Home Malware Programs Adware GoSave

GoSave

Posted: September 25, 2014

Threat Metric

Ranking: 8,087
Threat Level: 2/10
Infected PCs: 13,882
First Seen: September 18, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


GoSave, also known as GGooSave, is a browser extension compatible with Firefox and Chrome. Its marketing describes GoSave as an add-on that helps deliver shopping savings through your browser. However, in practical terms, GoSave is nothing more than adware: a potential problem for your PC and a general performance hazard. Malware researchers and other industry experts agree that removing adware is beneficial – but most unintentional users of GoSave add-ons have a history of struggling with attempts at a successful deletion. Therefore, a reliance on competent anti-adware products can provide the robust software-removal functions required to guarantee that you've deleted GoSave permanently.

The Savings that Cost Your Browser Too Much to Afford

Internet Explorer often is remarked upon as one of the most often-targeted browsers by both the authors of threats and adware producers. Despite that widespread belief, other browsers like Chrome and Firefox appear to be fast at catching up to Microsoft's product. GoSave is adware specializing in Chrome and Firefox, although the advertisements GoSave delivers show little differences from any other adware content also known to afflict additional Web browsers. Although GoSave is self-described as a shopping savings assistant, malware experts find that its method of providing savings, via unrequested advertisements, is more of a disadvantage than a help to your browser.

GoSave also has been highlighted for analysis as a direct result of its recent distribution campaign, which is using non-consensual methods that may include:

  • Bundles, or installers that claim to install one application, but also install at least one other, secondary program (with or without any notification).

GoSave often, but not always is installed along with other adware and PUPs. Related programs seen alongside GoSave include IOBit, Chromatic Browser, YTDownloader, Pando Media Booster and Google Update Helper. All of these products, like GoSave, itself, are programs with poor business histories and long reputations for being installed automatically. Many of them, such as Google Update Helper, additionally are implicated in poorly-managed functions that could corrupt your operating system files or incorrectly configure your system settings.

Getting on the Go Away from GoSave

GoSave advertisements may not be intentional threats to your PC, but the networks favored by GoSave and similar adware may be compromised by threat authors. Along with these risks, GoSave also attempts to block its deletion, which is a behavior malware experts would be unable to condone even in otherwise entirely benign software, let alone adware. Rather than attempting to delete GoSave or remove the browser affected by its advertisements, you should remove GoSave through anti-adware products with proven experience against this type of PUP.

Avoiding GoSave's installation is simpler than removing GoSave, although it may involve many of the same PC security utilities. Downloading files from torrents, trusting unknown software links, using out-of-date security products or allowing scripted Web content to run indiscriminately are some of the possible causes of a GoSave installation. However, with safe browsing habits and updated anti-adware defenses, your PC should never experience the questionable 'savings' that GoSave has to offer.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\GGoSave.GGoSaveSOFTWARE\Classes\GGoSave.GGoSave.2.0SOFTWARE\Classes\GoSave.GoSaveSOFTWARE\Classes\GoSave.GoSave.2.0SOFTWARE\Classes\GoSavEE.GoSavEESOFTWARE\Classes\GoSavEE.GoSavEE.2.0SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{22398e14-76fe-402d-bc0c-c2190cb287d4}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{240ea01e-8f26-4be1-b10e-14bb30c23ec8}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{372f77e6-72c7-49ad-93b0-86fd01c51e70}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{40D4C047-2B8A-12EB-407E-03547D22B0D5}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{4dc6c16d-e4da-49ba-a634-c20234e19499}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6cab2e08-a3d9-418b-9759-59019cf4db27}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{8af548d0-6b57-4aa8-a845-f95555e9bafa}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{a110bdb3-4f32-4544-adbf-cb626c08ea9b}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{b863a163-25d7-4d49-aed7-587e8445df9f}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{cbfd00bd-fd32-46fa-98f3-23dc0bb7458e}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{cc3c665f-b681-48b0-b956-372cd19f317c}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{e2e8e863-0eb9-4c9d-a6d0-6032134099ac}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{e8f64eba-385e-43fe-9ae5-ff14ca20c434}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F38F7180-C11D-96A3-81B4-E512C2ECF92A}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{C87834EB-A2A0-B9D4-AA9A-C263D1191051}

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\fiflfpkilaifoconefongagpdmfacnnm
The following URL's were detected:
GoSAveGoSavEE

Related Posts

Loading...