Discount_Frenzy

Discount_Frenzy

Known Adware

by Kimahri Software inc.

What is Discount_Frenzy?

Discount_Frenzy is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 57.45% of installations running this operating system. Discount_Frenzy's installer is typically 9.00 MB in size and installs around 306 files. The most common release is 1.36.01.22 with 34.04% of all installations currently using this version.

Discount_Frenzy is most popular in the United States with 12.51% of installations residing in this country.

Discount_Frenzy adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Discount_Frenzy?

DiscountFrenzy is a web browser extension designed to deliver advertisements to users while they browse the internet. The ads are in the form of static and video banners, as well as contextual hyperlinks. This adware is commonly bundled with third-party download managers and potentially unwanted programs (PUPs). The adware injects ads onto various web pages, not limited to those associated with the software or its affiliates. Additionally, the program periodically connects to remote servers to download new ad feeds and reports back the domains, URLs, and advertisements the user interacts with while browsing the web.

Multiple virus scanners have detected malware in Discount_Frenzy.

4d16900c-aacc-40e6-8e55-3eecdeec38eb-6.exe (MD5: 3fb2dcfd69a3ff53d971e84307fb1cfc) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Az1@mSB!Efli
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
Arcabit Application.Heur.EAD1A6B
avast! Win32:Crossrider-CD [PUP]
AVG Generic.2FB
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.Az1@mSB!Efli
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.Az1@mSB!Efli
G Data Gen:Application.Heur.Az1@mSB!Efli
Jiangmin Trojan/NSIS.geu
K7 AntiVirus Unwanted-Program ( 0040fa071 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee Artemis!3FB2DCFD69A3
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.Az1@mSB!Efli
NANO AntiVirus Trojan.Win32.Crossrider1.dnmkke
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.f43
Sophos Generic PUA MM
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.F0C2C00BN15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2879
Rising Antivirus PE:Trojan.GoogUpdate!6.1DFB
Tencent Trojan.Win32.Qudamah.Gen.2
TrendMicro-HouseCall TROJ_GEN.F0C2C00A215
Vba32 AntiVirus Trojan.GoogUpdate
Clam AntiVirus Win.Adware.Agent-36928
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
nProtect Trojan/W32.Agent.887712
4d16900c-aacc-40e6-8e55-3eecdeec38eb-5.exe (MD5: 9c6c0202f0c4cde4309b0c2adb01fafc) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.jv1@mijHzRpO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
Arcabit Application.Heur.E9B80B
avast! Win32:Crossrider-CN [PUP]
AVG Toolbar.Crossrider.AA
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CC
Bitdefender Gen:Application.Heur.jv1@mijHzRpO
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CC potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.jv1@mijHzRpO
G Data Gen:Application.Heur.jv1@mijHzRpO
Jiangmin Trojan/NSIS.geu
K7 AntiVirus Unwanted-Program ( 0040fa071 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee Artemis!9C6C0202F0C4
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.jv1@mijHzRpO
NANO AntiVirus Trojan.Win32.Crossrider1.dnmcye
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18131CFD!403905789
Sophos Generic PUA DI
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R000C0EBF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2890
Clam AntiVirus Win.Adware.Agent-36928
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.F0C2C00AS15
Agnitum Outpost PUA.Toolbar.CrossRider!
Vba32 AntiVirus Trojan.GoogUpdate
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
nProtect Trojan/W32.Agent.887712
4d16900c-aacc-40e6-8e55-3eecdeec38eb-4.exe (MD5: 8ce73be7653d465d7ee3ae5d05db64d7) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Ev1@mmwUXFgO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
avast! Win32:Crossrider-CD [PUP]
AVG Generic.2FB
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CB
Bitdefender Gen:Application.Heur.Ev1@mmwUXFgO
Bkav FE W32.HfsAdware.B26B
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/Application.XETP-5346
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CH potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.Ev1@mmwUXFgO
G Data Gen:Application.Heur.Ev1@mmwUXFgO
K7 AntiVirus Trojan ( 004b534f1 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee Artemis!8CE73BE7653D
MicroWorld-eScan Gen:Application.Heur.Ev1@mmwUXFgO
NANO AntiVirus Trojan.Win32.Crossrider1.dnmddj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.3df
Sophos Generic PUA ME
Symantec Trojan.Gen
Tencent Trojan.Win32.YY.Gen.4
Trend Micro TROJ_GEN.F0C2C00BH15
TrendMicro-HouseCall TROJ_GEN.F0C2C00BH15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2887
Comodo Security ApplicUnwnt
F-Prot W32/Crossrider.C.gen!Eldorado
Jiangmin Trojan/NSIS.byt
McAfee-GW-Edition Artemis!PUP
Vba32 AntiVirus AdWare.Adwapper
Clam AntiVirus Win.Adware.Crossrider-206
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Rising Antivirus PE:Malware.Obscure!1.9C59
IKARUS anti.virus not-a-virus:AdWare.Adwapper
nProtect Trojan/W32.Agent.887712
ALYac Gen:Variant.Adware.Graftor.171733
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
4d16900c-aacc-40e6-8e55-3eecdeec38eb-1-7.exe (MD5: d5eba3e2ffe60d9c78ac273c4afa5211) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.gv1@m8ooVFbO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
Arcabit Application.Heur.E2B67F
avast! Win32:Adware-CTY [PUP]
AVG Crossrider.NHD
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.gv1@m8ooVFbO
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.gv1@m8ooVFbO
G Data Gen:Application.Heur.gv1@m8ooVFbO
Jiangmin Trojan/NSIS.geu
K7 AntiVirus Unwanted-Program ( 0040fa071 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee PUP-FNR
McAfee-GW-Edition PUP-FNR
MicroWorld-eScan Gen:Application.Heur.gv1@m8ooVFbO
NANO AntiVirus Trojan.Win32.Crossrider1.dnptna
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.de5
Rising Antivirus PE:Adware.Zusy!6.1E7E
Sophos Generic PUA OC
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R047C0EBF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2883
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.R047C0EAG15
Clam AntiVirus Win.Adware.Agent-31379
Agnitum Outpost PUA.Toolbar.CrossRider!
Vba32 AntiVirus Trojan.GoogUpdate
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
nProtect Trojan/W32.Agent.887712
4d16900c-aacc-40e6-8e55-3eecdeec38eb-1-6.exe (MD5: 43617fe591ad8dfbb3f002b648bd8ded) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.wz1@mCVdIBai
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar]/Win32.CroRi.ftr
Arcabit Application.Heur.EBD7E8
avast! Win32:Adware-CPB [PUP]
AVG Toolbar.Crossrider.E
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.Agent.Elnx
Bitdefender Gen:Application.Heur.wz1@mCVdIBai
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Clam AntiVirus Win.Adware.Crossrider-259
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.wz1@mCVdIBai
G Data Gen:Application.Heur.wz1@mCVdIBai
Jiangmin AdWare/NSIS.gsm
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee PUP-FTK
McAfee-GW-Edition PUP-FTK
MicroWorld-eScan Gen:Application.Heur.wz1@mCVdIBai
NANO AntiVirus Trojan.Win32.Crossrider1.dozwcj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.de5
Rising Antivirus PE:Malware.CrossRider!6.1CE1
Sophos Generic PUA DL
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R00UC0EBF15
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2441
nProtect Trojan/W32.Agent.2057120
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.F0C2C00C615
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003

