Home Malware Programs Adware Adware.eDeals

Adware.eDeals

Posted: July 30, 2014

Threat Metric

Ranking: 17,071
Threat Level: 2/10
Infected PCs: 16,200
First Seen: July 30, 2014
Last Seen: July 19, 2023
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\jfbackup\OS\AdwCleaner\Quarantine\C\Program Files (x86)\eDealsPop\eDealsPop.exe.vir File name: eDealsPop.exe.vir
Size: 7.16 KB (7168 bytes)
MD5: 0cd18a9b522aa5342b2da479293541f1
Detection count: 10,572
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\jfbackup\OS\AdwCleaner\Quarantine\C\Program Files (x86)\eDealsPop\eDealsPop.exe.vir
Group: Malware file
Last Updated: April 9, 2023
%SYSTEMDRIVE%\jfbackup\OS\AdwCleaner\Quarantine\C\Program Files (x86)\edealpop\eDealPop.exe.vir File name: eDealPop.exe.vir
Size: 6.14 KB (6144 bytes)
MD5: 8dec4a4360efa6b9f97b489ee792ecb2
Detection count: 4,042
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\jfbackup\OS\AdwCleaner\Quarantine\C\Program Files (x86)\edealpop\eDealPop.exe.vir
Group: Malware file
Last Updated: July 19, 2023
%LOCALAPPDATA%\DefaultFreewareSyntax\DefaultFreewareSyntax.exe File name: DefaultFreewareSyntax.exe
Size: 165.37 KB (165376 bytes)
MD5: be0bd0148cdb45d75cddef7c36acc235
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\DefaultFreewareSyntax
Group: Malware file
Last Updated: December 10, 2019
%WINDIR%\SysWOW64\DefaultMBROffice\DefaultMBROffice.exe File name: DefaultMBROffice.exe
Size: 67.58 KB (67584 bytes)
MD5: 3b86fbe4bc3621161a3550a74afad990
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\DefaultMBROffice
Group: Malware file
Last Updated: December 10, 2019

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Windows\CurrentVersion\Run\eDealPopSoftware\Microsoft\Windows\CurrentVersion\Run\eDealsPopSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\eDealPopSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\eDealsPopHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}eDealPop_is1eDeals_is1eDealsPop_is1

Additional Information

The following directories were created:
%PROGRAMFILES%\eDealPop%PROGRAMFILES%\eDealsPop%PROGRAMFILES(x86)%\eDealPop%PROGRAMFILES(x86)%\eDealsPop
Loading...