dealvault.exe
Savings Vault
Innovative Apps
This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application dealvault.exe, “Savings Vault Installer” by Innovative Apps has been detected as adware by 8 anti-malware scanners. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps (signed by Innovative Apps)
Description:
Savings Vault Installer
MD5:
33913709e01493ac34201dfc5047a891
SHA-1:
9f1a68cf74e154e0e8986de0d35a8dde3c7ba7d0
SHA-256:
57c4b6a93f6922aef148541b6b4694590a52eba95435294b6dc17e4e4e68632d
Scanner detections:
8 / 68
Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.
Analysis date:
12/25/2024 1:28:56 PM UTC (today)
Scan engine
Detection
Engine version
avast!
Win32:Installer-M [Adw]
2014.9-130802
Boost by Reason
Trojan.Adw.Installer.InnovativeApps.J
2013.8.2.23
Dr.Web
Adware.Downware.1054
9.0.1.0214
ESET NOD32
Win32/Packed.ScrambleWrapper
7.8937
G Data
Win32.Trojan.Agent.7M8RUH
13.11.22
Reason Heuristics
PUP.Installer.InnovativeApps.J
14.8.7.17
Trend Micro House Call
TROJ_GEN.F47V0331
7.2.214
VIPRE Antivirus
GamePlayLabs
22514
File size:
3.2 MB (3,340,128 bytes)
Copyright:
Copyright 215 Apps
File type:
Executable application (Win32 EXE)
Language:
English (United States)
Common path:
C:\users\{user}\downloads\dealvault.exe
Valid from:
1/8/2013 4:00:00 PM
Valid to:
1/9/2014 3:59:59 PM
Subject:
CN=Innovative Apps, O=Innovative Apps, L=Philadelphia, S=Pennsylvania, C=US
Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US
Serial number:
5419E32FDAD7A6E5666A35066C5EAAC5
Compilation timestamp:
1/5/2010 4:09:32 AM
CTPH (ssdeep):
98304:hneSKz/w7jgbBBwosPGfSuz0lelN7rtjP6OFV:xeSB7jgvAuzrvjFV
Code size:
33 KB (33,792 bytes)
The file dealvault.exe has been seen being distributed by the following URL.