Home Malware Programs Potentially Unwanted Programs (PUPs) SmartSaver

SmartSaver

Posted: March 27, 2014

Threat Metric

Ranking: 6,610
Threat Level: 2/10
Infected PCs: 19,786
First Seen: March 27, 2014
Last Seen: October 16, 2023
OS(es) Affected: Windows


SmartSaver is a browser add-on that may state to help PC users save time and money when shopping online. SmartSaver is categorized as adware or a potentially unwanted program (PUP). In truth, the plug-in of SmartSaver is not a valuable application. SmartSaver may generate and display annoying pop-up ads labelled as 'Ads not by this site' that may carry discount coupons, sponsored links, shopping comparison, deals, banners, content suggestions, pop-ups and pop-under advertisements. If the computer user clicks on ads shown by SmartSaver, he may unknowingly allow adware creators generate advertising income from these clicks. The browser extension of SmartSaver may also keep track of the computer user's Internet surfing by recording the web pages read, movement from one web page to another, the computer user's online requests, Internet Protocol address, Web browser information and application numbers, cookies, geographical location, referring page, time, date and other information.

Aliases

Generic_r.PD [AVG]Riskware/Toolbar_CrossRider [Fortinet]Trojan/Win32.TSGeneric [Antiy-AVL]Artemis!D2955DDDB419 [McAfee-GW-Edition]Adware/CrossRider.A.5162 [AntiVir]ApplicUnwnt [Comodo]Generic PUA PP [Sophos]Win32:Adware-gen [Adw] [Avast]RDN/Generic PUP.x!chn [McAfee]Trojan/Win32.SGeneric [Antiy-AVL]Trojan.Crossrider.7519 [DrWeb]Adware.Crossid [Symantec]WS.Reputation.1 [Symantec]Artemis!ABCCB4A7B797 [McAfee]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\SmartSaver+ 21\SmartSaver+ 21-codedownloader.exe File name: SmartSaver+ 21-codedownloader.exe
Size: 521.72 KB (521728 bytes)
MD5: b8e2b1b9d160b976c3c350636ec7d781
Detection count: 95
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SmartSaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\SmartSaver+ 21\d6e856ae-9cea-4f89-8d2a-f0a06d59708e-2.exe File name: d6e856ae-9cea-4f89-8d2a-f0a06d59708e-2.exe
Size: 345.08 KB (345088 bytes)
MD5: e1dd92bfb31909b7767ac7415b288234
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SmartSaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\SmartSaver+ 21\d6e856ae-9cea-4f89-8d2a-f0a06d59708e-3.exe File name: d6e856ae-9cea-4f89-8d2a-f0a06d59708e-3.exe
Size: 2.03 MB (2036224 bytes)
MD5: dcfd485b4da0b1916695cdb5509a8fc8
Detection count: 93
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SmartSaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\SmartSaver+ 21\d6e856ae-9cea-4f89-8d2a-f0a06d59708e-4.exe File name: d6e856ae-9cea-4f89-8d2a-f0a06d59708e-4.exe
Size: 807.93 KB (807936 bytes)
MD5: f2fbdaf3460c04b90d26304a876c858d
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SmartSaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\SmartSaver+ 21\d6e856ae-9cea-4f89-8d2a-f0a06d59708e-5.exe File name: d6e856ae-9cea-4f89-8d2a-f0a06d59708e-5.exe
Size: 365.05 KB (365056 bytes)
MD5: f309681733512febc86774baa34cbf1e
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\SmartSaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\Smart - 23\dc5dc299-20b8-48be-897b-b9b0d40020e0-2.exe File name: dc5dc299-20b8-48be-897b-b9b0d40020e0-2.exe
Size: 334.33 KB (334336 bytes)
MD5: 7816d58f878fa2fcfa7fcf27a3ae217b
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Smart - 23
Group: Malware file
Last Updated: May 14, 2014
%PROGRAMFILES(x86)%\SmartSaver+ 21\SmartSaver+ 21-bho64.dll File name: SmartSaver+ 21-bho64.dll
