BetterDeals

BetterDeals

Known Adware

by Revizer Technologies

What is BetterDeals?

BetterDeals is software application developed by Revizer Technologies. It is most commonly found on computers running Windows 10 with nearly 50.94% of installations running this operating system. BetterDeals's installer is typically 4.00 MB in size and installs around 50 files.

BetterDeals is most popular in the United States with 85.34% of installations residing in this country.

BetterDeals adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About BetterDeals?

BetterDeals is a web browser extension that delivers third-party advertisements, including coupons, price comparisons, and affiliate links. These advertisements may be presented in various forms, such as display media or overlaying the page. This software may modify web page content to display these advertisements.

Multiple virus scanners have detected malware in BetterDeals.

187.dll (MD5: b8f7be911583f2b31bffd5a8b6ee8396) has been flagged by 38 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.173239
Agnitum Outpost PUA.AddLyrics!
AhnLab-V3 PUP/Win32.BlockAndSurf
ALYac Gen:Variant.Adware.Graftor.173239
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG AddLyrics_r.HK
Avira ADWARE/AddLyrics.485376.18
AVware Revizer.b (fs)
Baidu-International Adware.Win32.AddLyrics.DN
Bitdefender Gen:Variant.Adware.Graftor.173239
CAT-QuickHeal Adware.Addlyrics.A5
Comodo Security ApplicUnwnt
Cyren W32/Adware.QZDJ-3049
Dr.Web Trojan.Lyrics.344
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.173239 (B)
ESET-NOD32 a variant of Win32/Adware.AddLyrics.DN
Fortinet FortiGate Riskware/AddLyrics
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.173239
K7 AntiVirus Adware ( 004b456b1 )
K7GW Adware ( 004b456b1 )
McAfee Artemis!B8F7BE911583
MicroWorld-eScan Gen:Variant.Adware.Graftor.173239
NANO AntiVirus Trojan.Win32.Lyrics.dnkjbs
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.f9f
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.14
Trend Micro TROJ_GEN.R047C0EBF15
TrendMicro-HouseCall TROJ_GEN.R047C0EBF15
VIPRE Antivirus Revizer.b (fs)
Zillya Adware.AddLyrics.Win32.2077
F-Prot W32/S-0ca349d1!Eldorado
IKARUS anti.virus AdWare.AddLyrics
McAfee-GW-Edition RDN/Generic PUP.x!ctt
Sophos Generic PUA KH
184.dll (MD5: 1a58f1b60a61be9d1d1ffdf0d740ea9b) has been flagged by 32 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.168074
Agnitum Outpost PUA.AddLyrics!
AhnLab-V3 PUP/Win32.BlockAndSurf
ALYac Gen:Variant.Adware.Graftor.168074
avast! Win32:Adware-gen [Adw]
AVG AddLyrics.AV
AVware Revizer.b (fs)
Baidu-International Adware.Win32.AddLyrics.DU
Bitdefender Gen:Variant.Adware.Graftor.168074
CAT-QuickHeal Adware.Addlyrics.A5
Comodo Security ApplicUnwnt
Cyren W32/Adware.YEAS-3263
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.168074 (B)
ESET-NOD32 a variant of Win32/Adware.AddLyrics.DU
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.168074
McAfee Artemis!1A58F1B60A61
MicroWorld-eScan Gen:Variant.Adware.Graftor.168074
Panda Antivirus Trj/Genetic.gen
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen.2
Tencent Win32.Trojan.Adware.Dyqq
Trend Micro TROJ_GEN.R00UC0OC115
TrendMicro-HouseCall TROJ_GEN.R00UC0OC115
VIPRE Antivirus Revizer.b (fs)
Dr.Web Trojan.Lyrics.640
Fortinet FortiGate Riskware/AddLyrics
K7 AntiVirus Adware ( 004b4a6f1 )
K7GW Adware ( 004b4a6f1 )
NANO AntiVirus Riskware.Win32.AddLyrics.dpqtxy
Qihoo-360 Win32/Virus.Adware.c3b
Sophos Generic PUA GM
186.dll (MD5: 29e209578364bf57a0393686f907daf5) has been flagged by 40 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.173239
Agnitum Outpost PUA.AddLyrics!
AhnLab-V3 PUP/Win32.BlockAndSurf
ALYac Gen:Variant.Adware.Graftor.173239
Antiy-AVL Trojan/Win32.TSGeneric
Arcabit Trojan.Adware.Graftor.D2A4B7
AVG AddLyrics.AN
Avira ADWARE/AddLyrics.512512.40
AVware Revizer.b (fs)
Baidu-International Adware.Win32.AddLyrics.DN
Bitdefender Gen:Variant.Adware.Graftor.173239
CAT-QuickHeal Adware.Addlyrics.A5
Comodo Security ApplicUnwnt
Dr.Web Trojan.Lyrics.790
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.173239 (B)
ESET-NOD32 a variant of Win32/Adware.AddLyrics.DN
