Home Malware Programs Adware Savings Avenger

Savings Avenger

Posted: March 31, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 3,183
First Seen: March 31, 2014
Last Seen: December 14, 2023
OS(es) Affected: Windows


Savings Avenger is adware which, once installed on the computer, may insert an unwanted plug-in, add-on or browser extension. Savings Avenger may surreptitiously access and integrate itself into the computer without the PC user's consent, or it may be installed as an extra program to the free application. Savings Avenger may make changes to the default system and Web browser settings that later may lead to numerous PC problems. Savings Avenger may propagate and enter the PC through packed free applications. Computer users may download free software from a variety of questionable download websites that may add Savings Avenger with its toolbar into the program installation package. Savings Avenger may show disturbing pop-up advertisements and messages that may encompass sponsored links to multiple unknown websites that may offer computer users various sales, discount coupons, deals and other offers for online services and products.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Savings Avenger\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 288.81 KB (288816 bytes)
MD5: 637721d342e0d5d11bfca46aea565b76
Detection count: 112
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Avenger
Group: Malware file
Last Updated: April 5, 2019
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 282.67 KB (282672 bytes)
MD5: c1d1ef4d857912de3338cb58c4e1ef3e
Detection count: 87
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 2, 2014
%PROGRAMFILES(x86)%\Savings Avenger\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 345.64 KB (345648 bytes)
MD5: c1c943a4d319ac7507d58ba50f66d833
Detection count: 66
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Avenger
Group: Malware file
Last Updated: April 5, 2019
Savings Avenger.exe File name: Savings Avenger.exe
Size: 1.07 MB (1074160 bytes)
MD5: d25b92ed2d9471ae96d40f7c9524cf3b
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: April 2, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{1720E857-8861-4F7F-B689-D0D9B79939AF}{1775E8E2-8893-4F03-9392-44D97B991BAF}{5D56C96E-DD47-462A-8192-7019F6E193A3}{5DE7C91D-DD50-46CF-8498-4C19E8E1EAA3}{9FF0F3E0-E593-4BFD-84E2-805C0491F1F9}{B484D3EA-4A2A-4F8E-B591-57E5FBE67DAB}{C06683F0-BFB7-42B3-BD85-4D66F8D42707}{C0AD836E-BF8C-4250-BEBF-1466FDD48207}HKEY..\..\..\..{RegistryKeys}SOFTWARE\38957SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FF0F3E0-E593-4BFD-84E2-805C0491F1F9}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D56C96E-DD47-462A-8192-7019F6E193A3}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D56C96E-DD47-462A-8192-7019F6E193A3}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5D56C96E-DD47-462A-8192-7019F6E193A3}SOFTWARE\Savings AvengerSOFTWARE\Wow6432Node\38957SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9FF0F3E0-E593-4BFD-84E2-805C0491F1F9}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5D56C96E-DD47-462A-8192-7019F6E193A3}SOFTWARE\Wow6432Node\Savings AvengerHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38957_Savings Avenger

Additional Information

The following directories were created:
%LOCALAPPDATA%\Savings Avenger%PROGRAMFILES%\Savings Avenger%PROGRAMFILES(x86)%\Savings Avenger
Loading...