Home Malware Programs Adware Bonanza Deals

Bonanza Deals

Posted: September 24, 2013

Threat Metric

Ranking: 2,456
Threat Level: 2/10
Infected PCs: 178,850
First Seen: September 24, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

Bonanza Deals is an adware application that may be installed onto Internet Explorer, Mozilla Firefox and Google Chrome. Bonanza Deals may add a browser extension that displays numerous messages while the target PC user is surfing the Internet. Bonanza Deals may also display numerous annoying pop-up ads that include coupons with discounts and other offers. Bonanza Deals expects computer users to click on these pop-up advertisements. Bonanza Deals attempts to raise traffic of commercial websites and make money from affiliate links. Bonanza Deals may redirect affected web users to dubious advertising websites and disturb the PC user's work with repeated pop-up advertisements and messages. Bonanza Deals may als pose risk to the affected Internet user's privacy and security. Bonanza Deals may keep track of the target PC user's browsing activities, that is what websites he is visiting, what information he enters while browsing on the web and other details. Then, Bonanza Deals may transfer this data to remote attackers.

Aliases

Adware.Shopper.363 [DrWeb]Application.Win32.Bonanza.gr [Comodo]Adware.BL [Symantec]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Downloads\Software\uninstall.exe File name: uninstall.exe
Size: 821.76 KB (821760 bytes)
MD5: b52c9369cfd0b07290aa3deba1599ab6
Detection count: 11,767
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Downloads\Software\uninstall.exe
Group: Malware file
Last Updated: September 25, 2024
D:\Program Files\DVD Maker\DealPly\Conduit\Camfrog\BonanzaDealsLive\BonanzaDeals\BonanzaDealsIE.dll File name: BonanzaDealsIE.dll
Size: 100.33 KB (100336 bytes)
MD5: cfe165943ae6cd3de8213856a1c66016
Detection count: 1,314
File type: Dynamic link library
Mime Type: unknown/dll
Path: D:\Program Files\DVD Maker\DealPly\Conduit\Camfrog\BonanzaDealsLive\BonanzaDeals\BonanzaDealsIE.dll
Group: Malware file
Last Updated: January 10, 2025
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDeals\BonanzaDealsUpdate.exe.vir File name: BonanzaDealsUpdate.exe.vir
Size: 78.38 KB (78384 bytes)
MD5: 5826462e5834594a81e0397a097b5d3e
Detection count: 1,269
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\BonanzaDeals\BonanzaDealsUpdate.exe.vir
Group: Malware file
Last Updated: January 10, 2025
C:\Program Files (x86)\700,000 Games\Game Collection 700,000\4500 Vegas Slots Bonus Bonanza\VegasBonusSlots.exe File name: VegasBonusSlots.exe
Size: 3.36 MB (3366967 bytes)
MD5: 5455684f1d75091f5ddef8e0a97dca49
Detection count: 108
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\700,000 Games\Game Collection 700,000\4500 Vegas Slots Bonus Bonanza\VegasBonusSlots.exe
Group: Malware file
Last Updated: April 15, 2024
%PROGRAMFILES%\Cooperweb\BackUpBonanza\BAT\JimBakUp.bat File name: JimBakUp.bat
Size: 6.63 KB (6637 bytes)
MD5: 7dbd136597004df276d615ad71938017
Detection count: 68
File type: Batch file
Mime Type: unknown/bat
Path: %PROGRAMFILES%\Cooperweb\BackUpBonanza\BAT
Group: Malware file
Last Updated: January 30, 2014
%APPDATA%\UpdateBonanza\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 99.84 KB (99840 bytes)
MD5: 07a480e25bb4697adc28212471115899
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\UpdateBonanza\UpdateProc
Group: Malware file
Last Updated: March 23, 2016
C:\System Volume Information\SystemRestore\AppxStaging\Program Files\WindowsApps\Infiapps.SlotBonanza_1.0.0.61_x64__kjw77hz2at8sa\SlotBonanza.exe File name: SlotBonanza.exe
Size: 171 KB (171008 bytes)
MD5: a5b7df6a53c1d440804de9483f9f7406
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\System Volume Information\SystemRestore\AppxStaging\Program Files\WindowsApps\Infiapps.SlotBonanza_1.0.0.61_x64__kjw77hz2at8sa\SlotBonanza.exe
Group: Malware file
Last Updated: July 18, 2021
%PROGRAMFILES%\Selectsoft\Business Card Bonanza\printgenerator.exe File name: printgenerator.exe
Size: 4.44 MB (4440064 bytes)
MD5: 8a78b12c248f64edbec6b5d9ffd4680f
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Selectsoft\Business Card Bonanza
Group: Malware file
Last Updated: May 27, 2019

