Adware.SavePass
Posted: May 22, 2014
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 6,923 |
---|---|
Threat Level: | 2/10 |
Infected PCs: | 32,928 |
First Seen: | May 22, 2014 |
---|---|
Last Seen: | October 16, 2023 |
OS(es) Affected: | Windows |
Adware.SavePass is adware that may compromise online searches of the computer user by replacing search results in any legitimate search engine with sponsored links and continuously diverting the PC user to suspicious websites carrying the promotional based content. Adware.SavePass may insert a potentially unwanted add-on, plug-in or browser extension in Web browsers such Internet Explorer, Mozilla Firefox, and Google Chrome when PC users install various free programs from the Internet. When the PC user installs any free program and do not pay attention to additional software that may be embedded into the installation process, they may also install unwanted browser extensions, add-ons or plug-ins like Adware.SavePass on their computer systems. Adware.SavePass may show annoying pop-up ads and unwillingly redirect PC users to untrustworthy websites that were designed to probably generate advertising revenue from increased Internet traffic and ad clicks.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%PROGRAMFILES%\SavePass 1.1\689e9ecb-955f-48c0-8418-965d20184ed0.exe
File name: 689e9ecb-955f-48c0-8418-965d20184ed0.exeSize: 333.16 KB (333160 bytes)
MD5: cea665874c59f236bea19b0eff4e7387
Detection count: 927
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass 1.1
Group: Malware file
Last Updated: November 19, 2019
%PROGRAMFILES%\SavePass 1.1\a40beeff-e63f-4bf9-8c06-95fb9203203f.exe
File name: a40beeff-e63f-4bf9-8c06-95fb9203203f.exeSize: 31.59 KB (31592 bytes)
MD5: 0e95d8bc03c33316bb1cd7cba9fe3256
Detection count: 707
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass 1.1
Group: Malware file
Last Updated: November 19, 2019
%PROGRAMFILES%\SavePass\SavePass-novainstaller.exe
File name: SavePass-novainstaller.exeSize: 531.45 KB (531456 bytes)
MD5: 0724e1368c0499c81effd7e897f2e798
Detection count: 50
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES%\SavePass\SavePass-codedownloader.exe
File name: SavePass-codedownloader.exeSize: 531.45 KB (531456 bytes)
MD5: ac539cc585e844a4c12bc7420a9d0451
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass
Group: Malware file
Last Updated: June 2, 2014
%PROGRAMFILES(x86)%\SavePass\Uninstall.exe
File name: Uninstall.exeSize: 79.36 KB (79360 bytes)
MD5: df1b2ec2ff05a50db3b98c407415531b
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SavePass
Group: Malware file
Last Updated: January 12, 2020
utils.exe
File name: utils.exeSize: 2.38 MB (2386824 bytes)
MD5: 905e61b3d3f4f794f297d948ac79e532
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: July 11, 2020
%PROGRAMFILES%\SavePass\SavePass-nova.exe
File name: SavePass-nova.exeSize: 612.86 KB (612864 bytes)
MD5: 837c43fcf4cc90ea350d2e171c50f25e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SavePass
Group: Malware file
Last Updated: June 2, 2014
Registry Modifications
CLSID{11111111-1111-1111-1111-110511701150}{22222222-2222-2222-2222-220522702250}{44444444-4444-4444-4444-440544704450}{55555555-5555-5555-5555-550555705550}{66666666-6666-6666-6666-660566706650}Regexp file mask%windir%\System32\Tasks\5aa3d933-32c7-4b03-9bcf-13d56020c4b9[RANDOM CHARACTERS]%windir%\Tasks\5aa3d933-32c7-4b03-9bcf-13d56020c4b9[RANDOM CHARACTERS]%windir%\Tasks\ec383aea-7d1a-4bec-9bd2-91a327cc8177[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Crossrider\onRequest\57050Software\AppDataLow\Software\SavePassSoftware\AppDataLow\Software\SavePass 1.1Software\AppDataLow\Software\Savepass 2.0SOFTWARE\Classes\CrossriderApp0057050.BHOSOFTWARE\Classes\CrossriderApp0057050.BHO.1SOFTWARE\Classes\CrossriderApp0057050.SandboxSOFTWARE\Classes\CrossriderApp0057050.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\SavePassSoftware\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\SavePass 1.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Savepass 2.0Software\InstalledBrowserExtensions\29777Software\InstalledBrowserExtensions\29777\61908Software\InstalledBrowserExtensions\OB\61908Software\InstalledBrowserExtensions\OB\63429Software\InstalledBrowserExtensions\OB\66161Software\InstalledBrowserExtensions\OB\69829Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110511701150}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{35a19911-67ec-4e46-843e-867760c12584}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3a3eb005-48ee-4e40-a3f9-d7fb953abcb9}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d2f31f2-06c9-49d2-9ceb-74af75caeb58}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{40120d92-046b-4023-8315-14abef7fa22a}Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{69d6946f-d754-43a2-8c5c-b216a49cf940}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cb1f0b5b-21ad-4204-a7cd-ae2ad82d4376}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass 1.1-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Savepass 2.0-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass-bg.exeSoftware\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass.exeSOFTWARE\Microsoft\Tracing\SavePass_RASAPI32SOFTWARE\Microsoft\Tracing\SavePass_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511701150}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511701150}SOFTWARE\SavePassSOFTWARE\SavePass 1.1SOFTWARE\SavePass 1.1-nvSOFTWARE\Savepass 2.0SOFTWARE\Wow6432Node\InstalledBrowserExtensions\29777SOFTWARE\Wow6432Node\InstalledBrowserExtensions\29777\61908SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{35a19911-67ec-4e46-843e-867760c12584}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3d2f31f2-06c9-49d2-9ceb-74af75caeb58}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{cb1f0b5b-21ad-4204-a7cd-ae2ad82d4376}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\C:\Program Files (x86)\SavePass\SavePass-nova.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass 1.1-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Savepass 2.0-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SavePass-bg.exeSOFTWARE\Wow6432Node\Microsoft\Tracing\SavePass_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\SavePass_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511701150}SOFTWARE\Wow6432Node\SavePassSOFTWARE\Wow6432Node\SavePass 1.1SOFTWARE\Wow6432Node\SavePass 1.1-nvSOFTWARE\Wow6432Node\Savepass 2.0HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SavePassSavePass 1.1Savepass 2.0{5823C449-6868-4154-B496-21E40C5F09DA}
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.