SavingsCool Ads
Posted: November 21, 2016
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 10,038 |
---|---|
Threat Level: | 2/10 |
Infected PCs: | 16,355 |
First Seen: | November 21, 2016 |
---|---|
Last Seen: | October 11, 2023 |
OS(es) Affected: | Windows |
SavingsCool is an adware application difficult to remove from the affected computer because it might hide some of its files in various folders to make sure that it'll continue to operate even after the user uninstalls it via the Windows Control Panel. While this adware is active, the affected user might end up seeing a large number of 'SavingsCool ads' in their Web browser, and the contents of these ads may often be associated with potentially harmful websites, products and services.
The individuals and companies who pay adware developers to distribute their ads may not be among the most honest in their branch so that it is safe to assume that the contents of the SavingsCool ads are not something that should be trusted. This adware, in particular, is able to inject its advertisements in popular browsing clients like Google Chrome, Mozilla Firefox, Opera, and Internet Explorer so that it is safe to say that any user who comes across SavingsCool will end up being affected by its nagging advertisements.
As the name of the extension suggests, SavingsCool might be promoted as a program that can help users save money while shopping online. This might happen via notifications regarding exclusive offers, discounts and coupon codes, but this content also might be accompanied by the rest of the low-quality advertisements mentioned earlier. The removal of SavingsCool is not as simple as it may sound because the executable files linked to the adware might be spread to different folders. For example, one of the files associated with this adware is 'NTCACHE.exe,' which is situated in the default 'Downloads' folder.
If you suspect that the advertisements you are seeing while browsing the Web are linked to SavingsCool, then you should install and run an anti-malware tool that can take care of the issue for you immediately. Modern anti-malware utilities should be able to identify and remove the files linked to SavingsCool Ads quickly, therefore solving the problem permanently.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\wlupdater.exe
File name: wlupdater.exeSize: 7.08 MB (7082496 bytes)
MD5: 55698be1a03cee539fd34f4360e051a4
Detection count: 358
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: March 14, 2017
%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\slinit.exe
File name: slinit.exeSize: 7.07 MB (7074304 bytes)
MD5: ae9f2bb3c4718e512dd6fa76e9b99ed7
Detection count: 183
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: August 21, 2018
%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\slinit.exe
File name: slinit.exeSize: 7.08 MB (7081984 bytes)
MD5: 37bc7f1308735df5ede44dc48ae6eefb
Detection count: 176
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: August 14, 2018
%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\wlupdater.exe
File name: wlupdater.exeSize: 7.08 MB (7081472 bytes)
MD5: c94147a719d7df6fcd416132c793eaa5
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater
Group: Malware file
Last Updated: March 23, 2020
Registry Modifications
Regexp file mask%ALLUSERSPROFILE%\Microsoft\Windows\WinLogonUpdater\slinit.exe%COMMONPROGRAMFILES%\Lonanwidroad\Lonanwidroad.exe%COMMONPROGRAMFILES(x86)%\Lonanwidroad\Lonanwidroad.exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\SavingsCoolSOFTWARE\Wow6432Node\SavingsCoolHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SavingsC00LSavingsCool
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.