Home Malware Programs Adware Adware.iSaver

Adware.iSaver

Posted: May 29, 2014

Threat Metric

Ranking: 7,576
Threat Level: 2/10
Infected PCs: 16,748
First Seen: May 29, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


Isaver is a program categorized as adware that is created by InstalleRex-WebPick and, therefore, it is known as Adware.iSaver. Adware.iSaver may insert a browser extension into a Web browser for Internet Explorer, Google Chrome and Mozilla Firefox. Adware.iSaver may generate and display annoying advertisements in search engines such as Bing and Google. Adware.iSaver may spread and install itself as a browser extension, BHO (Browser Helper Object), add-on or plug-in and run as a background process. Upon installation, Adware.iSaver may display non-stop ads in search websites and numerous other web pages that may use third-party advertising and substitute these ads with its own. Adware.iSaver uses the InstalleRex download manager from WebPicks Holdings to install itself on the PC. InstalleRex is known for dispersing potentially unwanted progarms involving bad Web browser toolbars and a variety of ad-supported extensions.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\IIsauver\4YbNXe.dll File name: 4YbNXe.dll
Size: 425.47 KB (425472 bytes)
MD5: 8e0e3d481a68daf7e6cb2d90050282b8
Detection count: 83
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\IIsauver
Group: Malware file
Last Updated: May 29, 2014
%ALLUSERSPROFILE%\IsauvEr\YQbZh8oRL1.x64.dll File name: YQbZh8oRL1.x64.dll
Size: 474.62 KB (474624 bytes)
MD5: ed35a1620818392530cc800ecd6141f2
Detection count: 81
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\IsauvEr
Group: Malware file
Last Updated: May 29, 2014
%ALLUSERSPROFILE%\Isauver\33mCB65BQw.x64.dll File name: 33mCB65BQw.x64.dll
Size: 475.13 KB (475136 bytes)
MD5: 31b0b6bea7b6635ae4ca0a2849e54150
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%\Isauver
Group: Malware file
Last Updated: May 29, 2014
C:\ProgramData\isaver\6s0rqn.exe File name: C:\ProgramData\isaver\6s0rqn.exe
MD5: bc82f2cd7b3df7a7c780a76992cfc78f
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\ProgramData\isaver\6s0rqn.dll File name: C:\ProgramData\isaver\6s0rqn.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\ProgramData\isaver\6s0rqn.x64.dll File name: C:\ProgramData\isaver\6s0rqn.x64.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\iSaver.iSaverSOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{073C597A-6D67-84C2-2B42-5A1CA2D4BE3A}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{91D02681-9E8D-CB00-6911-4FB273EC4EAA}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{CB6A4591-7FFE-35E3-BF69-C9BD2D4DE74C}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{CC6062EB-35F7-4AE2-719C-014E9FA3A35F}

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Isauver%PROGRAMFILES%\Isauver%PROGRAMFILES%\Isaveri%PROGRAMFILES(x86)%\Isauver%PROGRAMFILES(x86)%\Isaveri
Loading...