Threat Database Adware EverSave Ads

EverSave Ads

By GoldSparrow in Adware

Threat Scorecard

Popularity Rank: 22,183
Threat Level: 20 % (Normal)
Infected Computers: 472
First Seen: January 4, 2016
Last Seen: May 26, 2026
OS(es) Affected: Windows

The EverSave browser add-on from Dealz Unlimited Inc. is a modified version of the Dealz adware that has an improved perseverance. The EverSave adware might alter the settings of your Internet browser that govern the layout of your homepage, new tab page and search aggregator. Computer users may notice the EverSave adware to be offered as a shopping adviser in free software installers under the 'Advanced' and 'Custom' option. Security experts reveal that the EverSave adware is programmed to modify the way your browser renders Web pages to load banners at the start and the end of pages you visit. The EverSave adware is known to use custom CSS styles and JavaScript to prevent users from closing the ads it might display. The code of the EverSave adware suggests that it might show pop-up and pop-under windows loaded with promotions when you visit Amazon.com, Snapdeal.com, Jabong.com and Flipkart.com.

The EverSave adware might change your homepage to Dealz.yourshoppingwizard.com and users may be obstructed in their attempts to use alternative sites. The EverSave adware might edit your Windows Registry settings to cement the changes applied to your system and might appear in the 'Programs and Features' module under the name of MoneySaver. It is imperative to know that the EverSave adware may connect to remote hosts to download advertising content on your PC, which may contain harmful code. The developers of the EverSave adware do not use security certificates, and third parties may intercept the communications of EverSave. Needless to say, the EverSave adware represents a security risk, and the Windows Firewall may not be enough to filter remote code execution on your system. The EverSave adware may use DLL libraries to remain undetected by most scanners and run as a browser plug-in. You might need to install a reputable anti-malware solution to remove the EverSave adware and boost your defenses against threats like Woozlist and Binuflix.

Analysis Report

General information

Family Name: Adware.Multiplug.FA
Signature status: No Signature

Known Samples

MD5: be7937fe421d8661d2f8fc1301f91068
SHA1: 3dbed534c3e89b1e4be6efc54c2e1928d2a126d5
SHA256: 5503247085171609ECBD916736D8EF8966F55E0D055916BE0ABD0C0704AF2A9F
File Size: 1.20 MB, 1200640 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 64-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name might Database
File Description tools structure the
Legal Copyright Copyright (C) 2015
Original Filename 2015080410035685
Product Name might Database

File Traits

  • dll
  • x64

Block Information

Total Blocks: 2,166
Potentially Malicious Blocks: 577
Whitelisted Blocks: 1,589
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 x x x x x 0 0 x x 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x 0 x 0 0 x x 0 x 0 0 x 0 x x x 0 0 x x x x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 x x 0 0 x x x x 0 0 0 0 0 x 0 x 0 0 0 x 0 x 0 x 0 0 0 0 x x 0 0 0 x x x x x x 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x 0 0 x x 0 x 0 x x x 0 x x 0 0 0 0 x x x x x x 0 x x x x 0 x x 0 x x x x x x x x x x 0 x x x x x x x x x 0 0 0 x x x 0 x x x x 0 x 0 x x x x x x x x 0 x 0 x x x x x 0 x x x 0 0 0 0 x x x x 0 x x x 0 0 0 0 0 x 0 x x 0 x x x x 0 0 x 0 x 0 0 x x x x 0 x x x x x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 0 0 0 x x 0 x 0 x x 0 x x 0 0 0 0 0 0 0 x 0 0 0 x x 0 x x x 0 x 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 x x 0 x x x 0 0 0 0 0 x x 0 x x 0 0 0 x x 0 x 0 x x 0 0 x 0 0 0 0 x x x x x x 0 x 0 0 x 0 x x x x x 0 x x x x 0 0 0 x 0 0 0 x 0 x x 0 0 0 x x 0 x x 0 0 0 x x x x x x x 0 0 0 0 0 0 0 x 0 x 0 x x x 0 0 0 0 0 0 0 0 x x 0 x 0 0 x x 0 0 0 0 x 0 x 0 0 x 0 0 0 0 0 0 x 0 x x x 0 x x x x x 0 x 0 x 0 0 x x x x x x x 0 0 x x x 0 x x x x x x x 0 x x 0 x x x x x x x x 0 x x 0 x 0 x 0 x x 0 0 x x 0 x x x x x x x x 0 0 x x x 0 x x x x x x x 0 0 0 0 x 0 x x x x x x 0 x x 0 x x x x x 0 x 0 x x x x x x 0 x x x 0 x x x x x x x x x x x x x x 0 x x x x x x x x 0 1 1 1 1 0 1 0 0 0 0 0 0 0 0 0 1 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x 0 x x x x 0 x x 0 x x 0 x 0 x x x 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x x x x 0 x x x x 0 x x x x 0 0 x x 0 0 x x x x 0 x x 0 x x x x x x x x x x x 0 0 x x x x x x 0 x x 0 0 0 x x x 0 x x x x 0 x x x x x x x 0 x x x x 0 x 0 0 x x x x x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Multiplug.F
  • Multiplug.FA

Files Modified

File Attributes
c:\users\user\appdata\local\temp.dat Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
Show More
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtQueryWnfStateData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseSemaphore
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSubscribeWnfStateChange
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtUnmapViewOfSectionEx
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Trending

Most Viewed

Loading...