Software Behaviors

Scheduled tasks:
  • 7c1eb14f-b3f1-4945-85fa-988d3442f0e1-11.exe is scheduled as a task named '7c1eb14f-b3f1-4945-85fa-988d3442f0e1-11'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-7.exe is scheduled as a task named 'f0a729ed-49e4-4935-82ba-17c41f3af784-7'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-6.exe is scheduled as a task named 'temp_f0a729ed-49e4-4935-82ba-17c41f3af784-6'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-4.exe is scheduled as a task named 'f0a729ed-49e4-4935-82ba-17c41f3af784-4'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-11.exe is scheduled as a task named 'f0a729ed-49e4-4935-82ba-17c41f3af784-11'.
  • 9f5053c4-52e0-4132-9e68-3b20b2a464ea-7.exe is scheduled as a task named '9f5053c4-52e0-4132-9e68-3b20b2a464ea-7'.

Startup Entries

Startup tasks:
  • Discount_Frenzy-codedownloader.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-1.
  • c9a7118a-59f7-4bc8-a85a-5f943507edfc-5.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-5_user.
  • c9a7118a-59f7-4bc8-a85a-5f943507edfc-4.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-4.
  • c9a7118a-59f7-4bc8-a85a-5f943507edfc-11.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-11.
  • be92f461-1d03-4005-858c-ae158a508499-5.exe is automatically launched at startup through a scheduled task named be92f461-1d03-4005-858c-ae158a508499-5_user.
  • be92f461-1d03-4005-858c-ae158a508499-4.exe is automatically launched at startup through a scheduled task named be92f461-1d03-4005-858c-ae158a508499-4.

Software Details

URL:
https://crossrider.com/install/45362-discountfrenzy
Support:
–
Installation path:
C:\Program Files\discount_frenzy
Uninstaller:
C:\Program Files\Discount_Frenzy\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

Discount_Frenzy Executable Details

Primary executable:
Discount_Frenzy-bg.exe
Name:
Discount_Frenzy
Path:
C:\Program Files\discount_frenzy\Discount_Frenzy-bg.exe
MD5:
e5ff79e82f81da459db40bfc5f2cd102
SHA-1:
–
SHA-256:
–
Files installed by Discount_Frenzy
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
a0bdc8051a740904d9e5f24d697f6875
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
77a2716c4a2f92178670f2c22e0c7ac3
EXE
4d4c7684d8a2305038160af4ff57ce45