TheBestDeals

TheBestDeals

Known Adware

by Revizer Technologies

What is TheBestDeals?

TheBestDeals is software application developed by Revizer Technologies. It is most commonly found on computers running Windows 7 with nearly 47.83% of installations running this operating system. TheBestDeals's installer is typically 1.00 MB in size and installs around 61 files.

TheBestDeals is most popular in the United States with 79.40% of installations residing in this country.

TheBestDeals adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About TheBestDeals?

TheBestDeals is a web browser extension/plugin compatible with Internet Explorer, Firefox, and Chrome. The primary function of this software is to inject advertising into the web browser in the form of banner ads, display ads, coupons, popups, price comparisons, and in-line text hyperlinks. The extension adds a proxy server between the browser and the internet to track visited web pages and inject these ads. Additionally, the plugin modifies the functionality of the browser and operating system and enables itself using a protection feature to prevent third-party programs, including antivirus programs, from disabling the ad-serving proxy server.

Multiple virus scanners have detected malware in TheBestDeals.

182.dll (MD5: 2515b53107a85e021affc6db9c0746c6) has been flagged by 46 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.158405
Agnitum Outpost PUA.AddLyrics!
AhnLab-V3 PUP/Win32.Addlyrics
ALYac Gen:Variant.Adware.Graftor.158405
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.CISZ
Avira ADWARE/Adware.Gen7
AVware Revizer.b (fs)
Baidu-International Adware.Win32.AddLyrics.CE
Bitdefender Gen:Variant.Adware.Graftor.158405
Comodo Security ApplicUnwnt
Cyren W32/Adware.YHVD-3342
Dr.Web Trojan.Lyrics.191
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.158405 (B)
ESET-NOD32 a variant of Win32/Adware.AddLyrics.CE
Fortinet FortiGate Riskware/AddLyrics
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.158405
K7 AntiVirus Adware ( 004afbd91 )
K7GW Adware ( 004afbd91 )
McAfee Artemis!2515B53107A8
McAfee-GW-Edition BehavesLike.Win32.AdwareBetterSurf.dh
MicroWorld-eScan Gen:Variant.Adware.Graftor.158405
NANO AntiVirus Trojan.Win32.Lyrics.dhzefj
Qihoo-360 HEUR/QVM30.1.Malware.Gen
SUPERAntiSpyware Adware.AddLyrics/Variant
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R047H09KI14
VIPRE Antivirus Revizer.b (fs)
Zillya Adware.AddLyrics.Win32.545
Avira AntiVir Adware/Zusy.91730
F-Prot W32/A-c15b742b!Eldorado
IKARUS anti.virus not-a-virus:AdWare.Agent
Kaspersky not-a-virus:AdWare.Win32.Agent.dgfe
Malwarebytes PUP.Optional.Revizer
Panda Antivirus Trj/Chgt.B
Sophos Generic PUA IE
Tencent Win32.Adware.Agent.Piad
Trend Micro TROJ_GEN.R0CBC0EHL14
Rising Antivirus PE:Trojan.Win32.Generic.178C09BC!395053500
Kingsoft AntiVirus Win32.Troj.Agent.dd.(kcloud)
AegisLab AdWare.MSIL.DomaIQ
nProtect Trojan.GenericKD.1900343
Norman Suspicious_Gen5.AWAUA
CAT-QuickHeal Adware.Addlyrics.A5
181.dll (MD5: 08093200e80be930b498460d44dd54f4) has been flagged by 46 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.158405
Agnitum Outpost PUA.AddLyrics!
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.CGQZ
Avira Adware/AddLyrics.330752.9
AVware Revizer.b (fs)
Baidu-International Adware.Win32.AddLyrics.BCE
Bitdefender Gen:Variant.Adware.Graftor.158405
Comodo Security ApplicUnwnt
Dr.Web Trojan.Lyrics.191
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.158405 (B)
ESET-NOD32 a variant of Win32/Adware.AddLyrics.CE
Fortinet FortiGate Riskware/AddLyrics
F-Secure Gen:Variant.Adware.Graftor.158405
G Data Gen:Variant.Adware.Graftor.158405
IKARUS anti.virus Win32.SuspectCrc
K7 AntiVirus Adware ( 004afbd91 )
K7GW Adware ( 004afbd91 )
Malwarebytes PUP.Optional.Graftor
McAfee Artemis!08093200E80B
McAfee-GW-Edition BehavesLike.Win32.GameVance.fh
MicroWorld-eScan Gen:Variant.Adware.Graftor.158405
NANO AntiVirus Trojan.Win32.Lyrics.dhergf
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.178C09BC!395053500
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R08NH09JR14
VIPRE Antivirus Revizer.b (fs)
Zillya Adware.AddLyrics.Win32.342