Size: 660.99 KB (660992 bytes)
MD5: e1df659a98e05c59222ac061bf6dcf31
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SmartSaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES(x86)%\SmartSaver+ 8\SmartSaver+ 8-bho64.dll File name: SmartSaver+ 8-bho64.dll
Size: 660.99 KB (660992 bytes)
MD5: 7dfe5b67525c886218cd86a4080d4b34
Detection count: 21
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SmartSaver+ 8
Group: Malware file
Last Updated: April 17, 2014
%PROGRAMFILES%\Smart - 23\c781eede-6853-4022-8b26-fb0e7ea06508-2.exe File name: c781eede-6853-4022-8b26-fb0e7ea06508-2.exe
Size: 334.33 KB (334336 bytes)
MD5: ff2b64017d53ac3a831dd196a569a383
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Smart - 23
Group: Malware file
Last Updated: May 14, 2014
%PROGRAMFILES(x86)%\smartsaver+ 21\smartsaver+ 21-bg.exe File name: smartsaver+ 21-bg.exe
Size: 519.16 KB (519168 bytes)
MD5: 2eb1a1b65fc6ad43a72dc5596053ae44
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\smartsaver+ 21
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\S10\c9be3240-f799-4a90-98b0-20142cc7a3e8-2.exe File name: c9be3240-f799-4a90-98b0-20142cc7a3e8-2.exe
Size: 394.24 KB (394240 bytes)
MD5: bfda5b2853201a67b13f0b99827686a3
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\S10
Group: Malware file
Last Updated: July 2, 2014
%PROGRAMFILES%\Smart - 23\Smart - 23-codedownloader.exe File name: Smart - 23-codedownloader.exe
Size: 518.14 KB (518144 bytes)
MD5: c9c5aedc782a085d8caa2dbb8fb7c0ce
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Smart - 23
Group: Malware file
Last Updated: May 14, 2014
%PROGRAMFILES%\Smart - 23\be1228f3-e8ce-4089-ba3d-44efdfc4632c-5.exe File name: be1228f3-e8ce-4089-ba3d-44efdfc4632c-5.exe
Size: 315.39 KB (315392 bytes)
MD5: 792c70b80118da4514b5fc3d48788c87
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Smart - 23
Group: Malware file
Last Updated: May 14, 2014
%PROGRAMFILES%\Smart - 23\Smart - 23-nova.exe File name: Smart - 23-nova.exe
Size: 600.57 KB (600576 bytes)
MD5: 0722783bd3444e6a385f943ca311cab7
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Smart - 23
Group: Malware file
Last Updated: May 14, 2014
%PROGRAMFILES(x86)%\smart - 23\smart - 23-bg.exe File name: smart - 23-bg.exe
Size: 513.53 KB (513536 bytes)
MD5: fbd69051538b56d10b298872ff8463ba
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\smart - 23
Group: Malware file
Last Updated: May 14, 2014
%PROGRAMFILES(x86)%\SmartSaver+ 8\72cb4a48-c55b-4f72-a0c6-43dec13bb2d2-3.exe File name: 72cb4a48-c55b-4f72-a0c6-43dec13bb2d2-3.exe
Size: 1.86 MB (1861120 bytes)
MD5: 8235b0cfddc210801c1fb1933dd3abf0
Detection count: 6
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SmartSaver+ 8
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES%\SmartSaver+ 10\SmartSaver+ 10-bho.dll File name: SmartSaver+ 10-bho.dll
Size: 495.1 KB (495104 bytes)
MD5: 29bc6f5095ab4df07b6e2d2a739a4b94
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\SmartSaver+ 10
Group: Malware file
Last Updated: April 16, 2014
%PROGRAMFILES(x86)%\SmartSaver+ 10\Uninstall.exe File name: Uninstall.exe
Size: 78.33 KB (78336 bytes)
MD5: 3f5bfc148a64af9957defea6443cbd13
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SmartSaver+ 10
Group: Malware file
Last Updated: April 15, 2014
%PROGRAMFILES(x86)%\Smart - 23\Uninstall.exe File name: Uninstall.exe
Size: 78.84 KB (78848 bytes)
MD5: d82964124ed3f240a0c185b67a945545
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Smart - 23
Group: Malware file
Last Updated: May 14, 2014

