BitSaver

BitSaver

Known Toolbar

by InstalleRex-WebPick

What is BitSaver?

BitSaver is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 73.17% of installations running this operating system. BitSaver's installer is typically 1.00 MB in size and installs around 44 files.

BitSaver is most popular in the United States with 30% of installations residing in this country.

About BitSaver?

This web browser extension is a JustPlug.It adware program that is distributed through the WebPick (InstalleRex) download and install manager. It is bundled with various adware offers and functions as a cross-browser extension with multiple components, including a Windows service, an auto-starting component, and a browser toolbar/plugin. Its primary purpose is to inject advertisements in the form of banner ads, hyper-text links, pop-ups, and potentially hijack existing advertisements on websites. Additionally, it may inject affiliate codes in links as coupon offers. Upon installation, the program will create a folder with a random name in Program Files or ProgramData, and the included files will also have randomly generated names such as SaveNShare, Surf And Keep, Download Keeper, and numerous others.

Multiple virus scanners have detected malware in BitSaver.

CP.dll (MD5: 1305e75a5e77ece0845806814d753836) has been flagged by 30 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Agent
AVG Generic5.AYSX
AVware Trojan.Win32.Generic!BT
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.AY
Fortinet FortiGate Riskware/MultiPlug
Malwarebytes PUP.Optional.MultiPlug
McAfee RDN/Generic PUP.x!chv
McAfee-GW-Edition RDN/Generic PUP.x!chv
Sophos Generic PUA KF
TrendMicro-HouseCall TROJ_GEN.R0C9H06GB14
VIPRE Antivirus Trojan.Win32.Generic!BT
avast! Win64:Malware-gen
Baidu-International PUA.Win32.CRXDrop.77
IKARUS anti.virus PUA.Multiplug
G Data Win64.Adware.Megasearch.C
Symantec Adware.BL
Avira AntiVir ADWARE/Adware.Gen
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Rising Antivirus PE:Malware.Adware!6.1293
Lavasoft Ad-Aware Gen:Variant.Adware.61989
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
F-Secure Gen:Variant.Adware.61989
MicroWorld-eScan Gen:Variant.Adware.61989
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Antiy-AVL Trojan/Win32.TGeneric
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG
wg.exe (MD5: 19e5eb31641597fa245deb887aa25817) has been flagged by 32 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
avast! Win32:Adware-gen [Adw]
AVG Generic_r.GV
Baidu-International Adware.Win32.MegaSearch.Asdt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Malwarebytes PUP.Optional.MultiPlug.A
McAfee PUP-FFY!19E5EB316415
McAfee-GW-Edition PUP-FFY!19E5EB316415
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos Generic PUA EC
TrendMicro-HouseCall TROJ_GEN.R08NH06B314
VIPRE Antivirus MegaSearch Toolbar
AegisLab AdWare.Win64.MegaSearch
AVware Win64.Adware.MultiPlug
Comodo Security ApplicUnwnt
K7 AntiVirus Adware ( 004a86af1 )
K7GW Adware ( 004a86af1 )
Fortinet FortiGate Riskware/MultiPlug
G Data Win64.Adware.Megasearch.C
Symantec Adware.BL
Avira AntiVir ADWARE/Adware.Gen
Rising Antivirus PE:Malware.Adware!6.1293
Lavasoft Ad-Aware Gen:Variant.Adware.61989
Bitdefender Gen:Variant.Adware.61989
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
F-Secure Gen:Variant.Adware.61989
MicroWorld-eScan Gen:Variant.Adware.61989
Antiy-AVL Trojan/Win32.TGeneric
Trend Micro ADW_MULTIPLUG
yxgvOD.x64.dll (MD5: 2a05aaa383857ecbdd6100c34595b5df) has been flagged by 43 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11089445
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
Antiy-AVL Trojan/Win32.SGeneric
avast! Win64:Adware-gen [Adw]
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.A
Bitdefender Trojan.Generic.11089445
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11089445 (B)
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
F-Secure Trojan.Generic.11089445
G Data Trojan.Generic.11089445
IKARUS anti.virus AdWare.MultiPlug
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Mplug!2A05AAA38385
McAfee-GW-Edition Mplug!2A05AAA38385
MicroWorld-eScan Trojan.Generic.11089445
Norman Multiplug.A
nProtect Trojan.Generic.11089445
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.273
Rising Antivirus PE:Adware.MultiPlug!6.166A
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.R0CBH06DC14
VIPRE Antivirus MPlug
ViRobot Adware.Agent.474112
Agnitum Outpost PUA.BHO!
Bkav FE W32.ToolbarEscort.Adware
CAT-QuickHeal AdWare.BHO.r6 (Not a Virus)
Kaspersky not-a-virus:AdWare.Win32.BHO.bdnc
NANO AntiVirus Riskware.Win32.BHO.dbdfeq
Trend Micro ADW_MULTIPLUG
Vba32 AntiVirus AdWare.BHO
Fortinet FortiGate Riskware/MultiPlug
Tencent Win32.Risk.Adware.Lmkl
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
AVware Trojan.Win32.Generic!BT
AegisLab AdWare.Win64.MegaSearch
yxgvOD.dll (MD5: ea89a5cfcf37d160e1b20b40e5111e89) has been flagged by 40 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.607493
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Bitdefender Application.Generic.607493
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.607493
G Data Application.Generic.607493
IKARUS anti.virus AdWare.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
MicroWorld-eScan Application.Generic.607493
NANO AntiVirus Riskware.Win32.MultiPlug.cvyxyu
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
TrendMicro-HouseCall TROJ_GEN.R047H06CO14
VIPRE Antivirus JustPlugIt (fs)
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Adware-gen [Adw]
Bkav FE W32.Clod3fd.Trojan.2240
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.F0C2C00A414
Vba32 AntiVirus BScope.Trojan.Agent
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Norman Multiplug.A
AVware Trojan.Win32.Generic!BT
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
wg.x64.dll (MD5: bab49b61943c026b825a714d2175635a) has been flagged by 36 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.40
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
G Data Win64.Trojan.Multiplug.B
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee RDN/Generic PUP.x!brl
McAfee-GW-Edition RDN/Generic PUP.x!brl
Norman Multiplug.A
Qihoo-360 Win32/Trojan.Adware.273
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Trend Micro ADW_MULTIPLG
TrendMicro-HouseCall ADW_MULTIPLG
VIPRE Antivirus Win64.Adware.MultiPlug
avast! Win32:Adware-gen [Adw]
Fortinet FortiGate Adware/Megasearch
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Panda Antivirus Trj/Genetic.gen
Vba32 AntiVirus BScope.Trojan.Agent
Lavasoft Ad-Aware Application.Generic.649799
Bitdefender Application.Generic.649799
F-Secure Application.Generic.649799
MicroWorld-eScan Application.Generic.649799
AVware Trojan.Win32.Generic!BT
AegisLab AdWare.Win64.MegaSearch
Symantec Adware.BL
Rising Antivirus PE:Malware.Adware!6.1293
Emsisoft Anti-Malware Gen:Variant.Adware.61989 (B)
Antiy-AVL Trojan/Win32.TGeneric

