Home Malware Programs Potentially Unwanted Programs (PUPs) PUP.FindBestDeal

PUP.FindBestDeal

Posted: March 18, 2014

Threat Metric

Ranking: 7,038
Threat Level: 2/10
Infected PCs: 51,173
First Seen: March 18, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


PUP.FindBestDeal is adware that loads advertisements in your Web browser while pretending that its advertisements provide shopping-related advantages, such as exclusive discounts or low prices. While malware analysts haven't found much of value from PUP.FindBestDeal's so-called best deals, they have found that PUP.FindBestDeal displays many traits common to Potentially Unwanted Programs that aren't advantageous to keep on your browser. Removing PUP.FindBestDeal always is encouraged for your browser's performance and safety, with anti-adware products having the best chances of doing so without any unnecessary stress for the PC user.

Why the 'Best' Deal is More Subjective Than PUP.FindBestDeal Might Indicate

PUP.FindBestDeal, also referred to as Find Best DEaL 1.5 (although malware experts have been unable to find any previous versions of this software) is another adware program that displays advertisements that, superficially, might seem to benefit your online shopping searches, while, in reality, provides few benefits, except to PUP.FindBestDeal's profit margins. PUP.FindBestDeal's masquerade hardly is an unusual one, but malware researchers have found some evidence that blurs the line between its classification as adware or as a threat: a suspicious program.

These negative traits include PUP.FindBestDeal concealing its files within randomly-named folders to prevent its deletion, along with other anti-deletion defenses that may reinstall PUP.FindBestDeal after its partial removal (albeit not ones stringent enough to block appropriate security products). Nonetheless, PUP.FindBestDeal's automatically-loaded, in-browser advertisements continue to be its most important symptoms, even though PUP.FindBestDeal's installation is, so far, limited to the Chrome browser.

Finding Your Way Away from the PUP.FindBestDeal Extension

Most of the characteristics surrounding PUP.FindBestDeal's implementation and overall distribution indicate that PUP.FindBestDeal is an update or clone of previous adware with similar limitations, which malware experts have seen being especially prolific in the past few months. Some related adware products following this pattern include UTAdRReMoovalAppa, ExstraCoupon, Shopdruopp, WatchItNoAds, RoboSavEr and Adware.Win32.FastSaveApp, most of which also claim that they provide online shopping discounts through their advertisements. Although Chrome is singled out as the browser of choice for all of these adware programs, other add-ons identical to PUP.FindBestDeal add-ons are just as able to compromise other brands of browsers.

Since PUP.FindBestDeal may conceal itself with randomly-named locations, using anti-adware scans for removing PUP.FindBestDeal is simpler, and sure to succeed, than trying to remove PUP.FindBestDeal manually. Malware researchers also stress that anti-adware and anti-malware tools also can detect the freely-downloaded bundles that are most likely to carry PUP.FindBestDeal and clones of similar adware to your hard drive.

