‘Continue To Save’

‘Continue To Save’ Description

‘Continue To Save’ is an adware program that displays annoying pop-up ads in a form of coupons and deals. Even though ‘Continue To Save’ delivers various pop-up ads and discounts, it is not advisable to use it.

» Learn more about SpyHunter's Spyware Detection Tool
and steps to uninstall SpyHunter.

‘Continue To Save’ comes bundled together with free software products. ‘Continue To Save’ uses tricky techniques to install itself on the vulnerable PC. Pop-up advertisements from ‘Continue To Save’ can be seen when Internet are browsing the web using Internet Explorer, Mozilla Firefox, and Google Chrome. ‘Continue To Save’ can change the homepage search settings and can redirect affected PC users to suspicious websites. When installed on the hacked Internet browser, ‘Continue To Save’ adds a browser extension. ‘Continue To Save’ adware can also keep track of the victim’s browsing habits. ‘Continue To Save’ can steal the target computer user’s personal information.

‘Continue To Save’ Automatic Detection Tool (Recommended)

Is your PC infected with ‘Continue To Save’? To safely & quickly detect ‘Continue To Save’ we highly recommend you run the malware scanner listed below.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
  • The following files were created in the system:
    # File Name Detection Count
    1 %PROGRAMFILES(x86)%\ContinueToSave 294
    2 %PROGRAMFILES%\ContinueToSave 290
    3 %ALLUSERSPROFILE%\Application Data\continuEttoSave 100
    4 %ALLUSERSPROFILE%\continuEttoSave 97
    5 %USERPROFILE%\Microsoft\Windows\Start Menu\Programs\ContinueToSave 19
    6 %APPDATA%\Microsoft\Windows\Start Menu\Programs\ContinueToSave 16
    7 %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\bkicklfdkakgmmikbhghgbjjphknecbm 12
    8 %UserProfile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bkicklfdkakgmmikbhghgbjjphknecbm 9
    9 %ALLUSERSPROFILE%\cuontinuyetoysauve 3

Registry Modifications

Tutorial: To edit and delete registry entries manually, read the tutorial on how to remove malicious registry entries.

Tip & Warning: Editing and removing the wrong registry keys can severely damage your PC, so remember to backup your Windows Registry! To optimize your Windows Registry and speed up your PC, download RegHunter's registry cleaner.
  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A471032A-1557-2057-9FB4-C0AC087C9AFE}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D6C93088-934B-5ABC-66C4-EC0CA328B4C5}SOFTWARE\Wow6432Node\Microsoft\Tracing\ContinueToSave_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\ContinueToSave_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2A6BCB41-65CF-C803-B02D-FBF3554096CD}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A471032A-1557-2057-9FB4-C0AC087C9AFE}Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D6C93088-934B-5ABC-66C4-EC0CA328B4C5}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {A471032A-1557-2057-9FB4-C0AC087C9AFE}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{FA1A0B09-3ACB-16A3-C1D0-240DDA0812C5}
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {A471032A-1557-2057-9FB4-C0AC087C9AFE}{2A6BCB41-65CF-C803-B02D-FBF3554096CD}
Posted: May 31, 2013 | By
Rate this article:
1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...
Threat Metric
Threat Level: 2/10
Detection Count: 7,520
Home Malware ProgramsAdware ‘Continue To Save’

Leave a Reply

What is 8 + 15 ?
Please leave these two fields as-is:
IMPORTANT! To be able to proceed, you need to solve the following simple math (so we know that you are a human) :-)