Fun Apps

Publisher Information

Fun Apps is a software publisher located in Philadelphia, Pennsylvania in the United States*. The company is a primary distributor of unwanted software. Fun Apps (International Web Services, LLC d/b/a GamePlayLabs/ Red Online Marketing Group LP) is an adware producer of web browser extensions that are designed to inject advertisements and affiliate deals within the web pages the user is browsing. The company re-distributes a few dozen of the same adware type programs under a variety of product names (such as Luck Savings, Discount Buddy, Solid Savings, etc.) and company names through monetized bundled installations.
Remove Fun Apps Malware - Powered by Reason Core Security
Authority:
Thawte, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN=Fun Apps, O=Fun Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
684b8cfa6a114f5ee6a8115e415bf20a

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.FunApps.O, PUP.Crossrider.FunApps.Z, PUP.Crossrider.FunApps.d, PUP.Crossrider.FunApps.b, PUP.FunApps.M, PUP.Crossrider.FunApps.P, PUP.Crossrider.FunApps.U, PUP.Crossrider.FunApps.W, PUP.50OnRed.FunApps.Installer (M), Adware.Crossrider.50OnRed (M), PUP.50OnRed.FunApps (M)
100.00%

VIPRE Antivirus
Crossrider, Threat.4789396, GamePlayLabs
30.00%

AVG
Adware AdInject.FunApps
18.00%

Dr.Web
Adware.Downware.1306, Trojan.Crossrider.27966, Adware.Plugin.90, Trojan.Crossrider.1
14.00%

ESET NOD32
Win32/Toolbar.CrossRider (variant), Win32/Packed.ScrambleWrapper, Win32/Toolbar.CrossRider.H potentially unwanted (variant)
12.00%

Malwarebytes
PUP.Optional.DealBoat.A, PUP.Optional.Crossrider, PUP.Optional.CrossRider, Adware.Packed.Ranver, PUP.Optional.SupremeSavings.A
12.00%

Avira AntiVirus
ADWARE/CrossRider.Gen2, Adware/IWantThis.AB.3, ADWARE/CrossRider.A.16566
12.00%

Kingsoft AntiVirus
Win32.Troj.Generic.a.(kcloud), Win32.Troj.Lyckriks.cw.(kcloud)
10.00%

Trend Micro House Call
TROJ_GEN.R047H07KK14, TROJ_GEN.F47V0827, TROJ_GEN.R021C0EIS14, TROJ_GEN.R0C9H01H213, TROJ_GEN.R02KC0EA315
10.00%

McAfee
Artemis!31227C33900C, Artemis!898DF5A279AF, Artemis!CCA3E4A56936, Artemis!400C386E0E81, Artemis!E946BD551017
10.00%

1 / 68      (Adware)
supremesavings.exe (Rzmstm by Xzcydp)  (86a05412e343cde4ce4aa69738ecdd81)

1 / 68      (Adware)
deal boat-bho.dll (Deal Boat by Innovative Apps)  (684a8a657edfe292492975f3f38bc64a)

1 / 68      (Adware)
deal boat-helper.exe  (3b81789c5aa6d75165595b198be303b3)

1 / 68      (Adware)
deal boat-buttonutil.exe (Deal Boat by Innovative Apps)  (a36c7ef91a27469fbfdb6641ab0533bc)

1 / 68      (Adware)
dbus.exe (Fsalbzhgek by Iiykkakef)  (f99f179bb219b0c079306f5fb6792298)

1 / 68      (Adware)

1 / 68      (Adware)
deal boat-bg.exe (Deal Boat by Innovative Apps)  (199f3193c029c7754b6d5a71ae6ec74b)

1 / 68      (Adware)
updater12747.exe (Deal Boat by Innovative Apps)  (da9fb776de6b7de80fd8e799fa901a76)

1 / 68      (Adware)
deal boat-helper.exe  (7c9af2dc58fbb38c23df5a14428e8141)

1 / 68      (Adware)
deal boat-buttonutil64.exe (Deal Boat by Innovative Apps)  (11b648722a6f481af8aa1f50d027179a)

1 / 68      (Adware)
deal boat-buttonutil64.dll  (93b096dd3554b89386fe1c0dd488d7e4)

1 / 68      (Adware)
deal boat-buttonutil.dll  (e6074f2d353eafd84764cac0aa58eaa1)

1 / 68      (Adware)
solid savings plugin-helper.exe  (0eeeac56a07a56b13e6571e7f7a5621b)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
solid savings plugin-buttonutil64.dll  (1933749fb1e40192cb0d14acec104d5d)

1 / 68      (Adware)

1 / 68      (Adware)
solid savings plugin-buttonutil.dll  (a1aec95c71ff8ab8188dea9ec132622c)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
solid savings plugin-helper.exe  (ecb879fcd836ed87e32e2d95a0a550b4)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)

1 / 68      (Adware)
updater12747.exe (Deal Boat by Innovative Apps)  (51d6832223121f5bc7b9a8353718cd68)

1 / 68      (Adware)

1 / 68      (Adware)
updater12767.exe (Tiger Savings by Innovative Apps)  (191fc7b37f7aa06f3a2df0e3142fd59b)

1 / 68      (Adware)

 
Latest 30 of 74 files

The following publishers (by Authenticode signature organization name) are related.

Remove Fun Apps Malware - Powered by Reason Core Security
* Note, the details and description above are based on the code signing digital signature issued to Fun Apps by Thawte, Inc. on June 03, 2013 with the serial number '684b8cfa6a114f5ee6a8115e415bf20a'.