84,488,480 programs installed

Should I remove Easy Deals?

What percent of users and experts removed it?
67% remove it33% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Reach 0.0013%
Lifespan of installation (until removal)
< 37.08 days
631.69 days >
Average installed length: 331.90 days

Versions

VersionDistribution
1.34.3.17 3.85%
1.34.2.13 92.31%
1.34.1.29 3.85%

Easy Deals

What is Easy Deals?

This is a JustPlug.It web browser extension that is delivered via the WebPick (InstalleRex) download and install manager. It is included with various adware offer bundles and is a cross browser extension that runs with multiple parts including a Windows service, an auto-starting component and the browser toolbar/plugin which is designed to inject advertisements in the browser in form of banner ads, hyper-text links and popups. In addition, some versions might hijack existing advertising on web sites as well as inject affiliate codes in links as coupon offers. The advertisements that are displayed in the browser could include deceptive malvertising ads for 'required' updates of known common programs as well as unwanted pop-ups advertisements. If downloaded these programs install a number of bundled adware utilities and additional browser extensions. Additionally components of the program will modify the browser's default security levels.

Overview

The most used version is 1.34.2.13, with over 98% of all installations currently using this version. During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a Browser Helper Object (BHO) to Internet Explorer. The main program executable is utils.exe. A vast majority of those who have this installed end up removing it just after a couple weeks. The software installer includes 17 files and is usually about 9.15 MB (9,593,157 bytes). Easy Deals-updater.exe is the automatic update component of the software designed to download and apply new updates should new versions be released.

