Home Malware Programs Adware SaveNet

SaveNet

Posted: April 14, 2014

Threat Metric

Ranking: 8,748
Threat Level: 2/10
Infected PCs: 3,452
First Seen: April 14, 2014
Last Seen: October 15, 2023
OS(es) Affected: Windows


SaveNet Screenshot 1SaveNet or Savve Nnet is an adware threat created by SuperWebLLC. SaveNet may declare to be a great application that can save time and money for those PC users who shop online. SaveNet may spread and enter random computer systems as an optional program bundled with freeware, or it may be installed on a computer without a PC user's consent. Once installed, SaveNet may start monitoring the PC user's browsing routine and generate and display unwanted pop-up ads and messages while the computer user is surfing online. If SaveNet pop-up ads and message are displayed when the computer user is shopping online, he may find them useful, because they mainly offer various discount coupons, deals, promo codes or sales to make the computer user's purchases cheaper. However, SaveNet may deliver and display them repeatedly and soon the PC user may find them intrusive. SaveNet may be created to generate advertising revenue from clicks on ads and messages.

SaveNet Screenshot 2

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 252.8 KB (252800 bytes)
MD5: bdfcc6faacb92849eba2ac8ee19705f2
Detection count: 98
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 16, 2014

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}neTSOFTWARE\Classes\inet.5.14SOFTWARE\Classes\neot.5.14SOFTWARE\Classes\neTSOFTWARE\Classes\net.5.14SOFTWARE\Classes\net.saaveSOFTWARE\Classes\net.saveSOFTWARE\Classes\net.savEeSOFTWARE\Classes\neTTSOFTWARE\Classes\nett.5.14SOFTWARE\Classes\nett.sAVeSOFTWARE\Classes\saaveSOFTWARE\Classes\saaveuSOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{2155D92F-EAAA-9327-4889-1C926BB78ED8}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6072E31E-D347-F6DB-D8E8-E90BA11C9097}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{ED66B46F-A1E0-8798-2A0E-E547D0F66A3C}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{FF3DF744-4FA7-66B7-9A93-1D342AE32B4F}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\save neet%ALLUSERSPROFILE%\Application Data\save net%ALLUSERSPROFILE%\Application Data\savvE net%ALLUSERSPROFILE%\saave naet%ALLUSERSPROFILE%\sauvve neT%ALLUSERSPROFILE%\savE neat%ALLUSERSPROFILE%\save ineT%ALLUSERSPROFILE%\save neet%ALLUSERSPROFILE%\save neit%ALLUSERSPROFILE%\save net%ALLUSERSPROFILE%\savvE net%ALLUSERSPROFILE%\suave Net%PROGRAMFILES%\saave naet%PROGRAMFILES%\savE nEtt%PROGRAMFILES%\save neet%PROGRAMFILES%\save neit%PROGRAMFILES%\save net%PROGRAMFILES%\savvE net%PROGRAMFILES(x86)%\saave naet%PROGRAMFILES(x86)%\sauvve neT%PROGRAMFILES(x86)%\savE nEtt%PROGRAMFILES(x86)%\savE neat%PROGRAMFILES(x86)%\save ineT%PROGRAMFILES(x86)%\save neet%PROGRAMFILES(x86)%\save neit%PROGRAMFILES(x86)%\save net%PROGRAMFILES(x86)%\savvE net
The following URL's were detected:
savE netsavee netssave naet
Loading...