Home Malware Programs Adware Adware.ShopSave

Adware.ShopSave

Posted: April 22, 2014

Threat Metric

Ranking: 13,328
Threat Level: 2/10
Infected PCs: 18,823
First Seen: April 22, 2014
Last Seen: March 7, 2025
OS(es) Affected: Windows

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\ShopSave Toolbar\2.4.3\KangoBHO.dll File name: KangoBHO.dll
Size: 273.92 KB (273920 bytes)
MD5: 810664ef434de83407b84c4bc742f98b
Detection count: 7,464
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files\ShopSave Toolbar\2.4.3\KangoBHO.dll
Group: Malware file
Last Updated: November 6, 2023
C:\Program Files (x86)\ShopSave Toolbar\2.4.2\KangoBHO64.dll File name: KangoBHO64.dll
Size: 330.24 KB (330240 bytes)
MD5: 393bcc5b0e4120b712b1f9e82a848811
Detection count: 4,127
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\ShopSave Toolbar\2.4.2\KangoBHO64.dll
Group: Malware file
Last Updated: November 6, 2023
file.exe File name: file.exe
Size: 677.56 KB (677565 bytes)
MD5: 3a9523a330d3e7e956f1792d89a6813a
Detection count: 39
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 22, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{033BE5FC-ED4C-48A0-8F07-E0128384D828}{2EF06180-4445-4307-8892-EAE0C0780A84}{6CC4BF79-7708-4ECB-8F2B-A11264A67989}{892CB4DC-3EEB-425D-B348-63F350A0AD9B}{91EE0830-B539-45AB-83F2-741FED0B0E2F}HKEY..\..\..\..{RegistryKeys}Software\Classes\Software\Microsoft\Internet Explorer\Low Rights\Elevation Policy\{9DAD918E-AEED-9FC5-3C30C97CA343}Software\Microsoft\Internet Explorer\Approved Extensions\{033BE5FC-ED4C-48A0-8F07-E0128384D828}Software\Microsoft\Internet Explorer\Approved Extensions\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}Software\Microsoft\Internet Explorer\Low Rights\Elevation Policy\{9DAD918E-AEED-9FC5-3C30C97CA343}SOFTWARE\Microsoft\Internet Explorer\Toolbar\{033BE5FC-ED4C-48A0-8F07-E0128384D828}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{033BE5FC-ED4C-48A0-8F07-E0128384D828}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}SOFTWARE\Wow6432Node\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}SOFTWARE\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{6CC4BF79-7708-4ECB-8F2B-A11264A67989}

Additional Information

The following directories were created:
%AppData%\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}%PROGRAMFILES%\ShopSave Toolbar%PROGRAMFILES(x86)%\ShopSave Toolbar%USERPROFILE%\AppData\LocalLow\{6CC4BF79-7708-4ECB-8F2B-A11264A67989}
Loading...