Home Malware Programs Adware Savings Hero

Savings Hero

Posted: August 1, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 12,191
First Seen: August 1, 2013
Last Seen: February 26, 2023
OS(es) Affected: Windows

Savings Hero is an adware program that displays shopping discount-related advertisements in your browser. Since Savings Hero's advertisements are not easy to disable and Savings Hero also has a habit of failing to uninstall itself in a timely manner, SpywareRemove.com malware researchers recommend removing Savings Hero with anti-malware software in any circumstance where you have no interest in its advertising content. While not classified as a high-level PC threat, Savings Hero still may display potentially dangerous Web content or be responsible for various browser performance issues, as is typical of many similar adware-based browser add-ons.

Savings Hero: Coming to Save the Day... from a Lack of Advertisements?

Savings Hero is identified by most anti-malware products as a confirmed adware program, although the label used to detect Savings Hero may vary – some examples include Win32:Installer-M [Adw], Adware.Downware.1306 and Win32/Toolbar.CrossRider.C. Savings Hero's primary function is the delivery of advertising content to your browser, which can't be disabled or controlled through any settings related to Savings Hero or your browser. Although Savings Hero may use pop-ups or other methods of displaying its advertisements, Savings Hero primarily is known for using Web injection techniques that allow Savings Hero to display its advertisements within a Web page that you're already viewing. SpywareRemove.com malware experts warn that such functions often are abused to display misleading search results, even when you're using a trustworthy search engine (since Savings Hero's injections take place independently of the content that the site you're viewing chooses to display).

While Savings Hero has not been confirmed as guilty of using its advertisements to display malicious content, SpywareRemove.com malware experts usually find that adware like Savings Hero often uses less strenuous methods of sorting advertising content than those of a reputable company. You should interact with bargains, discounts and offers from Savings Hero with a high default level of caution and use all relevant browser security features while doing so.

Saving Your Browser from this Hero-for-Hire

Savings Hero, like all adware, is not a net benefit to your computer and usually should be deleted unless you're absolutely sure you have a reason to desire and trust its advertising content. Since software related to Savings Hero usually will be difficult to remove through usual methods, SpywareRemove.com malware researchers suggest using anti-malware products that can delete Savings Hero and any browser changes Savings Hero may have caused in the course of its installation.

Advertising content from adware like Savings Hero may often be a source of other attacks against a compromised PC. While dealing with Savings Hero, you also should be alert for phishing attacks, including fake surveys, contests and other prize-awarding activities that try to gather your confidential information under misleading pretenses. In particular, any software updates offered through Savings Hero's advertisements, rather than official sources, always should be regarded as potential attacks against your computer.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: 433269e6462aabbcfc1957f99ee168f5
Detection count: 56
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: e8dc30a160fcf40c008a413e7280fb9a
Detection count: 26
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: 51159d655e32d0ea783351a34f320591
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 256.55 KB (256552 bytes)
MD5: e770432b3a8a51cd5bc28c59eeeb4442
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: 41cce1f9e911add5bde3ef34b8c4a9de
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 258.08 KB (258088 bytes)
MD5: f32036e4975f417e2e8637253a9e464d
Detection count: 19
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: 3e30d3e264397dbe28194b27482c3324
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 256.55 KB (256552 bytes)
MD5: e88c1aec787bbeac84238dfa49c89488
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 7b5ecb7d858a9ba8690cd6075daed3d9
Detection count: 16
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%LOCALAPPDATA%\Savings Hero\repair.js File name: repair.js
Size: 1.76 KB (1762 bytes)
MD5: 214b241da26896ab3901203219b71de8
Detection count: 14
File type: JavaScript file
Mime Type: unknown/js
Path: %LOCALAPPDATA%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: 27900981c741e761c64d94bc28b3d226
Detection count: 14
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 256.55 KB (256552 bytes)
MD5: 22b24095c299785d50c437eea854c53f
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: b51f4fea317cec452c6ed2d00b5544b1
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 256.55 KB (256552 bytes)
MD5: de9bfc3d0000c93a01f069f486c0562d
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: 68db9302d6face87a3376c06fb1eab03
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 323.11 KB (323112 bytes)
MD5: 47250e1039f89349759a0ecc8622f126
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES(x86)%\Savings Hero\FrameworkBHO64.dll File name: FrameworkBHO64.dll
Size: 325.16 KB (325160 bytes)
MD5: 27d580b012e53b7ecc0c7bcd3947109c
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014
%PROGRAMFILES%\Savings Hero\FrameworkBHO.dll File name: FrameworkBHO.dll
Size: 256.55 KB (256552 bytes)
MD5: b16f109c23902e4b5b967162045927c2
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\Savings Hero
Group: Malware file
Last Updated: April 9, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110211991107}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Savings Hero-bg.exe

Additional Information

The following directories were created:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\databases\chrome-extension_eadkaencnfblndmbcfmiibbagnoohfpm_0%LOCALAPPDATA%\Updater29907%PROGRAMFILES%\Savings Hero%PROGRAMFILES(x86)%\Savings Hero
Loading...