Shop and Save Up

Shop and Save Up

Known Adware

by BrightCircle Investments Limited

What is Shop and Save Up?

Shop and Save Up is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 7 with nearly 57.84% of installations running this operating system. Shop and Save Up's installer is typically 10.00 MB in size and installs around 145 files.

Shop and Save Up is most popular in the United States with 16.88% of installations residing in this country.

Shop and Save Up adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Shop and Save Up?

Shop and Save Up is a browser plugin program designed to display advertisements. It delivers various types of ads such as banner ads, text-links, coupons, and other offers within the user's web browser, and may also generate pop-ups outside of the browser. These advertisements may come from hijacked search engines with low relevance, and may potentially expose the user to malware, adware, or other potentially unwanted programs (PUPs). Furthermore, the program may track the user's web browsing history and actions and transmit this information to a command and control server.

Multiple virus scanners have detected malware in Shop and Save Up.

utils.exe (MD5: f872596129da13064fa52305e10f65dc) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Parj.1
Agnitum Outpost PUA.Toolbar.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Arcabit Application.Parj.1
avast! NSIS:Crossrider-ES [PUP]
AVG Crossrider
Avira ADWARE/CrossRider.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.CrossAd.CF
Bitdefender Gen:Application.Parj.1
Cyren W32/Application.IFMS-5863
Dr.Web Trojan.DownLoader14.10941
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CM potentially unwanted
F-Secure Gen:Application.Parj.1
G Data Gen:Application.Parj
K7 AntiVirus Adware
K7GW Adware ( 004b98a11 )
Kaspersky not-a-virus:AdWare.Win32.CrossRider
Malwarebytes PUP.Optional.ShopAndSave.A
McAfee Artemis!F872596129DA
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
MicroWorld-eScan Gen:Application.Parj.1
NANO AntiVirus Riskware.Win32.CrossRider.dsxfkx
Panda Antivirus Trj/CI.A
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18C743FB!415712251
SUPERAntiSpyware PUP.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R08NC0OFN15
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Trojan.BlackGen.Win32.11

Software Behaviors

Scheduled tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is scheduled as a task named 'cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-1-6.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-14'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10_user'.

Startup Entries

Startup tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is automatically launched at startup through a scheduled task named cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.
  • 1f8fdff3-ba86-40f4-a012-a61ff631e986-1-7.exe is automatically launched at startup through a scheduled task named 1f8fdff3-ba86-40f4-a012-a61ff631e986-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-11.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-11.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-10.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-10_user.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.

Software Details

URL:
Support:
Installation path:
C:\Program Files\shop and save up
Uninstaller:
C:\Program Files\Shop and Save Up\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

Shop and Save Up Executable Details

Primary executable:
utils.exe
Name:
Shop and Save Up
Path:
C:\Program Files\shop and save up\utils.exe
MD5:
f872596129da13064fa52305e10f65dc
SHA-1:
SHA-256:
Files installed by Shop and Save Up
File Type Filename MD5
DLL
f14e2357c444fcb9aea4822b01efd9f3
EXE
110751d1e25fb5dbba6be56e9be281de
CRX
9ab45e605f286061a8aa9c1955579cfb
DLL
0a0e017d117f9fcc20e0f0291eab95ef
DLL
ec5ce48eb8a4c61b8c490cf0403127e2
DLL
58886d0fe8d91201a8d4eee4970859b0
EXE
c4ae4389d8ce360c136669115deefb84
EXE
957fe2d389445042c0a07c329505885f
EXE
d9e2c4896637b759662038f8b13eefca
EXE
17d2b3ae349db91eb907f0ef291cb42f