BitSaver

BitSaver

Known Toolbar

by InstalleRex-WebPick

What is BitSaver?

BitSaver is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 73.17% of installations running this operating system. BitSaver's installer is typically 1.00 MB in size and installs around 44 files.

BitSaver is most popular in the United States with 30% of installations residing in this country.

About BitSaver?

This web browser extension is a JustPlug.It adware program that is distributed through the WebPick (InstalleRex) download and install manager. It is bundled with various adware offers and functions as a cross-browser extension with multiple components, including a Windows service, an auto-starting component, and a browser toolbar/plugin. Its primary purpose is to inject advertisements in the form of banner ads, hyper-text links, pop-ups, and potentially hijack existing advertisements on websites. Additionally, it may inject affiliate codes in links as coupon offers. Upon installation, the program will create a folder with a random name in Program Files or ProgramData, and the included files will also have randomly generated names such as SaveNShare, Surf And Keep, Download Keeper, and numerous others.

Multiple virus scanners have detected malware in BitSaver.

CP.dll (MD5: 1305e75a5e77ece0845806814d753836) has been flagged by 30 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Agent
AVG Generic5.AYSX
AVware Trojan.Win32.Generic!BT
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AY
Fortinet FortiGate Riskware/MultiPlug
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!chv
McAfee-GW-Edition RDN/Generic PUP.x!chv
Sophos Generic PUA KF
TrendMicro-HouseCall TROJ_GEN.R0C9H06GB14
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win64:Malware-gen
Baidu-International PUA.Win32.CRXDrop.77
IKARUS anti.virus PUA.Multiplug
G Data Win64.Adware.Megasearch.C
Symantec Adware.BL
Avira AntiVir ADWARE/Adware.Gen
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Rising Antivirus PE:Malware.Adware!6.1293
Lavasoft Ad-Aware Gen:Variant.Adware.61989
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
F-Secure Gen:Variant.Adware.61989
MicroWorld-eScan Gen:Variant.Adware.61989
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Antiy-AVL Trojan/Win32.TGeneric
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG
wg.exe (MD5: 19e5eb31641597fa245deb887aa25817) has been flagged by 32 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Adware-gen [Adw]
AVG Generic_r.GV
Baidu-International Adware.Win32.MegaSearch.Asdt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Malwarebytes PUP.Optional.MultiPlug.A
McAfee PUP-FFY!19E5EB316415
McAfee-GW-Edition PUP-FFY!19E5EB316415
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos Generic PUA EC
TrendMicro-HouseCall TROJ_GEN.R08NH06B314
VIPRE Antivirus MegaSearch Toolbar
AegisLab AdWare.Win64.MegaSearch
AVware Win64.Adware.MultiPlug
Comodo Security ApplicUnwnt
K7 AntiVirus Adware ( 004a86af1 )
K7GW Adware ( 004a86af1 )
Fortinet FortiGate Riskware/MultiPlug
G Data Win64.Adware.Megasearch.C
Symantec Adware.BL
Avira AntiVir ADWARE/Adware.Gen
Rising Antivirus PE:Malware.Adware!6.1293
Lavasoft Ad-Aware Gen:Variant.Adware.61989
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
F-Secure Gen:Variant.Adware.61989
MicroWorld-eScan Gen:Variant.Adware.61989
Antiy-AVL Trojan/Win32.TGeneric
Trend Micro ADW_MULTIPLUG
yxgvOD.x64.dll (MD5: 2a05aaa383857ecbdd6100c34595b5df) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11089445
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
Antiy-AVL Trojan/Win32.SGeneric
avast! Win64:Adware-gen [Adw]
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.A
Bitdefender Trojan.Generic.11089445
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11089445 (B)
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
