Home Malware Programs Adware Savings Hen

Savings Hen

Posted: May 19, 2014

Threat Metric

Ranking: 13,392
Threat Level: 2/10
Infected PCs: 738
First Seen: May 19, 2014
Last Seen: August 9, 2023
OS(es) Affected: Windows


Savings Hen is a potentially unwanted ad-supported Web browser plug-in that may generate and show various types of advertisements such as banner ads, pop-unders and interstitial ads, for example, pop up ads that may show up when a website is loaded, or they may be displayed between the contents of a website on a PC. The sponsored links added by Savings Hen may occur as in-text advertisements when a PC user hovers his cursor over certain words and phrases on a website he is visiting. Savings Hen is categorized as adware. Savings Hen is created and spread by International Web Services/ 50onRed and may usually be added as an optional offer in the installation package of freeware. The Savings Hen plug-in customizes and improves the computer user's Web browsing activity by enabling the PC user to assert more control over his viewing activity. Savings Hen may provide computer users with numerous features, which may involve text links, search links, product comparisons, video and reviews, coupons, banners or graphics, or other interactive content displayed through the Web browser.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Savings Hen\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 296.79 KB (296792 bytes)
MD5: bbf3c5e48d74077b4be47549e2c383d4
Detection count: 267
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Hen
Group: Malware file
Last Updated: May 20, 2014
%PROGRAMFILES(x86)%\Savings Hen\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 296.79 KB (296792 bytes)
MD5: 57e5b6fd8389b313b59f8d0f859ccdfe
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Hen
Group: Malware file
Last Updated: May 20, 2014
%PROGRAMFILES%\Savings Hen\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 297.7 KB (297704 bytes)
MD5: a2ecc38f9fce92c4635b6bcb47330ea3
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Savings Hen
Group: Malware file
Last Updated: May 20, 2014
%PROGRAMFILES(x86)%\Savings Hen\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 296.55 KB (296552 bytes)
MD5: 884037f4919486a14b0c343895f1bd9b
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Hen
Group: Malware file
Last Updated: May 20, 2014
%PROGRAMFILES(x86)%\Savings Hen\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 296.55 KB (296552 bytes)
MD5: bfad951c29b1d64de7c4b7dc72e64382
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Hen
Group: Malware file
Last Updated: May 20, 2014
%PROGRAMFILES(x86)%\Savings Hen\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 297.52 KB (297520 bytes)
MD5: 499494bdb99b0020618e46428ec1051e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Hen
Group: Malware file
Last Updated: May 20, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}{15E7A21D-9C50-4CCF-8498-4C0BE8C0EA9A}{3D36A93B-7A0D-4492-9731-6ABE1E1690A9}{97208957-CC61-467F-B689-D0B9B7393967}{9759897D-CC10-46AF-8964-47B97F39CC67}{B3ADFA6E-B58C-4150-BEBF-1402FD8482B5}{B3DAFA9A-B57B-4108-B354-7102DE84BEB5}HKEY..\..\..\..{RegistryKeys}SOFTWARE\38959SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D36A93B-7A0D-4492-9731-6ABE1E1690A9}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}SOFTWARE\Wow6432Node\38959SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D36A93B-7A0D-4492-9731-6ABE1E1690A9}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}SOFTWARE\Wow6432Node\Savings HenHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38959_Savings Hen

Additional Information

The following directories were created:
%APPDATA%\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}%AppData%\Microsoft\Windows\Start Menu\Programs\Savings Hen%LOCALAPPDATA%\Savings Hen%PROGRAMFILES%\Savings Hen%PROGRAMFILES(x86)%\Savings Hen%USERPROFILE%\AppData\LocalLow\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
The following URL's were detected:
Savings Hen
Loading...