Home Malware Programs Adware Discount Buddy

Discount Buddy

Posted: March 27, 2013

Threat Metric

Ranking: 13,273
Threat Level: 2/10
Infected PCs: 3,860
First Seen: March 27, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

Discount Buddy Screenshot 1Discount Buddy is a potentially unwanted program made by 215 apps for Internet Explorer, Mozilla Firefox and Google Chrome that is usually added when PC users install other free applications. Deal Boat will display ads, coupons and sponsored links via a pop-up box on Amazon, Walmart, Ebay and other shopping websites that PC users are visiting. These pop-up ads will be displayed as boxes, which include a variety of coupons that are available or as underlined keywords, which when clicked will illustrate a pop-up ad that declares it is sent to the target computer user by Deal Boat. When Internet users install free applications, they will also install Deal Boat. When installed, Deal Boat will illustrate a box, which includes related keyword suggestions, ads and sponsored links, in the right top part of the hijacked web browser, whenever the computer user will surf Facebook, Expedia, Best Buy or any other similar websites.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110211671166}{22222222-2222-2222-2222-220222672266}{44444444-4444-4444-4444-440244674466}{55555555-5555-5555-5555-550255675566}{66666666-6666-6666-6666-660266676666}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Discount BuddySOFTWARE\Classes\CrossriderApp0026766.BHOSOFTWARE\Classes\CrossriderApp0026766.BHO.1SOFTWARE\Classes\CrossriderApp0026766.SandboxSOFTWARE\Classes\CrossriderApp0026766.Sandbox.1Software\InstalledBrowserExtensions\215 Apps\26766Software\InstalledBrowserExtensions\Innovative Apps\26766SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211671166}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31111111-1111-1111-1111-110211671166}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater26766.exeSOFTWARE\Proxy\Installations\Discount BuddySOFTWARE\Wow6432Node\Discount BuddySOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211671166}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211671166}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Discount Buddy-bg.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\Discount Buddy_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Discount Buddy_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\Updater26766_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Updater26766_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211671166}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Discount Buddy

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Discount Buddy%LOCALAPPDATA%\Discount Buddy%LOCALAPPDATA%\Updater26766%PROGRAMFILES%\Discount Buddy%PROGRAMFILES(x86)%\Discount Buddy%UserProfile%\Local Settings\Application Data\Discount Buddy%UserProfile%\Local Settings\Application Data\Updater26766
The following URL's were detected:
Discount Buddy
Loading...