Discount_Frenzy

Discount_Frenzy

Known Adware

by Kimahri Software inc.

What is Discount_Frenzy?

Discount_Frenzy is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 57.45% of installations running this operating system. Discount_Frenzy's installer is typically 9.00 MB in size and installs around 306 files. The most common release is 1.36.01.22 with 34.04% of all installations currently using this version.

Discount_Frenzy is most popular in the United States with 12.51% of installations residing in this country.

Discount_Frenzy adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Discount_Frenzy?

DiscountFrenzy is a web browser extension designed to deliver advertisements to users while they browse the internet. The ads are in the form of static and video banners, as well as contextual hyperlinks. This adware is commonly bundled with third-party download managers and potentially unwanted programs (PUPs). The adware injects ads onto various web pages, not limited to those associated with the software or its affiliates. Additionally, the program periodically connects to remote servers to download new ad feeds and reports back the domains, URLs, and advertisements the user interacts with while browsing the web.

Multiple virus scanners have detected malware in Discount_Frenzy.

4d16900c-aacc-40e6-8e55-3eecdeec38eb-6.exe (MD5: 3fb2dcfd69a3ff53d971e84307fb1cfc) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Az1@mSB!Efli
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
Arcabit Application.Heur.EAD1A6B
avast! Win32:Crossrider-CD [PUP]
AVG Generic.2FB
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.Az1@mSB!Efli
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.Az1@mSB!Efli
G Data Gen:Application.Heur.Az1@mSB!Efli
Jiangmin Trojan/NSIS.geu
K7 AntiVirus Unwanted-Program ( 0040fa071 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee Artemis!3FB2DCFD69A3
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.Az1@mSB!Efli
NANO AntiVirus Trojan.Win32.Crossrider1.dnmkke
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.f43
Sophos Generic PUA MM
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.F0C2C00BN15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2879
Rising Antivirus PE:Trojan.GoogUpdate!6.1DFB
Tencent Trojan.Win32.Qudamah.Gen.2
TrendMicro-HouseCall TROJ_GEN.F0C2C00A215
Vba32 AntiVirus Trojan.GoogUpdate
Clam AntiVirus Win.Adware.Agent-36928
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
nProtect Trojan/W32.Agent.887712
4d16900c-aacc-40e6-8e55-3eecdeec38eb-5.exe (MD5: 9c6c0202f0c4cde4309b0c2adb01fafc) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.jv1@mijHzRpO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
Arcabit Application.Heur.E9B80B
avast! Win32:Crossrider-CN [PUP]
AVG Toolbar.Crossrider.AA
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CC
Bitdefender Gen:Application.Heur.jv1@mijHzRpO
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CC potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.jv1@mijHzRpO
G Data Gen:Application.Heur.jv1@mijHzRpO
Jiangmin Trojan/NSIS.geu
K7 AntiVirus Unwanted-Program ( 0040fa071 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee Artemis!9C6C0202F0C4
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.jv1@mijHzRpO
NANO AntiVirus Trojan.Win32.Crossrider1.dnmcye
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18131CFD!403905789
Sophos Generic PUA DI
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R000C0EBF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2890
Clam AntiVirus Win.Adware.Agent-36928
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.F0C2C00AS15
Agnitum Outpost PUA.Toolbar.CrossRider!
Vba32 AntiVirus Trojan.GoogUpdate
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
nProtect Trojan/W32.Agent.887712
4d16900c-aacc-40e6-8e55-3eecdeec38eb-4.exe (MD5: 8ce73be7653d465d7ee3ae5d05db64d7) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.Ev1@mmwUXFgO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
avast! Win32:Crossrider-CD [PUP]
AVG Generic.2FB
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CB
Bitdefender Gen:Application.Heur.Ev1@mmwUXFgO
Bkav FE W32.HfsAdware.B26B
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/Application.XETP-5346
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CH potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.Ev1@mmwUXFgO
G Data Gen:Application.Heur.Ev1@mmwUXFgO
K7 AntiVirus Trojan ( 004b534f1 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee Artemis!8CE73BE7653D
MicroWorld-eScan Gen:Application.Heur.Ev1@mmwUXFgO
NANO AntiVirus Trojan.Win32.Crossrider1.dnmddj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.3df
Sophos Generic PUA ME
Symantec Trojan.Gen
Tencent Trojan.Win32.YY.Gen.4
Trend Micro TROJ_GEN.F0C2C00BH15
TrendMicro-HouseCall TROJ_GEN.F0C2C00BH15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2887
Comodo Security ApplicUnwnt
F-Prot W32/Crossrider.C.gen!Eldorado
Jiangmin Trojan/NSIS.byt
McAfee-GW-Edition Artemis!PUP
Vba32 AntiVirus AdWare.Adwapper
Clam AntiVirus Win.Adware.Crossrider-206
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Rising Antivirus PE:Malware.Obscure!1.9C59
IKARUS anti.virus not-a-virus:AdWare.Adwapper
nProtect Trojan/W32.Agent.887712
ALYac Gen:Variant.Adware.Graftor.171733
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
4d16900c-aacc-40e6-8e55-3eecdeec38eb-1-7.exe (MD5: d5eba3e2ffe60d9c78ac273c4afa5211) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.gv1@m8ooVFbO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.lpz
Arcabit Application.Heur.E2B67F
avast! Win32:Adware-CTY [PUP]
AVG Crossrider.NHD
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.gv1@m8ooVFbO
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.gv1@m8ooVFbO
G Data Gen:Application.Heur.gv1@m8ooVFbO
Jiangmin Trojan/NSIS.geu
K7 AntiVirus Unwanted-Program ( 0040fa071 )
K7GW Unwanted-Program ( 0040fa071 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee PUP-FNR
McAfee-GW-Edition PUP-FNR
MicroWorld-eScan Gen:Application.Heur.gv1@m8ooVFbO
NANO AntiVirus Trojan.Win32.Crossrider1.dnptna
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.de5
Rising Antivirus PE:Adware.Zusy!6.1E7E
Sophos Generic PUA OC
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R047C0EBF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2883
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.R047C0EAG15
Clam AntiVirus Win.Adware.Agent-31379
Agnitum Outpost PUA.Toolbar.CrossRider!
Vba32 AntiVirus Trojan.GoogUpdate
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
nProtect Trojan/W32.Agent.887712
4d16900c-aacc-40e6-8e55-3eecdeec38eb-1-6.exe (MD5: 43617fe591ad8dfbb3f002b648bd8ded) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.wz1@mCVdIBai
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar]/Win32.CroRi.ftr
Arcabit Application.Heur.EBD7E8
avast! Win32:Adware-CPB [PUP]
AVG Toolbar.Crossrider.E
Avira ADWARE/CrossRider.ZR
AVware Crossrider (fs)
Baidu-International Adware.Win32.Agent.Elnx
Bitdefender Gen:Application.Heur.wz1@mCVdIBai
Bkav FE W32.HfsAdware.4389
CAT-QuickHeal PUA.BrightCircle.OD6
Clam AntiVirus Win.Adware.Crossrider-259
Comodo Security ApplicUnwnt
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.22980
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.wz1@mCVdIBai
G Data Gen:Application.Heur.wz1@mCVdIBai
Jiangmin AdWare/NSIS.gsm
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.lpz
Malwarebytes PUP.Optional.DiscountFrenzy.A
McAfee PUP-FTK
McAfee-GW-Edition PUP-FTK
MicroWorld-eScan Gen:Application.Heur.wz1@mCVdIBai
NANO AntiVirus Trojan.Win32.Crossrider1.dozwcj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.de5
Rising Antivirus PE:Malware.CrossRider!6.1CE1
Sophos Generic PUA DL
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R00UC0EBF15
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.2441
nProtect Trojan/W32.Agent.2057120
Tencent Win32.Adware.Bp-browser.Luqs
TrendMicro-HouseCall TROJ_GEN.F0C2C00C615
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
IKARUS anti.virus Gen.Application.Heur
ALYac Gen:Variant.Adware.Kazy.133003

