Home Malware Programs Adware InstantSavingsApp

InstantSavingsApp

Posted: February 26, 2013

Threat Metric

Ranking: 19,409
Threat Level: 2/10
Infected PCs: 4,579
First Seen: February 26, 2013
Last Seen: January 28, 2025
OS(es) Affected: Windows

InstantSavingsApp Screenshot 1Instant Savings App is adware that displays a pop-up box with ads when installed on the computer system. Usually, pop-ups displayed by InstantSavingsApp may include discount coupons, deals, offers or savings for the products that the PC user may be interested in. InstantSavingsApp may be able to monitor the PC user's browsing habits, visited websites, and words or phrases that he is searching on the Internet. With this data, Instant Savings App may then show relevant pop-up ads and messages once the computer user is surfing online shopping websites. Instant Savings App may appear as a bundled application with free software that computer users may download from download websites.

InstantSavingsApp Screenshot 2InstantSavingsApp Screenshot 3InstantSavingsApp Screenshot 4

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Local Settings\Application Data\Instant Savings App\repair.js File name: repair.js
Size: 1.76 KB (1760 bytes)
MD5: d65af8a6e83f1e34df4b2546d7b61fcb
Detection count: 1,834
File type: JavaScript file
Mime Type: unknown/js
Path: %USERPROFILE%\Local Settings\Application Data\Instant Savings App
Group: Malware file
Last Updated: May 7, 2022
%PROGRAMFILES(x86)%\Instant Savings App\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 163e4fb17e03acf25c3746d0e45d8ce2
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Instant Savings App
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Instant Savings App\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 427799514ea163e613a2d5872040c406
Detection count: 45
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Instant Savings App
Group: Malware file
Last Updated: February 10, 2014
C:\Program Files (x86)\Instant Savings App\KangoEngine.exe File name: KangoEngine.exe
Size: 276.48 KB (276480 bytes)
MD5: 468fb48bed34208a55c73dd3c6d73874
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Instant Savings App\KangoEngine.exe
Group: Malware file
Last Updated: July 13, 2021
%PROGRAMFILES%\Instant Savings App\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: e6e4039d6fde2c4acea33e6e7c189c13
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Instant Savings App
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES%\Instant Savings App\Instant Savings App-bho.dll File name: Instant Savings App-bho.dll
Size: 602.5 KB (602504 bytes)
MD5: cf7dad2203457e5533763218877da661
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Instant Savings App
Group: Malware file
Last Updated: February 10, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{15BE519B-2D82-431B-8747-26F9877D1116}{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}{6EE7A41D-6050-4DCF-8498-4C70E84BEAE8}{77AD9A6E-DB8C-4550-BEBF-146FFDD7820A}{D620FD57-1C61-407F-B689-D072B7A439AF}{D629FDE2-1C75-40B2-9B20-CE72D3A430AF}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\CrossriderApp0004351.BHOSOFTWARE\Classes\CrossriderApp0004351.BHO.1SOFTWARE\Classes\CrossriderApp0004351.SandboxSOFTWARE\Classes\CrossriderApp0004351.Sandbox.1SOFTWARE\Instant Savings AppSoftware\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110011431151}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5DF1907E-15A0-44C8-918A-F9C0DE745BB0}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Instant Savings App-bg.exeSoftware\Microsoft\Windows\CurrentVersion\Ext\Settings\{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}SOFTWARE\Wow6432Node\Instant Savings AppSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5DF1907E-15A0-44C8-918A-F9C0DE745BB0}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Instant Savings App-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}4351_Instant Savings AppInstant Savings App

Additional Information

The following directories were created:
%LOCALAPPDATA%\Instant Savings App%LOCALAPPDATA%\Updater4351%PROGRAMFILES%\Instant Savings App%PROGRAMFILES(x86)%\Instant Savings App%USERPROFILE%\AppData\LocalLow\{6EB4A4C0-6036-4D2E-B010-20707C4B62E8}%appdata%\Microsoft\Windows\Start Menu\Programs\Instant Savings App
The following URL's were detected:
Instant Savings App
Loading...