Content is republished with permission from Malwarebytes.
What is Supra Savings?
The Malwarebytes research team has determined that Supra Savings is adware. Adware typically shows you advertisements that do not belong on the site you are visiting.
How do I know if my computer is affected by Supra Savings?
You may find this listing in you list of installed programs:
How did Supra Savings get on my computer?
Adware applications use different methods for distributing themselves. This particular one was bundled with other software.
How do I remove Supra Savings?
Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
Is there anything else I need to do to get rid of Supra Savings?
How would the full version of Malwarebytes Anti-Malware help protect me?
We hope our application and this guide have helped you eradicate this hijacker.
As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Supra Savings rogue. It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.
Technical details for experts
Signs in a HijackThis log:
O23 - Service: buuoujqmrk32 - Unknown owner - C:\Program Files\003\buuoujqmrk32.exe
Note: the name of the service and the file seem to be random.
Alterations made by the installer:
File system details --------------------------------------------- Adds the folder C:\Program Files\003 Adds the file buuoujqmrk32.exe"="3/29/2014 9:46 AM, 541696 bytes, A Adds the folder C:\Program Files\suprasavings Adds the file uninstaller.exe"="3/27/2014 2:26 PM, 80058 bytes, A Registry details ---------------------------------------------- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\suprasavings] "DisplayIcon"="REG_SZ", "C:\Program Files\suprasavings\uninstaller.exe" "DisplayName"="REG_SZ", "suprasavings" "DisplayVersion"="REG_SZ", "2.0.1" "EstimatedSize"="REG_DWORD", 1024 "Publisher"="REG_SZ", "suprasavings" "UninstallString"="REG_SZ", "C:\Program Files\suprasavings\uninstaller.exe -source="F978377C-B7D4-4536-8E10-14CA97B13394" -remove="739027FD-0200-4F32-A9AC-8E4058065C1A D12C40DB-CD7D-4D86-9285-5E2FE23693E4 E6B105B8-1F65-4428-9397-1DFD8A03B94D 3566FB70-E722-4182-8266-815EAE862998 9B65F9A3-9D24-452A-B6EF-1457D65E4259 6DDE8071-E4BA-461B-8A96-990DFAA0EBD1 9B5C9A87-ED19-4510-A63F-A23FB580CA75 BFB5F375-2733-465B-B3AC-842F6A6BE527 DB8B6107-7401-470E-9203-F83DF395F044 813BA625-B0FA-48D8-9B75-59759C88C219 6E810AB6-F34E-49A3-A93F-9E503660F718 286B09BC-F9BD-4F71-B767-2AE0CE2F8CE5" " "URLInfoAbout"="REG_SZ", "${application_url}" [HKEY_LOCAL_MACHINE\SOFTWARE\suprasavings] "key"="REG_SZ", "F978377C-B7D4-4536-8E10-14CA97B13394" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\buuoujqmrk32] "DisplayName"="REG_SZ", "buuoujqmrk32" "ErrorControl"="REG_DWORD", 1 "FailureActions"="REG_BINARY, .....................6 "ImagePath"="REG_EXPAND_SZ, "C:\Program Files\003\buuoujqmrk32.exe run options=01110010030000000000000000000000 sourceguid=F978377C-B7D4-4536-8E10-14CA97B13394" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 [HKEY_CURRENT_USER\Software\AppDataLow\Software\suprasavings] "key"="REG_SZ", "F978377C-B7D4-4536-8E10-14CA97B13394"
Malwarebytes Anti-Malware log:
Malwarebytes Anti-Malware www.malwarebytes.org Scan Date: 3/29/2014 Scan Time: 10:09:28 AM Logfile: mbamSupra.txt Administrator: Yes Version: 2.00.0.1000 Malware Database: v2014.03.29.01 Rootkit Database: v2014.03.27.01 License: Free Malware Protection: Disabled Malicious Website Protection: Disabled Chameleon: Disabled OS: Windows 7 Service Pack 1 CPU: x86 File System: NTFS User: Malwarebytes Scan Type: Threat Scan Result: Completed Objects Scanned: 205114 Time Elapsed: 18 min, 9 sec Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Shuriken: Enabled PUP: Enabled PUM: Enabled Processes: 1 Trojan.Agent.SVR, C:\Program Files\003\buuoujqmrk32.exe, 6828, Delete-on-Reboot, [17ee14f58dee082e27db4f1533ceb24e] Modules: 0 (No malicious items detected) Registry Keys: 3 Trojan.Agent.SVR, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\buuoujqmrk32, Quarantined, [17ee14f58dee082e27db4f1533ceb24e], PUP.Optional.SupraSavings.A, HKLM\SOFTWARE\suprasavings, Quarantined, [d92c1cedb7c4a294203f104780820ef2], PUP.Optional.SupraSavings.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\suprasavings, Quarantined, [15f0d33694e78ea82839a3b4649e7789], Registry Values: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Folders: 1 PUP.Optional.SupraSavings.A, C:\Program Files\suprasavings, Quarantined, [f90c8782b0cbdf57b6593f18d230639d], Files: 3 Trojan.Agent.SVR, C:\Program Files\003\buuoujqmrk32.exe, Delete-on-Reboot, [17ee14f58dee082e27db4f1533ceb24e], PUP.Optional.SupraSavings.A, C:\Users\{username}\Desktop\Supra Savings ( AdPeak variant).exe, Quarantined, [6c99a267ff7cb77fd93947bf847ea957], PUP.Optional.SupraSavings.A, C:\Program Files\suprasavings\uninstaller.exe, Quarantined, [f90c8782b0cbdf57b6593f18d230639d], Physical Sectors: 0 (No malicious items detected) (end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
Save yourself the hassle and get protected.