WebSaavie

By GoldSparrow in Adware

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 33
First Seen: August 6, 2014
Last Seen: March 6, 2026
OS(es) Affected: Windows

WebSaavie is an adware program that comes as a browser extension in many cases. Usually WebSaavie is loaded through installing bundled software or freeware apps. Once this has taken place, WebSaavie may attempt to offer various ads or pop-up messages that could display various products and services through the internet. Use of the WebSaavie ads may redirect your web browser to various sites where you could be presented with unwanted content. In the best interest of computer users who are not keen to accepting ads or pop-ups on their screen, WebSaavie may be removed utilizing an updated antispyware tool.

Analysis Report

General information

Family Name: Trojan.Injector.CC
Signature status: No Signature

Known Samples

MD5: 32244e7acbda652f2e08f00411462c88
SHA1: e9b809807e6ef6abae337bfdda2897e2c3b8a656
SHA256: 688EF8325CCE1F509892791A01CBB7A598270E3C28B8312EECF73B6C152E8BB0
File Size: 32.77 KB, 32768 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description RAS PPPoE mini-port/call-manager driver
File Version 10.0.19041.3636 (WinBuild.160101.0800)
Internal Name raspppoe.exe
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename raspppoe.exe
Product Name Microsoft® Windows® Operating System
Product Version 10.0.19041.3636

File Traits

  • x86

Block Information

Total Blocks: 10
Potentially Malicious Blocks: 6
Whitelisted Blocks: 4
Unknown Blocks: 0

Visual Map

x x x x x 0 x 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Injector.CC

Trending

Most Viewed

Loading...