Shop and Save Up

Shop and Save Up

Known Adware

by BrightCircle Investments Limited

What is Shop and Save Up?

Shop and Save Up is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 7 with nearly 57.84% of installations running this operating system. Shop and Save Up's installer is typically 10.00 MB in size and installs around 145 files.

Shop and Save Up is most popular in the United States with 16.88% of installations residing in this country.

Shop and Save Up adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Shop and Save Up?

Shop and Save Up is a browser plugin program designed to display advertisements. It delivers various types of ads such as banner ads, text-links, coupons, and other offers within the user's web browser, and may also generate pop-ups outside of the browser. These advertisements may come from hijacked search engines with low relevance, and may potentially expose the user to malware, adware, or other potentially unwanted programs (PUPs). Furthermore, the program may track the user's web browsing history and actions and transmit this information to a command and control server.

Multiple virus scanners have detected malware in Shop and Save Up.

utils.exe (MD5: f872596129da13064fa52305e10f65dc) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Parj.1
Agnitum Outpost PUA.Toolbar.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Arcabit Application.Parj.1
avast! NSIS:Crossrider-ES [PUP]
AVG Crossrider
Avira ADWARE/CrossRider.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.CrossAd.CF
Bitdefender Gen:Application.Parj.1
Cyren W32/Application.IFMS-5863
Dr.Web Trojan.DownLoader14.10941
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CM potentially unwanted
F-Secure Gen:Application.Parj.1
G Data Gen:Application.Parj
K7 AntiVirus Adware
K7GW Adware ( 004b98a11 )
Kaspersky not-a-virus:AdWare.Win32.CrossRider
Malwarebytes PUP.Optional.ShopAndSave.A
McAfee Artemis!F872596129DA
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
MicroWorld-eScan Gen:Application.Parj.1
NANO AntiVirus Riskware.Win32.CrossRider.dsxfkx
Panda Antivirus Trj/CI.A
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18C743FB!415712251
SUPERAntiSpyware PUP.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R08NC0OFN15
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Trojan.BlackGen.Win32.11

Software Behaviors

Scheduled tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is scheduled as a task named 'cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-1-6.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-14'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10_user'.

Startup Entries

Startup tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is automatically launched at startup through a scheduled task named cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.
  • 1f8fdff3-ba86-40f4-a012-a61ff631e986-1-7.exe is automatically launched at startup through a scheduled task named 1f8fdff3-ba86-40f4-a012-a61ff631e986-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-11.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-11.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-10.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-10_user.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.

Software Details

URL:
Support:
Installation path:
C:\Program Files\shop and save up
Uninstaller:
C:\Program Files\Shop and Save Up\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

Shop and Save Up Executable Details

Primary executable:
utils.exe
Name:
Shop and Save Up
Path:
C:\Program Files\shop and save up\utils.exe
MD5:
f872596129da13064fa52305e10f65dc
SHA-1:
SHA-256:
Files installed by Shop and Save Up
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
32b87f6b7c5d9ed6f0df7618a364736d
EXE
8ec2742838e8ae222ace5ae545421014
EXE
3141c8aa7a279de4aa420778735a58d9
EXE
252519f164b4aae8425b875ea838b86a
EXE
375fe16c56dcc08c991fc877546ecb98
EXE
347c096da42509755aae71f3b11a42a4
EXE
0f9a9c261e3acb6d50bd6390e07ef35d
EXE
9486edbef9a2d0da208fef3de5e3bd2e
EXE
1e7780905e676d42797f374fe47b614f