Home Malware Programs Adware Adware.DownSave

Adware.DownSave

Posted: May 28, 2014

Threat Metric

Ranking: 8,506
Threat Level: 2/10
Infected PCs: 10,249
First Seen: May 28, 2014
Last Seen: September 24, 2023
OS(es) Affected: Windows


Adware.DownSave is adware that may create and show disturbing pop-up ads on a PC when a computer user is visiting online shopping and social networking websites. The pop-up ads displayed by Adware.DownSave may recommend computer users numerous discount coupons, deals, sales and offers. If the PC user clicks on the pop-up advertisements sent by Adware.DownSave, this adware may continuously redirect him to questionable websites that may be designed possibly for advertising purposes. Adware.DownSave may be integrated into popular Web browsers such as Internet Explorer, Mozilla Firefox and Google Chrome while the PC user is installing free software from unreliable download websites. Once installed on the PC, Adware.DownSave may modify the default browser settings and replace the default homepage, search engine or a new tab window with a suspicious website. Adware.DownSave may keep track of the computer user's browsing routine and transmit and use gathered information for the intention of delivering targeted pop-up ads.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\DownSavE\C.x64.dll File name: C.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: c8625b7c0f5a6d22c9bf4eeea9ec5f00
Detection count: 93
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSavE
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSAve\rNYImj1v.dll File name: rNYImj1v.dll
Size: 425.47 KB (425472 bytes)
MD5: 251663ab1aed04f2e8d1c4132fcf7638
Detection count: 84
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSAve
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSave\zvG.dll File name: zvG.dll
Size: 426.49 KB (426496 bytes)
MD5: 103122a3729dbd73e0751688d046610a
Detection count: 81
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSavei\R9DQQv.x64.dll File name: R9DQQv.x64.dll
Size: 476.67 KB (476672 bytes)
MD5: 37ae4bb2f20ca4f2ecc2ae3fa2eee59f
Detection count: 76
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSavei
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DOwnSave\HWik.dll File name: HWik.dll
Size: 427 KB (427008 bytes)
MD5: 3edf79b76fd875a74d02c141983a6774
Detection count: 73
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DOwnSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\Dane aplikacji\DownSAve\do.dll File name: do.dll
Size: 423.93 KB (423936 bytes)
MD5: 1900c268b3f17ec68cb463de2606956d
Detection count: 71
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Dane aplikacji\DownSAve
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DowNSave\twh8j.dll File name: twh8j.dll
Size: 425.47 KB (425472 bytes)
MD5: 64abc957845f504506bed87543dca48c
Detection count: 70
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DowNSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DDowNSAve\PMzRH91o.x64.dll File name: PMzRH91o.x64.dll
Size: 473.08 KB (473088 bytes)
MD5: bbdb948208d7d37f01dc04e6cbb4e71a
Detection count: 65
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DDowNSAve
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DDowNSavei\grsWp.dll File name: grsWp.dll
Size: 426.49 KB (426496 bytes)
MD5: 56efa3b2409ec8f402a9bf465def9afe
Detection count: 65
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DDowNSavei
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSave\WqClrP.x64.dll File name: WqClrP.x64.dll
Size: 472.57 KB (472576 bytes)
MD5: b614cb72894e75e8df5092746d3c5705
Detection count: 61
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSave\G4I.x64.dll File name: G4I.x64.dll
Size: 476.67 KB (476672 bytes)
MD5: 702a1113559c8f2b95d919f15a962d9a
Detection count: 43
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DOwnSAVe\DBR.x64.dll File name: DBR.x64.dll
Size: 475.64 KB (475648 bytes)
MD5: 3e552f61a7ab6b5266c11fd3533f22f8
Detection count: 40
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DOwnSAVe
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSaVe\ex3NW5.x64.dll File name: ex3NW5.x64.dll
Size: 473.6 KB (473600 bytes)
MD5: a7f83e82a8b6e11de5ea62efee860351
Detection count: 35
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSaVe
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSave\BxRK7cNl.dll File name: BxRK7cNl.dll
Size: 424.44 KB (424448 bytes)
MD5: db12f6284aba0a58615c4e8ad62a3ec5
Detection count: 31
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DowNSave\twh8j.x64.dll File name: twh8j.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: 631ebe123ecceeac45c25a2e20306e78
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DowNSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSave\g.dll File name: g.dll
Size: 426.49 KB (426496 bytes)
MD5: 0e3542dffc5be4a409e036db9c73d4e9
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DownSavee\GDs.dll File name: GDs.dll
Size: 421.88 KB (421888 bytes)
MD5: 4f87d11ef47f6a99c58f7a7f5a867fab
Detection count: 22
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DownSavee
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DowNSaVe\17eGOVLzdA.x64.dll File name: 17eGOVLzdA.x64.dll
Size: 474.62 KB (474624 bytes)
MD5: 3118c03f55f1973105a9fb4aab0d8eea
Detection count: 20
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DowNSaVe
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\Dane aplikacji\DownSaveE\R5Y.dll File name: R5Y.dll
Size: 424.96 KB (424960 bytes)
MD5: 693c04619316e64d4cde981c3cf193cc
Detection count: 6
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Dane aplikacji\DownSaveE
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\DoWnSave\DfOikEyrJ.x64.dll File name: DfOikEyrJ.x64.dll
Size: 476.67 KB (476672 bytes)
MD5: 29191683f396a123ca9a53f3ef503a73
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\DoWnSave
Group: Malware file
Last Updated: May 28, 2014
%ALLUSERSPROFILE%\Datos de programa\DownSave\z.dll File name: z.dll
Size: 427.52 KB (427520 bytes)
MD5: 4f0e57d09310d4f684cd65f454130460
Detection count: 3
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Datos de programa\DownSave
Group: Malware file
Last Updated: May 28, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{5E89CCA9-B9B8-FC18-23F6-0EA90BFF2507}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{6A471BE0-7449-CF10-6F5A-A3EDE81789E6}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{E5B7E1B4-21FC-6765-A3D7-BA0416DC6AF7}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\DownSave%ALLUSERSPROFILE%\DownSave%ALLUSERSPROFILE%\DowunSave%PROGRAMFILES%\DownSave%PROGRAMFILES(x86)%\DownSave
The following URL's were detected:
DownSaVeDownSavEDownSave
Loading...