Home Malware Programs Adware Savings Vault

Savings Vault

Posted: February 22, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 358
First Seen: February 22, 2013
Last Seen: October 26, 2022
OS(es) Affected: Windows

Savings Vault is an adware program that gives computer users an access to numerous online websites that offer discounts for various products. Savings Vault is not a virus itself but rather a program that can be installed on the hacked web browser without an affected PC user's permission. Savings Vault is often downloaded by computer users as packaged to other applications. When Savings Vault is installed on the targeted computer, it will make changes on the hacked Internet browser. Savings Vault affects Google Chrome, Internet Explorer, and Mozilla Firefox. Usually, Savings Vault is loaded as an add-on to the Internet browser, which enables it to start every time computer users are browsing the web. Savings Vault is not harmful; however, some PC users get annoyed with pop-up ads displayed on the screen while they are shopping online. Pop-up ads produced by Savings Vault includes links to websites and services, which offer savings and coupons.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110211391186}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Savings VaultSOFTWARE\Classes\CrossriderApp0023986.BHOSOFTWARE\Classes\CrossriderApp0023986.BHO.1SOFTWARE\Classes\CrossriderApp0023986.SandboxSOFTWARE\Classes\CrossriderApp0023986.Sandbox.1Software\Cr_Installer\23986Software\InstalledBrowserExtensions\215 Apps\23986Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110211391186}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211391186}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{21111111-1111-1111-1111-110211391186}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Savings Vault-bg.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\Savings Vault-InternalInstaller_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Savings Vault-InternalInstaller_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\Savings Vault_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\Savings Vault_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211391186}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Savings Vault

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\alocmpjlljemiokibhkkhikmkakdiaeh%LOCALAPPDATA%\Savings Vault%LOCALAPPDATA%\Updater23986%PROGRAMFILES%\Savings Vault%PROGRAMFILES(x86)%\Savings Vault
Loading...