Threat Database Adware Slick Savings

Slick Savings

By JubileeX in Adware

Threat Scorecard

Popularity Rank: 3,041
Threat Level: 20 % (Normal)
Infected Computers: 140,201
First Seen: September 4, 2013
Last Seen: January 12, 2026
OS(es) Affected: Windows

Slick Savings is an adware application that can be installed onto affected PCs together with other applications from the net. Slick Savings may show numerous annoying pop-up advertisements which carry offers and discounts on the screen of the corrupted PC. Slick Savings may offer the attacked PC user to check some price comparisons, for example, when the PC user is visiting shopping websites such as Amazon, Ebay and others. The pop-up advertisements declare to come from Slick Savings. If the PC user clicks on these pop-up advertisements, Slick Savings may reroute the computer user to doubtful or even infected websites. Slick Saving may push misleading advertisement websites, services and products. Slick Savings may also grab information about the computer user's browsing habits, search queries and visited websites. This data can be very beneficial for marketing campaigns, especially, showing targeted advertisements. Slick Saving is not a malware infection, but it may set the PC in dager of being infected with various malware infections.

SpyHunter Detects & Remove Slick Savings

File System Details

Slick Savings may create the following file(s):
# File Name MD5 Detections
1. CouponsHelper.exe.vir 719f6d7047c2744e21756a336f86ab90 2,975
2. Coupons.dll{3258A6E4-5E6B-4EE8-9433-6761ECD6F4FA}.old 6b1a43ff810aaceb2dc7cfa541e89cf3 2,649
3. Coupons64.dll{76FB9D0A-346B-4005-922C-17F9FCFB1530}.old 2b371a3d2c24fde1be29f1716752243b 1,762
4. coupons.dll{96A67BB8-F56E-4022-BCA0-B94AE158C1B1}.old.vir 1f3950302ba2cd77491146081b427c07 792
5. A0166104.exe aa5467b50056e3d11c6f1d5bc2774e56 488
6. Coupons64.dll#8A974E229A7629FA c721fecb7a649d7b36042f047a8d5526 480
7. coupons.dll{5E6A5D73-6104-44AE-B6E7-FE9ADB7D3DB2}.old.vir e3e9daf4948c1244b10be0b015fef52c 464
8. Coupons.dll#404358478ABC0737 db440de69140b562d95b6411d5dd70f0 388
9. Coupons.dll.vir 49b3426a3dd468cfcfefb858930a79bb 29
10. Coupons64.dll.vir 2811ba97199aa7ea97022dd04e6dd72a 19
11. ndfbmklh.dll 60261c3e510bec1b53e11e26ab8eff55 3
12. uninstall.exe 930c6fb8638fb1b2e4798b8717ac4dd0 1
13. CouponsHelper.exe 837c68de3c67f9a6a4ad20266ccf6839 1
14. Coupons64.dll 047fad4a79b78ed522628e2eea716d4b 1
15. Coupons.dll 6d523c5afec0c7808b486e1a6705e913 1
More files

Registry Details

Slick Savings may create the following registry entry or registry entries:
CLSID
{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Software\AppDataLow\Software\Browser Extensions\firefox\saamazon@mybrowserbar.com
Software\AppDataLow\Software\Browser Extensions\firefox\saebay@mybrowserbar.com
Software\AppDataLow\Software\Browser Extensions\firefox\savingsslider@mybrowserbar.com
Software\AppDataLow\Software\Browser Extensions\firefox\{58d2a791-6199-482f-a9aa-9b725ec61362}
Software\AppDataLow\Software\Slick Savings
Software\Microsoft\Internet Explorer\Approved Extensions\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Browser Extensions
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchSettings
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Slick Savings
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\SearchSettings
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\Slick Savings

Directories

Slick Savings may create the following directory or directories:

%APPDATA%\Browser Extensions
%APPDATA%\BrowserExtensions
%APPDATA%\Slick Savings
%LOCALAPPDATA%\Slick Savings
%USERPROFILE%\Local Settings\Application Data\Slick Savings

URLs

Slick Savings may call the following URLs:

Spigot, Inc.

Analysis Report

General information

Family Name: Adware.Slick Savings
Signature status: No Signature

Known Samples

MD5: d25088a0a5da8f0b9950335a5e298ee2
SHA1: 036722092ce2b3f4bba67aa71bc122a7fb255dc2
SHA256: 736F8A0E8F77A429AFB4BB683DBA92C76A28EC6164156BE9D511D24D89037FF8
File Size: 188.20 KB, 188199 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Spigot, Inc.
File Description Slick Savings setup launcher
File Version 1.3
Internal Name Slick Savings Setup
Legal Copyright 2013 (c) Spigot, Inc. All rights reserved.
Original Filename SlickSavingsSetup.exe
Product Name Slick Savings
Product Version 1.3

File Traits

  • Installer Manifest
  • Installer Version
  • nosig nsis
  • Nullsoft Installer
  • x86

Block Information

Total Blocks: 89
Potentially Malicious Blocks: 0
Whitelisted Blocks: 89
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • AdGazelle.A
  • Downloader.Agent.TJ
  • Mobogenie
  • SearchSuite.C
  • Zusy.CA

Files Modified

File Attributes
c:\users\user\appdata\local\temp\nsc5248.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsd53d0.tmp\nsiscouponsplugin.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsd53d0.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsd53d0.tmp\userinfo.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsn53bf.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\downloads Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Ivuqxwlf\AppData\Local\Temp\~nsu.tmp\Au_.exe RegNtPreCreateKey
HKLM\system\controlset001\control\session manager::pendingfilerenameoperations \??\C:\Users\Ivuqxwlf\AppData\Local\Temp\~nsu.tmp\Au_.exe\??\C:\Users\Ivuqxwlf\AppData\Local\Temp\~nsu.tmp RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess

Shell Command Execution

"C:\Users\Ivuqxwlf\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...