Home Malware Programs Adware Savings Wizard

Savings Wizard

Posted: November 13, 2013

Threat Metric

Ranking: 19,505
Threat Level: 2/10
Infected PCs: 9,736
First Seen: November 13, 2013
Last Seen: January 18, 2025
OS(es) Affected: Windows

Savings Wizard Screenshot 1Savings Wizard is an adware coupon application that is known to display random ads through online gaming sites. Savings Wizard may offer coupon saving deals while it loads offers and redirects to other unwanted sites. Use of Savings Wizard is not recommended as it could lead to several unwanted sites that may eventually cause issues with your computer. At times Savings Wizard may change your default internet settings loading up another site as your default home page. Removal of Savings Wizard will eliminate the unwanted redirects.

Savings Wizard Screenshot 2Savings Wizard Screenshot 3Savings Wizard Screenshot 4

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\Savings Wizard\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: f5d7b9c2cc901742953c1ea031366975
Detection count: 87
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Wizard
Group: Malware file
Last Updated: June 11, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 247.84 KB (247848 bytes)
MD5: 87cb5b97cbb8c607cf0fccb795bd54d7
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014
%PROGRAMFILES(x86)%\Savings Wizard\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 75368d4ca8eb32e83cca1c041dd6aaab
Detection count: 34
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Wizard
Group: Malware file
Last Updated: February 10, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{39B931CF-F1E2-4D04-8129-9EE8159A91C5}{41994F48-3EBD-4921-A3FC-A7886C6205B8}{5682CA62-1A80-40AE-82A0-B67833CE75FF}{CE7FAE28-E04D-496F-B56B-CD9E40998548}{CEADAE6E-E08C-4950-BEBF-149EFD998248}{E7574A3D-0F2D-478D-85F3-9224D7B230EA}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{39B931CF-F1E2-4D04-8129-9EE8159A91C5}SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5682CA62-1A80-40AE-82A0-B67833CE75FF}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5682CA62-1A80-40AE-82A0-B67833CE75FF}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Savings WizardSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Savings Wizard-repairJobSOFTWARE\Savings WizardSoftware\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5682CA62-1A80-40AE-82A0-B67833CE75FF}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Savings WizardSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Savings Wizard-repairJobSOFTWARE\Wow6432Node\Savings WizardHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}38906_Savings Wizard

Additional Information

The following directories were created:
%LOCALAPPDATA%\Savings Wizard%ProgramFiles%\Savings Wizard%ProgramFiles(x86)%\Savings Wizard
The following URL's were detected:
Savings Wizard
Loading...