Home Malware Programs Adware Deal Boat

Deal Boat

Posted: March 27, 2013

Threat Metric

Ranking: 11,572
Threat Level: 2/10
Infected PCs: 1,391
First Seen: March 27, 2013
Last Seen: August 26, 2023
OS(es) Affected: Windows

Deal Boat Screenshot 1Deal Boat is a potentially unwanted program produced by 215 apps for Internet Explorer, Mozilla Firefox and Google Chrome that is typically added when computer users install other free software. Deal Boat will display advertisements, coupons and sponsored links via a pop-up box on Amazon, Walmart, Ebay and other shopping websites that Internet users are visiting. These pop-up advertisements will be illustrated as boxes, which contain numerous coupons that are available or as underlined keywords, which when clicked will show a pop-up advertisement that claims it is sent to the affected web user by Deal Boat. When web users install free software products, they will also install Deal Boat. Once installed, Deal Boat will show a box, which contains related keyword suggestions, ads and sponsored links, in the right top part of the hacked web browser, whenever the PC user will browse Facebook, Expedia, Best Buy or any other similar websites.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110111271147}{22222222-2222-2222-2222-220122272247}{44444444-4444-4444-4444-440144274447}{55555555-5555-5555-5555-550155275547}{66666666-6666-6666-6666-660166276647}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Deal BoatSOFTWARE\Classes\CrossriderApp0012747.BHOSOFTWARE\Classes\CrossriderApp0012747.BHO.1SOFTWARE\Classes\CrossriderApp0012747.SandboxSOFTWARE\Classes\CrossriderApp0012747.Sandbox.1Software\Cr_Installer\12747SOFTWARE\Deal BoatSoftware\InstalledBrowserExtensions\215 Apps\12747SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater12747.exeSOFTWARE\Proxy\Installations\Deal BoatSOFTWARE\Wow6432Node\Deal BoatSOFTWARE\Wow6432Node\Microsoft\Tracing\Deal Boat_RASAPI32SOFTWARE\Wow6432Node\Proxy\Installations\Deal BoatHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Deal Boat

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Deal Boat%LOCALAPPDATA%\Deal Boat%LOCALAPPDATA%\Updater12747%PROGRAMFILES%\Deal Boat%PROGRAMFILES(x86)%\Deal Boat
The following URL's were detected:
Deal Boat
Loading...