Shop and Save Up

Shop and Save Up

Known Adware

by BrightCircle Investments Limited

What is Shop and Save Up?

Shop and Save Up is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 7 with nearly 57.84% of installations running this operating system. Shop and Save Up's installer is typically 10.00 MB in size and installs around 145 files.

Shop and Save Up is most popular in the United States with 16.88% of installations residing in this country.

Shop and Save Up adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Shop and Save Up?

Shop and Save Up is a browser plugin program designed to display advertisements. It delivers various types of ads such as banner ads, text-links, coupons, and other offers within the user's web browser, and may also generate pop-ups outside of the browser. These advertisements may come from hijacked search engines with low relevance, and may potentially expose the user to malware, adware, or other potentially unwanted programs (PUPs). Furthermore, the program may track the user's web browsing history and actions and transmit this information to a command and control server.

Multiple virus scanners have detected malware in Shop and Save Up.

utils.exe (MD5: f872596129da13064fa52305e10f65dc) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Parj.1
Agnitum Outpost PUA.Toolbar.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Arcabit Application.Parj.1
avast! NSIS:Crossrider-ES [PUP]
AVG Crossrider
Avira ADWARE/CrossRider.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.CrossAd.CF
Bitdefender Gen:Application.Parj.1
Cyren W32/Application.IFMS-5863
Dr.Web Trojan.DownLoader14.10941
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CM potentially unwanted
F-Secure Gen:Application.Parj.1
G Data Gen:Application.Parj
K7 AntiVirus Adware
K7GW Adware ( 004b98a11 )
Kaspersky not-a-virus:AdWare.Win32.CrossRider
Malwarebytes PUP.Optional.ShopAndSave.A
McAfee Artemis!F872596129DA
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
MicroWorld-eScan Gen:Application.Parj.1
NANO AntiVirus Riskware.Win32.CrossRider.dsxfkx
Panda Antivirus Trj/CI.A
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18C743FB!415712251
SUPERAntiSpyware PUP.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R08NC0OFN15
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Trojan.BlackGen.Win32.11

Software Behaviors

Scheduled tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is scheduled as a task named 'cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-1-6.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-14'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10_user'.

Startup Entries

Startup tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is automatically launched at startup through a scheduled task named cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.
  • 1f8fdff3-ba86-40f4-a012-a61ff631e986-1-7.exe is automatically launched at startup through a scheduled task named 1f8fdff3-ba86-40f4-a012-a61ff631e986-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-11.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-11.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-10.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-10_user.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.

Software Details

URL:
Support:
Installation path:
C:\Program Files\shop and save up
Uninstaller:
C:\Program Files\Shop and Save Up\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

Shop and Save Up Executable Details

Primary executable:
utils.exe
Name:
Shop and Save Up
Path:
C:\Program Files\shop and save up\utils.exe
MD5:
f872596129da13064fa52305e10f65dc
SHA-1:
SHA-256:
Files installed by Shop and Save Up
File Type Filename MD5
EXE
8d645b59c9fc8a55cc0d5996db533a91
DLL
cacc09404edad3ca8ebf444efb83ecb9
EXE
4cd02970937666f629b61f1f4d9b20d1
EXE
79e667e7e9f947ca2c37f5a40a4be2dd
EXE
49d537fce81b78fe72956d3d777a97d8
EXE
d6c4d61cb19c1e0cd37556332251d19a
EXE
46ef4adb385ff4cc021c20c5840d5028
DLL
ee5c57b76b01e6a4b3294f7f272e5992
EXE
utils.exe
Malware
f872596129da13064fa52305e10f65dc
EXE
b8aa4bc4efc8131887c8aef0441e57a0