Home Malware Programs Adware Solid Savings

Solid Savings

Posted: March 14, 2013

Threat Metric

Ranking: 14,716
Threat Level: 2/10
Infected PCs: 3,590
First Seen: March 14, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

Solid Savings is an adware application/browser add-on that displays numerous coupons, offers and special deals that supposedly save PC users' money while they are shopping online. Solid Savings claims it works with such companies like Expedia, Toysrus, kmart, Zales and many other. The company that owes Solid Savings is 215Apps (Innovative Apps), known to be a developer of Savings Vault, Deals Plugin, Instant Savings App and many other browser extensions. Although Solid Savings can be downloaded from its official website, computer users almost never do this. Usually Solid Savings is spread using deceptive methods, such as packing it together with other applications such as a free video file converter. After Solid Savings is installed automatically, it changes the websites you visit and flood a screen of a targeted PC numerous with pop-up advertisements.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110211621178}{22222222-2222-2222-2222-220222622278}{44444444-4444-4444-4444-440244624478}{55555555-5555-5555-5555-550255625578}{66666666-6666-6666-6666-660266626678}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Solid SavingsSOFTWARE\Classes\CrossriderApp0026278.BHOSOFTWARE\Classes\CrossriderApp0026278.BHO.1SOFTWARE\Classes\CrossriderApp0026278.SandboxSOFTWARE\Classes\CrossriderApp0026278.Sandbox.1Software\Cr_Installer\26278Software\InstalledBrowserExtensions\215 Apps\26278SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater26278.exeSOFTWARE\Proxy\Installations\Solid SavingsSOFTWARE\Solid SavingsSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211621178}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211621178}SOFTWARE\Wow6432Node\Microsoft\Tracing\Solid Savings_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Solid Savings_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211621178}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110211621178}SOFTWARE\Wow6432Node\Proxy\Installations\Solid SavingsSOFTWARE\Wow6432Node\Solid SavingsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Solid Savings

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\Solid Savings%LOCALAPPDATA%\Solid Savings%LOCALAPPDATA%\Updater26278%PROGRAMFILES%\Solid Savings%PROGRAMFILES(x86)%\Solid Savings%UserProfile%\Local Settings\Application Data\Solid Savings%UserProfile%\Local Settings\Application Data\Updater26278
The following URL's were detected:
Solid Savings
Loading...