Adware programs rarely exert especially strong security measures over their choices in advertisements. Even when PUP.FindBestDeal and other PUPs aren't categorized as threats, they may endanger your computer. Phishing attacks, tech support misleading tactics, exploits and other PC threats sometimes are found being promoted by adware unintentionally, and may ignore any advertisement-blocking functions your browser might have. As usual, exercising a little safety in your Web-browsing behavior can stall more troublesome problems later down the road.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\FindBestDEAl\2O_2BQ2n.dll File name: 2O_2BQ2n.dll
Size: 426.49 KB (426496 bytes)
MD5: 532932f33709b3aa82acfd24c619e661
Detection count: 124
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDEAl
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FiNdBestDoEaaL\_H.x64.dll File name: _H.x64.dll
Size: 478.72 KB (478720 bytes)
MD5: 8229b0429f40903367b6fea2a2d63137
Detection count: 96
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FiNdBestDoEaaL
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDeal\uoOr7Ko0.x64.dll File name: uoOr7Ko0.x64.dll
Size: 474.11 KB (474112 bytes)
MD5: 9ab52ac969d78ae005b5a24a9e7e4057
Detection count: 94
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FiNDBestDeual\nJFWrRA.x64.dll File name: nJFWrRA.x64.dll
Size: 471.55 KB (471552 bytes)
MD5: 6b2dd6d9da049383303f170cd7fe7a88
Detection count: 84
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FiNDBestDeual
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDeal\aKML9J.x64.dll File name: aKML9J.x64.dll
Size: 474.11 KB (474112 bytes)
MD5: 4d8b46c0e09d16345671c084539e0cd8
Detection count: 72
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDeal\YNC0jNVat.dll File name: YNC0jNVat.dll
Size: 425.47 KB (425472 bytes)
MD5: 784fe3aceaca6bbfa99fae1249d34499
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FInDBestDeal\SMVzskXW.dll File name: SMVzskXW.dll
Size: 424.44 KB (424448 bytes)
MD5: 5826dcedfa21a6f7daea343c32b4c8f4
Detection count: 52
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FInDBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FinidBestDeal\c2cZAwwI.x64.dll File name: c2cZAwwI.x64.dll
Size: 474.62 KB (474624 bytes)
MD5: 4ec63cf49b6f6600967e7ef5eb41faa5
Detection count: 51
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FinidBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FFindBestDeall\wKAR.dll File name: wKAR.dll
Size: 429.56 KB (429568 bytes)
MD5: c162a14911f88eedda62115baaf501cc
Detection count: 50
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FFindBestDeall
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FInddBestDeal\isbT.x64.dll File name: isbT.x64.dll
Size: 477.69 KB (477696 bytes)
MD5: aaec5458ebb1bb98b05dba2bd2957f13
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FInddBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDeal\R2sxejvb.dll File name: R2sxejvb.dll
Size: 425.47 KB (425472 bytes)
MD5: 40548046ec5f3ae422d5127c67c56414
Detection count: 31
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FINDBestDeaalu\w.x64.dll File name: w.x64.dll
Size: 476.67 KB (476672 bytes)
MD5: 6424efc20b33bd1989b679edc74f1566
Detection count: 31
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FINDBestDeaalu
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDDEal\b.dll File name: b.dll
Size: 483.67 KB (483676 bytes)
MD5: 94f1c3186ce4181f2aeb2eba1c23bc05
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDDEal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDEoal\1Ty.x64.dll File name: 1Ty.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 927c843918d4037e4fb08cf768f9b641
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDEoal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FIndBestDeall\cFc.dll File name: cFc.dll
Size: 425.98 KB (425984 bytes)
MD5: 977db6b0ab39484f2ddc0e58ddfb6ae7
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FIndBestDeall
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDeial\tt.dll File name: tt.dll
Size: 425.47 KB (425472 bytes)
MD5: 76862f6cede16ce206f564dc2d1c5977
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDeial
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\Datos de programa\FinddBEstDeal\UCmYiZblc_.dll File name: UCmYiZblc_.dll
Size: 424.96 KB (424960 bytes)
MD5: 17007d867052a397b5d8db2bab8dbeb2
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Datos de programa\FinddBEstDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FIndBestDeall\cFc.x64.dll File name: cFc.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: 2668407ddda7c600c6367af1a06008ba
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FIndBestDeall
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDaeAl\Z.x64.dll File name: Z.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: be68dcf55d874d92e9320bb667cc53e3
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDaeAl
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FiundBestDeal\T9IRzERefF.x64.dll File name: T9IRzERefF.x64.dll
Size: 476.67 KB (476672 bytes)
MD5: c1ea94c66990a58647e845cebc292a87
Detection count: 4
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FiundBestDeal
Group: Malware file
Last Updated: June 4, 2014
%ALLUSERSPROFILE%\FindBestDEal\NRtEBgu.x64.dll File name: NRtEBgu.x64.dll
Size: 473.08 KB (473088 bytes)
MD5: ec37182aa8bb40cfab0ba0f829c21ecc
Detection count: 3
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\FindBestDEal
Group: Malware file
Last Updated: June 4, 2014
C:\ProgramData\findbestdealZb.dll File name: C:\ProgramData\findbestdealZb.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\findbestdealZb.x64.dll File name: C:\ProgramData\findbestdealZb.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%ALLUSERSPROFILE%\Application Data\FiundBeStDeal\JED.dll File name: JED.dll
Size: 424.96 KB (424960 bytes)
MD5: 84239af6930ba0b26c506206c2f1b8b6
Detection count: 0
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Application Data\FiundBeStDeal
Group: Malware file
Last Updated: June 4, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{79C32D1E-68A2-06BD-03F2-5733A90BB27B}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\FindBestDeal%ALLUSERSPROFILE%\FindBestDeal%PROGRAMFILES%\FindBestDeal%PROGRAMFILES(x86)%\FindBestDeal
Loading...