Home Malware Programs Adware SlamDunkSavings

SlamDunkSavings

Posted: July 9, 2014

Threat Metric

Threat Level: 2/10
Infected PCs: 515
First Seen: July 9, 2014
Last Seen: February 7, 2023
OS(es) Affected: Windows


SlamDunkSavings is an adware application. Most times SlamDunkSavings is loaded without much notice to the computer user by means of installing a previously downloaded freeware program or bundled software application. After loaded, SlamDunkSavings could then render several ads that attempt to offer various coupon deals or online savings for shopping over the internet. Use of the SlamDunkSavings ads could then redirect your web browser to unwanted or questionable sites. The SlamDunkSavings ads themselves are not computer viruses and they may not harm your system. However, SlamDunkSavings could reduce performance of your web browser making normal surfing of the internet a difficult or cumbersome process. Removing the SlamDunkSavings adware and its related files is essential to stop the ads that it displays, which may lead to unwanted site redirects.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\SlamDunk Savings\FrameworkEngine.exe File name: FrameworkEngine.exe
Size: 264.75 KB (264752 bytes)
MD5: 3e327aa1d72946d0efb26a161aad5871
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SlamDunk Savings
Group: Malware file
Last Updated: July 11, 2014
%PROGRAMFILES(x86)%\SlamDunk Savings\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 576.33 KB (576336 bytes)
MD5: 4f4799e2d4c5f0b600a6165ac2cbab2d
Detection count: 41
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SlamDunk Savings
Group: Malware file
Last Updated: July 11, 2014
%PROGRAMFILES%\SlamDunk Savings\SlamDunk Savings-bho.dll File name: SlamDunk Savings-bho.dll
Size: 750.47 KB (750472 bytes)
MD5: 7fe00f924eb4d6b240dd8ceb1d8d5d06
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\SlamDunk Savings
Group: Malware file
Last Updated: July 11, 2014
%PROGRAMFILES%\SlamDunk Savings\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 409.32 KB (409320 bytes)
MD5: 9e6678aab6fa62531683cea4024926a6
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\SlamDunk Savings
Group: Malware file
Last Updated: July 11, 2014
%PROGRAMFILES(x86)%\SlamDunk Savings\SlamDunk Savings-updater.exe File name: SlamDunk Savings-updater.exe
Size: 356.74 KB (356744 bytes)
MD5: 3198d385590dee2acbb1f3365c52f81c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SlamDunk Savings
Group: Malware file
Last Updated: July 11, 2014
%PROGRAMFILES(x86)%\SlamDunk Savings\SlamDunk Savings-bho64.dll File name: SlamDunk Savings-bho64.dll
Size: 969.6 KB (969608 bytes)
MD5: cb6069096870c5ae27ad06fed7484cf1
Detection count: 2
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SlamDunk Savings
Group: Malware file
Last Updated: July 11, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{4D808FAB-2CB5-4B55-AA98-96FEA847EE6E}HKEY..\..\..\..{RegistryKeys}SOFTWARE\38946SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{77485378-8666-4E81-8EFD-9AE859196224}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F33E90F9-C11A-442C-823D-F382190F93E5}SOFTWARE\Wow6432Node\38946SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{77485378-8666-4E81-8EFD-9AE859196224}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F33E90F9-C11A-442C-823D-F382190F93E5}SOFTWARE\Wow6432Node\SlamDunk Savings

Additional Information

The following directories were created:
%APPDATA%\Microsoft\Windows\Start Menu\Programs\SlamDunk Savings%APPDATA%\{F33E90F9-C11A-442C-823D-F382190F93E5}%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\eoofckbahbagadoifcjabhaklkhjmafo%LOCALAPPDATA%\SlamDunk Savings%PROGRAMFILES%\SlamDunk Savings%PROGRAMFILES(x86)%\SlamDunk Savings%USERPROFILE%\AppData\LocalLow\{F33E90F9-C11A-442C-823D-F382190F93E5}
Loading...