Home Malware Programs Adware Savings Avenger

Savings Avenger

Posted: March 31, 2014

Threat Metric

Ranking: 17,035
Threat Level: 2/10
Infected PCs: 3,178
First Seen: March 31, 2014
Last Seen: October 3, 2023
OS(es) Affected: Windows


Savings Avenger is adware which, once installed on the computer, may insert an unwanted plug-in, add-on or browser extension. Savings Avenger may surreptitiously access and integrate itself into the computer without the PC user's consent, or it may be installed as an extra program to the free application. Savings Avenger may make changes to the default system and Web browser settings that later may lead to numerous PC problems. Savings Avenger may propagate and enter the PC through packed free applications. Computer users may download free software from a variety of questionable download websites that may add Savings Avenger with its toolbar into the program installation package. Savings Avenger may show disturbing pop-up advertisements and messages that may encompass sponsored links to multiple unknown websites that may offer computer users various sales, discount coupons, deals and other offers for online services and products.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Savings Avenger\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 060c887c6ffa05f44f9ea10c07dffe25
Detection count: 571
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 498077651a879eaa6a32db7444de8fd4
Detection count: 415
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 5fe4865034681d8412512a243d49ace5
Detection count: 386
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 46ce93e2047f56e3b93e3b5d4dd68a3c
Detection count: 206
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES%\Savings Avenger\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 288.81 KB (288816 bytes)
MD5: 637721d342e0d5d11bfca46aea565b76
Detection count: 112
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 5, 2019
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 8a002b65c729949cd29c1e48d3cd2f54
Detection count: 70
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES%\Savings Avenger\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 97e8ac363ca21c5c88eb88871d5ecd16
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES%\Savings Avenger\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: cf2d5a683b9b4ae2bc3ae4cea5c9a977
Detection count: 42
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES%\Savings Avenger\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: d2d1633f96d93abda8c4a083a69c3dd8
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 88c7d95b2ff3c17ab7683d52c95b39b0
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 4f68a1ba5e3fb973ec59b9b9a19b83c7
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
Savings Avenger.exe File name: Savings Avenger.exe
Size: 1.07 MB (1074160 bytes)
MD5: d25b92ed2d9471ae96d40f7c9524cf3b
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES%\Savings Avenger\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 8036d53009c42b71a34303d7e304eacf
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{1720E857-8861-4F7F-B689-D0D9B79939AF}{1775E8E2-8893-4F03-9392-44D97B991BAF}{5D56C96E-DD47-462A-8192-7019F6E193A3}{5DE7C91D-DD50-46CF-8498-4C19E8E1EAA3}{9FF0F3E0-E593-4BFD-84E2-805C0491F1F9}{B484D3EA-4A2A-4F8E-B591-57E5FBE67DAB}{C06683F0-BFB7-42B3-BD85-4D66F8D42707}{C0AD836E-BF8C-4250-BEBF-1466FDD48207}HKEY..\..\..\..{RegistryKeys}SOFTWARE\38957SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FF0F3E0-E593-4BFD-84E2-805C0491F1F9}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D56C96E-DD47-462A-8192-7019F6E193A3}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D56C96E-DD47-462A-8192-7019F6E193A3}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5D56C96E-DD47-462A-8192-7019F6E193A3}SOFTWARE\Savings AvengerSOFTWARE\Wow6432Node\38957SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FF0F3E0-E593-4BFD-84E2-805C0491F1F9}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5D56C96E-DD47-462A-8192-7019F6E193A3}SOFTWARE\Wow6432Node\Savings AvengerHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38957_Savings Avenger

Additional Information

The following directories were created:
%LOCALAPPDATA%\Savings Avenger%PROGRAMFILES%\Savings Avenger%PROGRAMFILES(x86)%\Savings Avenger
Loading...