Home Malware Programs Adware SaveSense

SaveSense

Posted: December 18, 2013

Threat Metric

Ranking: 3,966
Threat Level: 2/10
Infected PCs: 122,845
First Seen: December 18, 2013
Last Seen: March 8, 2025
OS(es) Affected: Windows

SaveSense is adware that may show advertisements, banners, messages and deals via a pop-up box in popular shopping related websites and social networking websites that are visited by PC users. SaveSense may embed an ad-supported web browser extension, add-on or plug-in in Internet Explorer, Mozilla Firefox and Google Chrome that may display banner, pop-up, pop-under, search, and in-text link interstitial advertisements. SaveSense may spread through a variety of monetization platforms during the installation process of various freeware. SaveSense may usually be inserted in the web browser when the PC user installs other free software that may have included into their installation SaveSense. When the computer user installs free applications, he may also install SaveSense on the machine. When installed, the SaveSense browser plug-in, add-on or plug-in may highlight words on websites that are visited by PC users changing them with hyperlinks. These SaveSense links may be added within the text and may come with a double underline to separate them from normal web-links. When the computer user rolls the mouse over the link, the pop-up advertisements of SaveSense may occur on the screen of the PC. If the computer user clicks on the SaveSense pop-up links, the creators of the browser add-on, plug-in or extension may earn easy money from these clicks.

