Threat Database Adware Savings Hen

Savings Hen

By GoldSparrow in Adware

Threat Scorecard

Ranking: 13,121
Threat Level: 20 % (Normal)
Infected Computers: 315
First Seen: May 19, 2014
Last Seen: August 9, 2023
OS(es) Affected: Windows

Savings Hen is a potentially unwanted ad-supported Web browser extension that may create and display a variety of types of ads such as banner ads, pop-unders and interstitial ads, for example, advertisements that may occur when a website is loaded, or they may be shown between the contents of a website on a computer system. The affiliated links embedded by Savings Hen may emerge as in-text ads when a computer user hovers his cursor over certain words and phrases on a website he visits. Savings Hen is categorized as adware. Savings Hen is produced and propagates by International Web Services/ 50onRed and may commonly be inserted as an extra offer in the installation package of free tools. The Savings Hen browser extension customizes and makes a PC user's Internet surfing quality better by permitting the computer user to assert more control over his viewing activity. Savings Hen may give PC users a variety of features, which may incorporate product comparisons, video and reviews, text links, search links, banners or graphics, coupons, or other interactive content shown through the Web browser.

SpyHunter Detects & Remove Savings Hen

File System Details

Savings Hen may create the following file(s):
# File Name MD5 Detections
1. FrameworkEngine.exe bbf3c5e48d74077b4be47549e2c383d4 114
2. FrameworkEngine.exe bfad951c29b1d64de7c4b7dc72e64382 2
3. FrameworkEngine.exe 884037f4919486a14b0c343895f1bd9b 1
4. FrameworkEngine.exe 499494bdb99b0020618e46428ec1051e 1
5. FrameworkEngine.exe 57e5b6fd8389b313b59f8d0f859ccdfe 1
6. FrameworkEngine.exe a2ecc38f9fce92c4635b6bcb47330ea3 1
7. C:\Users\\appdata\Local\Savings Hen\SoftwareDetector.exe a1539cd73b1c2bd08106b52ca6668baf
8. C:\Users\\appdata\Local\Savings Hen\gpedit.exe
9. C:\Users\\appdata\Local\Savings Hen\sqlite3.exe
10. C:\Users\\appdata\Local\Savings Hen\SoftwareDetector.exe
11. C:\Users\\appdata\Local\Savings Hen\storageedit.exe
12. C:\Users\\appdata\Local\Savings Hen\uninstall.exe

Registry Details

Savings Hen may create the following registry entry or registry entries:
CLSID
{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
{15E7A21D-9C50-4CCF-8498-4C0BE8C0EA9A}
{3D36A93B-7A0D-4492-9731-6ABE1E1690A9}
{97208957-CC61-467F-B689-D0B9B7393967}
{9759897D-CC10-46AF-8964-47B97F39CC67}
{B3ADFA6E-B58C-4150-BEBF-1402FD8482B5}
{B3DAFA9A-B57B-4108-B354-7102DE84BEB5}
SOFTWARE\38959
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D36A93B-7A0D-4492-9731-6ABE1E1690A9}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
SOFTWARE\Wow6432Node\38959
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D36A93B-7A0D-4492-9731-6ABE1E1690A9}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
SOFTWARE\Wow6432Node\Savings Hen

Directories

Savings Hen may create the following directory or directories:

%APPDATA%\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}
%AppData%\Microsoft\Windows\Start Menu\Programs\Savings Hen
%LOCALAPPDATA%\Savings Hen
%PROGRAMFILES%\Savings Hen
%PROGRAMFILES(x86)%\Savings Hen
%USERPROFILE%\AppData\LocalLow\{1564A235-9C55-4C1F-8CE4-B30B77C0B99A}

URLs

Savings Hen may call the following URLs:

Savings Hen

Trending

Most Viewed

Loading...