Home Malware Programs Adware CheapNEnjoy

CheapNEnjoy

Posted: January 16, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 23
First Seen: January 15, 2015
Last Seen: April 8, 2022
OS(es) Affected: Windows

CheapNEnjoy is a PUP that forces your Web browsers to load additional content promoting its advertising partners. Adware like CheapNEnjoy shouldn't be assumed to be a threat, but, as a consequence of its automatically-delivered advertisements, may cause security issues for any browser. Although malware researchers do suggest removing CheapNEnjoy, any attempted removal methods also should be able to identify other PUPs or even threats that might have installed CheapNEnjoy automatically.

The Advertising Enjoyment that's Forced upon You

CheapNEnjoy is adware that most recently saw abuse in campaigns installing multiple brands of adware, and other forms of Potentially Unwanted Programs, at the same time. Trojan downloaders such as Rogue.Multiple, along with compromised installers of the Popcorn Time service, are the currently estimated infection vectors. In 2014, malware researchers also saw unofficial Popcorn Time installers distributing PUPs like VideoCnv, Giftssoft and ClipCnv, although this list is by no means complete. Confirmation for CheapNEnjoy use of these distribution methods came in 2014's last month and continuing into January of the new year.

Once CheapNEnjoy has been installed, CheapNEnjoy modifies your browser in much the same manner as prior adware, including such 'features' as:

  • Editing pages your browser loads to include new advertisements. Advertisements from CheapNEnjoy extensions may include both graphical elements, such as product comparison windows, as well as text-based ones, such as keyword-cued hyperlinks.
  • CheapNEnjoy also may monitor which websites load in your browser, as well as which search terms you enter, to display content related to keywords.
  • Depending on the manner of CheapNEnjoy's installation, you also may see a CheapNEnjoy entry in your browser's extension manager. The presence or lack of this entry does not necessarily affect the settings changes made by CheapNEnjoy for loading its advertisements.

Enjoying a Cheap Exit from a CheapNEnjoy Add-On

CheapNEnjoy advertisements may slow your browser's loading times, cause problems with accessing websites or even risk exposing your PC to attacks delivered through their content, such as fake software updates. Other PUPs also may be installed with CheapNEnjoy, with recent partners including AZLyrics, Ads by ReMarkable and EasToBuy. These three products also deliver browser advertisements in formats similar to CheapNEnjoy's own, although, in most cases, advertisements will be provided with identifiable tags of their origins.

CheapNEnjoy, like most of its compatriots, also includes some functions meant to prevent PC users from uninstalling CheapNEnjoy through standard procedures, such as via your browser's extensions menu. Deleting CheapNEnjoy entirely, along with advertisements and associated PUPs, should be viable for any anti-adware program that's competent and armed with the latest threat definitions available. PCs displaying symptoms of an unwanted CheapNEnjoy installation should enjoy complete scans by such security solutions, ideally with additional protection, such as Safe Mode.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\ProgramData\cheapnenjoy\cheapnenjoy.exe File name: C:\ProgramData\cheapnenjoy\cheapnenjoy.exe
MD5: 79f9311ac6a5009fef1a5756a0a529d3
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
"C:\ProgramData\cheapnenjoy\cheapnenjoy.exe" /progname=cheapnenjoy /progver=3.4.2 /progpub=cheapnenjoy /proguninstallurl=asdahjka.com /deleteappfolder File name: "C:\ProgramData\cheapnenjoy\cheapnenjoy.exe" /progname=cheapnenjoy /progver=3.4.2 /progpub=cheapnenjoy /proguninstallurl=asdahjka.com /deleteappfolder
Mime Type: unknown/com /deleteappfolder
Group: Malware file

Additional Information

The following URL's were detected:
installerex.com
Loading...