Home Malware Programs Browser Plugins SpecialSavings

SpecialSavings

Posted: March 7, 2013

Threat Metric

Ranking: 8,058
Threat Level: 2/10
Infected PCs: 15,638
First Seen: October 24, 2011
Last Seen: October 14, 2023
OS(es) Affected: Windows

SpecialSavings is a browser add-on or plugin that serves up several online deals and shopping savings. Through SpecialSavings it may display repeated advertisement popups, which may cause a system to operate slowly. SpecialSavings may load within all of the popular web browsers including Google Chrome, Firefox and Internet Explorer. SpecialSavings may be automatically removed using an antispyware application instead of finding all related files and manually deleting.

Aliases

ADSPY/SuperFish.A [AntiVir]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll File name: SpecialSavingsSinged.dll
Size: 221.18 KB (221184 bytes)
MD5: d8e638465254e844a0049ac9108fc483
Detection count: 3,012
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll
Group: Malware file
Last Updated: May 24, 2023
C:\Program Files (x86)\Superfish\Special Savings\SpecialSavings.dll File name: SpecialSavings.dll
Size: 307.2 KB (307200 bytes)
MD5: 4d24bf22483cb058e769d43abe953b6d
Detection count: 2,611
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Superfish\Special Savings\SpecialSavings.dll
Group: Malware file
Last Updated: October 20, 2022
%SYSTEMDRIVE%\$SysReset\OldOS\AdwCleaner\Quarantine\C\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll.vir File name: SpecialSavingsSinged.dll.vir
Size: 223.23 KB (223232 bytes)
MD5: 1266f1c721741bce32890ad0de9aff76
Detection count: 543
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\$SysReset\OldOS\AdwCleaner\Quarantine\C\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll.vir
Group: Malware file
Last Updated: October 14, 2023
DealFinderSetup.exe File name: DealFinderSetup.exe
Size: 620.79 KB (620792 bytes)
MD5: 1203d06c42a49ed753a316bd534c35b9
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 7, 2013
%PROGRAMFILES%\SpecialSavings\SpecialSavingsSinged.dll File name: SpecialSavingsSinged.dll
Size: 287.7 KB (287702 bytes)
MD5: 135ebb4819704fa52a9221419191e80e
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\SpecialSavings
Group: Malware file
Last Updated: May 10, 2012

Registry Modifications

The following newly produced Registry Values are:

CLSID{4EC06F7F-2290-4D9E-8D24-54CE42766B04}{52F4D3D2-195C-4A46-AEE6-ED2D56BDE1C3}{56493971-6146-42C3-BFC3-3E4CBB768777}{938958E8-355C-49FF-92B0-53C1B87ACEA9}{A49B770D-F83D-40D9-9478-C7DA97736004}{AFFE513B-69AD-4C97-A74F-95AB17C9D42C}{C718BDD4-197A-4A23-B539-EB3B3A2B0C09}{E0C361C8-1477-45C2-BC83-C1C8C913551F}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\specialsavings.BackgroundHostObjectSOFTWARE\Classes\specialsavings.BackgroundHostObject.1SOFTWARE\Classes\specialsavings.NavbarSOFTWARE\Classes\specialsavings.Navbar.1SOFTWARE\Classes\SpecialSavings.ScriptHostObjectSOFTWARE\Classes\SpecialSavings.ScriptHostObject.1SOFTWARE\Classes\specialsavings.ToolSOFTWARE\Classes\specialsavings.Tool.1Software\Microsoft\Internet Explorer\Approved Extensions\{938958E8-355C-49FF-92B0-53C1B87ACEA9}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{938958E8-355C-49FF-92B0-53C1B87ACEA9}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{938958E8-355C-49FF-92B0-53C1B87ACEA9}Software\Mozilla\Firefox\Extensions\SpecialSavings@SpecialSavings.comHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SpecialSavings

Additional Information

The following directories were created:
%APPDATA%\SpecialSavings%PROGRAMFILES%\SpecialSavings%PROGRAMFILES(x86)%\SpecialSavings
The following URL's were detected:
specialsavings.com
Loading...