Home Malware Programs Adware Deal Fairy

Deal Fairy

Posted: June 18, 2013

Threat Metric

Ranking: 10,928
Threat Level: 2/10
Infected PCs: 4,998
First Seen: June 18, 2013
Last Seen: September 19, 2023
OS(es) Affected: Windows

Deal Fairy is an adware program that displays advertisements, coupons and sponsored links via a pop-up box on Amazon, Walmart, Ebay and other shopping websites that web users are visiting. Deal Fairy pop-up advertisements will be displayed as boxes, which contain numerous coupons that are available or as underlined keywords, which when clicked will show a pop-up advertisement that claims it is sent to you by DealFairy. Deal Fairy is an extension for Internet Explorer, Mozilla Firefox and Google Chrome that is usually added when computer users install another free program, such as video recording/streaming, download-managers or PDF creators, that had bundled into their installation Deal Fairy. When PC users install these free software programs, they will also install Deal Fairy. When installed, whenever the computer user will visit Expedia, Best Buy, Facebook or any other similar websites, Deal Fairy will display a 'See Similar' button on product images, which when clicked will display pop-up ads by Deal Fairy. Deal Fairy may also show advertising banners on the websites that Internet users are visiting, and as they browse the web, Deal Fairy will display coupons and other deals available on numerous websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



df21.exe File name: df21.exe
Size: 1.17 MB (1176225 bytes)
MD5: fb2e910f09510c13f18484e18effe549
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{2CA83CAD-84D1-4A4D-B6E4-645515A32A7A}Software\Microsoft\Internet Explorer\Approved Extensions\{963B125B-8B21-49A2-A3A8-E37092276531}

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\gdbneecmoiogmieamidpejdifipmkfgb%PROGRAMFILES%\dealfairytb%PROGRAMFILES(x86)%\dealfairytb%USERPROFILE%\AppData\LocalLow\dealfairytb
Loading...