Home Malware Programs Adware Shop for Rewards

Shop for Rewards

Posted: October 7, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 16,437
First Seen: October 7, 2014
Last Seen: December 4, 2024
OS(es) Affected: Windows


Shop for Rewards is an adware application that may be designed for displaying random ads that try to offer random shopping discounts or coupon deals. Use of the Shop for Rewards ads may cause redirects on most popular web browsers. Through the sites that Shop for Rewards ads may load up some computer users will find the content to be unwanted and questionable in some cases. Stopping the annoyances of Shop for Rewards may take finding its components or plugins and removing each of them. The removal process for Shop for Rewards may be done automatically by use of an updated antimalware application.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\SysWOW64\lsrvc.exe File name: lsrvc.exe
Size: 191.8 KB (191800 bytes)
MD5: dc65dae62f1f9809dfeece6b8d2824aa
Detection count: 7,424
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: January 12, 2020
file.exe File name: file.exe
Size: 1.98 MB (1988608 bytes)
MD5: dd0fbfa6f04b3aecc275ea05a04c28fb
Detection count: 8
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 8, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{0902EBD9-C5B4-4400-8CF1-7ACA8E8805D9}{2AABD627-FCAB-4bc6-8DA7-1A87510BC0CF}{5075DFCC-F3F5-4B15-B364-270BC7C585AD}{787D3F9B-69C6-427c-BF55-4419F932474A}{895F78F3-9620-49AD-8AA8-E6802E5AC64E}{9AE7A6AE-162E-44C4-9A2B-A6B4EF19909D}{BF883488-0379-470e-8BF2-C5D1F3828428}{D52F7CE0-A4BA-4220-A907-444CB6158A09}{E4C3E50F-5761-4BF8-95A0-939A819DF1C3}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\AppID\eson32.DLLSOFTWARE\Classes\Extension.ehlpoSOFTWARE\Classes\Extension.ehlpo.1SOFTWARE\Classes\Wow6432Node\AppID\eson32.DLLSoftware\Microsoft\Internet Explorer\Approved Extensions\{BF883488-0379-470e-8BF2-C5D1F3828428}Software\Microsoft\Internet Explorer\Stats\{BF883488-0379-470e-8BF2-C5D1F3828428}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{BF883488-0379-470e-8BF2-C5D1F3828428}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Shop For RewardsSOFTWARE\Microsoft\Windows\CurrentVersion\Run\Shop For Rewards64SOFTWARE\Mozilla\Firefox\Extensions\{BF883488-0379-470e-8BF2-C5D1F3828428}SOFTWARE\Shop For RewardsSOFTWARE\Wow6432Node\Classes\AppID\eson32.DLLSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{BF883488-0379-470e-8BF2-C5D1F3828428}SOFTWARE\Wow6432Node\Mozilla\Firefox\Extensions\{BF883488-0379-470e-8BF2-C5D1F3828428}SOFTWARE\Wow6432Node\Shop For RewardsSYSTEM\ControlSet001\services\0A053C05-52A5-49a0-9B9B-AC9FC38D7FF0SYSTEM\ControlSet001\services\Shop For Rewards UpdaterSYSTEM\CurrentControlSet\services\0A053C05-52A5-49a0-9B9B-AC9FC38D7FF0SYSTEM\CurrentControlSet\services\Shop For Rewards UpdaterHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{BF883488-0379-470e-8BF2-C5D1F3828428}_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\Shop For Rewards%PROGRAMFILES(x86)%\Shop For Rewards
Loading...