Solid Savings is an adware application/browser add-on that displays numerous coupons, offers and special deals that supposedly save PC users’ money while they are shopping online. Solid Savings claims it works with such companies like Expedia, Toysrus, kmart, Zales and many other. The company that owes Solid Savings is 215Apps (Innovative Apps), known to be a developer of Savings Vault, Deals Plugin, Instant Savings App and many other browser extensions. Although Solid Savings can be downloaded from its official website, computer users almost never do this. Usually Solid Savings is spread using deceptive methods, such as packing it together with other applications such as a free video file converter. After Solid Savings is installed automatically, it changes the websites you visit and flood a screen of a targeted PC numerous with pop-up advertisements.

Technical Details

File System Modifications

  • The following files were created in the system:
    # File Name Detection Count
    1 %ALLUSERSPROFILE%\Start Menu\Programs\Solid Savings 287
    2 %APPDATA%\Microsoft\Windows\Start Menu\Programs\Solid Savings 284
    3 %USERPROFILE%\Microsoft\Windows\Start Menu\Programs\Solid Savings 281
    4 %PROGRAMFILES%\ Solid Savings\ Solid Savings.dll 172
    5 SolidSavings.exe 166
    6 %PROGRAMFILES%\Solid Savings 50
    7 %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\cijeeimilokkhlfjombmalgpabbonmah 47
    8 %UserProfile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\cijeeimilokkhlfjombmalgpabbonmah 44
    9 %UserProfile%\Local Settings\Application Data\Updater26278 41
    10 %LOCALAPPDATA%\Updater26278 37

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}CrossriderApp0026278.SandboxCrossriderApp0026278.Sandbox.1Software\AppDataLow\Software\Solid SavingsSOFTWARE\Classes\CrossriderApp0026278.BHOSOFTWARE\Classes\CrossriderApp0026278.BHO.1Software\Cr_Installer\26278Software\InstalledBrowserExtensions\215 Apps, value: 26278SOFTWARE\Proxy\Installations\Solid SavingsSOFTWARE\Solid SavingsSOFTWARE\Wow6432Node\Microsoft\Tracing\26278-internal-installer_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\26278-internal-installer_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\Solid Savings_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Solid Savings_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211621178}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {11111111-1111-1111-1111-110211621178}SOFTWARE\Wow6432Node\Proxy\Installations\Solid SavingsSOFTWARE\Wow6432Node\Solid SavingsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Solid Savings
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {44444444-4444-4444-4444-440244624478}{66666666-6666-6666-6666-660266626678}{55555555-5555-5555-5555-550255625578}{11111111-1111-1111-1111-110211621178}{22222222-2222-2222-2222-220222622278}
Threat Metric
Threat Level: 2/10
Detection Count: 25,260

