Home Malware Programs Adware Adware.Slick Savings

Adware.Slick Savings

Posted: September 4, 2013

Threat Metric

Ranking: 2,842
Threat Level: 2/10
Infected PCs: 327,465
First Seen: September 4, 2013
Last Seen: March 10, 2025
OS(es) Affected: Windows

Slick Savings is an adware program that displays advertisements in your browser, supposedly as a way to provide you with shopping-related sales and offers. While there may be some beneficial content included in Slick Savings's advertisements, SpywareRemove.com malware experts have noted Slick Savings's poor advertisement-displaying controls, its tendency to be installed and its tendency to refuse to be uninstalled directly as typical traits of undesirable adware. Slick Savings and similar adware programs usually should be uninstalled by dependable anti-malware tools when they're seen. Fortunately, since Slick Savings identifies its advertisements clearly, noticing Slick Savings in the first place shouldn't be a serious challenge.

The Shopping Saver that's Slick About Saving Itself the Trouble of Marketing

Although Slick Savings doesn't make any efforts to hide its intentions as a shopping-themed adware add-on, neither does Slick Savings bother to invest in anything resembling stereotypical Web marketing practices. SpywareRemove.com malware researchers thusly warn that Slick Savings installations most likely are distributed in bundles with separate programs through commonly-exploited infection vectors like inauspicious freeware websites, torrenting networks and the like.

After Slick Savings has been installed (a process that usually does not give you an opt-out option), Slick Savings will proceed with displaying various advertisements related to online shopping bargains. SpywareRemove.com malware experts have not yet analyzed all of the advertising content promoted by Slick Savings, but still suggest that you keep all of the usual warnings regarding potentially harmful advertisement content in mind while dealing with Slick Savings. Advertisements may display fraudulent offers, trick you into compromising your personal information or simply fail to provide you with better deals than you would be able to find yourself with an appropriate search engine and a little effort.

However, SpywareRemove.com malware researchers are happy to find that Slick Savings does identify its advertisements separately from any normal Web page content. Therefore, identifying Slick Savings and sorting its advertisements from a normal website's content should be a trivial affair.

Saving Yourself the Bother of Dealing with Slick Savings

Because Slick Savings usually is installed along with several other browser add-ons, including other forms of adware and PUPs, deleting Slick Savings often will include deleting some additional toolbars, as well. Quite naturally, SpywareRemove.com malware researchers consider basic anti-malware scans to be the simplest and most time-effective way of removing Slick Savings and related PC threats, and no additional security steps should be necessary, in most cases. However, Slick Savings does tend to try to prevent itself from being removed from your browser's normal add-on management settings.

