DealKeeperBrowserFilter.exe

Deal Keeper

Installed as part of the Yontoo Deal Keeper branded web browser extension, the BrowserFilter component is responsible for injecting advertising in the browser based on the context of the HTML being rendered. Ads are injected in the browser in the form of inline text, coupons, multi-site searching and additional offers. The application DealKeeperBrowserFilter.exe by Deal Keeper has been detected as adware by 16 anti-malware scanners. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages.
Publisher:
Deal Keeper  (signed and verified)

Version:
0.0.0.0

MD5:
e62402d202a7fe1f6b0f490f1df75a55

SHA-1:
2b8eb94e249e4b68850056bbd83b2f752b0206ce

SHA-256:
cfa4048dbfbe3ab66434fb6022972672a4ed37abc757900a9276e2855a8762f0

Scanner detections:
16 / 68

Status:
Adware

Explanation:
Part of the Yontoo ad injection web browser add-on.

Analysis date:
4/24/2024 7:53:12 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.MPlug.Q
868

Avira AntiVirus
ADWARE/BrowseFox.Gen7
7.11.173.122

AVG
Generic
2015.0.3346

Baidu Antivirus
Adware.MSIL.BrowseFox
4.0.3.14919

Bitdefender
Adware.MPlug.Q
1.0.20.1310

Emsisoft Anti-Malware
Adware.MPlug.Q
14.09.19

ESET NOD32
MSIL/BrowseFox.B potentially unwanted application
7.0.302.0

F-Secure
Adware.MPlug.Q
11.2014-19-09_6

G Data
Adware.MPlug
14.9.24

Malwarebytes
v2014.09.19.10

MicroWorld eScan
Adware.MPlug.Q
15.0.0.786

nProtect
Adware.MPlug.Q
14.09.19.01

Qihoo 360 Security
Win32/Virus.Adware.708
1.0.0.1015

Reason Heuristics
Adware.Yontoo.DealKeeper.X
14.9.19.22

Sophos
Browse Fox
4.98

VIPRE Antivirus
Threat.4741131
33120

File size:
41.2 KB (42,232 bytes)

Product version:
0.0.0.0

Original file name:
DealKeeperBrowserFilter.exe

File type:
Executable application (Win32 EXE)

Language:
Language Neutral

Common path:
C:\Program Files\deal keeper\bin\dealkeeperbrowserfilter.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2014 4:00:00 AM

Valid to:
5/13/2015 3:59:59 AM

Subject:
CN=Deal Keeper, O=Deal Keeper, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2D5A91A625D274EE29AFF6E5DC4A33AC

File PE Metadata
Compilation timestamp:
9/19/2014 2:04:32 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
768:/ojCXFl1jIWl6Oiwp3OoyPQVYN/hDJNxo:gGXPyWFikyPQI/h1N

Entry address:
0xA006

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.0334

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
32.5 KB (33,280 bytes)

Remove DealKeeperBrowserFilter.exe - Powered by Reason Core Security