Fortinet FortiGate Riskware/AddLyrics
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.173239
K7 AntiVirus Adware ( 004b456b1 )
K7GW Adware ( 004b456b1 )
McAfee Artemis!29E209578364
McAfee-GW-Edition BehavesLike.Win32.PUP.hh
MicroWorld-eScan Gen:Variant.Adware.Graftor.173239
NANO AntiVirus Trojan.Win32.Lyrics.drtzpe
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.181B8758!404457304
Sophos Generic PUA DJ
SUPERAntiSpyware Adware.AddLyrics/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_SPNR.14BN15
TrendMicro-HouseCall TROJ_SPNR.14BN15
VIPRE Antivirus Revizer.b (fs)
Zillya Adware.AddLyrics.Win32.2861
avast! Win32:Adware-gen [Adw]
Cyren W32/Adware.QZDJ-3049
Tencent Trojan.Win32.Qudamah.Gen.14
F-Prot W32/S-0ca349d1!Eldorado
IKARUS anti.virus AdWare.AddLyrics
YSResultsSetup.exe (MD5: 12d81541a7d90ff39f6d9763f36a1b3f) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Strictor.74971
Agnitum Outpost PUA.Agent!
AhnLab-V3 PUP/Win32.BrowseFox
ALYac Gen:Variant.Adware.Strictor.74971
Antiy-AVL RiskWare[Downloader]/Win32.Montiera.al
Arcabit Trojan.Adware.Strictor.D124DB
avast! Win32:Adware-COP [PUP]
AVG Generic.CE9
Avira PUA/Montiera.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.BrowseFox.81
Bitdefender Gen:Variant.Adware.Strictor.74971
Bkav FE W32.HfsAdware.E40D
CAT-QuickHeal Adware.Kazy.g5
Cyren W32/Application.SFCQ-7771
Dr.Web Adware.Downware.12026
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.74971 (B)
ESET-NOD32 a variant of Win32/Toolbar.Montiera.AE potentially unwanted
F-Secure Gen:Variant.Adware.Strictor
G Data Gen:Variant.Adware.Strictor.74971
K7 AntiVirus Riskware ( 0040eff71 )
K7GW Riskware ( 0040eff71 )
Kaspersky not-a-virus:Downloader.Win32.Montiera.al
Malwarebytes PUP.Optional.PayByAds.A
McAfee Artemis!12D81541A7D9
McAfee-GW-Edition Artemis
MicroWorld-eScan Gen:Variant.Adware.Strictor.74971
NANO AntiVirus Trojan.Win32.Montiera.dscpdk
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA HO (PUA)
SUPERAntiSpyware PUP.PayByAds/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R02LC0EDP15
Vba32 AntiVirus Downloader.Montiera
VIPRE Antivirus Trojan.Win32.Generic!BT
ViRobot Adware.Strictor.1216768[h]
Comodo Security ApplicUnwnt
Fortinet FortiGate Riskware/AddLyrics
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.181B8758!404457304
TrendMicro-HouseCall TROJ_SPNR.14BN15
Zillya Adware.AddLyrics.Win32.2861
Tencent Trojan.Win32.Qudamah.Gen.14
F-Prot W32/S-0ca349d1!Eldorado
IKARUS anti.virus AdWare.AddLyrics
a3BetterDealsM73.exe (MD5: 36f2453215d3584b73e078e136811866) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Symmi.48640
AhnLab-V3 PUP/Win32.Addlyrics
ALYac Gen:Variant.Adware.Symmi.48640
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Evo-gen [Susp]
AVG Generic5
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.AddLyrics.bCF
Bitdefender Gen:Variant.Adware.Symmi.48640
Cyren W32/Application.WGXL-1237
Emsisoft Anti-Malware Gen:Variant.Adware.Symmi.48640
ESET-NOD32 a variant of Win32/Adware.AddLyrics.CF
Fortinet FortiGate Riskware/AddLyrics
F-Secure Gen:Variant.Adware.Symmi
G Data Gen:Variant.Adware.Symmi.48640
IKARUS anti.virus PUA.AddLyrics
K7 AntiVirus Adware
K7GW Adware ( 004afd1c1 )
McAfee RDN/Generic PUP.x!ctz
McAfee-GW-Edition RDN/Generic PUP.x!ctz
MicroWorld-eScan Gen:Variant.Adware.Symmi.48640
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA HM
SUPERAntiSpyware Adware.AddLyrics/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R047C0OL714
TrendMicro-HouseCall TROJ_GEN.R047C0OL714
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.AddLyrics.Win32.1444
Agnitum Outpost PUA.Agent!
Arcabit Trojan.Adware.Strictor.D124DB
Avira PUA/Montiera.Gen7
Bkav FE W32.HfsAdware.E40D
CAT-QuickHeal Adware.Kazy.g5
Dr.Web Adware.Downware.12026
Kaspersky not-a-virus:Downloader.Win32.Montiera.al
Malwarebytes PUP.Optional.PayByAds.A
NANO AntiVirus Trojan.Win32.Montiera.dscpdk
Vba32 AntiVirus Downloader.Montiera
ViRobot Adware.Strictor.1216768[h]
Comodo Security ApplicUnwnt
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.181B8758!404457304
Tencent Trojan.Win32.Qudamah.Gen.14
F-Prot W32/S-0ca349d1!Eldorado

