dealkeeper.browserfilter.helper.dll

Deal Keeper

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module dealkeeper.browserfilter.helper.dll by Deal Keeper has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Deal Keeper by Yontoo Technology, Inc. which is a potentially unwanted software program.
Publisher:
Deal Keeper  (signed and verified)

MD5:
357df63230d6f7dd5e1c6d57ed271189

SHA-1:
3331ba0c72b297cf76b87c141d5622847a00f6cb

SHA-256:
c7893720f04e0dd11731f8b53810db39f4202a948f4da7b221dd73aa64306807

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Belongs to the Sambreel/Yontoo progam that inserts various forms of advertising in the user's web browser, installed with minimal or no user consent.

Analysis date:
5/3/2024 7:09:57 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Yontoo (M)
17.3.8.0

File size:
388.7 KB (398,072 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\Program Files\deal keeper\dealkeeper.browserfilter.helper.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
7/22/2014 3:00:00 AM

Valid to:
5/13/2015 2:59:59 AM

Subject:
CN=Deal Keeper, O=Deal Keeper, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
2D5A91A625D274EE29AFF6E5DC4A33AC

File PE Metadata
Compilation timestamp:
7/23/2014 8:39:54 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x1A2DA

Entry point:
8B, FF, 55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, F5, 61, 00, 00, FF, 75, 08, 8B, 4D, 10, 8B, 55, 0C, E8, EC, FE, FF, FF, 59, 5D, C2, 0C, 00, 8B, FF, 55, 8B, EC, 81, EC, 28, 03, 00, 00, A3, 40, D4, 05, 10, 89, 0D, 3C, D4, 05, 10, 89, 15, 38, D4, 05, 10, 89, 1D, 34, D4, 05, 10, 89, 35, 30, D4, 05, 10, 89, 3D, 2C, D4, 05, 10, 66, 8C, 15, 58, D4, 05, 10, 66, 8C, 0D, 4C, D4, 05, 10, 66, 8C, 1D, 28, D4, 05, 10, 66, 8C, 05, 24, D4, 05, 10, 66, 8C, 25, 20, D4, 05, 10, 66, 8C, 2D, 1C, D4, 05, 10, 9C, 8F, 05, 50, D4...
 
[+]

Entropy:
4.9091

Code size:
174 KB (178,176 bytes)

The file dealkeeper.browserfilter.helper.dll has been discovered within the following program.

Deal Keeper  by Yontoo Technology, Inc.
Deal Keeper is an web browser advertisement extension that delivers ads to the user's web browser. Ads are in the form of traditional banners as well as context-hyper links.
mightydealkeeper.com/support
86% remove it
 
Powered by Should I Remove It?

Remove dealkeeper.browserfilter.helper.dll - Powered by Reason Core Security