Home Malware Programs Adware Toolbar.Dealio

Toolbar.Dealio

Posted: July 24, 2009

Threat Metric

Ranking: 3,618
Threat Level: 2/10
Infected PCs: 12,699
First Seen: July 24, 2009
Last Seen: October 16, 2023
OS(es) Affected: Windows

Dealio Toolbar is an add-on component that finds its way onto popular web browsers. The installation of Dealio Toolbar, known to take place from bundled software installs, may attempt to offer other shortcut services to various websites on the internet. Additionally, Dealio Toolbar will attempt to offer coupon and deal offers for shopping online. These offers may be laced with several advertisements and misleading propaganda. Most times the Dealio Toolbar and its components will change the default home page and default search engine making it a seriously aggravating situation for computer users who want to load their preferred page when opening a new browser window. The removal of Dealio Toolbar and its components is usually accomplished through use of an updated antispyware application.

Aliases

Dealio Installer [Sophos]BackDoor.Sturf.48 [DrWeb]Artemis!4AC870C6DA03 [McAfee]Win32/Adware.Toolbar.Dealio [NOD32]Artemis!DF13B8F5A476 [McAfee+Artemis]Unclassified Malware [Comodo]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\IObit Toolbar\IE\4.1\iobitToolbarIE.dll File name: iobitToolbarIE.dll
Size: 726.01 KB (726016 bytes)
MD5: d6e6c591e43f17981cd32eeb792742a3
Detection count: 1,731
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\IObit Toolbar\IE\4.1\iobitToolbarIE.dll
Group: Malware file
Last Updated: June 1, 2023
%SYSTEMDRIVE%\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\YTD Toolbar\WidgiHelper.exe File name: WidgiHelper.exe
Size: 112.44 KB (112448 bytes)
MD5: 77b1b2b4bacd122a78bb58ac56f897ed
Detection count: 227
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\YTD Toolbar\WidgiHelper.exe
Group: Malware file
Last Updated: August 17, 2022
file.exe File name: file.exe
Size: 4.26 MB (4262792 bytes)
MD5: b32ca052601c77a68056c5f342f8f6f2
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022
C:\Program Files\Dealio\kb126\Dealio Deskbar.exe File name: Dealio Deskbar.exe
Size: 4.15 MB (4154120 bytes)
MD5: df13b8f5a476b1022c5730eec66b4515
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Dealio\kb126\Dealio Deskbar.exe
Group: Malware file
Last Updated: January 28, 2021
C:\Users\<username>\Downloads\Personalize seu msn\emotions\free-msn-emoticons-pack-01-ingles.exe File name: free-msn-emoticons-pack-01-ingles.exe
Size: 875.12 KB (875126 bytes)
MD5: 4ac870c6da035d325b14f8325101ae5b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\Personalize seu msn\emotions\free-msn-emoticons-pack-01-ingles.exe
Group: Malware file
Last Updated: February 25, 2021

Registry Modifications

The following newly produced Registry Values are:

CLSID{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\DealioSOFTWARE\Classes\Installer\Products\31DF8B43BC380E4468DAEEF4766B6F16Software\DealioSoftware\Microsoft\Internet Explorer\Approved Extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}Software\Microsoft\Internet Explorer\UrlSearchHooks\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}SOFTWARE\Wow6432Node\DealioSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{4F30976E-356B-45F3-A760-66954ED55893}{B9123641-0094-4C1D-A181-627F725FD122}{D7BB45D3-1001-431D-A01E-11E407790E9A}

Additional Information

The following directories were created:
%ProgramFiles%\Dealio Toolbar%ProgramFiles(x86)%\Dealio Toolbar%USERPROFILE%\AppData\LocalLow\Dealio%USERPROFILE%\Application Data\Dealio
Loading...