Slick Savings and other adware programs usually don't install themselves as separate programs. Instead, they're reliant on the software bundles of other products. If you're careful about refusing installers from suspicious websites and always look through any installation options attentively, your computer usually will never be bothered by Slick Savings – or most other types of adware.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\Slick Savings\Coupons.dll{3258A6E4-5E6B-4EE8-9433-6761ECD6F4FA}.old File name: Coupons.dll{3258A6E4-5E6B-4EE8-9433-6761ECD6F4FA}.old
Size: 538.94 KB (538944 bytes)
MD5: 6b1a43ff810aaceb2dc7cfa541e89cf3
Detection count: 6,204
Mime Type: unknown/old
Path: C:\Users\<username>\AppData\Roaming\Slick Savings\Coupons.dll{3258A6E4-5E6B-4EE8-9433-6761ECD6F4FA}.old
Group: Malware file
Last Updated: October 19, 2021
C:\Users\<username>\AppData\Roaming\Slick Savings\Coupons64.dll{76FB9D0A-346B-4005-922C-17F9FCFB1530}.old File name: Coupons64.dll{76FB9D0A-346B-4005-922C-17F9FCFB1530}.old
Size: 629.05 KB (629056 bytes)
MD5: 2b371a3d2c24fde1be29f1716752243b
Detection count: 4,127
Mime Type: unknown/old
Path: C:\Users\<username>\AppData\Roaming\Slick Savings\Coupons64.dll{76FB9D0A-346B-4005-922C-17F9FCFB1530}.old
Group: Malware file
Last Updated: March 4, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\Slick Savings\coupons.dll{96A67BB8-F56E-4022-BCA0-B94AE158C1B1}.old.vir File name: coupons.dll{96A67BB8-F56E-4022-BCA0-B94AE158C1B1}.old.vir
Size: 605.54 KB (605544 bytes)
MD5: 1f3950302ba2cd77491146081b427c07
Detection count: 1,855
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\Slick Savings\coupons.dll{96A67BB8-F56E-4022-BCA0-B94AE158C1B1}.old.vir
Group: Malware file
Last Updated: July 27, 2020
%SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20200812.155641\1\BrowserExtensions\Coupons64.dll#8A974E229A7629FA File name: Coupons64.dll#8A974E229A7629FA
Size: 272.36 KB (272368 bytes)
MD5: c721fecb7a649d7b36042f047a8d5526
Detection count: 1,120
Mime Type: unknown/dll#8A974E229A7629FA
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20200812.155641\1\BrowserExtensions\Coupons64.dll#8A974E229A7629FA
Group: Malware file
Last Updated: October 29, 2024
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\Slick Savings\coupons.dll{5E6A5D73-6104-44AE-B6E7-FE9ADB7D3DB2}.old.vir File name: coupons.dll{5E6A5D73-6104-44AE-B6E7-FE9ADB7D3DB2}.old.vir
Size: 609.12 KB (609128 bytes)
MD5: e3e9daf4948c1244b10be0b015fef52c
Detection count: 1,087
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\Slick Savings\coupons.dll{5E6A5D73-6104-44AE-B6E7-FE9ADB7D3DB2}.old.vir
Group: Malware file
Last Updated: March 4, 2023
%SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20200812.155641\1\BrowserExtensions\Coupons.dll#404358478ABC0737 File name: Coupons.dll#404358478ABC0737
Size: 248.81 KB (248816 bytes)
MD5: db440de69140b562d95b6411d5dd70f0
Detection count: 902
Mime Type: unknown/dll#404358478ABC0737
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\v1\20200812.155641\1\BrowserExtensions\Coupons.dll#404358478ABC0737
Group: Malware file
Last Updated: October 29, 2024
%APPDATA%\Slick Savings\uninstall.exe File name: uninstall.exe
Size: 188.23 KB (188236 bytes)
MD5: 930c6fb8638fb1b2e4798b8717ac4dd0
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Slick Savings
Group: Malware file
Last Updated: December 20, 2013
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\Browser Extensions\Coupons.dll.vir File name: Coupons.dll.vir
Size: 248.81 KB (248816 bytes)
MD5: 49b3426a3dd468cfcfefb858930a79bb
Detection count: 68
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Users\<username>\AppData\Roaming\Browser Extensions\Coupons.dll.vir
Group: Malware file
Last Updated: February 14, 2022
%SystemDrive%\Users\<username>\AppData\Roaming\BrowserExtensions\Coupons64.dll File name: Coupons64.dll
Size: 272.36 KB (272368 bytes)
MD5: 047fad4a79b78ed522628e2eea716d4b
Detection count: 20
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Roaming\BrowserExtensions
Group: Malware file
Last Updated: March 23, 2016
%APPDATA%\BrowserExtensions\Coupons.dll File name: Coupons.dll
Size: 248.81 KB (248816 bytes)
MD5: 6d523c5afec0c7808b486e1a6705e913
Detection count: 4
File type: Dynamic link library
Mime Type: unknown/dll
Path: %APPDATA%\BrowserExtensions
Group: Malware file
Last Updated: March 26, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Browser Extensions\firefox\saamazon@mybrowserbar.comSoftware\AppDataLow\Software\Browser Extensions\firefox\saebay@mybrowserbar.comSoftware\AppDataLow\Software\Browser Extensions\firefox\savingsslider@mybrowserbar.comSoftware\AppDataLow\Software\Browser Extensions\firefox\{58d2a791-6199-482f-a9aa-9b725ec61362}Software\AppDataLow\Software\Slick SavingsSoftware\Microsoft\Internet Explorer\Approved Extensions\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Browser ExtensionsSOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchSettingsSOFTWARE\Microsoft\Windows\CurrentVersion\Run\Slick SavingsSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\SearchSettingsSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Slick SavingsHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{3A787631-66A2-4634-B928-A37E73B58FB6}

Additional Information

The following directories were created:
%APPDATA%\Browser Extensions%APPDATA%\BrowserExtensions%APPDATA%\Slick Savings%LOCALAPPDATA%\Slick Savings%USERPROFILE%\Local Settings\Application Data\Slick Savings
The following URL's were detected:
Spigot, Inc.
Loading...