Home Malware Programs Adware DropinSavings

DropinSavings

Posted: December 10, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 199
First Seen: December 10, 2012
Last Seen: May 2, 2022
OS(es) Affected: Windows

DropinSavings is an adware program that will display its own ads on eBay, Amazon, Facebook and other websites. These advertisements will be displayed as boxes including various coupons that are available, or as underlined keywords, which, when clicked, will display an advertisement that declares it is brought to you by DropinSavings. DropinSavings invades the infected computer after PC users have installed another application that had bundled in their installer the adware application called DropinSavings. Computer users should always pay attention when installing applications because often, a program installer involves optional installs, such as DropinSavings. Computer users should be very careful what they agree to install. It is recommended to always opt for the custom installation and deselect anything that is not known, especially optional software that you never intended to download and install on your PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



DropinSavings.exe File name: DropinSavings.exe
Size: 1.01 MB (1010632 bytes)
MD5: efc943b6b4a1f81caeb7aac485a5baa2
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 9, 2014
%LOCALAPPDATA%\DropinSavings\uninstall.exe File name: uninstall.exe
Size: 219.05 KB (219052 bytes)
MD5: 2165d6c41e1f4c549a53c7dddb302e0e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\DropinSavings
Group: Malware file
Last Updated: July 9, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\DropinSavings-bg.exeSOFTWARE\Wow6432Node\DropinSavingsSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\DropinSavings-bg.exe

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\DropinSavings%LOCALAPPDATA%\DropinSavings%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\mbekfhpolalnahfbbojljmelgnbchaak%PROGRAMFILES%\DropinSavings%PROGRAMFILES(X86)%\DropinSavings
Loading...