Home Malware Programs Adware Adware.Atomic Savings

Adware.Atomic Savings

Posted: April 7, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 752
First Seen: April 7, 2014
Last Seen: October 27, 2022
OS(es) Affected: Windows


Atomic Savings is considered to be adware that may be installed onto the computer as an extra application together with numerous free programs from the Internet. Atomic Savings may display various unwanted pop-up ads and banners, which may contain a variety of offers, discount coupons, sales and deals on the computer system. The pop-up ads shown by Atomic Savings may be random or linked to the computer user's online surfing habits. If the computer user clicks on these pop-up advertisements and messages, Atomic Savings may continuously divert the PC user to questionable websites that may be produced for advertising purposes. Atomic Savings may advertise suspicious websites, services and products. Atomic Savings may collect information about the PC user's browsing activity including search requests and websites visited, or other browsing details.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Atomic Savings\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 70bd4caa8333bffa83d29f1721c2311a
Detection count: 62
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Atomic Savings
Group: Malware file
Last Updated: April 7, 2014
%PROGRAMFILES%\Atomic Savings\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 288.81 KB (288816 bytes)
MD5: e3142b30a086fbdaad1fbae3fad9b98a
Detection count: 59
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Atomic Savings
Group: Malware file
Last Updated: April 7, 2014
%PROGRAMFILES(x86)%\Atomic Savings\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 282.67 KB (282672 bytes)
MD5: 35c9049eb2652c48f7e366dbd42ad554
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Atomic Savings
Group: Malware file
Last Updated: April 7, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\38904SOFTWARE\Atomic SavingsSOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC9920FE-5C04-439B-AE0D-A86D1D38DB4B}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD54B52E-A521-4C98-A65E-2213146AE98D}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{FD54B52E-A521-4C98-A65E-2213146AE98D}SOFTWARE\Wow6432Node\38904SOFTWARE\Wow6432Node\Atomic SavingsSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{AC9920FE-5C04-439B-AE0D-A86D1D38DB4B}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{FD54B52E-A521-4C98-A65E-2213146AE98D}

Additional Information

The following directories were created:
%APPDATA%\{FD54B52E-A521-4C98-A65E-2213146AE98D}%LOCALAPPDATA%\Atomic Savings%PROGRAMFILES%\Atomic Savings%PROGRAMFILES(x86)%\Atomic Savings%USERPROFILE%\AppData\LocalLow\{FD54B52E-A521-4C98-A65E-2213146AE98D}
Loading...