Home Malware Programs Browser Plugins SpecialSavings

SpecialSavings

Posted: March 7, 2013

Threat Metric

Ranking: 14,480
Threat Level: 2/10
Infected PCs: 15,760
First Seen: October 24, 2011
Last Seen: March 2, 2025
OS(es) Affected: Windows

SpecialSavings is a browser add-on or plugin that serves up several online deals and shopping savings. Through SpecialSavings it may display repeated advertisement popups, which may cause a system to operate slowly. SpecialSavings may load within all of the popular web browsers including Google Chrome, Firefox and Internet Explorer. SpecialSavings may be automatically removed using an antispyware application instead of finding all related files and manually deleting.

Aliases

ADSPY/SuperFish.A [AntiVir]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files (x86)\Superfish\Special Savings\SpecialSavings.dll File name: SpecialSavings.dll
Size: 307.2 KB (307200 bytes)
MD5: 4d24bf22483cb058e769d43abe953b6d
Detection count: 2,611
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files (x86)\Superfish\Special Savings\SpecialSavings.dll
Group: Malware file
Last Updated: October 20, 2022
%SYSTEMDRIVE%\$SysReset\OldOS\AdwCleaner\Quarantine\C\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll.vir File name: SpecialSavingsSinged.dll.vir
Size: 223.23 KB (223232 bytes)
MD5: 1266f1c721741bce32890ad0de9aff76
Detection count: 553
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\$SysReset\OldOS\AdwCleaner\Quarantine\C\Program Files (x86)\SpecialSavings\SpecialSavingsSinged.dll.vir
Group: Malware file
Last Updated: August 30, 2024
DealFinderSetup.exe File name: DealFinderSetup.exe
Size: 620.79 KB (620792 bytes)
MD5: 1203d06c42a49ed753a316bd534c35b9
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 7, 2013
%PROGRAMFILES%\SpecialSavings\SpecialSavingsSinged.dll File name: SpecialSavingsSinged.dll
Size: 287.7 KB (287702 bytes)
MD5: 135ebb4819704fa52a9221419191e80e
Detection count: 28
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\SpecialSavings
Group: Malware file
Last Updated: May 10, 2012

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{4EC06F7F-2290-4D9E-8D24-54CE42766B04}{52F4D3D2-195C-4A46-AEE6-ED2D56BDE1C3}{56493971-6146-42C3-BFC3-3E4CBB768777}{938958E8-355C-49FF-92B0-53C1B87ACEA9}{A49B770D-F83D-40D9-9478-C7DA97736004}{AFFE513B-69AD-4C97-A74F-95AB17C9D42C}{C718BDD4-197A-4A23-B539-EB3B3A2B0C09}{E0C361C8-1477-45C2-BC83-C1C8C913551F}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\specialsavings.BackgroundHostObjectSOFTWARE\Classes\specialsavings.BackgroundHostObject.1SOFTWARE\Classes\specialsavings.NavbarSOFTWARE\Classes\specialsavings.Navbar.1SOFTWARE\Classes\SpecialSavings.ScriptHostObjectSOFTWARE\Classes\SpecialSavings.ScriptHostObject.1SOFTWARE\Classes\specialsavings.ToolSOFTWARE\Classes\specialsavings.Tool.1Software\Microsoft\Internet Explorer\Approved Extensions\{938958E8-355C-49FF-92B0-53C1B87ACEA9}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{938958E8-355C-49FF-92B0-53C1B87ACEA9}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{938958E8-355C-49FF-92B0-53C1B87ACEA9}Software\Mozilla\Firefox\Extensions\SpecialSavings@SpecialSavings.comHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SpecialSavings

Additional Information

The following directories were created:
%APPDATA%\SpecialSavings%PROGRAMFILES%\SpecialSavings%PROGRAMFILES(x86)%\SpecialSavings
The following URL's were detected:
specialsavings.com
Loading...