Home Malware Programs Adware Trusted Saver

Trusted Saver

Posted: July 12, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 340
First Seen: July 12, 2013
Last Seen: May 2, 2022
OS(es) Affected: Windows

Trusted Saver is an adware application that displays pop-up ads and advertising banners on Amazon, Youtube, Walmart and other websites that computer user are visiting. Trusted Saver pop-up ads will be displayed as boxes, which include a variety of coupons that are available or as underlined keywords, which when clicked will show an advertisement that declares it is sent to the PC user by Trusted Saver. Trusted Saver is an extension for Internet Explorer, Mozilla Firefox and Google Chrome that is usually added when web users install another free software products, such as video recording/streaming, download-managers or PDF creators, that had packaged into their installation Trusted Saver. When computer users install these free software products, they will also install Trusted Saver. When installed, whenever the PC user will visit Best Buy, Expedia, Facebook or any other websites, Trusted Saver will show a 'See Similar' button on product images, which when clicked will display pop-up ads by Trusted Saver. Trusted Saver may also show advertising banners on the websites that Internet user are visiting, and as they browse the web, it will display coupons and other deals available on a number of websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Trusted Saver Generic\Trusted Saver Generic-chromeinstaller.exe File name: Trusted Saver Generic-chromeinstaller.exe
Size: 460.8 KB (460800 bytes)
MD5: 729c2125668118e4b3e8f93a3bdbad6e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trusted Saver Generic
Group: Malware file
Last Updated: December 18, 2013
%PROGRAMFILES(x86)%\Trusted Saver Generic\Trusted Saver Generic-codedownloader.exe File name: Trusted Saver Generic-codedownloader.exe
Size: 476.67 KB (476672 bytes)
MD5: e6f3b32666a67d4ec2a87dd3b50bfc87
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trusted Saver Generic
Group: Malware file
Last Updated: December 18, 2013
%PROGRAMFILES(x86)%\Trusted Saver Generic\Trusted Saver Generic-enabler.exe File name: Trusted Saver Generic-enabler.exe
Size: 342.52 KB (342528 bytes)
MD5: 7d3f7216368a4f3ba7d5ace1642f3347
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trusted Saver Generic
Group: Malware file
Last Updated: December 18, 2013
%PROGRAMFILES(x86)%\Trusted Saver Generic\Trusted Saver Generic-firefoxinstaller.exe File name: Trusted Saver Generic-firefoxinstaller.exe
Size: 722.43 KB (722432 bytes)
MD5: 98aca359fa10874485488be385163e5c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trusted Saver Generic
Group: Malware file
Last Updated: December 18, 2013
%PROGRAMFILES(x86)%\Trusted Saver Generic\Trusted Saver Generic-updater.exe File name: Trusted Saver Generic-updater.exe
Size: 361.98 KB (361984 bytes)
MD5: 453beeeec284983b59de0ed3c443d1a2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trusted Saver Generic
Group: Malware file
Last Updated: December 18, 2013
%PROGRAMFILES(x86)%\Trusted Saver\Trusted Saver-updater.exe File name: Trusted Saver-updater.exe
Size: 367.97 KB (367976 bytes)
MD5: 7334ddcee0c3b7beb3cbc1f3d013948d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Trusted Saver
Group: Malware file
Last Updated: December 18, 2013

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\InstalledBrowserExtensions\Trusted SaverSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110311561154}Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{11111111-1111-1111-1111-110311561154}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Trusted Saver Generic-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Trusted Saver Generic-bg.exe

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ccclgllakiohikpgfopakgdlmmgcphhf%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_ccclgllakiohikpgfopakgdlmmgcphhf_0%LOCALAPPDATA%\Trusted Saver Generic%PROGRAMFILES%\Trusted Saver Generic%PROGRAMFILES(x86)%\Trusted Saver Generic
Loading...