allday savings

allday savings

Known Malware

by Adpeak, Inc.

What is allday savings?

allday savings is software application developed by Adpeak, Inc.. It is most commonly found on computers running Windows 7 with nearly 52.90% of installations running this operating system. allday savings's installer is typically 2.00 MB in size and installs around 13 files.

allday savings is most popular in the United States with 52.91% of installations residing in this country.

About allday savings?

AllDaySavings, a product of AllDaySavings, Inc., offers the Coupon Amazing variant, a web browser advertising injection software. This software is bundled by 3rd party developers and injects various advertising formats into the user's web browser, including text links and traditional banner placements on non-affiliated websites. Additionally, the plug-in may contain banner ads and interstitial advertising, displaying full-screen web pages for a limited amount of time between the current and destination pages, as outlined in the Terms.

Multiple virus scanners have detected malware in allday savings.

sbmrwsyodt.exe (MD5: caa002ec7a0513a4a91b1dc453a674a7) has been flagged by 21 scanners:
Scanner Software Result
Lavasoft Ad-Aware Adware.Agent.OFV
Agnitum Outpost Trojan.BPlug!
AVG Generic5.BDXG
Baidu-International Adware.Win32.CouponAmazing.81
Bitdefender Adware.Agent.OFV
Dr.Web Trojan.BPlug.114
Emsisoft Anti-Malware Adware.Agent.OFV (B)
ESET-NOD32 a variant of Win32/AdWare.Adpeak.J
F-Secure Adware.Agent.OFV
G Data Adware.Agent.OFV
MicroWorld-eScan Adware.Agent.OFV
nProtect Adware.Agent.OFV
Sophos Generic PUA MC
TrendMicro-HouseCall TROJ_GEN.R092H09GV14
Antiy-AVL Trojan/Win32.SGeneric
AVware Trojan.Win32.Generic!BT
VIPRE Antivirus Trojan.Win32.Generic!BT
Comodo Security Application.Win32.CouponAmazing.AA
Kaspersky not-a-virus:AdWare.Win32.Suppad.fa
Rising Antivirus PE:Adware.CouponAmazing!6.4A
Trend Micro ADW_DAYSAVE
rzlsndddma.dll (MD5: 209d7c736d1f9fa33c45f242666d4493) has been flagged by 5 scanners:
Scanner Software Result
Baidu-International Adware.Win32.CouponAmazing.77
Comodo Security Application.Win32.CouponAmazing.AA
Rising Antivirus PE:Adware.CouponAmazing!6.4A
TrendMicro-HouseCall Suspicious_GEN.F47V0725
Kaspersky not-a-virus:AdWare.Win32.Suppad.fb
kzhxnitccw.dll (MD5: 767ee825a22a5a2c5e1974d73819ddf2) has been flagged by 7 scanners:
Scanner Software Result
Baidu-International Adware.Win32.CouponAmazing.77
Comodo Security Application.Win32.CouponAmazing.AA
Dr.Web Trojan.Siggen6.21938
Kaspersky not-a-virus:AdWare.Win32.Suppad.fa
Rising Antivirus PE:Adware.CouponAmazing!6.4A
Trend Micro ADW_DAYSAVE
TrendMicro-HouseCall ADW_DAYSAVE
etmajyzoqm.exe (MD5: 0ad8b70e3ec89560f477f28d9715b949) has been flagged by 12 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.SGeneric
AVG Generic5.BDRC
AVware Trojan.Win32.Generic!BT
Baidu-International Trojan.Win32.Adpeak.BJ
ESET-NOD32 a variant of Win32/AdWare.Adpeak.J
TrendMicro-HouseCall Suspicious_GEN.F47V0802
VIPRE Antivirus Trojan.Win32.Generic!BT
Comodo Security Application.Win32.CouponAmazing.AA
Dr.Web Trojan.Siggen6.21938
Kaspersky not-a-virus:AdWare.Win32.Suppad.fa
Rising Antivirus PE:Adware.CouponAmazing!6.4A
Trend Micro ADW_DAYSAVE
crxkzhfdje.dll (MD5: cc29ceff68486494ad291ae0b10de829) has been flagged by 4 scanners:
Scanner Software Result
Comodo Security Application.Win32.CouponAmazing.AA
Kaspersky not-a-virus:AdWare.Win32.Suppad.fb
Rising Antivirus PE:Adware.CouponAmazing!6.4A
TrendMicro-HouseCall Suspicious_GEN.F47V0731

Software Behaviors

Services:
  • etmajyzoqm.exe runs as a service named 'AllDaySavingsService' (AllDaySavingsService).
  • sbmrwsyodt.exe runs as a service named 'AllDaySavingsService' (AllDaySavingsService).

Software Details

URL:
https://www.alldaysavings.org
Support:
Installation path:
C:\Program Files\b021cbbd-e38e-4f8c-8e93-6624b0597a23
Uninstaller:
C:\Program Files\B021CBBD-E38E-4F8C-8E93-6624B0597A23\uninstaller.exe -source="B021CBBD-E38E-4F8C-8E93-6624B0597A23" -clean=1 -remove="739027FD-0200-4
Size:
2.00 MB
Language:
English

allday savings Executable Details

Primary executable:
qlotcjgnnn.dll
Name:
allday savings
Path:
C:\Program Files\b021cbbd-e38e-4f8c-8e93-6624b0597a23\qlotcjgnnn.dll
MD5:
0f65d67dcf9bace722c7987ca2e81b6a
SHA-1:
SHA-256:
Files installed by allday savings
File Type Filename MD5
EXE
0ad8b70e3ec89560f477f28d9715b949
DLL
cc29ceff68486494ad291ae0b10de829
DLL
0f65d67dcf9bace722c7987ca2e81b6a