OffersWizard

OffersWizard

by OffersWizard-software

What is OffersWizard?

OffersWizard is software application developed by OffersWizard-software. It is most commonly found on computers running Windows 7 with nearly 72.45% of installations running this operating system. OffersWizard's installer is typically 3.00 MB in size and installs around 11 files.

OffersWizard is most popular in the United States with 37.43% of installations residing in this country.

OffersWizard adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times.

About OffersWizard?

This is a type of ad injector malware that is often distributed as part of bundled software offers for legitimate programs. Once installed, it can be difficult to remove and has the potential to compromise the security of the user's computer by displaying intrusive advertisements in the web browser. These ads can lead to the installation of other unwanted adware or malware. Upon installation, the malware runs as a startup process in the background and injects ads into web pages, either by adding new ads or replacing existing ones. These ads often promote low-quality products and potentially malicious content. The malware achieves this by intercepting the user's web browser connections and injecting new content before the page is served to the user. It is important to note that this variant is a part of the CMI/WinCheck family of adware.

Software Behaviors

Services:
  • B9eG190.exe runs as a service named 'OffersWizard' (OffersWizard) "OffersWizard".
Scheduled tasks:
  • e6OffersWizard66.exe is scheduled as a task named 'OffersWizard Update' (runs daily at 5:23 PM).

Startup Entries

Startup tasks:
  • e6OffersWizard66.exe is automatically launched at startup through a scheduled task named OffersWizard Update.

Software Details

URL:
Support:
Installation path:
C:\Program Files\ver2offerswizard
Uninstaller:
C:\Program Files\ver2OffersWizard\Uninstall.exe
Size:
3.00 MB
Language:
English

OffersWizard Executable Details

Primary executable:
uninstall.exe
Name:
OffersWizard
Path:
C:\Program Files\ver2offerswizard\uninstall.exe
MD5:
9afeb11ed616a10f6c5d44a04fbe3797
SHA-1:
SHA-256:
Files installed by OffersWizard
File Type Filename MD5
EXE
9afeb11ed616a10f6c5d44a04fbe3797
DLL
5b2776a1be63c678b4d5b8a8eab9ddb5
DLL
db8c8f2775a57d3ebd7629bf7214945c
XPI
f317cbd4f167da89a8ada802883954f6
DLL
c57f160f4f68b467e8f9d30a06625794
EXE
605594217cbb8354e8775e6d5d1dcf53
EXE
0646ef6df57bd5f5a7c6cf588e4cd9e1
DLL
f082f943439570dc3cb6a02f62223fa6
EXE
a117d93042eeca4e50cf6c8ebb3e8eda
DLL
7482842b302c517d5c0b394caba53f46