save on

save on

Known Adware

by WebPick Internet Holdings Ltd.

What is save on?

save on is software application developed by WebPick Internet Holdings Ltd.. It is most commonly found on computers running Windows XP with nearly 50.00% of installations running this operating system. save on's installer is typically 1.00 MB in size and installs around 90 files. The most common release is 1.3.0.1798 with 50.00% of all installations currently using this version.

save on is most popular in the United States with 71.43% of installations residing in this country.

About save on?

The Save On software, distributed under the alias publisher picitup, is an adware browser extension created by Saveon. It injects ads on web pages that are not affiliated with the ads or the extension, including new ads in whitespace on the page or on top of existing banner advertisements. Clicking on any displayed coupons will redirect the user to advertiser pages and drop affiliate cookies onto their computer. Save On also communicates with a remote server to track user habits, including visited URLs and domains, viewed pages, and clicked-on advertisements. Note that this software collects and shares user data. Please use this software responsibly and ensure you are compliant with all pertinent laws and regulations.

Multiple virus scanners have detected malware in save on.

NB.exe (MD5: eaeda7f410d1a034224482cdaef0443a) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.667718
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir Adware/MultiPlug.AB.4
AVG Generic5.AYMI
Baidu-International Adware.Win32.MultiPlug.BAB
Bitdefender Application.Generic.667718
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AB
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.667718
G Data Application.Generic.667718
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic.bfr!hk
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.667718
Panda Antivirus Trj/CI.A
Sophos Generic PUA DC
TrendMicro-HouseCall TROJ_GEN.R0C1H06G614
VIPRE Antivirus Trojan.Win32.Generic!BT
Agnitum Outpost PUA.MultiPlug!
avast! Win32:Dropper-gen [Drp]
Avira SPR/Tool.689664.1
AVware Trojan.Win32.Generic!BT
ByteHero BDV Trojan.Exception.gen.101
Cyren W32/Application.SEEW-0376
NANO AntiVirus Riskware.Win32.MultiPlug.dfmntw
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.3
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MULTIPLUG
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
IKARUS anti.virus Trojan.Symmi
Norman Suspicious_Gen5.ARFZD
Antiy-AVL Trojan/Win32.TSGeneric
n2NLA8h2xn_.exe (MD5: dd659ac85fad1370a5969577de786e3e) has been flagged by 22 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.AXXO
Baidu-International Adware.Win32.MultiPlug.BY
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fortinet FortiGate Riskware/MultiPlug
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic.bfr!hk
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall Suspicious_GEN.F47V0625
VIPRE Antivirus Trojan.Win32.Generic!BT
G Data Win32.Trojan.Agent.I1F0VQ
Lavasoft Ad-Aware Application.Generic.649344
Bitdefender Application.Generic.649344
F-Secure Application.Generic.649344
MicroWorld-eScan Application.Generic.649344
Symantec WS.Reputation.1
Sophos Generic PUA AO
LqFa.exe (MD5: e5f153c2c145745fcce03e555ca9b637) has been flagged by 11 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
AVG Generic5.AVNK
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E5F153C2C145
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall TROJ_GEN.F47V0528
VIPRE Antivirus Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.BY
Symantec WS.Reputation.1
Antiy-AVL Trojan/Win32.TSGeneric
jmi.exe (MD5: 692b15082eeaa2006c68b39d78f49dbf) has been flagged by 27 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.649799
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir SPR/Tool.643072.7
AVG Generic5.AVZR
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender Application.Generic.649799
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.649799
G Data Application.Generic.649799
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!692B15082EEA
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.649799
Sophos Generic PUA EI
TrendMicro-HouseCall Suspicious_GEN.F47V0611
VIPRE Antivirus Win32.Malware!Drop
avast! Win32:Dropper-gen [Drp]
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MULTIPLUG
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
IKARUS anti.virus Trojan.Symmi
Norman Suspicious_Gen5.ARFZD
Antiy-AVL Trojan/Win32.TSGeneric
Symantec WS.Reputation.1
iMSnVnDy.exe (MD5: d174e8a812b28df049a7f8bc1c4633b1) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.661949
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir Adware/MultiPlug.Y.3
avast! Win32:Adware-gen [Adw]
AVG Generic5.AYAO
Baidu-International Adware.Win32.MultiPlug.BY
Bitdefender Application.Generic.661949
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.661949
G Data Application.Generic.661949
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic PUP.x!chc
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.661949
Panda Antivirus Trj/CI.A
Sophos Generic PUA BE
TrendMicro-HouseCall TROJ_GEN.R0CBH06FT14
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE W32.MultiPlugCB.Adware
Agnitum Outpost PUA.MultiPlug!
Avira SPR/Tool.689664.1
AVware Trojan.Win32.Generic!BT
ByteHero BDV Trojan.Exception.gen.101
Cyren W32/Application.SEEW-0376
NANO AntiVirus Riskware.Win32.MultiPlug.dfmntw
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.3
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MULTIPLUG
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
IKARUS anti.virus Trojan.Symmi
Norman Suspicious_Gen5.ARFZD
Antiy-AVL Trojan/Win32.TSGeneric

Software Details

URL:
https://saveonapp.info
Support:
https://picitup.com
Installation path:
C:\Documents and Settings\user\Local\save on
Uninstaller:
"C:\Documents and Settings\user\Local\save on\tjL.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

save on Executable Details

Primary executable:
4ZAoqRZ.exe
Name:
save on
Path:
C:\Documents and Settings\user\Local\save on\4ZAoqRZ.exe
MD5:
dafad4360169dae111d3f5b1fe777ba7
SHA-1:
SHA-256:
Files installed by save on
File Type Filename MD5
EXE
e700a7c75654a3b567bb34106c4e9d52
EXE
7e649cdc6f07ae94559e821a024b4190
EXE
47b14be12d4e81c2dd00fb1b0aa4ba8f
EXE
NB.exe
Malware
eaeda7f410d1a034224482cdaef0443a
EXE
dd659ac85fad1370a5969577de786e3e
EXE
074fdbec16dcf4bc211b27f64c3512ae
EXE
dafad4360169dae111d3f5b1fe777ba7
EXE
LqFa.exe
Malware
e5f153c2c145745fcce03e555ca9b637
EXE
a3a7122be69f78be5482b8d8108c99ea
EXE
074fdbec16dcf4bc211b27f64c3512ae