Avira AntiVir Adware/Graftor.150872.63
Kaspersky not-a-virus:AdWare.Win32.Agent.ddun
Kingsoft AntiVirus Win32.Troj.Agent.dd.(kcloud)
Panda Antivirus Trj/Chgt.B
Sophos Generic PUA BF
Tencent Win32.Adware.Agent.Afhr
AhnLab-V3 Adware/Win32.AddLyrics
AegisLab AdWare.MSIL.DomaIQ
nProtect Trojan.GenericKD.1900343
Norman Suspicious_Gen5.AWAUA
Trend Micro TROJ_GEN.R0C1C0OJ414
ALYac Gen:Variant.Adware.Graftor.168074
CAT-QuickHeal Adware.Addlyrics.A5
Cyren W32/Adware.CUFW-2481
SUPERAntiSpyware Adware.Graftor/Variant
F-Prot W32/A-6b1bf21b!Eldorado
180.dll (MD5: b580e73c842b225bdcaef8665f6cefa6) has been flagged by 35 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Graftor.158405
AegisLab AdWare.MSIL.DomaIQ
Antiy-AVL Trojan/Win32.TSGeneric
AVware Revizer.b (fs)
Baidu-International Adware.Win32.AddLyrics.BBV
Bitdefender Gen:Variant.Graftor.158405
Emsisoft Anti-Malware Gen:Variant.Graftor.158405 (B)
ESET-NOD32 a variant of Win32/AdWare.AddLyrics.BV
Fortinet FortiGate Riskware/AddLyrics
F-Secure Gen:Variant.Graftor.158405
G Data Gen:Variant.Graftor.158405
Malwarebytes PUP.Optional.Graftor
MicroWorld-eScan Gen:Variant.Graftor.158405
Symantec Trojan.Gen.2
VIPRE Antivirus Revizer.b (fs)
AVG Generic5.BPZD
IKARUS anti.virus PUA.AdLyrics
TrendMicro-HouseCall TROJ_GEN.R047H09IE14
avast! Win32:Adware-BXP [Adw]
Comodo Security ApplicUnwnt
Sophos Generic PUA LJ
Kaspersky not-a-virus:HEUR:AdWare.Win32.Agent.heur
NANO AntiVirus Riskware.Win32.Agent.dbvefl
McAfee Artemis!582A0B8BEBA7
McAfee-GW-Edition Artemis!582A0B8BEBA7
Panda Antivirus Trj/Chgt.C
Agnitum Outpost PUA.AddLyrics!
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
AhnLab-V3 PUP/Win32.Agent
K7 AntiVirus Adware ( 0049fcbc1 )
K7GW Adware ( 0049fcbc1 )
F-Prot W32/A-c15b742b!Eldorado
Qihoo-360 Win32/Trojan.ae9
Rising Antivirus PE:Trojan.Win32.Generic.172C275A!388769626
nProtect Trojan.Generic.11834757
175.dll (MD5: 8ceffe6fc5424c15eda420ba4f03aa71) has been flagged by 12 scanners:
Scanner Software Result
AVware Revizer.b (fs)
Baidu-International Trojan.Win32.AddLyrics.bBD
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.AddLyrics.BD
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0731
VIPRE Antivirus Revizer.b (fs)
Sophos BlockNSurf
avast! Win32:Adware-BNS [PUP]
Qihoo-360 Malware.QVM10.Gen
Kaspersky not-a-virus:HEUR:AdWare.Win32.Lyckriks.heur
Malwarebytes PUP.Optional.Graftor
W3TheBestDealsN57.exe (MD5: 255fa2cc099b606d05895bb2649168ba) has been flagged by 47 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Symmi.48640
Agnitum Outpost PUA.AddLyrics!
AhnLab-V3 PUP/Win32.Addlyrics
ALYac Gen:Variant.Adware.Symmi.48640
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.CIYG
Avira ADWARE/Adware.Gen4
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.AddLyrics.CF
Bitdefender Gen:Variant.Adware.Symmi.48640
Comodo Security ApplicUnwnt
Cyren W32/A-b618dbff!Eldorado
Emsisoft Anti-Malware Gen:Variant.Adware.Symmi.48640 (B)
ESET-NOD32 a variant of Win32/Adware.AddLyrics.CF
Fortinet FortiGate Riskware/AddLyrics
F-Prot W32/A-b618dbff!Eldorado
F-Secure Gen:Variant.Adware.Symmi
G Data Gen:Variant.Adware.Symmi.48640
IKARUS anti.virus PUA.AddLyrics
K7 AntiVirus Adware ( 004afd1c1 )
K7GW Adware ( 004afd1c1 )
McAfee Artemis!255FA2CC099B
McAfee-GW-Edition BehavesLike.Win32.BadFile.gh
MicroWorld-eScan Gen:Variant.Adware.Symmi.48640
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos Generic PUA AC
SUPERAntiSpyware Adware.Strictor/Variant
Symantec Trojan.Gen.2
TrendMicro-HouseCall TROJ_GEN.R0C1H09KG14
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.AddLyrics.Win32.859
Arcabit Trojan.Adware.Kazy.D9296B
Dr.Web Trojan.Lyrics.544
NANO AntiVirus Trojan.Win32.Lyrics.dptpso
Panda Antivirus Trj/Genetic.gen
Tencent Win32.Risk.Adware.Hsip
Trend Micro TROJ_GEN.R0C1C0ODR15
CAT-QuickHeal Adware.Addlyrics.A5
Avira AntiVir Adware/Zusy.91730
Kaspersky not-a-virus:AdWare.Win32.Agent.dgfe
Malwarebytes PUP.Optional.Revizer
Rising Antivirus PE:Trojan.Win32.Generic.178C09BC!395053500
Kingsoft AntiVirus Win32.Troj.Agent.dd.(kcloud)
AegisLab AdWare.MSIL.DomaIQ
nProtect Trojan.GenericKD.1900343
Norman Suspicious_Gen5.AWAUA

