Home Malware Programs Adware AllDay Savings

AllDay Savings

Posted: July 21, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 2,007
First Seen: July 21, 2014
Last Seen: March 23, 2024
OS(es) Affected: Windows


AllDay Savings is an adware program that may be committed to displaying random ads attempting to offer various discounts or coupon deals for shopping on the internet. The AllDay Savings ads may come in various formats where pop-ups, pop-unders or banners are displayed on your web browser while you are surfing the internet. The display of the random AllDay Savings ads may reduce performance of your web browser making it an annoying situation to surf the web or view certain sites. The AllDay Savings application and its associated files could load up on your computer automatically without your permission due to installing random freeware programs or bundled software apps. Through the use of antispyware tool you may easily eliminate AllDay Savings and its associated files thus stopping its actions of displaying random unwanted advertisements on your screen.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Windows.old.000\Users\<username>\AppData\Local\Temp\air6C96.exe File name: air6C96.exe
Size: 1.43 MB (1434512 bytes)
MD5: 489b33a7140f4bebd432cfec11705655
Detection count: 68
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows.old.000\Users\<username>\AppData\Local\Temp\air6C96.exe
Group: Malware file
Last Updated: December 15, 2022

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\allday savingsSOFTWARE\AllDaySavingsSOFTWARE\B021CBBD-E38E-4F8C-8E93-6624B0597A23SOFTWARE\Wow6432Node\AllDaySavingsSYSTEM\ControlSet001\Services\AllDaySavingsServiceSYSTEM\ControlSet001\Services\AllDaySavingsService64SYSTEM\ControlSet001\services\cyycfhtzro64SYSTEM\ControlSet002\Services\AllDaySavingsServiceSYSTEM\ControlSet002\Services\AllDaySavingsService64SYSTEM\ControlSet002\services\cyycfhtzro64SYSTEM\CurrentControlSet\Services\AllDaySavingsServiceSYSTEM\CurrentControlSet\Services\AllDaySavingsService64SYSTEM\CurrentControlSet\services\cyycfhtzro64HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}B021CBBD-E38E-4F8C-8E93-6624B0597A23

Additional Information

The following directories were created:
%PROGRAMFILES%\06E8E229-66C7-47D9-BED6-AEA2B027D6CD%PROGRAMFILES%\0979EC39-B1D4-47D3-9D25-1305B55C64DF%PROGRAMFILES%\2B6A3384-29F8-4469-8585-001604CFE056%PROGRAMFILES%\3CC1B5D1-59F3-4415-8A91-3C80196471F7%PROGRAMFILES%\57811C9B-47BF-473D-9216-8BABBA33DE1C%PROGRAMFILES%\60951E57-596F-4F68-8D9E-F32C835AE122%PROGRAMFILES%\60DFCCEC-70F7-413B-8AA4-F82B76E1EB9F%PROGRAMFILES%\6309A20B-AE43-4AF1-9139-6C217CA9AD33%PROGRAMFILES%\7DC27B1-9B37-469B-A163-7A046D20BFCE%PROGRAMFILES%\AllDaySavings%PROGRAMFILES%\B021CBBD-E38E-4F8C-8E93-6624B0597A23%PROGRAMFILES%\C13DB9D9-D8B8-4E8F-B4ED-BCFCC8C284E7%PROGRAMFILES%\C19E5206-B324-4F60-9A43-1E83FFD73086%PROGRAMFILES%\D41A468B-210E-4C1E-8C19-6245063B4032%PROGRAMFILES%\F39EE28F-D410-4882-9303-A2D760308B70%PROGRAMFILES%\FF822B94-D02A-4A2C-BF00-D6D6A858F456%PROGRAMFILES(x86)%\06E8E229-66C7-47D9-BED6-AEA2B027D6CD%PROGRAMFILES(x86)%\0979EC39-B1D4-47D3-9D25-1305B55C64DF%PROGRAMFILES(x86)%\2B6A3384-29F8-4469-8585-001604CFE056%PROGRAMFILES(x86)%\3CC1B5D1-59F3-4415-8A91-3C80196471F7%PROGRAMFILES(x86)%\57811C9B-47BF-473D-9216-8BABBA33DE1C%PROGRAMFILES(x86)%\60951E57-596F-4F68-8D9E-F32C835AE122%PROGRAMFILES(x86)%\60DFCCEC-70F7-413B-8AA4-F82B76E1EB9F%PROGRAMFILES(x86)%\6309A20B-AE43-4AF1-9139-6C217CA9AD33%PROGRAMFILES(x86)%\7DC27B1-9B37-469B-A163-7A046D20BFCE%PROGRAMFILES(x86)%\B021CBBD-E38E-4F8C-8E93-6624B0597A23%PROGRAMFILES(x86)%\C13DB9D9-D8B8-4E8F-B4ED-BCFCC8C284E7%PROGRAMFILES(x86)%\C19E5206-B324-4F60-9A43-1E83FFD73086%PROGRAMFILES(x86)%\D41A468B-210E-4C1E-8C19-6245063B4032%PROGRAMFILES(x86)%\F39EE28F-D410-4882-9303-A2D760308B70%PROGRAMFILES(x86)%\FF822B94-D02A-4A2C-BF00-D6D6A858F456
Loading...