Home Malware Programs Adware Adware.GreatSaver

Adware.GreatSaver

Posted: December 27, 2013

Threat Metric

Ranking: 12,354
Threat Level: 2/10
Infected PCs: 5,314
First Seen: December 27, 2013
Last Seen: October 2, 2023
OS(es) Affected: Windows

Aliases

Generic_r.HD [AVG]Trojan/Win32.Preloader [AhnLab-V3]Adware ( 004922f61 ) [K7AntiVirus]RDN/Generic PUP.x!bqt [McAfee]Generic5.AKXU [AVG]Riskware/MultiPlug [Fortinet]Win32.SuspectCrc [Ikarus]Suspicious file [Panda]ADWARE/Adware.A.2773 [AntiVir]ApplicUnwnt [Comodo]Adware ( 004923a41 ) [K7AntiVirus]Artemis!FFE3F0C62F2F [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Archivos de programa\SNT\M.x64.dll File name: M.x64.dll
Size: 408.57 KB (408576 bytes)
MD5: baabc2931a5624f5e299eb32417f40fe
Detection count: 54
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Archivos de programa\SNT\M.x64.dll
Group: Malware file
Last Updated: November 11, 2021
settings.ini File name: settings.ini
Size: 7.01 KB (7014 bytes)
MD5: 37f1349fe846799ada59e47f063e9616
Detection count: 6
Mime Type: unknown/ini
Group: Malware file
Last Updated: December 27, 2013
pjakibllfljmbnmhfdagbemihjkilocn.crx File name: pjakibllfljmbnmhfdagbemihjkilocn.crx
Size: 8.47 KB (8473 bytes)
MD5: bce210d45c9de7e67d1e93546a65eabf
Detection count: 4
Mime Type: unknown/crx
Group: Malware file
Last Updated: December 27, 2013

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\grEatsaaverr.grEatsaaverrSOFTWARE\Classes\grEatsaaverr.grEatsaaverr.2.7SOFTWARE\Classes\gREatsaVeer.gREatsaVeerSOFTWARE\Classes\gREatsaVeer.gREatsaVeer.2.7SOFTWARE\Classes\greatsaver.greatsaverSOFTWARE\Classes\greatsaver.greatsaver.2.7SOFTWARE\Classes\grEaTSaveur.grEaTSaveurSOFTWARE\Classes\grEaTSaveur.grEaTSaveur.2.7SOFTWARE\Classes\greAtssaVer.greAtssaVerSOFTWARE\Classes\greAtssaVer.greAtssaVer.2.7SOFTWARE\Classes\greatsuaver.greatsuaverSOFTWARE\Classes\greatsuaver.greatsuaver.2.7SOFTWARE\Classes\greeaTsaver.greeaTsaverSOFTWARE\Classes\greeaTsaver.greeaTsaver.2.7SOFTWARE\Classes\GuReatsaver.GuReatsaverSOFTWARE\Classes\GuReatsaver.GuReatsaver.2.7Software\Microsoft\Internet Explorer\Approved Extensions\{CA11228B-2BD7-4F3D-7F61-AD7A77802074}Software\Microsoft\Internet Explorer\Approved Extensions\{FA314450-D6DD-19A0-2DDB-5FD8415640C6}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{03EAF529-C055-C20A-A3E9-8867CA0D7274}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{25191C3E-BA4F-8BE7-0331-0B9957F545C9}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{4219A5E4-F761-7067-F778-246F5F251A2E}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{55FEF647-A771-A581-C07F-4FE40BFF2560}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{690276D0-6E67-EDF0-87F6-4B076E70C387}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{7BD51B22-B4B8-F771-31FB-9C92D080A4C9}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{90C23E8A-EB1F-A7F8-468E-12D09D1B53F2}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A7DD9744-0571-972B-6E6D-FC75C7B0D0B7}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{A9008E8A-2146-0996-6EFB-25654D3617BC}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{ACAC8DD5-8706-7AD4-4226-7CA79A6F84BF}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{AD17FB2A-0BA6-D1F4-11A1-6BDB2A5DC0C6}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{AECAE41F-43F4-CA77-5898-1174E7D5D65A}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{B427936C-9A2F-1240-ED45-43900ED08985}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{B92CA931-A1E8-06DD-4D99-F74BEE127065}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{BBB2C77B-F168-6ECE-B64D-9028464D579E}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{CAAECBEF-BFB3-18B7-59F8-171CC891B819}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{EF4D6360-3841-0845-42FD-F5F38F88505C}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{F9F4C568-897E-9E1B-FFE5-D3038C347067}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{FA314450-D6DD-19A0-2DDB-5FD8415640C6}SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CA41BB14-E67B-1653-C57B-5CA99418A866}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\greaatsaver%ALLUSERSPROFILE%\gRReeatsaver%ALLUSERSPROFILE%\gReatsavaer%ALLUSERSPROFILE%\gReatsuaveR%ALLUSERSPROFILE%\ggreatsaVeer%ALLUSERSPROFILE%\ggreatsaver%ALLUSERSPROFILE%\greATisaver%ALLUSERSPROFILE%\greaitSavEr%ALLUSERSPROFILE%\greatsaaveeR%ALLUSERSPROFILE%\greatsaever%ALLUSERSPROFILE%\greatssaveRR%ALLUSERSPROFILE%\greiAtsaveR%ALLUSERSPROFILE%\grreaTSaaver%APPDATA%\gReatsuaveR%APPDATA%\greatsaaveeR%APPDATA%\greatsaveeer%AllUsersProfile%\Application Data\greatsaver%AllUsersProfile%\greaatsaver%AllUsersProfile%\greatsaver%PROGRAMFILES%\Graeatsaver%PROGRAMFILES%\gRReeatsaver%PROGRAMFILES%\gReatsavaer%PROGRAMFILES%\ggreatsaVeer%PROGRAMFILES%\ggreatsaver%PROGRAMFILES%\ggreatssAver%PROGRAMFILES%\greaitSavEr%PROGRAMFILES%\greatSaver%PROGRAMFILES%\greatsavinG%PROGRAMFILES%\greatssaveRR%PROGRAMFILES%\grreaTSaaver%PROGRAMFILES(X86)%\gReatsuaveR%PROGRAMFILES(X86)%\ggreatsaver%PROGRAMFILES(x86)%\Graeatsaver%PROGRAMFILES(x86)%\gReatsavaer%PROGRAMFILES(x86)%\ggreatssAver%PROGRAMFILES(x86)%\greATisaver%PROGRAMFILES(x86)%\greaitSavEr%PROGRAMFILES(x86)%\greatSaver%PROGRAMFILES(x86)%\greatsaever%PROGRAMFILES(x86)%\greatsavinG%PROGRAMFILES(x86)%\greatssaveRR%PROGRAMFILES(x86)%\greiAtsaveR%ProgramFiles%\greaatsaver%ProgramFiles(x86)%\greaatsaver
The following URL's were detected:
greaatsavergreatSavergreatsaver
Loading...