Software Behaviors

Services:
  • X4pD189.exe runs as a service named 'BetterDeals' (BetterDeals) "BetterDeals".
Scheduled tasks:
  • E2BetterDealsU61.exe is scheduled as a task named 'BetterDeals Update' (runs daily at 9:41 PM).
  • j9BetterDealsz66.exe is scheduled as a task named 'BetterDeals Update' (runs daily at 10:19 AM).
  • R5BetterDealsW24.exe is scheduled as a task named 'BetterDeals Update' (runs daily at 10:18 PM).
  • j2BetterDealsb30.exe is scheduled as a task named 'BetterDeals Update' (runs daily at 6:53 PM).
  • r0BetterDealsC88.exe is scheduled as a task named 'BetterDeals Update' (runs daily at 1:53 PM).
  • w4BetterDealsX90.exe is scheduled as a task named 'BetterDeals Update' (runs daily at 5:26 PM).

Startup Entries

Startup tasks:
  • E2BetterDealsU61.exe is automatically launched at startup through a scheduled task named BetterDeals Update.
  • j9BetterDealsz66.exe is automatically launched at startup through a scheduled task named BetterDeals Update.
  • R5BetterDealsW24.exe is automatically launched at startup through a scheduled task named BetterDeals Update.
  • j2BetterDealsb30.exe is automatically launched at startup through a scheduled task named BetterDeals Update.
  • r0BetterDealsC88.exe is automatically launched at startup through a scheduled task named BetterDeals Update.
  • w4BetterDealsX90.exe is automatically launched at startup through a scheduled task named BetterDeals Update.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\ver1betterdeals
Uninstaller:
C:\Program Files\ver1BetterDeals\Uninstall.exe
Size:
4.00 MB
Language:
English

BetterDeals Executable Details

Primary executable:
a3BetterDealsM73.exe
Name:
BetterDeals
Path:
C:\Program Files\ver1betterdeals\a3BetterDealsM73.exe
MD5:
36f2453215d3584b73e078e136811866
SHA-1:
–
SHA-256:
–
Files installed by BetterDeals
File Type Filename MD5
EXE
43752270f65b979207b0b66022e96ae9
DLL
5b2776a1be63c678b4d5b8a8eab9ddb5
DLL
b026c487837739abd073c9f1314fcd30
DLL
65631e2afcb494c7b9cf3cf075ed7d7f
DLL
1c843d984cb465563f1553c4ae45e91d
XPI
3357f527fd2acf3f728b2f6aa13d8a18
DLL
187.dll
Malware
b8f7be911583f2b31bffd5a8b6ee8396
DLL
6ecdb76458142ef29dff053aee43c446
XPI
2e9307000fe9a83de39882b9091f86d0
DLL
184.dll
Malware
1a58f1b60a61be9d1d1ffdf0d740ea9b