Home Malware Programs Adware SavingsCool Ads

SavingsCool Ads

Posted: November 21, 2016

Threat Metric

Ranking: 10,038
Threat Level: 2/10
Infected PCs: 16,355
First Seen: November 21, 2016
Last Seen: October 11, 2023
OS(es) Affected: Windows


SavingsCool is an adware application difficult to remove from the affected computer because it might hide some of its files in various folders to make sure that it'll continue to operate even after the user uninstalls it via the Windows Control Panel. While this adware is active, the affected user might end up seeing a large number of 'SavingsCool ads' in their Web browser, and the contents of these ads may often be associated with potentially harmful websites, products and services.

The individuals and companies who pay adware developers to distribute their ads may not be among the most honest in their branch so that it is safe to assume that the contents of the SavingsCool ads are not something that should be trusted. This adware, in particular, is able to inject its advertisements in popular browsing clients like Google Chrome, Mozilla Firefox, Opera, and Internet Explorer so that it is safe to say that any user who comes across SavingsCool will end up being affected by its nagging advertisements.

As the name of the extension suggests, SavingsCool might be promoted as a program that can help users save money while shopping online. This might happen via notifications regarding exclusive offers, discounts and coupon codes, but this content also might be accompanied by the rest of the low-quality advertisements mentioned earlier. The removal of SavingsCool is not as simple as it may sound because the executable files linked to the adware might be spread to different folders. For example, one of the files associated with this adware is 'NTCACHE.exe,' which is situated in the default 'Downloads' folder.

If you suspect that the advertisements you are seeing while browsing the Web are linked to SavingsCool, then you should install and run an anti-malware tool that can take care of the issue for you immediately. Modern anti-malware utilities should be able to identify and remove the files linked to SavingsCool Ads quickly, therefore solving the problem permanently.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\wlupdater.exe File name: wlupdater.exe
Size: 7.08 MB (7082496 bytes)
MD5: 55698be1a03cee539fd34f4360e051a4
Detection count: 358
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: March 14, 2017
%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\slinit.exe File name: slinit.exe
Size: 7.07 MB (7074304 bytes)
MD5: ae9f2bb3c4718e512dd6fa76e9b99ed7
Detection count: 183
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: August 21, 2018
%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\slinit.exe File name: slinit.exe
Size: 7.08 MB (7081984 bytes)
MD5: 37bc7f1308735df5ede44dc48ae6eefb
Detection count: 176
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: August 14, 2018
%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\wlupdater.exe File name: wlupdater.exe
Size: 7.08 MB (7081472 bytes)
MD5: c94147a719d7df6fcd416132c793eaa5
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: March 23, 2020

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\slinit.exe%COMMONPROGRAMFILES%\Lonanwidroad\Lonanwidroad.exe%COMMONPROGRAMFILES(x86)%\Lonanwidroad\Lonanwidroad.exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\SavingsCoolSOFTWARE\Wow6432Node\SavingsCoolHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SavingsC00LSavingsCool

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\CredManager
Loading...