Home Malware Programs Potentially Unwanted Programs (PUPs) SoftwareBundler:Win32/Protlerdob

SoftwareBundler:Win32/Protlerdob

Posted: October 29, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 33
First Seen: October 29, 2012
Last Seen: August 21, 2022
OS(es) Affected: Windows

SoftwareBundler:Win32/Protlerdob is a potentially unwanted program that presents itself as a free movie download, as an executable file such as "filme.exe", but instead, it comes bundled with numerous paid programs. Once installed on the compromised PC, SoftwareBundler:Win32/Protlerdob makes system changes by adding several files and registry entries. SoftwareBundler:Win32/Protlerdob also displays the certain images. Computer users may electively download SoftwareBundler:Win32/Protlerdob. SoftwareBundler:Win32/Protlerdob may set an uninstaller in the Add or Remove Programs window.

If SoftwareBundler:Win32/Protlerdob is run, a window will show up that looks like it's downloading offers. While the installation cannot be stopped through the GUI (graphical user interface), you can stop it by turning off your computer. Once the offers have been downloaded, the PC user will be presented with some offers. If the installation is continued, by clicking the 'Avancar' (Advance) button, one of the offers named DealPly, will be installed. The offers may show up in the Manage Add-ons window. One of the offers found is a horoscope service, which the computer user could sign up for, that would be sent to your mobile phone for the cost of a premium SMS. Finally, the computer user may get redirected to a website that offers paid movie downloads.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Documents and Settings%\All Users\Start Menu\Programs\DealPly File name: %Documents and Settings%\All Users\Start Menu\Programs\DealPly
Group: Malware file
%Documents and Settings%\All Users\Start Menu\Programs\Acelerador de Downloads File name: %Documents and Settings%\All Users\Start Menu\Programs\Acelerador de Downloads
Group: Malware file
%Documents and Settings%\All Users\Desktop\ CONTA PRIME.lnk File name: %Documents and Settings%\All Users\Desktop\ CONTA PRIME.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%Documents and Settings%\All Users\Desktop\Acelerador de Downloads.lnk File name: %Documents and Settings%\All Users\Desktop\Acelerador de Downloads.lnk
File type: Shortcut
Mime Type: unknown/lnk
Group: Malware file
%ProgramFiles%\Acelerador de Downloads File name: %ProgramFiles%\Acelerador de Downloads
Group: Malware file
%ProgramFiles%\DealPly File name: %ProgramFiles%\DealPly
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - DealPly BHOHKEY_LOCAL_MACHINE\Classes\CLSID\{A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - DealPly CLSIDHKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\DealPly

Additional Information

The following URL's were detected:
freedevicespeedsmart.cyou
Loading...