Home Malware Programs Adware Browse to Save

Browse to Save

Posted: December 3, 2012

Threat Metric

Ranking: 10,364
Threat Level: 2/10
Infected PCs: 7,588
First Seen: December 3, 2012
Last Seen: October 6, 2023
OS(es) Affected: Windows

Browse to Save Screenshot 1'Browse to Save' is an adware program that will display its own ads on eBay, Amazon, Walmart and other websites. These advertisements will be displayed as boxes including various coupons that are available or as underlined keywords, which when clicked will show an advertisement that claims it is brought to you by 'Browse to Save'. 'Browse to Save' can be installed on the compromised PC by another application that has bundled in its installer the 'Browse to Save' adware. Web users should always pay attention when installing programs because often, a program installer incorporates optional installs, such as the actual 'Browse to Save'. PC users should be very careful what they agree to install. They have to always select for the custom installation and deselect anything that is unknown, especially optional applications that they never wanted to download and install on their PCs.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



7zS.sfx.exe File name: 7zS.sfx.exe
Size: 256.77 KB (256779 bytes)
MD5: 227c43818ae609a0f300ec5670aefbd3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022
7zS.sfx.exe File name: 7zS.sfx.exe
Size: 261.66 KB (261665 bytes)
MD5: 3fc4ea421a5487fc5d36282b6d8c6e74
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 17, 2022

Registry Modifications

The following newly produced Registry Values are:

File name without pathBrowse2save.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{54132B7C-E994-948C-D67F-F91400A09989}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{E1CE57A7-0664-0C32-21F3-71302B1586D6}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{E4E81CBD-6726-D85B-ADD4-CEBBCE8D8CB3}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{C3F3165C-74D3-6FDB-3274-14FDA8698CFA}{EF6E8F19-F6ED-8C28-8FAD-002E908466A0}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\Browse2save%ALLUSERSPROFILE%\Barowwsoe2Save%ALLUSERSPROFILE%\Browse2save%ALLUSERSPROFILE%\BrowseToSave%APPDATA%\Microsoft\Windows\Start Menu\Programs\BrowseToSave%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\jgkkcpoognknojmjimfijflnoaglaefc%LocalAppData%\Google\Chrome\User Data\Default\Extensions\cbplgmakhdjoefdjajjpoghjeolbmjmp%LocalAppData%\Google\Chrome\User Data\Default\Extensions\flncacadcohnglflfbbaajblpbcmhndm%PROGRAMFILES%\BrowseToSave%PROGRAMFILES(x86)%\BrowseToSave
The following URL's were detected:
Borowuse2saaveBrOwwse2SaaveiBrowse2saveBrowseToSave
Loading...