OfferBoulevardW.exe

PennyBee

MY POP SHOP LTD

The application OfferBoulevardW.exe by MY POP SHOP has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘OfferBoulevard’. This file is typically installed with the program OfferBoulevard by MY POP SHOP LTD which is a potentially unwanted software program.
Publisher:
MY POP SHOP LTD  (signed and verified)

Product:
PennyBee

Version:
1.0.3.0

MD5:
f11f17f8900614e6ac83ecc69fd1c0e0

SHA-1:
50ca51dca02cd6d390c8ee675d3c85c4cf0d8fc6

SHA-256:
f369223b605a9c39446941f34003719da8536f2d73ebf70927ad70c67330de7e

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/24/2024 11:32:21 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Resoft (M)
16.11.21.16

File size:
370 KB (378,888 bytes)

Product version:
1.0.3.0

Copyright:
Copyright © 2014

Original file name:
OfferBoulevardW.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\offerboulevard\offerboulevardw.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
7/22/2014 9:00:00 AM

Valid to:
7/23/2015 8:59:59 AM

Subject:
CN=MY POP SHOP LTD, O=MY POP SHOP LTD, STREET=14 Shenkar Arie, L=HERZLIYA, S=NA, PostalCode=46725, C=IL

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B739C4F756EE55FB750952CE570BE48B

File PE Metadata
Compilation timestamp:
9/9/2014 11:32:14 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
6144:4XRlRoB+QrS1e6dj7lgdBOkWw4zCCqxt2FfwcLMz6IBnBvmvDbS:YoB+QrS1bdj7lgFZSISf7L6jBb

Entry address:
0x5BC46

Entry point:
FF, 25, 54, BC, 45, 00, 00, 00, 00, 00, 00, 00, 00, 00, 28, BC, 05, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.8996

Code size:
359.5 KB (368,128 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
OfferBoulevard

Command:
C:\Program Files\offerboulevard\offerboulevardw.exe


The file OfferBoulevardW.exe has been discovered within the following program.

OfferBoulevard  by MY POP SHOP LTD
OfferBoulevard, a branded version of DealPly is a potentially unwanted adware program that injects ads into the user's browser.
82% remove it
 
Powered by Should I Remove It?

Remove OfferBoulevardW.exe - Powered by Reason Core Security