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{118E1BF6-6279-432F-A285-373A77B90C7A}{14CEEA2F-3D21-46ED-A7D2-89056C520E5E}{1CC8D970-F626-4F19-815F-890032BB6606}{29494049-211F-4F5C-8545-7DA8BF7A6CF8}{33BAF587-9647-4281-A34F-F4830CDC1B9F}{5B5E5D0E-7C83-4A32-ADD2-E5F488DD6783}{6802463D-636F-41FE-9924-4CAD56906590}{806785D0-375F-4C2C-92E3-B8EE65D28E83}{944661E7-67B9-4DF7-BFF2-05388C166D34}{9EA8702C-EEDB-4731-BE68-E9A167DD3597}{A7CF66EF-4F0D-46B1-AF71-A500378D6C34}{B71934E5-6B93-448D-9D32-CBAA5150C5D8}{C4BEF720-313C-420A-ACF6-77DD95D8F553}{D34F391D-4CB7-467F-A543-F583857C63B0}{E970727E-0508-4BEB-8B72-BBA9D0D047C7}{EBF1F869-D2F0-4D31-A877-386C853A9C3D}{F3CF4912-CF0A-451B-AF3B-C4F216C715E4}{F904AC50-215C-42AB-A532-77E9FDBA9B19}{fe063412-bea4-4d76-8ed3-183be6220d17}File name without pathBonanzaDealsLiveUpdateTaskMachineCore.jobBonanzaDealsLiveUpdateTaskMachineUA.jobRegexp file mask%PROGRAMFILES%\BonanzaDealsLive\Update\BonanzaDealsLive.exe%PROGRAMFILES(x86)%\BonanzaDealsLive\Update\BonanzaDealsLive.exeHKEY..\..\..\..{RegistryKeys}Software\BonanzaDealsSoftware\BonanzaDealsLiveSOFTWARE\Classes\AppID\BonanzaDealsLive.exeSOFTWARE\Classes\BonanzaDealsLive.OneClickCtrl.9SOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachineSOFTWARE\Classes\BonanzaDealsLive.OneClickProcessLauncherMachine.1.0SOFTWARE\Classes\BonanzaDealsLive.Update3WebControl.3SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsyncSOFTWARE\Classes\BonanzaDealsLiveUpdate.CoCreateAsync.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClassSOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreClass.1SOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClassSOFTWARE\Classes\BonanzaDealsLiveUpdate.CoreMachineClass.1SOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachineSOFTWARE\Classes\BonanzaDealsLiveUpdate.CredentialDialogMachine.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineSOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachine.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallbackSOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassMachineFallback.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvcSOFTWARE\Classes\BonanzaDealsLiveUpdate.OnDemandCOMClassSvc.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncherSOFTWARE\Classes\BonanzaDealsLiveUpdate.ProcessLauncher.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassServiceSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3COMClassService.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachine.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallbackSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebMachineFallback.1.0SOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvcSOFTWARE\Classes\BonanzaDealsLiveUpdate.Update3WebSvc.1.0SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.oneclickctrl.9SOFTWARE\Classes\MIME\Database\Content Type\application/x-vnd.bdliveupdate.update3webcontrol.3SOFTWARE\Classes\Wow6432Node\AppID\BonanzaDealsLive.exeSoftware\Microsoft\Internet Explorer\Approved Extensions\{fe063412-bea4-4d76-8ed3-183be6220d17}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineCoreSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsLiveUpdateTaskMachineUASOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\BonanzaDealsUpdateSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063412-BEA4-4D76-8ED3-183BE6220D17}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4BEF720-313C-420A-ACF6-77DD95D8F553}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063412-BEA4-4D76-8ED3-183BE6220D17}SOFTWARE\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3SOFTWARE\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9SOFTWARE\Wow6432Node\BonanzaDealsSOFTWARE\Wow6432Node\BonanzaDealsLiveSOFTWARE\Wow6432Node\Classes\AppID\BonanzaDealsLive.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{33BAF587-9647-4281-A34F-F4830CDC1B9F}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BonanzaDealsLive.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{fe063412-bea4-4d76-8ed3-183be6220d17}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{29494049-211F-4F5C-8545-7DA8BF7A6CF8}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{C4BEF720-313C-420A-ACF6-77DD95D8F553}SOFTWARE\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=3SOFTWARE\Wow6432Node\MozillaPlugins\@tools.bdupdater.com/BonanzaDealsLive Update;version=9SYSTEM\ControlSet001\services\bonanzadealsliveSYSTEM\ControlSet001\services\bonanzadealslivemSYSTEM\ControlSet002\Services\bonanzadealsliveSYSTEM\ControlSet002\services\bonanzadealslivemSYSTEM\CurrentControlSet\services\bonanzadealsliveSYSTEM\CurrentControlSet\services\bonanzadealslivemHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Bonanza Deals

Additional Information

The following directories were created:
%APPDATA%\UpdateBonanza%AllUsersProfile%\Application Data\BonanzaDealsLive%AllUsersProfile%\BonanzaDealsLive%AppData%\Microsoft\Windows\Start Menu\Programs\BonanzaDeals%LocalAppData%\BonanzaDealsLive%ProgramFiles%\BonanzaDeals%ProgramFiles%\BonanzaDealsLive%ProgramFiles(x86)%\BonanzaDeals%ProgramFiles(x86)%\BonanzaDealsLive%UserProfile%\Local Settings\Application Data\BonanzaDealsLive%UserProfile%\Start Menu\Programs\BonanzaDeals
The following URL's were detected:
BonanzaDeals
Loading...