Software Behaviors

Services:
  • B2Ka184.exe runs as a service named 'TheBestDeals' (TheBestDeals) "TheBestDeals".
  • B5wN181.exe runs as a service named 'TheBestDeals' (TheBestDeals) "TheBestDeals".
  • S6Ev186.exe runs as a service named 'TheBestDeals' (TheBestDeals) "TheBestDeals".
  • r5Ju182.exe runs as a service named 'TheBestDeals' (TheBestDeals) "TheBestDeals".
  • b8Ne181.exe runs as a service named 'TheBestDeals' (TheBestDeals) "TheBestDeals".
  • C0we181.exe runs as a service named 'TheBestDeals' (TheBestDeals) "TheBestDeals".
Scheduled tasks:
  • TheBestDealsMDTcIw.exe is scheduled as a task named 'TheBestDeals_wd' (runs daily at 00:26).
  • TheBestDealsF86.exe is scheduled as a task named 'TheBestDeals Update' (runs daily at 00:15).
  • i2TheBestDealsh81.exe is scheduled as a task named 'TheBestDeals Update' (runs daily at 09:03 p. m.).
  • F4TheBestDealsf05.exe is scheduled as a task named 'TheBestDeals Update' (runs daily at 2:44 PM).
  • t1TheBestDealsB02.exe is scheduled as a task named 'TheBestDeals Update' (runs daily at 16:24).
  • D5TheBestDealsZ85.exe is scheduled as a task named 'TheBestDeals Update' (runs daily at 7:32 PM).

Startup Entries

Startup tasks:
  • F4TheBestDealsf05.exe is automatically launched at startup through a scheduled task named TheBestDeals Update.
  • TheBestDealsMDTcIw.exe is automatically launched at startup through a scheduled task named TheBestDeals_wd.
  • TheBestDealsF86.exe is automatically launched at startup through a scheduled task named TheBestDeals Update.
  • i2TheBestDealsh81.exe is automatically launched at startup through a scheduled task named TheBestDeals Update.
  • t1TheBestDealsB02.exe is automatically launched at startup through a scheduled task named TheBestDeals Update.
  • D5TheBestDealsZ85.exe is automatically launched at startup through a scheduled task named TheBestDeals Update.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\thebestdeals
Uninstaller:
C:\Program Files\TheBestDeals\Uninstall.exe
Size:
1.00 MB
Language:
English

TheBestDeals Executable Details

Primary executable:
TheBestDealsvoA.exe
Name:
TheBestDeals
Path:
C:\Program Files\thebestdeals\TheBestDealsvoA.exe
MD5:
ac9c2b5cce519dbcba7ef94ec1330489
SHA-1:
–
SHA-256:
–
Files installed by TheBestDeals
File Type Filename MD5
EXE
a3b0d218741ea825b94375682a75252d
DLL
5110a793b137b501f68ed3aad895e1a8
XPI
8d1fa0e3c4838c1fc7bc07cc2381df49
XPI
4fe2394aa679d26cad093f747de2e38f
CRX
08d501d1ad3d569429376d709d89588f
XPI
587152718990daf3f3c534f507759db4
DLL
e5af910710a3bbfab77a987d40e1d72c
CRX
5563b6f49a048b78be6f8142e698cb4b
DLL
cf0a25645ebec452e0092cbc6155b8f0
DLL
abba299200897ae28b1e5131f21e6b26