The program is built using the Crossrider framework, a cross browser monetization platform used to deploy a toolbar and extension for modern web browsers with monetization features including browser search and homepage redirection, contextual coupons and in-line text advertising. Crossrider extensions include background processes to monitor, update and automatically download new features/code without direct user interaction.
  • Possible malware installed by this program
  • Starts automatically
  • Loads into the web browser
  • Built on the Crossrider toolbar platform and potentially unwanted
  • May inject ads in the web browser
  • 'Offers' to modify the browser's home and search pages by default
  • Installs bundled adware using the WebPick InstalleRex
  • Lowers the security level of the web browser
  • Installs with little or no user consent as an 'optional' offer
  • Displays advertisements unassociated with the underlying web page
  • Many experts agree, if you don't use it you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Easy Deals.
utils.exe (b3d0c0862065eb8694ad650d451406d4) has been flagged by the following 6 scanners:
Anti-Virus softwareVersionDetection
avast! 2014.9-140422 Win32:Dropper-gen [Drp]
Baidu-International 4.0.3.14422 Adware.Win32.Somoto.71
Bkav FE 1.3.0.4959 HW32.CDB
Dr.Web 9.0.0.0112 Trojan.Crossrider.4794
ESET-NOD32 8.9654 a variant of Win32/Packed.VMDetector.E
Malwarebytes v2014.04.22.11 PUP.Optional.EasyDeals.A
Easy Deals-bho.dll (32aa4f0d2e04bc4533ae1b97af95d3b0) has been flagged by the following 22 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Trojan.Generic.11182234
Agnitum Outpost 5.5.1.3 PUA.Toolbar.CrossRider!
Avira AntiVir 7.11.150.160 TR/Rogue.11182234
AVG 14.0.0.3950 Generic5.APCA
Baidu-International 3.5.1.41473 Adware.Win32.CrossAd.77
Bitdefender 7.2 Trojan.Generic.11182234
ESET-NOD32 9823 a variant of Win32/Toolbar.CrossRider.AA
Fortinet FortiGate 4 Riskware/Toolbar_CrossRider
F-Secure 11.0.19100.45 Trojan.Generic.11182234
G Data 24 Trojan.Generic.11182234
IKARUS anti.virus T3.1.6.1.0 Trojan.SuspectCRC
K7 AntiVirus 9.177.12128 Trojan ( 004965ab1 )
K7GW 9.177.12128 Trojan ( 004965ab1 )
Malwarebytes 1.75.0001 PUP.Optional.EasyDeals.A
McAfee 6.0.4.564 RDN/Generic PUP.x!ccl
McAfee-GW-Edition 2013 RDN/Generic PUP.x!ccl
MicroWorld-eScan 12.0.250.0 Trojan.Generic.11182234
nProtect 2014-05-19.01 Trojan.Generic.11182234
Sophos 4.98.0 AppRider
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.F47V0405
VIPRE Antivirus 29410 Crossrider (fs)
Easy Deals-enabler.exe (4ab89eb7edaea46d5b3a7288c0782d12) has been flagged by the following 22 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Adware.Generic.912584
Antiy-AVL 0.1.0.1 Trojan/Win32.SGeneric
AVG 13.0.0.3169 Generic5.ANCJ
Baidu-International 3.5.1.41473 Adware.Win32.Lyrics.71
Bitdefender 7.2 Adware.Generic.912584
Dr.Web 7.00.9.04080 Trojan.Crossrider.7519
Emsisoft Anti-Malware 3.0.0.596 Adware.Generic.912584 (B)
ESET-NOD32 9728 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate 4 Riskware/Toolbar_CrossRider
F-Secure 11.0.19100.45 Adware.Generic.912584
G Data 24 Adware.Generic.912584
K7 AntiVirus 9.176.11896 Trojan ( 0049590e1 )
K7GW 9.176.11896 Trojan ( 0049590e1 )
Malwarebytes 1.75.0001 PUP.Optional.EasyDeals.A
McAfee 6.0.4.564 RDN/Generic PUP.x!bvq
McAfee-GW-Edition 2013 RDN/Generic PUP.x!bvq
MicroWorld-eScan 12.0.250.0 Adware.Generic.912584
NANO AntiVirus 0.28.0.59492 Trojan.Win32.Crossrider.cwggpx
Symantec 20131.1.5.61 Adware.Crossid
Trend Micro 9.740-1012 TROJ_GEN.R0CBC0ODM14
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.R0CBC0ODM14
VIPRE Antivirus 28622 Crossrider (fs)
Easy Deals-firefoxinstaller.exe (d5b377e2e92282f321c3edceb9aad967) has been flagged by the following 21 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Adware.Generic.910150
AVG 13.0.0.3169 Generic5.ANHX
Baidu-International 3.5.1.41473 Adware.Win32.AddLyrics.83
Bitdefender 7.2 Adware.Generic.910150
Dr.Web 7.00.9.04080 Trojan.Crossrider.7192
Emsisoft Anti-Malware 3.0.0.596 Adware.Generic.910150 (B)
ESET-NOD32 9728 a variant of Win32/Toolbar.CrossRider.Y
Fortinet FortiGate 4 Riskware/Toolbar_CrossRider
F-Secure 11.0.19100.45 Adware.Generic.910150
G Data 24 Adware.Generic.910150
K7 AntiVirus 9.176.11896 Trojan ( 004958cc1 )
K7GW 9.176.11896 Trojan ( 004958cc1 )
Malwarebytes 1.75.0001 PUP.Optional.EasyDeals.A
McAfee 6.0.4.564 Artemis!D5B377E2E922
McAfee-GW-Edition 2013 Artemis!D5B377E2E922
MicroWorld-eScan 12.0.250.0 Adware.Generic.910150
NANO AntiVirus 0.28.0.59492 Trojan.Win32.Crossrider.cwggpo
Sophos 4.98.0 Generic PUA OK
Symantec 20131.1.5.61 Adware.Crossid
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.R047H05BJ14
VIPRE Antivirus 28622 Crossrider (fs)
Easy Deals-codedownloader.exe (d5415f2d528eeaedaee63ed2a8c71940) has been flagged by the following 19 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Adware.Generic.914312
AVG 14.0.0.3955 Generic5.ANKB
Bitdefender 7.2 Adware.Generic.914312
Dr.Web 7.0.7.12100 Trojan.Crossrider.7913
Emsisoft Anti-Malware 3.0.0.599 Adware.Generic.914312 (B)
ESET-NOD32 9912 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate 5.1.147.0 Riskware/Toolbar_CrossRider
G Data 24 Adware.Generic.914312
K7 AntiVirus 9.179.12333 Trojan ( 0049590e1 )
K7GW 9.179.12333 Trojan ( 0049590e1 )
Malwarebytes 1.75.0.1 PUP.Optional.EasyDeals.A
McAfee 6.0.4.564 Artemis!D5415F2D528E
McAfee-GW-Edition 2013 Artemis!D5415F2D528E
MicroWorld-eScan 12.0.250.0 Adware.Generic.914312
NANO AntiVirus 0.28.0.60100 Trojan.Win32.Crossrider.cwggis
Sophos 4.98.0 AppRider
Symantec 20131.1.5.61 Adware.Crossid
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R0CBH05F414
VIPRE Antivirus 30086 Crossrider (fs)
Easy Deals-updater.exe (47bd70d4f2eea8bf97c1e053a9ef8df2) has been flagged by the following 18 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Adware.Generic.902093
AVG 13.0.0.3169 Generic5.ANJA
Baidu-International 3.5.1.41473 Adware.Win32.Lyrics.71
Bitdefender 7.2 Adware.Generic.902093
Dr.Web 7.00.7.12100 Trojan.Crossrider.7209
Emsisoft Anti-Malware 3.0.0.596 Adware.Generic.902093 (B)
ESET-NOD32 9612 a variant of Win32/Toolbar.CrossRider.X
Fortinet FortiGate 4 Riskware/Toolbar_CrossRider
F-Secure 11.0.19100.45 Adware.Generic.902093
G Data 24 Adware.Generic.902093
Malwarebytes 1.75.0001 PUP.Optional.EasyDeals.A
McAfee 6.0.4.564 Artemis!47BD70D4F2EE
McAfee-GW-Edition 2013 Artemis!47BD70D4F2EE
MicroWorld-eScan 12.0.250.0 Adware.Generic.902093
Sophos 4.98.0 Generic PUA LN
Symantec 20131.1.5.61 Adware.Crossid
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.R047H05BK14
VIPRE Antivirus 27852 Crossrider (fs)
Easy Deals-chromeinstaller.exe (004edbf6080c3acfaf028c955b0e1e25) has been flagged by the following 10 scanners:
Anti-Virus softwareSoftware versionDetection
Baidu-International 3.5.1.41473 Adware.Win32.CrossRider.40
ESET-NOD32 9704 a variant of Win32/Toolbar.CrossRider.Y
K7 AntiVirus 9.176.11833 Trojan ( 004958cc1 )
K7GW 9.176.11833 Trojan ( 004958cc1 )
Malwarebytes 1.75.0001 PUP.Optional.EasyDeals.A
McAfee 6.0.4.564 Artemis!004EDBF6080C
McAfee-GW-Edition 2013 Artemis!004EDBF6080C
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.F47V0303
VIPRE Antivirus 28474 Crossrider (fs)
Easy Deals-bho64.dll (da515c908336ab149f1cede95d109630) has been flagged by the following 4 scanners:
Anti-Virus softwareSoftware versionDetection
Baidu-International 3.5.1.41473 Adware.Win64.Crossrider.D
ESET-NOD32 9601 a variant of Win64/Toolbar.Crossrider.D
Malwarebytes 1.75.0001 PUP.Optional.EasyDeals.A
VIPRE Antivirus 27768 Crossrider (fs)
       View all 122 all detections

