2759a02ddd5c6b5026aa3d
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%SystemDrive%\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: f83ad31f8539cd4d881177b092735f3a
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Dokumente und Einstellungen\NetworkService\Anwendungsdaten\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe File name: BonanzaDealsLive.exe
Size: 155.62 KB (155628 bytes)
MD5: ac9b48c08bf7faa17d53743a0157f895
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BonanzaDealsLive\Update
Group: Malware file
Last Updated: January 30, 2014
%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe File name: BonanzaDealsLive.exe
Size: 148.97 KB (148976 bytes)
MD5: ed1875508b4b18de28894cd901c70989
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BonanzaDealsLive\Update
Group: Malware file
Last Updated: January 30, 2014
%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe File name: BonanzaDealsLive.exe
Size: 306.01 KB (306015 bytes)
MD5: e1e46ec61d711b340583513349742ced
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BonanzaDealsLive\Update
Group: Malware file
Last Updated: January 30, 2014
%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: 07a480e25bb4697adc28212471115899
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
C:\System Volume Information\SystemRestore\AppxStaging\Program Files\WindowsApps\Infiapps.SlotBonanza_1.0.0.61_x64__kjw77hz2at8sa\SlotBonanza.exe File name: SlotBonanza.exe
Size: 171 KB (171008 bytes)
MD5: a5b7df6a53c1d440804de9483f9f7406
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\SystemRestore\AppxStaging\Program Files\WindowsApps\Infiapps.SlotBonanza_1.0.0.61_x64__kjw77hz2at8sa\SlotBonanza.exe
Group: Malware file
Last Updated: July 18, 2021
%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe File name: BonanzaDealsLive.exe
Size: 218.6 KB (218608 bytes)
MD5: fa47e42b078b897b14e1ec25745ed965
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BonanzaDealsLive\Update
Group: Malware file
Last Updated: January 30, 2014
%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe File name: BonanzaDealsLive.exe
Size: 184.3 KB (184304 bytes)
MD5: d9b9bcd5648fa4763d6afe741bcacfbc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\BonanzaDealsLive\Update
Group: Malware file
Last Updated: January 30, 2014
%PROGRAMFILES(x86)%\BonanzaDealsLive\Update\BonanzaDealsLive.exe File name: BonanzaDealsLive.exe
Size: 141.82 KB (141824 bytes)
MD5: b0aae8f1d785ea02d86ba8cead6a4ae5
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\BonanzaDealsLive\Update
Group: Malware file
Last Updated: January 30, 2014
%APPDATA%\Bonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 129.02 KB (129024 bytes)
MD5: 0338d3a024fb2c2259bf2da77ebee6ee
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Bonanza\UpdateProc
Group: Malware file
Last Updated: January 30, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{118E1BF6-6279-432F-A285-373A77B90C7A}{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}{1CC8D970-F626-4F19-815F-890032BB6606}{29494049-211F-4F5C-8545-7DA8BF7A6CF8}{33BAF587-9647-4281-A34F-F4830CDC1B9F}{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}{6802463D-636F-41FE-9924-4CAD56906590}{806785D0-375F-4C2C-92E3-B8EE65D28E83}{944661E7-67B9-4DF7-BFF2-05388C166D34}{9EA8702C-EEDB-4731-BE68-E9A167DD3597}{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}{B71934E5-6B93-448D-9D32-CBAA5150C5D8}{C4BEF720-313C-420A-ACF6-77DD95D8F553}{D34F391D-4CB7-467F-A543-F583857C63B0}{E970727E-0508-4BEB-8B72-BBA9D0D047C7}{EBF1F869-D2F0-4D31-A877-386C853A9C3D}{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}{F904AC50-215C-42AB-A532-77E9FDBA9B19}{fe063412-bea4-4d76-8ed3-183be6220d17}File name without pathBonanzaDealsLiveUpdateTaskMachineCore.jobBonanzaDealsLiveUpdateTaskMachineUA.jobRegexp file mask%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe%PROGRAMFILES(x86)%\BonanzaDealsLive\Update\BonanzaDealsLive.exeHKEY..\..\..\..{RegistryKeys}Software\BonanzaDealsSoftware\BonanzaDealsLiveSOFTWARE\Classes\AppID\BonanzaDealsLive.exeSOFTWARE\Classes\BonanzaDealsLive.OneClickCtrl.9SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachineSOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0SOFTWARE\Classes\BonanzaDealsLive.Update3WebControl.3SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsyncSOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsync.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClassSOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass.1SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClassSOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass.1SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachineSOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineSOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallbackSOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvcSOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncherSOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassServiceSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallbackSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvcSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc.1.0SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.oneclickctrl.9SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.update3webcontrol.3SOFTWARE\Classes\Wow6432Node\AppID\BonanzaDealsLive.exeSoftware\Microsoft\Internet Explorer\Approved Extensions\{fe063412-bea4-4d76-8ed3-183be6220d17}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUASOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdateSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063412-BEA4-4D76-8ED3-183BE6220D17}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4BEF720-313C-420A-ACF6-77DD95D8F553}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17}SOFTWARE\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3SOFTWARE\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9SOFTWARE\Wow6432Node\BonanzaDealsSOFTWARE\Wow6432Node\BonanzaDealsLiveSOFTWARE\Wow6432Node\Classes\AppID\BonanzaDealsLive.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3SOFTWARE\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9SYSTEM\ControlSet001\services\bonanzadealsliveSYSTEM\ControlSet001\services\bonanzadealslivemSYSTEM\ControlSet002\Services\bonanzadealsliveSYSTEM\ControlSet002\services\bonanzadealslivemSYSTEM\CurrentControlSet\services\bonanzadealsliveSYSTEM\CurrentControlSet\services\bonanzadealslivemHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Bonanza Deals

Additional Information

The following directories were created:
%APPDATA%\UpdateBonanza%AllUsersProfile%\Application Data\BonanzaDealsLive%AllUsersProfile%\BonanzaDealsLive%AppData%\Microsoft\Windows\Start Menu\Programs\BonanzaDeals%LocalAppData%\BonanzaDealsLive%ProgramFiles%\BonanzaDeals%ProgramFiles%\BonanzaDealsLive%ProgramFiles(x86)%\BonanzaDeals%ProgramFiles(x86)%\BonanzaDealsLive%UserProfile%\Local Settings\Application Data\BonanzaDealsLive%UserProfile%\Start Menu\Programs\BonanzaDeals
The following URL's were detected:
BonanzaDeals
Loading...