Software Behaviors

Scheduled tasks:
  • 7c1eb14f-b3f1-4945-85fa-988d3442f0e1-11.exe is scheduled as a task named '7c1eb14f-b3f1-4945-85fa-988d3442f0e1-11'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-7.exe is scheduled as a task named 'f0a729ed-49e4-4935-82ba-17c41f3af784-7'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-6.exe is scheduled as a task named 'temp_f0a729ed-49e4-4935-82ba-17c41f3af784-6'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-4.exe is scheduled as a task named 'f0a729ed-49e4-4935-82ba-17c41f3af784-4'.
  • f0a729ed-49e4-4935-82ba-17c41f3af784-11.exe is scheduled as a task named 'f0a729ed-49e4-4935-82ba-17c41f3af784-11'.
  • 9f5053c4-52e0-4132-9e68-3b20b2a464ea-7.exe is scheduled as a task named '9f5053c4-52e0-4132-9e68-3b20b2a464ea-7'.

Startup Entries

Startup tasks:
  • Discount_Frenzy-codedownloader.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-1.
  • c9a7118a-59f7-4bc8-a85a-5f943507edfc-5.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-5_user.
  • c9a7118a-59f7-4bc8-a85a-5f943507edfc-4.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-4.
  • c9a7118a-59f7-4bc8-a85a-5f943507edfc-11.exe is automatically launched at startup through a scheduled task named c9a7118a-59f7-4bc8-a85a-5f943507edfc-11.
  • be92f461-1d03-4005-858c-ae158a508499-5.exe is automatically launched at startup through a scheduled task named be92f461-1d03-4005-858c-ae158a508499-5_user.
  • be92f461-1d03-4005-858c-ae158a508499-4.exe is automatically launched at startup through a scheduled task named be92f461-1d03-4005-858c-ae158a508499-4.

Software Details

URL:
https://crossrider.com/install/45362-discountfrenzy
Support:
–
Installation path:
C:\Program Files\discount_frenzy
Uninstaller:
C:\Program Files\Discount_Frenzy\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

Discount_Frenzy Executable Details

Primary executable:
Discount_Frenzy-bg.exe
Name:
Discount_Frenzy
Path:
C:\Program Files\discount_frenzy\Discount_Frenzy-bg.exe
MD5:
e5ff79e82f81da459db40bfc5f2cd102
SHA-1:
–
SHA-256:
–
Files installed by Discount_Frenzy
File Type Filename MD5
EXE
059a7d0f61d515f8c3d423de1c1569df
EXE
26cf71639bff4bc7f96c14abda8c4d8d
EXE
3b3ccd7f09384df550f7ec51d532412a
EXE
902a8873197f158ad2adaa4a43cb44b1
EXE
0eaf40b324124ffd3bfc38dac887a616
EXE
2e735489416942270bdd1297a75571d9
EXE
129fefb493b3bf523ea4ff834124a46e
EXE
cd7747e59f25080d45d07d8fb7e79e33
EXE
e6e72a474d4041add95df83944c2c1d7
EXE
084e15356010277968d7fbd32725fe21