Home Malware Programs Adware RRsavings

RRsavings

Posted: April 16, 2014

Threat Metric

Ranking: 6,423
Threat Level: 2/10
Infected PCs: 42,926
First Seen: April 16, 2014
Last Seen: October 14, 2023
OS(es) Affected: Windows


RRsavings is a Potentially Unwanted Program that's used for loading shopping-related advertisements, which RRsavings claims to provide as online coupons. Although you may find some limited savings through RRsavings's function, malware experts have seen RRsavings often surface in circumstances where RRsavings could be part of an overarching security problem for the affected Web browser. Along with having a decidedly poor distribution model, RRsavings also attempts to block its deletion, which is why applications with anti-malware or anti-adware functions are encouraged for keeping these 'savings' from staying on your browser longer than intended.

A Shortcut to Low Prices – or a Shortcut to Poor Web Security

RRsavings's website promotes RRsavings as a coupon dispenser that enables you to have effortless access to alternative prices while you are shopping at popular websites. Although this function is not necessarily dishonest, neither does it provide any true value to the user, since RRsavings provides these 'coupons' according to affiliate rankings, and not according to the best possible prices. Malware researchers usually would recommend that you uninstall shopping assistant-based adware, but in the case of this RRsavings, they have even more reason than usual to encourage you to do so.

RRsavings may be distributed through bundles that include up to dozens of other Potentially Unwanted Programs, along with itself, and has been seen being installed by PDF converters, Windows scheduling widgets and other unrelated, third-party products with poor reputations. While RRsavings's website offers particularly unorthodox instructions for its removal, malware researchers found the provided advice confusing and, in any case, noted that it should not be required to remove any normally-installed and legitimate application. With suspicious behavior both coming and going, RRsavings clearly is an example of adware that pretends to be helpful to its users, when its actual job is to provide profits at their expense.

Saving Your Browser from a Fake Savings Add-On

RRsavings's advertising campaign has been particularly active as of April 2014, but does not yet appear to have spread significantly beyond US residents. To do your part in keeping its unwanted distribution under control, malware researchers would recommend avoiding known adware-installing sites and illegal software-downloading networks. You also can scan any possible RRsavings-bundling files with anti-adware utilities that have the ability to detect these common bundler programs.

