Shop and Save Up

Shop and Save Up

Known Adware

by BrightCircle Investments Limited

What is Shop and Save Up?

Shop and Save Up is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 7 with nearly 57.84% of installations running this operating system. Shop and Save Up's installer is typically 10.00 MB in size and installs around 145 files.

Shop and Save Up is most popular in the United States with 16.88% of installations residing in this country.

Shop and Save Up adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Shop and Save Up?

Shop and Save Up is a browser plugin program designed to display advertisements. It delivers various types of ads such as banner ads, text-links, coupons, and other offers within the user's web browser, and may also generate pop-ups outside of the browser. These advertisements may come from hijacked search engines with low relevance, and may potentially expose the user to malware, adware, or other potentially unwanted programs (PUPs). Furthermore, the program may track the user's web browsing history and actions and transmit this information to a command and control server.

Multiple virus scanners have detected malware in Shop and Save Up.

utils.exe (MD5: f872596129da13064fa52305e10f65dc) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Parj.1
Agnitum Outpost PUA.Toolbar.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Arcabit Application.Parj.1
avast! NSIS:Crossrider-ES [PUP]
AVG Crossrider
Avira ADWARE/CrossRider.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.CrossAd.CF
Bitdefender Gen:Application.Parj.1
Cyren W32/Application.IFMS-5863
Dr.Web Trojan.DownLoader14.10941
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CM potentially unwanted
F-Secure Gen:Application.Parj.1
G Data Gen:Application.Parj
K7 AntiVirus Adware
K7GW Adware ( 004b98a11 )
Kaspersky not-a-virus:AdWare.Win32.CrossRider
Malwarebytes PUP.Optional.ShopAndSave.A
McAfee Artemis!F872596129DA
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
MicroWorld-eScan Gen:Application.Parj.1
NANO AntiVirus Riskware.Win32.CrossRider.dsxfkx
Panda Antivirus Trj/CI.A
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18C743FB!415712251
SUPERAntiSpyware PUP.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R08NC0OFN15
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Trojan.BlackGen.Win32.11

Software Behaviors

Scheduled tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is scheduled as a task named 'cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-1-6.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-14'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10_user'.

Startup Entries

Startup tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is automatically launched at startup through a scheduled task named cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.
  • 1f8fdff3-ba86-40f4-a012-a61ff631e986-1-7.exe is automatically launched at startup through a scheduled task named 1f8fdff3-ba86-40f4-a012-a61ff631e986-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-11.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-11.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-10.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-10_user.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.

Software Details

URL:
Support:
Installation path:
C:\Program Files\shop and save up
Uninstaller:
C:\Program Files\Shop and Save Up\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

Shop and Save Up Executable Details

Primary executable:
utils.exe
Name:
Shop and Save Up
Path:
C:\Program Files\shop and save up\utils.exe
MD5:
f872596129da13064fa52305e10f65dc
SHA-1:
SHA-256:
Files installed by Shop and Save Up
File Type Filename MD5
CRX
642fccee8d849e38542a3fd3f12b7cbc
EXE
5c91eb33b4220e79df3bc260a12413af
EXE
fd79970415972bddf65c84ce44627f4f
EXE
f2beb68f961237adf1a1c046d69dc38c
EXE
c20b417f8b49866d60e42d64b58215b2
EXE
2b6b4b7186c25f5b96dc180fcdda9418
DLL
19697ac830a925ae380f9ba672ad8a4c
EXE
07107a930f5b2eef0173099f9c0cb17e
EXE
acfc9a0d294a70fe733b3314a3128404
EXE
223e6dcd516bc7bd8ed804bc7fde1105