Software Details

URL:
https://justplug.it
Support:
–
Installation path:
C:\ProgramData\bitsaver
Uninstaller:
"C:\ProgramData\BitSaver\yxgvOD.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

BitSaver Executable Details

Primary executable:
yxgvOD.exe
Name:
BitSaver
Path:
C:\ProgramData\bitsaver\yxgvOD.exe
MD5:
5779bbb0fe6c50419ddf9f84e73e4905
SHA-1:
–
SHA-256:
–
Files installed by BitSaver
File Type Filename MD5
EXE
S0rv.exe
Malware
a6786c28986b3261f026078a4c098436
EXE
23ad8c545557e4eb65bab348139383b5
DLL
600ff6994d8cddce04773e8c738d303d
DLL
mUNd.dll
Adware
6bdd2b931e45fa910c821a3beb07928c
DLL
S0rv.dll
Adware
374367ba293ed2c64cb7bfc4d1fe1417
EXE
SzBslB.exe
Malware
83c728a3d4b56127985b096478a943f8
EXE
e98029a85714a2c0514132ef7e5209e6
DLL
mB.x64.dll
Malware
f304e79ecc51db8c3bbc11388ff4548a
EXE
ZcW.exe
Malware
692b15082eeaa2006c68b39d78f49dbf
EXE
mB.exe
Adware
584cad63d062e99c0a4b07d334fbd440