Home Malware Programs Adware Adware.Scorpion Saver

Adware.Scorpion Saver

Posted: October 31, 2013

Threat Metric

Ranking: 9,294
Threat Level: 2/10
Infected PCs: 8,874
First Seen: October 31, 2013
Last Seen: October 9, 2023
OS(es) Affected: Windows

Scorpion Saver is an adware that may show annoying random adverts on the computer when the PC user is visiting shopping related and social networking websites. The pop-up adverts shown by Scorpion Saver may recommend web users numerous discounts and offers. If the computer user clicks on the pop-up adverts delivered by Scorpion Saver, Scorpion Saver may unwillingly divert him to suspicious advertising websites. Scorpion Saver may be installed into Internet Explorer, Mozilla Firefox and Google Chrome while the computer user is installing freeware and shareware. While being installed on the computer system, Scorpion Saver may change browser settings and modify the default start page and search engine with a certain commercial website. When the PC user attempts to look for anything on the net in any genuine search provider, he may see the toolbar of Scorpion Saver on the browser that may show a variety of pop-up adverts and sponsored links associated with the computer user's browsing habits. Scorpion Saver may trace the PC user's surfing activity and transmit collected data to third-parties for unknown intentions.

Aliases

AdPeak [Sophos]Adware-Adpeak [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Program Files\ScorpionSaver\IECore.dll File name: IECore.dll
Size: 82.94 KB (82944 bytes)
MD5: d679f78cfc72d0ce2e7d6ca68696e3ad
Detection count: 984
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Program Files\ScorpionSaver\IECore.dll
Group: Malware file
Last Updated: June 10, 2022
ss.exe File name: ss.exe
Size: 3.68 MB (3685898 bytes)
MD5: accb682919ecaf142306ad4ca427dccb
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 31, 2013

Registry Modifications

The following newly produced Registry Values are:

CLSID{10AD2C61-0898-4348-8600-14A342F22AC3}HKEY..\..\..\..{RegistryKeys}Software\Adpeak, Inc.\ScorpionSaverSoftware\AppDataLow\Software\Scorpion SaverSoftware\AppDataLow\Software\ScorpionSaverSOFTWARE\Classes\Installer\Features\3A9F56B942D9A2546BFE41756DE52495SOFTWARE\Classes\Installer\Products\3A9F56B942D9A2546BFE41756DE52495SOFTWARE\Classes\Installer\UpgradeCodes\5F4506BC6317E2F4E84CCA0CEEF2609ESOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\CCC9642C-CB76-46E5-AF27-7D7B5DD2348BSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{10AD2C61-0898-4348-8600-14A342F22AC3}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10AD2C61-0898-4348-8600-14A342F22AC3}Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\CCC9642C-CB76-46E5-AF27-7D7B5DD2348BSOFTWARE\Scorpion SaverSoftware\ScorpionSaverSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\CCC9642C-CB76-46E5-AF27-7D7B5DD2348BSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}{9B65F9A3-9D24-452A-B6EF-1457D65E4259}

Additional Information

The following directories were created:
%AllUsersProfile%\Package Cache\{f9ab2e02-fc46-4e6e-ad70-b424ce36cf51}%PROGRAMFILES%\ScorpionSaver Services%ProgramFiles%\ScorpionSaver%ProgramFiles(x86)%\ScorpionSaver
The following URL's were detected:
ScorpionSaver
Loading...