Home Malware Programs Adware 'Continue To Save'

'Continue To Save'

Posted: May 31, 2013

Threat Metric

Ranking: 11,575
Threat Level: 2/10
Infected PCs: 3,907
First Seen: May 31, 2013
Last Seen: September 14, 2023
OS(es) Affected: Windows

'Continue To Save' is an adware program that displays annoying pop-up ads in a form of coupons and deals. Even though 'Continue To Save' delivers various pop-up ads and discounts, it is not advisable to use it. 'Continue To Save' comes bundled together with free software products. 'Continue To Save' uses tricky techniques to install itself on the vulnerable PC. Pop-up advertisements from 'Continue To Save' can be seen when Internet are browsing the web using Internet Explorer, Mozilla Firefox, and Google Chrome. 'Continue To Save' can change the homepage search settings and can redirect affected PC users to suspicious websites. When installed on the hacked Internet browser, 'Continue To Save' adds a browser extension. 'Continue To Save' adware can also keep track of the victim's browsing habits. 'Continue To Save' can steal the target computer user's personal information.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A471032A-1557-2057-9FB4-C0AC087C9AFE}SOFTWARE\Wow6432Node\Microsoft\Tracing\ContinueToSave_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\ContinueToSave_RASMANCS

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\continuEttoSave%ALLUSERSPROFILE%\ContinueToSave%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\ContinueToSave%ALLUSERSPROFILE%\continuEttoSave%ALLUSERSPROFILE%\cuontinuyetoysauve%APPDATA%\Microsoft\Windows\Start Menu\Programs\ContinueToSave%PROGRAMFILES%\ContinueToSave%PROGRAMFILES(x86)%\ContinueToSave
The following URL's were detected:
ContinueToSave
Loading...