Shop and Save Up
What is Shop and Save Up?
Shop and Save Up is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 7 with nearly 57.84% of installations running this operating system. Shop and Save Up's installer is typically 10.00 MB in size and installs around 145 files.
Shop and Save Up is most popular in the United States with 16.88% of installations residing in this country.
Shop and Save Up adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.
About Shop and Save Up?
Shop and Save Up is a browser plugin program designed to display advertisements. It delivers various types of ads such as banner ads, text-links, coupons, and other offers within the user's web browser, and may also generate pop-ups outside of the browser. These advertisements may come from hijacked search engines with low relevance, and may potentially expose the user to malware, adware, or other potentially unwanted programs (PUPs). Furthermore, the program may track the user's web browsing history and actions and transmit this information to a command and control server.
Multiple virus scanners have detected malware in Shop and Save Up.
Scanner Software | Version | Result |
---|---|---|
Lavasoft Ad-Aware | 537 | Gen:Application.Parj.1 |
Agnitum Outpost | 7.1.1 | PUA.Toolbar.CrossRider |
AhnLab-V3 | 2015.07.02 | PUP/Win32.CrossRider |
Arcabit | 1.0.0.425 | Application.Parj.1 |
avast! | 2014.9-150816 | NSIS:Crossrider-ES [PUP] |
AVG | 2016.0.3015 | Crossrider |
Avira | 8.3.1.6 | ADWARE/CrossRider.Gen7 |
AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
Baidu-International | 4.0.3.15816 | Adware.Win32.CrossAd.CF |
Bitdefender | 1.0.20.1140 | Gen:Application.Parj.1 |
Cyren | 5.4.16.7 | W32/Application.IFMS-5863 |
Dr.Web | 9.0.0.0228 | Trojan.DownLoader14.10941 |
ESET-NOD32 | 9.11877 | a variant of Win32/Toolbar.CrossRider.CM potentially unwanted |
F-Secure | 11.2015-16-08_1 | Gen:Application.Parj.1 |
G Data | 15.8.25 | Gen:Application.Parj |
K7 AntiVirus | 13.205.16434 | Adware |
K7GW | 13.205.16434 | Adware ( 004b98a11 ) |
Kaspersky | 14.0.0.1571 | not-a-virus:AdWare.Win32.CrossRider |
Malwarebytes | v2015.08.16.06 | PUP.Optional.ShopAndSave.A |
McAfee | 5600.6671 | Artemis!F872596129DA |
McAfee-GW-Edition | 7.6671 | BehavesLike.Win32.Dropper.tc |
MicroWorld-eScan | 16.0.0.684 | Gen:Application.Parj.1 |
NANO AntiVirus | 0.30.24.2320 | Riskware.Win32.CrossRider.dsxfkx |
Panda Antivirus | 15.08.16.06 | Trj/CI.A |
Qihoo-360 | 1.0.0.1015 | HEUR/QVM20.1.Malware.Gen |
Rising Antivirus | 23.00.65.15814 | PE:Trojan.Win32.Generic.18C743FB!415712251 |
SUPERAntiSpyware | 9687 | PUP.CrossRider/Variant |
Symantec | 8/16/2015 rev. 1 | Trojan.Gen |
Trend Micro | 10.465.16 | TROJ_GEN.R08NC0OFN15 |
VIPRE Antivirus | 41642 | Trojan.Win32.Generic!BT |
Zillya | 2.0.0.2263 | Trojan.BlackGen.Win32.11 |
Software Behaviors
- Scheduled tasks:
-
- cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is scheduled as a task named 'cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6'.
- f6e9ae87-5ccd-4e52-958a-dccaadd641f8-1-6.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-14'.
- f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10_user'.
Startup Entries
- Startup tasks:
-
- cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is automatically launched at startup through a scheduled task named cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.
- 1f8fdff3-ba86-40f4-a012-a61ff631e986-1-7.exe is automatically launched at startup through a scheduled task named 1f8fdff3-ba86-40f4-a012-a61ff631e986-7.
- 2f282854-552d-42c5-89c0-12f1fab6979e-11.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-11.
- 2f282854-552d-42c5-89c0-12f1fab6979e-10.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-10_user.
- 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.
- 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.
Software Details
- URL:
- –
- Support:
- –
- Installation path:
- C:\Program Files\shop and save up
- Uninstaller:
- C:\Program Files\Shop and Save Up\Uninstall.exe /fcp=1
- Size:
- 10.00 MB
- Language:
- English
Shop and Save Up Executable Details
- Primary executable:
- utils.exe
- Name:
- Shop and Save Up
- Path:
- C:\Program Files\shop and save up\utils.exe
- MD5:
- f872596129da13064fa52305e10f65dc
- SHA-1:
- –
- SHA-256:
- –
File Type | Filename | MD5 |
---|---|---|
EXE
|
ab91a7350a5fddcdf0a7b0c60e8e4e71 | |
EXE
|
32b87f6b7c5d9ed6f0df7618a364736d | |
EXE
|
8ec2742838e8ae222ace5ae545421014 | |
EXE
|
3141c8aa7a279de4aa420778735a58d9 | |
EXE
|
252519f164b4aae8425b875ea838b86a | |
EXE
|
375fe16c56dcc08c991fc877546ecb98 | |
EXE
|
347c096da42509755aae71f3b11a42a4 | |
EXE
|
0f9a9c261e3acb6d50bd6390e07ef35d | |
EXE
|
9486edbef9a2d0da208fef3de5e3bd2e | |
EXE
|
1e7780905e676d42797f374fe47b614f |