Home Malware Programs Adware Adware.OffersWizard

Adware.OffersWizard

Posted: December 6, 2013

Threat Metric

Ranking: 10,935
Threat Level: 2/10
Infected PCs: 100,141
First Seen: December 6, 2013
Last Seen: March 8, 2025
OS(es) Affected: Windows

Aliases

Generic PUA JF [Sophos]Win32:Amonetize-CW [PUP] [Avast]Mal/Generic-L [Sophos]Trojan-Downloader.Win32.Agent.aadeh [Kaspersky]Win32:Downloader-VLT [Trj] [Avast]PUA.Gen [Symantec]PUP-Amonetize!38FA2BAF42C2 [McAfee]Malware/Win32.Generic [AhnLab-V3]Generic PUA NB [Sophos]Application.Win32.Amonetize.NZ [Comodo]Win32:Downloader-VLS [Trj] [Avast]Generic_r.PM [AVG]Mal/Generic-S [Sophos]Adware.Downware.6304 [DrWeb]ApplicUnwnt [Comodo]
More aliases (272)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\ver2OffersWizard\190.dll File name: 190.dll
Size: 496.12 KB (496128 bytes)
MD5: c57f160f4f68b467e8f9d30a06625794
Detection count: 1,166
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files\ver2OffersWizard\190.dll
Group: Malware file
Last Updated: April 1, 2023
%WINDIR%\SysWOW64\netupdsrv.exe File name: netupdsrv.exe
Size: 162.3 KB (162304 bytes)
MD5: e36f1cdbcfbe9dfff365b0e27232cb47
Detection count: 663
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: May 10, 2016
%WINDIR%\SysWOW64\nethtsrv.exe File name: nethtsrv.exe
Size: 369.66 KB (369664 bytes)
MD5: a36e55b3f9d3320d6f2473d4d6d6183b
Detection count: 557
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: November 26, 2019
c:\windows\system32\drivers\nethfdrv.sys File name: nethfdrv.sys
Size: 40.52 KB (40528 bytes)
MD5: 86c16406027af7b6bbb676c8038f4e6b
Detection count: 452
File type: System file
Mime Type: unknown/sys
Path: c:\windows\system32\drivers\nethfdrv.sys
Group: Malware file
Last Updated: March 3, 2025
%PROGRAMFILES%\ver2OffersWizard\B9eG190.exe File name: B9eG190.exe
Size: 442.86 KB (442861 bytes)
MD5: dec6bf6338138379eac5220d434ae807
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ver2OffersWizard
Group: Malware file
Last Updated: March 23, 2016
%PROGRAMFILES%\ver2OffersWizard\e6OffersWizard66.exe File name: e6OffersWizard66.exe
Size: 726.96 KB (726968 bytes)
MD5: 7eb7f61e6f34a9ec18ad568aa1e00076
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\ver2OffersWizard
Group: Malware file
Last Updated: March 23, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\SysWOW64\hfnapi.dllHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OffersWizard updateSoftware\OffersWizardSYSTEM\ControlSet001\Enum\Root\LEGACY_NETHFDRVSYSTEM\ControlSet001\services\nethfdrvSYSTEM\ControlSet001\services\NetHttpServiceSYSTEM\ControlSet002\Enum\Root\LEGACY_NETHFDRVSYSTEM\ControlSet002\services\nethfdrvSYSTEM\ControlSet002\services\NetHttpServiceSYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETHFDRVSYSTEM\CurrentControlSet\services\nethfdrvSYSTEM\CurrentControlSet\services\NetHttpServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}inethnfdOffersWizard
Loading...