Threat Database Adware Savings Season

Savings Season

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 2,321
First Seen: April 25, 2014
Last Seen: December 20, 2022
OS(es) Affected: Windows

Savings Season is considered to be an adware threat that may inject annoying ads with its affiliate advertising providers in an effort to serve a variety of advertisement types incorporating inline text links, banner and pop-ups. These advertisements may strive to market the installation of additional untrustworthy content incorporating Web browser toolbars, optimization applications and other tools, all so the author can benefit from this. Savings Season may interact with the PC by showing ads, involving without limitation by inserting into websites or showing over parts of such websites ads, banners or discount coupons that would not otherwise show up, converting words on websites the computer user views into hyperlinks that are associated with ads, communicating with the Savings Season servers to check for new offers, the placement of offers, the date and time the PC user installs and uninstalls the toolbar of Savings Season, and whether an updated version of the toolbar of Savings Season is available, controlling and recording the web address of every website the PC user visits, the ads that show up on these websites, and the ads that the computer user clicks.

SpyHunter Detects & Remove Savings Season

File System Details

Savings Season may create the following file(s):
# File Name MD5 Detections
1. FrameworkBHO64.dll 318dab5237bf514ed3d6311a4e5405ed 14
2. FrameworkBHO64.dll 2f71f76bb0e16c3fc49f6daaf26430c6 3
3. FrameworkBHO.dll 71822bc9539da8deee14e78daab02650 2
4. FrameworkBHO64.dll cf602a40216f408863db02826916fc85 2
5. FrameworkEngine.exe 8fb56c6ff602f165e76d430a1178b86a 2
6. FrameworkBHO64.dll 8b948b8f05aae923545675f24921deac 2
7. FrameworkEngine.exe 894e252f0520d508352f104201897ddf 2
8. FrameworkBHO.dll 689967933934cc73cdb2a7bb247fc8d4 1
9. FrameworkEngine.exe f95fa90f7dc15759dd5fc34e8e9189c7 1
10. FrameworkBHO64.dll 2b2f008f3cfe0f448fb526625f2753e4 1
11. FrameworkEngine.exe d41bd5d5e25af5a3002b58f25a992399 1
12. FrameworkBHO.dll ab7e9a3d3bb0b6339d193550c523b602 1
13. FrameworkEngine.exe f4565777735fcf83be25c97d4b9fbea3 1
14. FrameworkBHO64.dll 62d90fbb51117098d249a6b3046954df 1
15. FrameworkEngine.exe 508062f7582fdf7cd5a69f20e810c4f8 1
16. FrameworkBHO64.dll 64aa5a5299dc57a2af805cd263e2c0f5 1
17. FrameworkEngine.exe 07b3a25729f8b27a4ab9c015ec077eb4 1
18. FrameworkBHO64.dll c9c7c843bb9e752a4738a1b2df2a8269 1
19. FrameworkBHO64.dll ab9daccafbc4298a77b8b9a1206b9b02 1
20. FrameworkEngine.exe 47ecc5238822527dd0390ce1aab69a92 1
21. FrameworkBHO.dll 62b4586cd2c943bb22af8bf09c1e9438 1
22. FrameworkEngine.exe c761677edfa35ddd83e8f659c067efa5 1
23. FrameworkBHO64.dll d608718b47b86a8808b34919082d97df 1
24. FrameworkEngine.exe 52bb8aa64c2ba452e5cfbdf19c4fafd5 1
25. FrameworkBHO64.dll 2c48a6bdb76dabef6b8d9463e61a1dc6 1
26. FrameworkEngine.exe caee29746c07a78c0be00d0a504320d7 1
27. SoftwareDetector.exe
28. sqlite3.exe
29. uninstall.exe
More files

Registry Details

Savings Season may create the following registry entry or registry entries:
CLSID
{31ADD569-26AA-4730-A9F0-A06871A984F7}
{A0ADDC6E-418C-4550-BEBF-14CEFD628270}
{A0B5DC25-417B-45C3-8E3A-87CEB5624C70}
SOFTWARE\38960
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31ADD569-26AA-4730-A9F0-A06871A984F7}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77AE02BE-8EF5-43D6-9271-1FC448D63DE2}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{77AE02BE-8EF5-43D6-9271-1FC448D63DE2}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{77AE02BE-8EF5-43D6-9271-1FC448D63DE2}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{77AE02BE-8EF5-43D6-9271-1FC448D63DE2}
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\Savings Season-repairJob
SOFTWARE\Savings Season
SOFTWARE\Wow6432Node\38960
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{31ADD569-26AA-4730-A9F0-A06871A984F7}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{77AE02BE-8EF5-43D6-9271-1FC448D63DE2}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\Savings Season-repairJob
SOFTWARE\Wow6432Node\Savings Season

Directories

Savings Season may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\Savings Season
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\klcegljodcbfmmaglppopnbdcfopdmjo
%LOCALAPPDATA%\Savings Season
%PROGRAMFILES%\Savings Season
%PROGRAMFILES(x86)%\Savings Season
%USERPROFILE%\AppData\LocalLow\{77AE02BE-8EF5-43D6-9271-1FC448D63DE2}

Trending

Most Viewed

Loading...