Program detailsProgram details

Displayed publisher: Adassist
Installation folder: C:\Program Files\easy deals
Uninstaller: C:\Program Files\Easy Deals\Uninstall.exe /fromcontrolpanel=1
Estimated size: 9.15 MB

Program filesFiles installed by Easy Deals

Program executable:utils.exe (Malware detected)
Path:C:\Program Files\easy deals\utils.exe
MD5:b3d0c0862065eb8694ad650d451406d4
Additional files:
  • Easy Deals-bg.exe (by Adassist) - Easy Deals (Easy Deals exe)
  • (Malware detected) Easy Deals-bho.dll (by Adassist) - Easy Deals BHO
  • Easy Deals-bho64.dll
  • Easy Deals-buttonutil.exe
  • Easy Deals-buttonutil64.exe
  • (Malware detected) Easy Deals-chromeinstaller.exe
  • (Malware detected) Easy Deals-codedownloader.exe
  • (Malware detected) Easy Deals-enabler.exe
  • (Malware detected) Easy Deals-firefoxinstaller.exe
  • (Malware detected) Easy Deals-updater.exe
  • Easy Deals-buttonutil.dll
  • Easy Deals-helper.exe
  • Uninstall.exe

Program behaviorsBehaviors exhibited

2 Internet Explorer BHOs
  • Easy Deals-bho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Easy Deals' with the class of {11111111-1111-1111-1111-110311991194} (CrossriderApp0039994).
  • Easy Deals-bho64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Easy Deals' with the class of {11111111-1111-1111-1111-110311991194} (CrossriderApp0039994).
5 Scheduled Tasks (Boot/Login)
  • Easy Deals-updater.exe is automatically launched at startup through a scheduled task named Easy Deals-updater.
  • Easy Deals-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Easy Deals-firefoxinstaller.
  • Easy Deals-codedownloader.exe is automatically launched at startup through a scheduled task named Easy Deals-codedownloader.
  • Easy Deals-enabler.exe is automatically launched at startup through a scheduled task named Easy Deals-enabler.
  • Easy Deals-chromeinstaller.exe is automatically launched at startup through a scheduled task named Easy Deals-chromeinstaller.

How do I remove Easy Deals?

You can uninstall Easy Deals from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Easy Deals, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Easy Deals.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Easy Deals you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win 7 (SP1) 58%
Win XP 8%
 
HOW IT STARTS
Scheduled task? Yes
(Runs on Windows boot)
 
USER ACTIONS
Uninstall it 67%
Keep it 33%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 57.69%
Windows 10 34.62%
Windows XP 7.69%
Which OS releases does it run on?
Windows 7 Home Premium 32.00%
Windows 8.1 20.00%
Windows 7 Starter 12.00%
Windows 7 Professional 12.00%
Windows 8 4.00%
Windows 8 Pro 4.00%

Distribution by countryGeography

18.52% of installs come from the United States
Which countries install it?
  United States 18.52%
  France 14.81%
  Germany 14.81%
  United Kingdom 14.81%
  Brazil 11.11%
  Canada 7.41%
  LY 3.70%
  Finland 3.70%
  Netherlands 3.70%
  BA 3.70%
  Italy 3.70%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 30.00%
Acer 20.00%
ASUS 5.00%
Dell 5.00%
Lenovo 5.00%
Gateway 5.00%
GIGABYTE 5.00%
Sahara 5.00%
Samsung 5.00%
Toshiba 5.00%
Medion 5.00%
American Megatrends 5.00%
Common models
O.E.M O.E.M 4.76%
LENOVO 20080 4.76%
HP ProBook 4530s 4.76%
Hewlett-Packard G5450frm 4.76%
Hewlett-Packard Compaq Pr... 4.76%
Gigabyte G31M-S2L 4.76%

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.