Home Malware Programs Adware ZenDeals

ZenDeals

Posted: September 9, 2013

Threat Metric

Ranking: 14,743
Threat Level: 2/10
Infected PCs: 607
First Seen: September 9, 2013
Last Seen: September 13, 2023
OS(es) Affected: Windows

ZenDeals Screenshot 1ZenDeals is an adware program that markets itself as an online coupon-finding tool. Although ZenDeals does fulfill these functions as its marketing claims, ZenDeals also shows some traits common to adware, such as displaying advertisements on various unrelated sites, preventing you from making any changes to how these advertisements are displayed, tracking your Web-browsing behavior for self-serving purposes and being difficult to uninstall. SpywareRemove.com malware researchers currently categorize ZenDeals's advertisements as safe, but they also suggest removing ZenDeals with a reliable anti-malware scanner unless you have specific reasons for wanting ZenDeals to advertise coupons in your browser automatically.

The Add-On that Thinks It Can Sell You a Piece of Shopping Heaven

ZenDeals is a browser add-on that specializes in displaying shopping coupon-based advertisements (as both text hyperlinks and additional graphical advertisements superimposed over a Web page). While ZenDeals's content is genuine, ZenDeals doesn't allow you to control the display of these advertisements and may obfuscate the uninstallation process. Similar to adware like Lucky Leap or the Coupon Alert Toolbar, ZenDeals also monitors your website browsing and shopping habits and may share this information with third parties.

ZenDeals is compatible with both Windows and Mac OS X browsers. So far, affected browsers include Internet Explorer, Chrome, Firefox and Safari, including variants of these browsers that have been developed for Mac-brand operating systems. Interestingly, while ZenDeals claims to provide specific uninstallation instructions, these instructions may not remove all of ZenDeals's components and may allow some undesirable elements (such as its tracking behavior or coupon advertisements) to remain on your computer. Perhaps most suspiciously of all, the ZenDeals company even claims to have no liability if you're unable to uninstall ZenDeals coupon program through the provided instructions.

Finding Inner Internet Peace without Advertisements Intruding

While you'll need to make your own judgment call about whether or not it's worth putting up with ZenDeals's browser changes for the sake of the occasional shopping deal, SpywareRemove.com malware researchers usually don't see any reason to recommend keeping adware like ZenDeals on your computer. As noted earlier on, ZenDeals is not necessarily as easy to remove as ZenDeals would appear on first glance, but any competent anti-malware program should be able to delete ZenDeals during a system scan for general PC threats.

ZenDeals and other adware often are distributed by software packages that install several applications through a single installer file. You usually should be given the option to opt out of installing ZenDeals, although this option may be unusually difficult to select or be obfuscated in some manner. However, if you stay away from sites known for distributing adware and other low-level PC threats, your chances of having a coupon encounter with ZenDeals will be fairly minimal.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\OpenCandy\31A1408ACC9E42C983E654D3EC88C9A9\ZDModular2OptInstall.exe File name: ZDModular2OptInstall.exe
Size: 1.4 MB (1408800 bytes)
MD5: 662ae748b526e12be3c51b2c69dd3f7f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\OpenCandy\31A1408ACC9E42C983E654D3EC88C9A9\ZDModular2OptInstall.exe
Group: Malware file
Last Updated: December 15, 2021

Registry Modifications

The following newly produced Registry Values are:

CLSID{18D6D197-45BB-465B-ADC0-274A70B49B55}{2C951E36-AA4C-4C18-9AFE-AE2E2DCED08B}Regexp file mask%LOCALAPPDATA%\ZDManager.ini%UserProfile%\Local Settings\Application Data\ZDManager.iniHKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\New Windows\Allow\*.zendeals.comHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ZDManager

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\ZDManagerService%ALLUSERSPROFILE%\ZDManagerService%ProgramFiles%\ZD Systems%ProgramFiles%\Zen Deals%ProgramFiles(x86)%\ZD Systems%ProgramFiles(x86)%\Zen Deals
The following URL's were detected:
ZenDeals
Loading...