Home Malware Programs Adware Outrageous Deal Ads

Outrageous Deal Ads

Posted: November 9, 2015

Threat Metric

Ranking: 11,013
Threat Level: 2/10
Infected PCs: 7,164
First Seen: November 9, 2015
Last Seen: October 15, 2023
OS(es) Affected: Windows

Outrageous Deal is a web browser extension that is advertised as a useful utility that can help online shoppers save time and money. The purpose of the Outrageous Deal Web browser extension is to provide its users with information about running promotions, coupon codes, and special offers related to products and services that may be relevant to the user's interests. However, all these product offers and special discounts may be accompanied by a fair number of aggressive ads and pop-ups which may make the user's browsing experience less enjoyable.

The Outrageous Deal browser extension is detected as adware by anti-malware software, so its suspicious behavior shouldn't come as a surprise. Outrageous Deal may be distributed via software bundles and offered as an optional component to install during the installation process of new applications. The installation of Outrageous Deal may be offered using misleading instructions and messages, therefore making it more likely that users will be tricked into agreeing to install this application.

Once Outrageous Deal is installed it may start injecting ads in all active instances of Web browsers on the target's computer. The advertisements may be part of a paid advertising campaign that promotes legitimate Web destinations, but there have been cases In which adware like Outrageous Deal has been used to promote compromised Web pages, suspicious files and other harmful content.

Aliases

GrayWare[AdWare:not-a-virus]/NSIS.BrowseFox [Antiy-AVL]Trojan.Yontoo.3094 [DrWeb]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%COMMONPROGRAMFILES%\65ad47d7-2e27-4a5c-b238-26643fdaeb98\updater.exe File name: updater.exe
Size: 604.89 KB (604896 bytes)
MD5: 76a601f46623676988b89256da959b06
Detection count: 60
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\65ad47d7-2e27-4a5c-b238-26643fdaeb98
Group: Malware file
Last Updated: December 11, 2015
%ALLUSERSPROFILE%\Anwendungsdaten\65ad47d7-2e27-4a5c-b238-26643fdaeb98\plugincontainer.exe File name: plugincontainer.exe
Size: 729.31 KB (729312 bytes)
MD5: 292f2edb763fc1d28dfa1334dc50be6d
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Anwendungsdaten\65ad47d7-2e27-4a5c-b238-26643fdaeb98
Group: Malware file
Last Updated: December 11, 2015
%ALLUSERSPROFILE%\Anwendungsdaten\65ad47d7-2e27-4a5c-b238-26643fdaeb98\plugincontainer.exe File name: plugincontainer.exe
Size: 729.31 KB (729312 bytes)
MD5: 0037a1bfa1d21ee0e5a40a52103a3ae2
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Anwendungsdaten\65ad47d7-2e27-4a5c-b238-26643fdaeb98
Group: Malware file
Last Updated: December 11, 2015
%COMMONPROGRAMFILES%\65ad47d7-2e27-4a5c-b238-26643fdaeb98\updater.exe File name: updater.exe
Size: 606.43 KB (606432 bytes)
MD5: 9d8326441300e57149903c52e6216597
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\65ad47d7-2e27-4a5c-b238-26643fdaeb98
Group: Malware file
Last Updated: December 11, 2015

Registry Modifications

The following newly produced Registry Values are:

CLSID{3A69CDF2-B56C-48D3-BB9B-ED2925AEE772}{4e2d2bf0-159f-4257-acf0-b1f29b376fa0}{4E7249F6-3124-4E09-BCA9-AE2B09F3D83E}{A3EC21A2-6923-4D87-A921-1BAC675ADF04}{cf4fb361-8f8e-4e04-8011-822cb0d1b082}{daa7a7c8-2d77-4032-b692-68ad96eb44ed}{EE786009-4939-4394-A6B3-2351DF7D49CF}File name without pathhttps_outrageousdeal-a.akamaihd.net_0.localstoragehttps_outrageousdeal-a.akamaihd.net_0.localstorage-journalHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{4e2d2bf0-159f-4257-acf0-b1f29b376fa0}Software\Microsoft\Internet Explorer\Approved Extensions\{EE786009-4939-4394-A6B3-2351DF7D49CF}Software\Microsoft\Internet Explorer\DOMStorage\outrageousdeal-a.akamaihd.netSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{4e2d2bf0-159f-4257-acf0-b1f29b376fa0}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4e2d2bf0-159f-4257-acf0-b1f29b376fa0}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e2d2bf0-159f-4257-acf0-b1f29b376fa0}SOFTWARE\OutrageousDealSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{4e2d2bf0-159f-4257-acf0-b1f29b376fa0}SOFTWARE\Wow6432Node\OutrageousDealSYSTEM\ControlSet001\services\Service Mgr OutrageousDealSYSTEM\ControlSet001\services\Update Mgr OutrageousDealSYSTEM\ControlSet002\services\Service Mgr OutrageousDealSYSTEM\ControlSet002\services\Update Mgr OutrageousDealSYSTEM\CurrentControlSet\services\Service Mgr OutrageousDealSYSTEM\CurrentControlSet\services\Update Mgr OutrageousDealHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Outrageous Deal

Additional Information

The following directories were created:
%PROGRAMFILES%\Outrageous Deal%PROGRAMFILES(x86)%\Outrageous Deal%TEMP%\Outrageous Deal
Loading...