Home Malware Programs Adware Adware.SavePass

Adware.SavePass

Posted: May 22, 2014

Threat Metric

Ranking: 6,923
Threat Level: 2/10
Infected PCs: 32,928
First Seen: May 22, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


Adware.SavePass is adware that may compromise online searches of the computer user by replacing search results in any legitimate search engine with sponsored links and continuously diverting the PC user to suspicious websites carrying the promotional based content. Adware.SavePass may insert a potentially unwanted add-on, plug-in or browser extension in Web browsers such Internet Explorer, Mozilla Firefox, and Google Chrome when PC users install various free programs from the Internet. When the PC user installs any free program and do not pay attention to additional software that may be embedded into the installation process, they may also install unwanted browser extensions, add-ons or plug-ins like Adware.SavePass on their computer systems. Adware.SavePass may show annoying pop-up ads and unwillingly redirect PC users to untrustworthy websites that were designed to probably generate advertising revenue from increased Internet traffic and ad clicks.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\SavePass 1.1\689e9ecb-955f-48c0-8418-965d20184ed0.exe File name: 689e9ecb-955f-48c0-8418-965d20184ed0.exe
Size: 333.16 KB (333160 bytes)
MD5: cea665874c59f236bea19b0eff4e7387
Detection count: 927
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass 1.1
Group: Malware file
Last Updated: November 19, 2019
%PROGRAMFILES%\SavePass 1.1\a40beeff-e63f-4bf9-8c06-95fb9203203f.exe File name: a40beeff-e63f-4bf9-8c06-95fb9203203f.exe
Size: 31.59 KB (31592 bytes)
MD5: 0e95d8bc03c33316bb1cd7cba9fe3256
Detection count: 707
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass 1.1
Group: Malware file
Last Updated: November 19, 2019
%PROGRAMFILES%\SavePass\SavePass-novainstaller.exe File name: SavePass-novainstaller.exe
Size: 531.45 KB (531456 bytes)
MD5: 0724e1368c0499c81effd7e897f2e798
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\SavePass\SavePass-codedownloader.exe File name: SavePass-codedownloader.exe
Size: 531.45 KB (531456 bytes)
MD5: ac539cc585e844a4c12bc7420a9d0451
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\SavePass\Uninstall.exe File name: Uninstall.exe
Size: 79.36 KB (79360 bytes)
MD5: df1b2ec2ff05a50db3b98c407415531b
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SavePass
Group: Malware file
Last Updated: January 12, 2020
utils.exe File name: utils.exe
Size: 2.38 MB (2386824 bytes)
MD5: 905e61b3d3f4f794f297d948ac79e532
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 11, 2020
%PROGRAMFILES%\SavePass\SavePass-nova.exe File name: SavePass-nova.exe
Size: 612.86 KB (612864 bytes)
MD5: 837c43fcf4cc90ea350d2e171c50f25e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass
Group: Malware file
Last Updated: June 2, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110511701150}{22222222-2222-2222-2222-220522702250}{44444444-4444-4444-4444-440544704450}{55555555-5555-5555-5555-550555705550}{66666666-6666-6666-6666-660566706650}Regexp file mask%windir%\System32\Tasks\5aa3d933-32c7-4b03-9bcf-13d56020c4b9[RANDOM CHARACTERS]%windir%\Tasks\5aa3d933-32c7-4b03-9bcf-13d56020c4b9[RANDOM CHARACTERS]%windir%\Tasks\ec383aea-7d1a-4bec-9bd2-91a327cc8177[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\onRequest\57050Software\AppDataLow\Software\SavePassSoftware\AppDataLow\Software\SavePass 1.1Software\AppDataLow\Software\Savepass 2.0SOFTWARE\Classes\CrossriderApp0057050.BHOSOFTWARE\Classes\CrossriderApp0057050.BHO.1SOFTWARE\Classes\CrossriderApp0057050.SandboxSOFTWARE\Classes\CrossriderApp0057050.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\SavePassSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\SavePass 1.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Savepass 2.0Software\InstalledBrowserExtensions\29777Software\InstalledBrowserExtensions\29777\61908Software\InstalledBrowserExtensions\OB\61908Software\InstalledBrowserExtensions\OB\63429Software\InstalledBrowserExtensions\OB\66161Software\InstalledBrowserExtensions\OB\69829Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{35a19911-67ec-4e46-843e-867760c12584}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3a3eb005-48ee-4e40-a3f9-d7fb953abcb9}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d2f31f2-06c9-49d2-9ceb-74af75caeb58}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{40120d92-046b-4023-8315-14abef7fa22a}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69d6946f-d754-43a2-8c5c-b216a49cf940}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cb1f0b5b-21ad-4204-a7cd-ae2ad82d4376}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass 1.1-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Savepass 2.0-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass-bg.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass.exeSOFTWARE\Microsoft\Tracing\SavePass_RASAPI32SOFTWARE\Microsoft\Tracing\SavePass_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511701150}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511701150}SOFTWARE\SavePassSOFTWARE\SavePass 1.1SOFTWARE\SavePass 1.1-nvSOFTWARE\Savepass 2.0SOFTWARE\Wow6432Node\InstalledBrowserExtensions\29777SOFTWARE\Wow6432Node\InstalledBrowserExtensions\29777\61908SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{35a19911-67ec-4e46-843e-867760c12584}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d2f31f2-06c9-49d2-9ceb-74af75caeb58}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cb1f0b5b-21ad-4204-a7cd-ae2ad82d4376}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\C:\Program Files (x86)\SavePass\SavePass-nova.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass 1.1-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Savepass 2.0-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass-bg.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\SavePass_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SavePass_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}SOFTWARE\Wow6432Node\SavePassSOFTWARE\Wow6432Node\SavePass 1.1SOFTWARE\Wow6432Node\SavePass 1.1-nvSOFTWARE\Wow6432Node\Savepass 2.0HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SavePassSavePass 1.1Savepass 2.0{5823C449-6868-4154-B496-21E40C5F09DA}

Additional Information

The following directories were created:
%PROGRAMFILES%\SavePass%PROGRAMFILES%\SavePass 1.1%PROGRAMFILES%\Savepass 2.0%PROGRAMFILES(x86)%\SavePass%PROGRAMFILES(x86)%\SavePass 1.1%PROGRAMFILES(x86)%\Savepass 2.0
Loading...