Home Malware Programs Adware GreatSaving

GreatSaving

Posted: August 29, 2014

Threat Metric

Ranking: 9,639
Threat Level: 2/10
Infected PCs: 4,930
First Seen: August 27, 2014
Last Seen: September 22, 2023
OS(es) Affected: Windows


GreatSaving is an unwanted program due to it potentially loading several pop-up or banner advertisements on a computer screen mostly during the time of surfing the internet. The GreatSaving ads may consist of random product offers or coupon deals that entice clicking. When clicked on, the GreatSaving ads are apt to redirecting your web browser to loading a questionable page where other offers may be presented through popular shopping sites. The GreatSaving ads can be rather intrusive and cause performance issues with some web browser applications. It is important to detect all related plugins or components of GreatSaving so that it may be removed for stopping all of its activities of displaying random ads on your computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\greaatsaving\s4G7Qx.x64.dll File name: s4G7Qx.x64.dll
Size: 477.18 KB (477184 bytes)
MD5: 5ee9c4718b0ef3f3f1ec5fd60b810b51
Detection count: 333
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\greaatsaving
Group: Malware file
Last Updated: September 17, 2014
%ALLUSERSPROFILE%\gREAitseaviingg\6Q.x64.dll File name: 6Q.x64.dll
Size: 476.67 KB (476672 bytes)
MD5: 9cb8aa5b192adf18d4c003be4663cacb
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\gREAitseaviingg
Group: Malware file
Last Updated: September 17, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{439763FF-59EC-FF1D-B0B5-CB9E213A7A5C}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\greatsaving
Loading...