Supreme Savings is an annoying adware threat that is known for rendering multiple advertisements offering savings and coupons on products. Usually Supreme Savings will load advertisements on popular shopping sites like eBay or Amazon. These offers may lead to other unwanted web pages. Supreme Savings could load into the popular web browser applications like Google Chrome and Internet Explorer. Supreme Savings can be automatically eliminated with the use of an updated antispyware application.

Technical Details

File System Modifications

  • The following files were created in the system:
    # File Name Detection Count
    1 %PROGRAMFILES(x86)%\Supreme Savings 294
    2 %PROGRAMFILES%\Supreme Savings 290
    3 %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ihkeoookbpemkdccdccdmacnidhooohk 287
    4 %UserProfile%\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ihkeoookbpemkdccdccdmacnidhooohk 284
    5 %UserProfile%\Local Settings\Application Data\Updater19962 281
    6 %appdata%\Supreme Savings 256
    7 %USERPROFILE%\AppData\LocalLow\Supreme Savings 253
    8 chrome-extension_ihkeoookbpemkdccdccdmacnidhooohk_0.localstorage 237
    9 %LOCALAPPDATA%\ Microsoft\ Windows\ Temporary Internet Files\ Content.IE5\ KDBIRM9J\ SupremeSavings.exe 128
    10 %ALLUSERSPROFILE%\Start Menu\Programs\Supreme Savings Helper 50

    More files

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}CrossriderApp0019962.BHOCrossriderApp0019962.BHO.1CrossriderApp0019962.SandboxCrossriderApp0019962.Sandbox.1Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Supreme SavingsSoftware\AppDataLow\Software\Supreme SavingsSOFTWARE\Classes\CrossriderApp0019962.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Supreme SavingsSoftware\Cr_Installer\19962Software\InstalledBrowserExtensions\215 Apps, value: 19962Software\InstalledBrowserExtensions\Innovative Apps, value: 19962SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updater19962.exeSOFTWARE\Supreme SavingsSOFTWARE\Supreme Savings HelperSOFTWARE\Wow6432Node\Microsoft\Tracing\Supreme Savings-InternalInstaller_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Supreme Savings-InternalInstaller_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\Supreme Savings_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Supreme Savings_RASMANCSHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Supreme Savings
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path} {22222222-2222-2222-2222-220122992262}{11111111-1111-1111-1111-110111991162}{44444444-4444-4444-4444-440144994462}{66666666-6666-6666-6666-660166996662}{55555555-5555-5555-5555-550155995562}
Threat Metric
Threat Level: 2/10
Detection Count: 38,691