F-Secure Trojan.Generic.11089445
G Data Trojan.Generic.11089445
IKARUS anti.virus AdWare.MultiPlug
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Mplug!2A05AAA38385
McAfee-GW-Edition Mplug!2A05AAA38385
MicroWorld-eScan Trojan.Generic.11089445
Norman Multiplug.A
nProtect Trojan.Generic.11089445
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.273
Rising Antivirus PE:Adware.MultiPlug!6.166A
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.R0CBH06DC14
VIPRE Antivirus MPlug
ViRobot Adware.Agent.474112
Agnitum Outpost PUA.BHO!
Bkav FE W32.ToolbarEscort.Adware
CAT-QuickHeal AdWare.BHO.r6 (Not a Virus)
Kaspersky not-a-virus:AdWare.Win32.BHO.bdnc
NANO AntiVirus Riskware.Win32.BHO.dbdfeq
Trend Micro ADW_MULTIPLUG
Vba32 AntiVirus AdWare.BHO
Fortinet FortiGate Riskware/MultiPlug
Tencent Win32.Risk.Adware.Lmkl
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
AVware Trojan.Win32.Generic!BT
AegisLab AdWare.Win64.MegaSearch
yxgvOD.dll (MD5: ea89a5cfcf37d160e1b20b40e5111e89) has been flagged by 40 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.607493
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Bitdefender Application.Generic.607493
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.607493
G Data Application.Generic.607493
IKARUS anti.virus AdWare.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
MicroWorld-eScan Application.Generic.607493
NANO AntiVirus Riskware.Win32.MultiPlug.cvyxyu
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
TrendMicro-HouseCall TROJ_GEN.R047H06CO14
VIPRE Antivirus JustPlugIt (fs)
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Adware-gen [Adw]
Bkav FE W32.Clod3fd.Trojan.2240
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.F0C2C00A414
Vba32 AntiVirus BScope.Trojan.Agent
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Norman Multiplug.A
AVware Trojan.Win32.Generic!BT
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
wg.x64.dll (MD5: bab49b61943c026b825a714d2175635a) has been flagged by 36 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.40
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
G Data Win64.Trojan.Multiplug.B
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee RDN/Generic PUP.x!brl
McAfee-GW-Edition RDN/Generic PUP.x!brl
Norman Multiplug.A
Qihoo-360 Win32/Trojan.Adware.273
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Trend Micro ADW_MULTIPLG
TrendMicro-HouseCall ADW_MULTIPLG
VIPRE Antivirus Win64.Adware.MultiPlug
avast! Win32:Adware-gen [Adw]
Fortinet FortiGate Adware/Megasearch
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Panda Antivirus Trj/Genetic.gen
Vba32 AntiVirus BScope.Trojan.Agent
Lavasoft Ad-Aware Application.Generic.649799
Bitdefender Application.Generic.649799
F-Secure Application.Generic.649799
MicroWorld-eScan Application.Generic.649799
AVware Trojan.Win32.Generic!BT
AegisLab AdWare.Win64.MegaSearch
Symantec Adware.BL
Rising Antivirus PE:Malware.Adware!6.1293
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
Antiy-AVL Trojan/Win32.TGeneric

Software Details

URL:
https://justplug.it
Support:
–
Installation path:
C:\ProgramData\bitsaver
Uninstaller:
"C:\ProgramData\BitSaver\yxgvOD.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

BitSaver Executable Details

Primary executable:
yxgvOD.exe
Name:
BitSaver
Path:
C:\ProgramData\bitsaver\yxgvOD.exe
MD5:
5779bbb0fe6c50419ddf9f84e73e4905
SHA-1:
–
SHA-256:
–
Files installed by BitSaver
File Type Filename MD5
DLL
CP.dll
Malware
1305e75a5e77ece0845806814d753836
DLL
5e418b12120edc3609d744bb467cb45e
EXE
wg.exe
Malware
19e5eb31641597fa245deb887aa25817
DLL
bd9fb537d3d37af56a526b60e5ab0166
EXE
80d691f736b42440928faba7ec88cf78
EXE
a3a7122be69f78be5482b8d8108c99ea
DLL
337519d300e79fcf5b8deb21fe1d031f
DLL
9b44cf590f064eaf267c2fe11a2f6d7a
DLL
7a2f8c98b4a1d1d2b38fa90a10cc66c2
DLL
2a05aaa383857ecbdd6100c34595b5df