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{11111111-1111-1111-1111-110411891124}{11111111-1111-1111-1111-110411891126}{22222222-2222-2222-2222-220422892226}{44444444-4444-4444-4444-440444894424}{44444444-4444-4444-4444-440444894426}{55555555-5555-5555-5555-550455895524}{55555555-5555-5555-5555-550455895526}{66666666-6666-6666-6666-660466896624}{66666666-6666-6666-6666-660466896626}HKEY..\..\..\..{RegistryKeys}Software\AppDataLow\Software\Sm23mSSoftware\AppDataLow\Software\Sm8mSSoftware\AppDataLow\Software\SmartSaver+ 12.2Software\AppDataLow\Software\SS21Software\AppDataLow\Software\ss8SOFTWARE\Classes\4a10fb40f32a013158ab33422def983b0061804.BHOSOFTWARE\Classes\4a10fb40f32a013158ab33422def983b0061804.BHO.1SOFTWARE\Classes\4a10fb40f32a013158ab33422def983b0061804.SandboxSOFTWARE\Classes\4a10fb40f32a013158ab33422def983b0061804.Sandbox.1SOFTWARE\Classes\CrossriderApp0048924.BHOSOFTWARE\Classes\CrossriderApp0048924.BHO.1SOFTWARE\Classes\CrossriderApp0048924.SandboxSOFTWARE\Classes\CrossriderApp0048924.Sandbox.1SOFTWARE\Classes\CrossriderApp0048926.BHOSOFTWARE\Classes\CrossriderApp0048926.BHO.1SOFTWARE\Classes\CrossriderApp0048926.SandboxSOFTWARE\Classes\CrossriderApp0048926.Sandbox.1Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\SmartSaver+ 12.2Software\InstalledBrowserExtensions\26549Software\InstalledBrowserExtensions\smart-saverplusSoftware\InstalledBrowserExtensions\smarts\63107Software\Microsoft\Internet Explorer\Approved Extensions\{11111111-1111-1111-1111-110411891126}SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Sm23mS-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SmartSaver+ 12.2-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SmartSaver+ 21-bg.exeSOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\ss8-bg.exeSOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411891124}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411891124}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411891124}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411891124}SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411891126}SOFTWARE\Sm23mSSOFTWARE\ss8SOFTWARE\Wow6432Node\InstalledBrowserExtensions\26549SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Sm23mS-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SmartSaver+ 12.2-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\SmartSaver+ 21-bg.exeSOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\ss8-bg.exeSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{11111111-1111-1111-1111-110411891126}SOFTWARE\Wow6432Node\Sm23mSSOFTWARE\Wow6432Node\Sm8mSSOFTWARE\Wow6432Node\ss8HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Sm23mSSm8mSss8

Additional Information

The following directories were created:
%PROGRAMFILES%\S10%PROGRAMFILES%\Sm23mS%PROGRAMFILES%\Sm8mS%PROGRAMFILES%\Smart - 23%PROGRAMFILES%\SmartSaver+ 12%PROGRAMFILES%\SmartSaver+ 15%PROGRAMFILES%\SmartSaver+ 21%PROGRAMFILES%\SmartSaver+ 3%PROGRAMFILES%\SmartSaver+ 8%PROGRAMFILES%\ss8%PROGRAMFILES(X86)%\S10%PROGRAMFILES(X86)%\SS21%PROGRAMFILES(X86)%\Sm23mS%PROGRAMFILES(X86)%\Sm8mS%PROGRAMFILES(X86)%\SmartSaver+ 12%PROGRAMFILES(X86)%\SmartSaver+ 15%PROGRAMFILES(X86)%\SmartSaver+ 3%PROGRAMFILES(X86)%\SmartSaver+ 8%PROGRAMFILES(x86)%\Smart - 23%PROGRAMFILES(x86)%\SmartSaver+ 21%PROGRAMFILES(x86)%\SmartSaver+ 23%PROGRAMFILES(x86)%\ss8
The following URL's were detected:
SmartSaver+
Loading...