Aliases

Adware.SaveSense.1 [DrWeb]Win32:Adware-gen [Adw] [Avast]MalSign.Generic.81E [AVG]Artemis!6F2939B1EC17 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe.vir File name: SaveSenseLive.exe.vir
Size: 146.92 KB (146920 bytes)
MD5: c495d8665a32539660625182d23d5c59
Detection count: 22,878
Mime Type: unknown/vir
Path: %SYSTEMDRIVE%\AdwCleaner\Quarantine\C\Program Files (x86)\SaveSenseLive\Update\1.3.23.0\SaveSenseLive.exe.vir
Group: Malware file
Last Updated: March 3, 2025
C:\Qoobox\Quarantine\C\Windows\SysWOW64\upd.exe.vir File name: upd.exe.vir
Size: 195.07 KB (195072 bytes)
MD5: 52da860708dc877b3c97c1bab8afeb72
Detection count: 2,981
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\Windows\SysWOW64\upd.exe.vir
Group: Malware file
Last Updated: December 16, 2023
C:\Qoobox\Quarantine\C\Users\<username>\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe.vir File name: UpdateTask.exe.vir
Size: 195.07 KB (195072 bytes)
MD5: ce969763d1753ecf9c05b199f280b252
Detection count: 728
Mime Type: unknown/vir
Path: C:\Qoobox\Quarantine\C\Users\<username>\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe.vir
Group: Malware file
Last Updated: December 8, 2022
C:\Users\<username>\AppData\Roaming\OpenCandy\FF65A00C4E194AE7A94A2F29EAB2D488\SaveSense_p1v2.exe File name: SaveSense_p1v2.exe
Size: 1.34 MB (1341680 bytes)
MD5: ed0d2ff9243af4c4021934ad7948981b
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\OpenCandy\FF65A00C4E194AE7A94A2F29EAB2D488\SaveSense_p1v2.exe
Group: Malware file
Last Updated: November 11, 2022
%APPDATA%\SaveSense\UpdateProc\UpdateTask.exe File name: UpdateTask.exe
Size: 260.6 KB (260608 bytes)
MD5: 4bcd59216ce6a7fcb1bc77ff285afe59
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SaveSense\UpdateProc
Group: Malware file
Last Updated: February 18, 2014
sas.exe File name: sas.exe
Size: 870.51 KB (870512 bytes)
MD5: d05cf41a2e1e01e7842e2b643a6f2370
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 5, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{0EE6D408-6ED5-40C6-8C42-A041D5DE9AB0}{0f21b1e5-5afc-43c9-9c66-515046e92ec2}{1070C156-160B-47A0-B7D9-1860396BAB57}{13A42355-1F94-4459-B19E-F60B2C607C77}{27CE191D-733B-4450-AFCD-096D105288C3}{293DD661-C540-4AC4-9B4C-42E68369CE1B}{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}{2EC58BDB-0694-4D54-80DD-A8F2AA0427A1}{313B508D-596D-4BDF-B0B5-E41F224E184A}{39A29266-D3E4-462D-AB05-F93B1053F6CF}{3AF4400F-CDC5-4F2D-B3F1-74348E5D5CCC}{422E1393-7A4C-44FF-A7E1-8B9D146E0666}{44FC7A33-2E5C-48DC-B6F5-B81E8005D122}{4807D6D8-ADC8-41AF-AB9D-AE1086D1E62F}{6E1CD171-29C1-4D56-A223-E31C57A0A25A}{70E96298-17FC-4020-A7CF-6F81ED8CF3AB}{73192D81-6D24-4C40-BF7B-2507C6FA0B1A}{84A81B7E-B8CD-4891-BEA0-548D65E9610A}{867DF9A9-D013-4A1A-B685-DFF65D225ED4}{889074FC-1456-4CE8-88F7-154264DC275F}{88C606E7-BA26-41CB-8CC3-D1E313E34E75}{91F4CF02-F675-4E6A-B4E8-C13DF09B9B1B}{93D3100A-BBB6-456C-96FC-82CAC5F383AC}{997E3BFB-F821-411C-8B96-D61D415EC8FA}{998745A3-2AE4-488D-8092-B98FB20A00C2}{99DCF141-03F9-4363-8D79-640FA646DEED}{9E0546FF-D44F-4FE4-A324-995FCACB8D33}{A18D16ED-27B2-4B83-B70C-15E73F099546}{A2D3FB7A-6873-45E8-AF96-57092D721828}{A902A36E-0C79-4BD7-B561-9C058BD60210}{AB778974-218E-4734-90F0-731BE7E50E77}{ADE6A9C0-12B3-457D-9A86-548FA87E04DB}{B7C67027-15EB-489F-A9EA-286076CF7540}{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}{C1424421-D274-491E-9D47-11C8D8CB5F9A}{CDB98856-BEA3-4073-AF57-23A3583AE9E4}{CDDAB3A4-E64D-4AE0-9E1D-F3132F5F913F}{CDED8922-BB3D-4E3A-9C2C-89B1C927F48B}{D79CBD8E-D857-4D05-B3AD-26F722CF5B6E}{E66A759D-367F-433E-85C6-ED7F040BCC32}{E7EA7058-B19B-4A27-B50A-87A1B8FC5F30}{F4B8D46C-4EEE-401B-8607-DC03025F34B1}HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}Software\Microsoft\Internet Explorer\Approved Extensions\{71e129ff-6c2a-4984-818c-7e2c998b8d99}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71E129FF-6C2A-4984-818C-7E2C998B8D99}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71E129FF-6C2A-4984-818C-7E2C998B8D99}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}Software\SaveSenseSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}SOFTWARE\Wow6432Node\SaveSenseSYSTEM\ControlSet001\Services\savesenseliveSYSTEM\ControlSet001\Services\savesenselivemSYSTEM\ControlSet002\Services\savesenseliveSYSTEM\ControlSet002\Services\savesenselivemSYSTEM\CurrentControlSet\Services\savesenseliveSYSTEM\CurrentControlSet\Services\savesenselivemHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Save SenseSaveSense

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Application Data\SaveSenseLive%ALLUSERSPROFILE%\SaveSenseLive%APPDATA%\Microsoft\Windows\Start Menu\Programs\SaveSense%APPDATA%\SaveSense%LOCALAPPDATA%\SaveSense%LOCALAPPDATA%\SaveSenseLive%PROGRAMFILES%\SaveSense%PROGRAMFILES%\SaveSenseLive%PROGRAMFILES(x86)%\SaveSense%PROGRAMFILES(x86)%\SaveSenseLive%USERPROFILE%\Start Menu\Programs\SaveSense%UserProfile%\Local Settings\Application Data\SaveSense
The following URL's were detected:
SaveSense
Loading...