Home Malware Programs Potentially Unwanted Programs (PUPs) TrusteDealz

TrusteDealz

Posted: April 17, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 492
First Seen: April 17, 2014
Last Seen: October 15, 2022
OS(es) Affected: Windows


TrusteDealz is an unwanted browser add-on developed by Bit Wise Publishing, LLC. By displaying discount coupon ads, TrusteDealz may state to save time and money for computer users who are shopping on the Internet. TrusteDealz is categorized as adware or a potentially unwanted program (PUP). The browser extension of TrusteDealz may often install itself on a Web browsers such as Internet Explorer, Google Chrome, and Mozilla Firefox as an additional application packaged with freeware downloaded from unreliable download websites. The TrusteDealz plug-in may track online browsing activity of the PC user and may transfer this information to third-parties. The plug-in of TrusteDealz may repeatedly reroute computer users to affiliated websites that may be commercial. TrusteDealz may be produced to possibly generate advertising revenue from clicks on ads and increased web traffic.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Trustedealz\MintCastHelper.exe File name: MintCastHelper.exe
Size: 805.37 KB (805376 bytes)
MD5: 477bc77c24ca44c9af83b37adad80da2
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Trustedealz
Group: Malware file
Last Updated: April 23, 2014
%PROGRAMFILES%\Trustedealz\IE\MintCastScript.dll File name: MintCastScript.dll
Size: 438.78 KB (438784 bytes)
MD5: 2f146d1c53f0a9316056b73c5063f716
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Trustedealz\IE
Group: Malware file
Last Updated: April 23, 2014
%PROGRAMFILES(x86)%\Trustedealz\IE64\MintCastScript64.dll File name: MintCastScript64.dll
Size: 426.49 KB (426496 bytes)
MD5: a6f80da521aea6dcedb401978fe1d45e
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Trustedealz\IE64
Group: Malware file
Last Updated: April 23, 2014
%PROGRAMFILES(x86)%\Trustedealz\IE64\MintCastBackground64.exe File name: MintCastBackground64.exe
Size: 457.72 KB (457728 bytes)
MD5: f1c6b47fe94839aef8b35e55c0faf7bc
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trustedealz\IE64
Group: Malware file
Last Updated: April 23, 2014
%PROGRAMFILES(x86)%\Trustedealz\IE64\MintCastScript64.dll File name: MintCastScript64.dll
Size: 425.98 KB (425984 bytes)
MD5: 3719eb6eae832a917a025aeee4250c8f
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Trustedealz\IE64
Group: Malware file
Last Updated: April 23, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{11DB3564-99C3-4D3E-9B28-CE0F9D4D20A5}{22AB7456-5415-4C61-A906-60F3AF71BC56}{6AF63CE5-0C9D-4EBF-8A09-F5BBBC191FBD}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{E1E069F7-03C0-4F9A-9150-362CE3DF0784}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\MintCastBackground.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD\MintCastBackground.exeSOFTWARE\MintCastNetworksSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\MintCastBackground.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD\MintCastBackground.exeSOFTWARE\Wow6432Node\MintCastNetworks

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\nhnogheaopefeadofmckijbnhffmekhe%PROGRAMFILES%\Trustedealz%PROGRAMFILES(x86)%\Trustedealz
Loading...