Home Malware Programs Adware EmailDescontos

EmailDescontos

Posted: June 30, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 2,515
First Seen: May 29, 2015
Last Seen: May 24, 2023
OS(es) Affected: Windows

EmailDescontos is a typical adware plugin, created on the AdwareROI platform. It promises to improve your on-line shopping experience by keeping you informed of the best deals and offers at the moment. However, the displayed discounts and coupons are unlikely to save you money. The true goal of the ads is to increase the popularity of some sponsored third-party pages. They may be newly created e-commerce sites, but may also host some questionable software. You should ignore the ads for the sake of keeping your PC safe. The developers of EmailDescontos earn revenues for each page impression they create, so they make everything possible to trick you into clicking on the ads. The pop-ups, banners and interstitial ads may be in considerable amounts and may even correspond to your needs properly. The latter happens because the adware monitors your on-line activities, including the history of visited pages. The presence of EmailDescontos often impairs the performance of the browser, no matter if you prefer Google Chrome, Mozilla Firefox or Internet Explorer. All in all, this adware plugin doesn't benefit the majority of clients in any way, so you should take measures to delete it.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\Shell&ServicesEngine\Shell&ServicesEngine.exe File name: Shell&ServicesEngine.exe
Size: 8.19 KB (8192 bytes)
MD5: 377e76504d704a8e1df73282332e1ab6
Detection count: 138
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Shell&ServicesEngine\Shell&ServicesEngine.exe
Group: Malware file
Last Updated: May 18, 2022
C:\Program Files\Shell&ServicesEngine\Shell&ServicesEngine_updater_service.exe File name: Shell&ServicesEngine_updater_service.exe
Size: 6.14 KB (6144 bytes)
MD5: cb7cefa03dde6649f533085ef5370965
Detection count: 115
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Shell&ServicesEngine\Shell&ServicesEngine_updater_service.exe
Group: Malware file
Last Updated: May 18, 2022

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\emaildescontos_RASAPI32SOFTWARE\Microsoft\Tracing\emaildescontos_RASMANCSSOFTWARE\Microsoft\Tracing\emaildescontos_updater_service_RASAPI32SOFTWARE\Microsoft\Tracing\emaildescontos_updater_service_RASMANCSSYSTEM\ControlSet001\services\emaildescontosSYSTEM\ControlSet001\services\emaildescontos_updater_serviceSYSTEM\ControlSet001\services\eventlog\Application\emaildescontosSYSTEM\ControlSet001\services\eventlog\Application\emaildescontos_updater_serviceSYSTEM\ControlSet001\services\eventlog\Application\NetworkAnalyser[ADWARE_ROI]SYSTEM\ControlSet002\services\eventlog\Application\emaildescontosSYSTEM\ControlSet002\services\eventlog\Application\emaildescontos_updater_serviceSYSTEM\CurrentControlSet\services\emaildescontosSYSTEM\CurrentControlSet\services\emaildescontos_updater_serviceSYSTEM\CurrentControlSet\services\eventlog\Application\emaildescontosSYSTEM\CurrentControlSet\services\eventlog\Application\emaildescontos_updater_serviceSYSTEM\CurrentControlSet\services\eventlog\Application\NetworkAnalyser[ADWARE_ROI]

Additional Information

The following directories were created:
%PROGRAMFILES%\emaildescontos%PROGRAMFILES(x86)%\emaildescontos
Loading...