RRsavings is part of a long series of similar adware programs that seem like they could offer shopping advantages, but end up being an overall drawback to your Web browser. Always be suspicious of third-party programs installed by unrelated products, such as RRsavings and its inclination for being installed through PDF conversion tools. These bundles occasionally include legitimate and benign software, but, most often, are modes of distribution for RRsavings and other, equally distasteful adware.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\164240281298608\Program Files\RrFilter\RrFilterService.exe File name: RrFilterService.exe
Size: 149.5 KB (149504 bytes)
MD5: f072f99c07c01207723095a39ac08655
Detection count: 7,118
File type: Executable File
Mime Type: unknown/exe
Path: C:\164240281298608\Program Files\RrFilter\RrFilterService.exe
Group: Malware file
Last Updated: September 19, 2021
%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\003\nuttkoqiez64.exe.vir File name: nuttkoqiez64.exe.vir
Size: 706.56 KB (706560 bytes)
MD5: 69ca9a1113f95f9c08c9031ab4418fbf
Detection count: 4,771
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files\003\nuttkoqiez64.exe.vir
Group: Malware file
Last Updated: June 6, 2022
%PROGRAMFILES%\003\xmkysecqun32.exe File name: xmkysecqun32.exe
Size: 541.69 KB (541696 bytes)
MD5: 949a54971ef61e9d84b7c559b405a585
Detection count: 2,907
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\003\xmkysecqun32.exe
Group: Malware file
Last Updated: August 16, 2022
%PROGRAMFILES%\RrSavings\2rs3.dll File name: 2rs3.dll
Size: 91.1 KB (91104 bytes)
MD5: ad77ff6e76a918992054b22ba4164cea
Detection count: 813
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\RrSavings
Group: Malware file
Last Updated: May 13, 2014
%PROGRAMFILES%\003\xmkysecqun64.exe File name: xmkysecqun64.exe
Size: 706.56 KB (706560 bytes)
MD5: 1be089f9429924f29cf0b37f75af2ea4
Detection count: 96
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\003
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\RrFilter\RrFilterService.exe File name: RrFilterService.exe
Size: 149.5 KB (149504 bytes)
MD5: 0871b8f26da9ce585f3d8b61e4c4ed22
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\RrFilter
Group: Malware file
Last Updated: May 13, 2014
%PROGRAMFILES%\RrSavings\2rs3.dll File name: 2rs3.dll
Size: 91.1 KB (91104 bytes)
MD5: 71fb9134b3f42ceaaa0f629d5ecb6736
Detection count: 70
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\RrSavings
Group: Malware file
Last Updated: May 13, 2014
%PROGRAMFILES%\003\vxlsnyaiet32.exe File name: vxlsnyaiet32.exe
Size: 719.32 KB (719328 bytes)
MD5: f042aa4ef6da54c329eccf0557bd2b2f
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\003
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\003\xmkysecqun32.exe File name: xmkysecqun32.exe
Size: 541.69 KB (541696 bytes)
MD5: 505bd26474cb5047f334e4d1ba42cea9
Detection count: 49
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\003
Group: Malware file
Last Updated: December 22, 2021
%PROGRAMFILES%\003\tzdmorukil32.exe File name: tzdmorukil32.exe
Size: 541.69 KB (541696 bytes)
MD5: faced93009d35911f54120f5fc69b405
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\003
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\rrsavings\uninstaller.exe File name: uninstaller.exe
Size: 80.29 KB (80299 bytes)
MD5: 8a7426eeca5871199e86fe9476e48ec2
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\rrsavings
Group: Malware file
Last Updated: July 23, 2020
%PROGRAMFILES%\003\buuoujqmrk32.exe File name: buuoujqmrk32.exe
Size: 1.09 MB (1094656 bytes)
MD5: d39b0c00f4aedfed4425c7c34b4b31f7
Detection count: 20
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\003
Group: Malware file
Last Updated: May 19, 2014
%PROGRAMFILES%\rrsavings\uninstaller.exe File name: uninstaller.exe
Size: 80.05 KB (80051 bytes)
MD5: 83a6c8de284ba5a9e186461b551196dc
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\rrsavings
Group: Malware file
Last Updated: February 28, 2020

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%PROGRAMFILES%\002\yewimmxqbs64.exeHKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Rr SavingsSoftware\AppDataLow\Software\rrsavingsSOFTWARE\Classes\Installer\Features\07BF6653227E2814286618E5EA689289SOFTWARE\Classes\Installer\Products\07BF6653227E2814286618E5EA689289Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\2D2D8A25-7FA3-4DEA-B84B-D55BA4E9AF2FSOFTWARE\Rr SavingsSOFTWARE\RrFilterSOFTWARE\rrsavingsSOFTWARE\Wow6432Node\RrFilterSYSTEM\ControlSet001\Services\EventLog\Application\RrFilterServiceSYSTEM\ControlSet001\services\eventlog\Application\RrFilterService64SYSTEM\ControlSet001\services\RrFilterServiceSYSTEM\ControlSet001\services\RrFilterService64SYSTEM\ControlSet001\services\yewimmxqbs64SYSTEM\ControlSet002\Services\EventLog\Application\RrFilterServiceSYSTEM\ControlSet002\services\eventlog\Application\RrFilterService64SYSTEM\ControlSet002\services\RrFilterServiceSYSTEM\ControlSet002\services\RrFilterService64SYSTEM\ControlSet002\services\yewimmxqbs64SYSTEM\CurrentControlSet\Services\EventLog\Application\RrFilterServiceSYSTEM\CurrentControlSet\services\eventlog\Application\RrFilterService64SYSTEM\CurrentControlSet\services\RrFilterServiceSYSTEM\CurrentControlSet\services\RrFilterService64SYSTEM\CurrentControlSet\services\yewimmxqbs64HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}rrsavings{3566FB70-E722-4182-8266-815EAE862998}

Additional Information

The following directories were created:
%PROGRAMFILES%\Rr Savings%PROGRAMFILES%\RrFilter%PROGRAMFILES%\rrsavings%PROGRAMFILES(x86)%\Rr Savings%PROGRAMFILES(x86)%\RrFilter%PROGRAMFILES(x86)%\rrsavings%WINDIR%\Installer\{3566FB70-E722-4182-8266-815EAE862998}
The following URL's were detected:
RrSavings
Loading...