save on

save on

Known Adware

by WebPick Internet Holdings Ltd.

What is save on?

save on is software application developed by WebPick Internet Holdings Ltd.. It is most commonly found on computers running Windows XP with nearly 50.00% of installations running this operating system. save on's installer is typically 1.00 MB in size and installs around 90 files. The most common release is 1.3.0.1798 with 50.00% of all installations currently using this version.

save on is most popular in the United States with 71.43% of installations residing in this country.

About save on?

The Save On software, distributed under the alias publisher picitup, is an adware browser extension created by Saveon. It injects ads on web pages that are not affiliated with the ads or the extension, including new ads in whitespace on the page or on top of existing banner advertisements. Clicking on any displayed coupons will redirect the user to advertiser pages and drop affiliate cookies onto their computer. Save On also communicates with a remote server to track user habits, including visited URLs and domains, viewed pages, and clicked-on advertisements. Note that this software collects and shares user data. Please use this software responsibly and ensure you are compliant with all pertinent laws and regulations.

Multiple virus scanners have detected malware in save on.

NB.exe (MD5: eaeda7f410d1a034224482cdaef0443a) has been flagged by 36 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.667718
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir Adware/MultiPlug.AB.4
AVG Generic5.AYMI
Baidu-International Adware.Win32.MultiPlug.BAB
Bitdefender Application.Generic.667718
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AB
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.667718
G Data Application.Generic.667718
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic.bfr!hk
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.667718
Panda Antivirus Trj/CI.A
Sophos Generic PUA DC
TrendMicro-HouseCall TROJ_GEN.R0C1H06G614
VIPRE Antivirus Trojan.Win32.Generic!BT
Agnitum Outpost PUA.MultiPlug!
avast! Win32:Dropper-gen [Drp]
Avira SPR/Tool.689664.1
AVware Trojan.Win32.Generic!BT
ByteHero BDV Trojan.Exception.gen.101
Cyren W32/Application.SEEW-0376
NANO AntiVirus Riskware.Win32.MultiPlug.dfmntw
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.3
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MULTIPLUG
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
IKARUS anti.virus Trojan.Symmi
Norman Suspicious_Gen5.ARFZD
Antiy-AVL Trojan/Win32.TSGeneric
n2NLA8h2xn_.exe (MD5: dd659ac85fad1370a5969577de786e3e) has been flagged by 22 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
Antiy-AVL Trojan/Win32.TSGeneric
avast! Win32:Adware-gen [Adw]
AVG Generic5.AXXO
Baidu-International Adware.Win32.MultiPlug.BY
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fortinet FortiGate Riskware/MultiPlug
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic.bfr!hk
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall Suspicious_GEN.F47V0625
VIPRE Antivirus Trojan.Win32.Generic!BT
G Data Win32.Trojan.Agent.I1F0VQ
Lavasoft Ad-Aware Application.Generic.649344
Bitdefender Application.Generic.649344
F-Secure Application.Generic.649344
MicroWorld-eScan Application.Generic.649344
Symantec WS.Reputation.1
Sophos Generic PUA AO
LqFa.exe (MD5: e5f153c2c145745fcce03e555ca9b637) has been flagged by 11 scanners:
Scanner Software Result
AhnLab-V3 Dropper/Win32.Preloader
AVG Generic5.AVNK
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!E5F153C2C145
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall TROJ_GEN.F47V0528
VIPRE Antivirus Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.BY
Symantec WS.Reputation.1
Antiy-AVL Trojan/Win32.TSGeneric
jmi.exe (MD5: 692b15082eeaa2006c68b39d78f49dbf) has been flagged by 27 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.649799
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir SPR/Tool.643072.7
AVG Generic5.AVZR
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender Application.Generic.649799
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.649799
G Data Application.Generic.649799
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!692B15082EEA
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.649799
Sophos Generic PUA EI
TrendMicro-HouseCall Suspicious_GEN.F47V0611
VIPRE Antivirus Win32.Malware!Drop
avast! Win32:Dropper-gen [Drp]
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MULTIPLUG
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
IKARUS anti.virus Trojan.Symmi
Norman Suspicious_Gen5.ARFZD
Antiy-AVL Trojan/Win32.TSGeneric
Symantec WS.Reputation.1
iMSnVnDy.exe (MD5: d174e8a812b28df049a7f8bc1c4633b1) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.661949
AhnLab-V3 Dropper/Win32.Preloader
Avira AntiVir Adware/MultiPlug.Y.3
avast! Win32:Adware-gen [Adw]
AVG Generic5.AYAO
Baidu-International Adware.Win32.MultiPlug.BY
Bitdefender Application.Generic.661949
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.Y
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.661949
G Data Application.Generic.661949
Malwarebytes PUP.Optional.Multiplug
McAfee RDN/Generic PUP.x!chc
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.H
MicroWorld-eScan Application.Generic.661949
Panda Antivirus Trj/CI.A
Sophos Generic PUA BE
TrendMicro-HouseCall TROJ_GEN.R0CBH06FT14
VIPRE Antivirus Trojan.Win32.Generic!BT
Bkav FE W32.MultiPlugCB.Adware
Agnitum Outpost PUA.MultiPlug!
Avira SPR/Tool.689664.1
AVware Trojan.Win32.Generic!BT
ByteHero BDV Trojan.Exception.gen.101
Cyren W32/Application.SEEW-0376
NANO AntiVirus Riskware.Win32.MultiPlug.dfmntw
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.3
Qihoo-360 Win32/Trojan.Dropper.c9f
Trend Micro ADW_MULTIPLUG
K7 AntiVirus Adware ( 0049b4c51 )
K7GW Adware ( 0049b4c51 )
IKARUS anti.virus Trojan.Symmi
Norman Suspicious_Gen5.ARFZD
Antiy-AVL Trojan/Win32.TSGeneric

Software Details

URL:
https://saveonapp.info
Support:
https://picitup.com
Installation path:
C:\Documents and Settings\user\Local\save on
Uninstaller:
"C:\Documents and Settings\user\Local\save on\tjL.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

save on Executable Details

Primary executable:
4ZAoqRZ.exe
Name:
save on
Path:
C:\Documents and Settings\user\Local\save on\4ZAoqRZ.exe
MD5:
dafad4360169dae111d3f5b1fe777ba7
SHA-1:
–
SHA-256:
–
Files installed by save on
File Type Filename MD5
EXE
1cecc27f6ba8a7187da764b450d8b63c
EXE
47b14be12d4e81c2dd00fb1b0aa4ba8f
EXE
bfc8248e4a46941c28971f7ace499154
EXE
jmi.exe
Malware
692b15082eeaa2006c68b39d78f49dbf
EXE
b0ee8864d103a51fc19984285099e53a
EXE
bfc8248e4a46941c28971f7ace499154
EXE
d174e8a812b28df049a7f8bc1c4633b1
EXE
2870564910cfcf2006d7b432809d5546
EXE
f82dc144bfd813a8d5389171d9ce92f0
EXE
ebc28e5d26d6526a25e5d641716e01ed