Home Malware Programs Adware Adware.Deal Spy

Adware.Deal Spy

Posted: April 2, 2013

Threat Metric

Ranking: 13,324
Threat Level: 2/10
Infected PCs: 691
First Seen: April 2, 2013
Last Seen: August 22, 2023
OS(es) Affected: Windows

Deal Spy Screenshot 1Deal Spy is a potentially unwanted program/adware, which is produced by 215 Apps. Deal Spy will display pop-up advertisements, savings coupon, and deals on the desktop of the infected computer while the PC user is surfing the Internet. Deal Spy will show up as a small box on upper right corner of the hijacked Internet browser when the computer users visits online shopping websites. Deal Spy shows up as a small button that, when clicked, will reveal the contents displaying links for numerous offers. Deal Spy usually installs a browser add-on on Internet Explorer, Google Chrome, and Mozilla Firefox. Deal Spy may come packed with free software products and applications that computer users have downloaded from different websites. When the PC users is installing the specific application, he/she also unknowingly loads Deal Spy or other types of adware without permission.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110211621176}{22222222-2222-2222-2222-220222622276}{55555555-5555-5555-5555-550255625576}{66666666-6666-6666-6666-660266626676}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Deal SpySOFTWARE\Classes\CrossriderApp0026276.SandboxSOFTWARE\Classes\CrossriderApp0026276.Sandbox.1Software\Cr_Installer\26276Software\InstalledBrowserExtensions\215 Apps\26276SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Deal Spy-updater.jobSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures\Deal Spy-updater.job.fpSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater26276.exeSOFTWARE\Wow6432Node\Deal SpySOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211621176}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211621176}SOFTWARE\Wow6432Node\Microsoft\Tracing\Deal Spy_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Deal Spy_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\Updater26276_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Updater26276_RASMANCS

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Deal Spy%LOCALAPPDATA%\Deal Spy%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\dieckmbeafcedhihaiadnaanclccfihd%LOCALAPPDATA%\Updater26276%PROGRAMFILES%\Deal Spy%PROGRAMFILES(x86)%\Deal Spy%USERPROFILE%\AppData\LocalLow\Deal Spy%UserProfile%\Local Settings\Application Data\Updater26276
The following URL's were detected:
https://www.dealspy.com/
Loading...