Shop and Save Up

Shop and Save Up

Known Adware

by BrightCircle Investments Limited

What is Shop and Save Up?

Shop and Save Up is software application developed by BrightCircle Investments Limited. It is most commonly found on computers running Windows 7 with nearly 57.84% of installations running this operating system. Shop and Save Up's installer is typically 10.00 MB in size and installs around 145 files.

Shop and Save Up is most popular in the United States with 16.88% of installations residing in this country.

Shop and Save Up adds 3 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About Shop and Save Up?

Shop and Save Up is a browser plugin program designed to display advertisements. It delivers various types of ads such as banner ads, text-links, coupons, and other offers within the user's web browser, and may also generate pop-ups outside of the browser. These advertisements may come from hijacked search engines with low relevance, and may potentially expose the user to malware, adware, or other potentially unwanted programs (PUPs). Furthermore, the program may track the user's web browsing history and actions and transmit this information to a command and control server.

Multiple virus scanners have detected malware in Shop and Save Up.

utils.exe (MD5: f872596129da13064fa52305e10f65dc) has been flagged by 31 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Parj.1
Agnitum Outpost PUA.Toolbar.CrossRider
AhnLab-V3 PUP/Win32.CrossRider
Arcabit Application.Parj.1
avast! NSIS:Crossrider-ES [PUP]
AVG Crossrider
Avira ADWARE/CrossRider.Gen7
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.CrossAd.CF
Bitdefender Gen:Application.Parj.1
Cyren W32/Application.IFMS-5863
Dr.Web Trojan.DownLoader14.10941
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CM potentially unwanted
F-Secure Gen:Application.Parj.1
G Data Gen:Application.Parj
K7 AntiVirus Adware
K7GW Adware ( 004b98a11 )
Kaspersky not-a-virus:AdWare.Win32.CrossRider
Malwarebytes PUP.Optional.ShopAndSave.A
McAfee Artemis!F872596129DA
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
MicroWorld-eScan Gen:Application.Parj.1
NANO AntiVirus Riskware.Win32.CrossRider.dsxfkx
Panda Antivirus Trj/CI.A
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Rising Antivirus PE:Trojan.Win32.Generic.18C743FB!415712251
SUPERAntiSpyware PUP.CrossRider/Variant
Symantec Trojan.Gen
Trend Micro TROJ_GEN.R08NC0OFN15
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Trojan.BlackGen.Win32.11

Software Behaviors

Scheduled tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is scheduled as a task named 'cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-1-6.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-14'.
  • f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10.exe is scheduled as a task named 'temp_f6e9ae87-5ccd-4e52-958a-dccaadd641f8-10_user'.

Startup Entries

Startup tasks:
  • cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.exe is automatically launched at startup through a scheduled task named cfe97967-d91c-4f9e-b66d-b19293c46c3c-1-6.
  • 1f8fdff3-ba86-40f4-a012-a61ff631e986-1-7.exe is automatically launched at startup through a scheduled task named 1f8fdff3-ba86-40f4-a012-a61ff631e986-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-11.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-11.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-10.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-10_user.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-7.
  • 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.exe is automatically launched at startup through a scheduled task named 2f282854-552d-42c5-89c0-12f1fab6979e-1-6.

Software Details

URL:
Support:
Installation path:
C:\Program Files\shop and save up
Uninstaller:
C:\Program Files\Shop and Save Up\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

Shop and Save Up Executable Details

Primary executable:
utils.exe
Name:
Shop and Save Up
Path:
C:\Program Files\shop and save up\utils.exe
MD5:
f872596129da13064fa52305e10f65dc
SHA-1:
SHA-256:
Files installed by Shop and Save Up
File Type Filename MD5
EXE
a449102d418489c3d68f1003091277c4
EXE
59c6c110c10e403f0f3002913b138587
DLL
c2783de286c2b044291be17f2c5a8c26
EXE
9982bcaa4475c3533d127f912ed2b7bf
EXE
22550b8408a0e286c25241c2bf13895b
EXE
6fcd2a7266e43b739b5547d79c72590f
EXE
8e716b226828655f67a0538d5632377d
EXE
72ea522f8a098e1e73d4c223f44337fa
EXE
3d5f4f6551dde68912e33a54a84bf6db
XPI
71e38c03435ec0c83d0de5bf00c0d065