easy deals-enabler.exe

The application easy deals-enabler.exe has been detected as a potentially unwanted program by 23 anti-malware scanners. By utilizing the Crossrider browser extension platform, the Enabler module is designed to manage the integration with the user's web browser and install/manage the plugin for Chrome, IE and Firefox.
MD5:
c1ddd0beb438c8ac130d13fd2fddc391

SHA-1:
f5651c6c93734b0ff5e83b69599dd1f43dcc3088

SHA-256:
6a87eaabad4d4fab485871e258a61305ae3a4d7b8c0155438d4c6ba013157c91

Scanner detections:
23 / 68

Status:
Potentially unwanted

Explanation:
May modify the web browser's settings including changing the homepage and search provider in addition to delivering ads (by injecting banner and text-links directly in the webpage).

Note:
Crossrider is the owner of a platform that enables the creation of cross-browser extensions by developers but is not the owner of this detected application.

Analysis date:
4/26/2024 1:43:53 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Plush.1
885

Agnitum Outpost
PUA.Toolbar
7.1.1

Avira AntiVirus
TR/Trash.Gen
7.11.30.172

AVG
Adware Generic5
2015.0.3363

Baidu Antivirus
Adware.Win32.CrossRider
4.0.3.1492

Bitdefender
Gen:Adware.Plush.1
1.0.20.1225

Dr.Web
Adware.Toolbar.230
9.0.1.0245

Emsisoft Anti-Malware
Gen:Adware.Plush
8.14.09.02.03

ESET NOD32
Win32/Toolbar.CrossRider.W potentially unwanted application
8.7.0.302.0

F-Secure
Gen:Adware.Plush.1
11.2014-02-09_3

G Data
Gen:Adware.Plush
14.9.24

K7 AntiVirus
Unwanted-Program
13.177.12128

Malwarebytes
PUP.Optional.PlusHD.A
v2014.09.02.03

McAfee
Artemis!4D6DD32FBC6B
5600.7019

MicroWorld eScan
Gen:Adware.Plush.1
15.0.0.735

NANO AntiVirus
Trojan.Win32.Toolbar.ctsoci
0.28.0.59911

Panda Antivirus
PUP/PlusHD
14.09.02.03

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Reason Heuristics
Threat.Win.Reputation.IMP
14.9.2.15

Sophos
AppRider
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Nullo[Short]
10384

Trend Micro House Call
TROJ_GEN.F47V1224
7.2.245

VIPRE Antivirus
Crossrider
25254

File size:
326.5 KB (334,336 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\easy deals\easy deals-enabler.exe

File PE Metadata
Compilation timestamp:
11/3/2013 10:06:59 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:fw2120DOyxVHY3k3PKsGGyV34eQfwM+JpJm4CkzhY9G3r5tpTBf0R+IcydRPxJre:fw21DFQsGGyVoe4Wf0G3r5tpTBwnh3P

Entry address:
0x2A5B8

Entry point:
E8, 62, 88, 00, 00, E9, 00, 00, 00, 00, 6A, 14, 68, 90, E8, 44, 00, E8, 02, 25, 00, 00, E8, 82, 16, 00, 00, 0F, B7, F0, 6A, 02, E8, F5, 87, 00, 00, 59, B8, 4D, 5A, 00, 00, 66, 39, 05, 00, 00, 40, 00, 74, 04, 33, DB, EB, 33, A1, 3C, 00, 40, 00, 81, B8, 00, 00, 40, 00, 50, 45, 00, 00, 75, EB, B9, 0B, 01, 00, 00, 66, 39, 88, 18, 00, 40, 00, 75, DD, 33, DB, 83, B8, 74, 00, 40, 00, 0E, 76, 09, 39, 98, E8, 00, 40, 00, 0F, 95, C3, 89, 5D, E4, E8, 92, 55, 00, 00, 85, C0, 75, 08, 6A, 1C, E8, DC, 00, 00, 00, 59, E8...
 
[+]

Entropy:
6.4426

Code size:
241 KB (246,784 bytes)

Remove easy deals-enabler.exe - Powered by Reason Core Security