Home Malware Programs Adware Savings Wizard

Savings Wizard

Posted: November 13, 2013

Threat Metric

Ranking: 17,007
Threat Level: 2/10
Infected PCs: 9,706
First Seen: November 13, 2013
Last Seen: September 9, 2023
OS(es) Affected: Windows

Savings Wizard Screenshot 1Savings Wizard is an adware coupon application that is known to display random ads through online gaming sites. Savings Wizard may offer coupon saving deals while it loads offers and redirects to other unwanted sites. Use of Savings Wizard is not recommended as it could lead to several unwanted sites that may eventually cause issues with your computer. At times Savings Wizard may change your default internet settings loading up another site as your default home page. Removal of Savings Wizard will eliminate the unwanted redirects.

Savings Wizard Screenshot 2Savings Wizard Screenshot 3Savings Wizard Screenshot 4

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: f5d7b9c2cc901742953c1ea031366975
Detection count: 87
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: June 11, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 17d511a68e1c2238012639ef0f63c4a8
Detection count: 82
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: June 11, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: d4e97ef83987c7abdd2a2d599a66819e
Detection count: 74
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 4b80f9a636066cfa1b900113b90e6d3b
Detection count: 73
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 5f509c0b59c447bd872ca6b8eda36776
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 8ab91db214b525494e774891541911e6
Detection count: 55
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 87cb5b97cbb8c607cf0fccb795bd54d7
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 75368d4ca8eb32e83cca1c041dd6aaab
Detection count: 34
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: a9a0cd024c72c7ac94352c0ec9c9ffdf
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 030abc4d0bace55a7ce072d03d5bc784
Detection count: 25
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 4da97e54e528d06ad242c7d4c39c8268
Detection count: 24
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 074d6eee5a25f21ce15add0f50f8f0dd
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: f6df8a9fb0558a1621c9fa6541f8f838
Detection count: 15
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 8dea80a12395afb1dc87d69a2948dd99
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: b66caa26b98413526ff4ff002ca435f2
Detection count: 13
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: aefa6a48f511a2e1756d58a296ae80c4
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 684ff5bde5b291b94894cab5f88b4c61
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 7881e89eded3f391b1adda1c99064757
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{39B931CF-F1E2-4D04-8129-9EE8159A91C5}{41994F48-3EBD-4921-A3FC-A7886C6205B8}{5682CA62-1A80-40AE-82A0-B67833CE75FF}{CE7FAE28-E04D-496F-B56B-CD9E40998548}{CEADAE6E-E08C-4950-BEBF-149EFD998248}{E7574A3D-0F2D-478D-85F3-9224D7B230EA}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39B931CF-F1E2-4D04-8129-9EE8159A91C5}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5682CA62-1A80-40AE-82A0-B67833CE75FF}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5682CA62-1A80-40AE-82A0-B67833CE75FF}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Savings WizardSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Savings Wizard-repairJobSOFTWARE\Savings WizardSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Savings WizardSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Savings Wizard-repairJobSOFTWARE\Wow6432Node\Savings WizardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38906_Savings Wizard

Additional Information

The following directories were created:
%LOCALAPPDATA%\Savings Wizard%ProgramFiles%\Savings Wizard%ProgramFiles(x86)%\Savings Wizard
The following URL's were detected:
Savings Wizard
Loading...