BuyNsave

BuyNsave

Known Toolbar

by InstalleRex-WebPick

What is BuyNsave?

BuyNsave is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 63.11% of installations running this operating system. BuyNsave's installer is typically 1.00 MB in size and installs around 61 files.

BuyNsave is most popular in the United States with 19.54% of installations residing in this country.

About BuyNsave?

This browser extension, delivered through the WebPick (InstalleRex) download and install manager, is a cross-browser extension developed by JustPlug.It. It includes a Windows service, an auto-starting component, and a browser toolbar/plugin designed to inject various forms of advertisements, such as banner ads, hyper-text links, and pop-ups. Some versions may also hijack existing advertising on websites and inject affiliate codes as coupon offers. The program installs itself in a folder with a randomly generated name in the Program Files or ProgramData directory, with each included file also having a shared random name. The advertisements displayed in the browser may include deceptive malvertising ads for 'required' updates of common programs and unwanted pop-up advertisements. Additionally, if downloaded, the program installs bundled adware utilities and additional browser extensions, and modifies the browser's default security levels.

Multiple virus scanners have detected malware in BuyNsave.

vWXJtcKwwhTZH3.dll (MD5: 21c9e4674785f07246d7c1d2a8636bf9) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BGY
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.49553
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.akpb
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee Multiplug-FRF
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.djsook
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA GH
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R0C1C0EA415
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA415
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.133589
Rising Antivirus PE:Trojan.Win32.Generic.17BE2E95!398339733
ViRobot Adware.Agent.767488.A[h]
Bkav FE W32.PmobeC.Trojan
Kaspersky HEUR:Trojan.Win32.Generic
IKARUS anti.virus Win32.SuspectCrc
Vba32 AntiVirus AdWare.Win64.MultiPlug
Clam AntiVirus Win.Adware.Agent-38486
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
dSglJ4trCitQiJ.dll (MD5: de3e803333347054a117544e42d8344f) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BJM
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.bEG
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.djzuso
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA JH
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Adware.Popuppers
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R02KC0EA415
TrendMicro-HouseCall TROJ_GEN.R02KC0EA415
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Backdoor.PePatch.Win32.55859
Dr.Web Trojan.Crossrider.48329
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.nbxh
Vba32 AntiVirus AdWare.MultiPlug
IKARUS anti.virus PUA.Generic
Jiangmin Adware/Agent.ajop
Rising Antivirus PE:Trojan.Win32.Generic.17DF78B9!400521401
Clam AntiVirus Win.Adware.Multiplug-33429
c6K16WCycvd7vk.dll (MD5: df7d0a67e09b23194245e0ec259b477f) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.DCB
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.47611
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.akzc
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.oaqj
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.dkmioj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA JF
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R0C1C0EA915
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA915
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.97508
Avira ADWARE/MultiPlug.Gen
ViRobot Adware.Graftor.754176[h]
IKARUS anti.virus Win32.SuspectCrc
Rising Antivirus PE:Trojan.Win32.Generic.17BE300D!398340109
Bkav FE W32.PmobeC.Trojan
Clam AntiVirus Win.Adware.Agent-38486
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
vusP0mwRImz81b.dll (MD5: 4d05aab49d1ad9626e309ea81112d6ea) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BKI
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal BrowserModifier.CouponRuc.r6 (Not a Virus)
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.48485
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.agay
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee Multiplug-FRF
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.djtcsa
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA GO
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R02KC0EA415
TrendMicro-HouseCall TROJ_GEN.R02KC0EA415
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.225346
Rising Antivirus PE:Trojan.Win32.Generic.17B6D06A!397856874
Tencent Trojan.Win32.Qudamah.Gen.12
ViRobot Adware.Graftor.769024[h]
Bkav FE W32.DropperAgentK.Trojan
IKARUS anti.virus Trojan.SuspectCRC
Kaspersky Trojan.Win32.Cosmu.csae
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
Vba32 AntiVirus TrojanDropper.Agent
Clam AntiVirus Win.Adware.Multiplug-33429
Rnipxo6wRyXk5I.dll (MD5: b999bb8773d171b35115d736624bd32a) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BBT
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.EG
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal BrowserModifier.CouponRuc.r6 (Not a Virus)
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-350365ee!Eldorado
Dr.Web Trojan.Crossrider.47681
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-350365ee!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.akts
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.Agent.djssoa
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.5c6
Sophos Generic PUA NI
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R01TC0EA215
TrendMicro-HouseCall TROJ_GEN.R01TC0EA215
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.127917
IKARUS anti.virus Win32.SuspectCrc
Vba32 AntiVirus AdWare.Win64.MultiPlug
Tencent Trojan.Win32.Qudamah.Gen.12
Clam AntiVirus Win.Adware.Agent-38486
Rising Antivirus PE:Trojan.Win32.Generic.17B6D06A!397856874
ViRobot Adware.Graftor.769024[h]
Bkav FE W32.DropperAgentK.Trojan
Kaspersky Trojan.Win32.Cosmu.csae
Norman Agent.BLMHC
nProtect Adware.Agent.PKA

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\buynsave
Uninstaller:
"C:\Program Files\BuyNsave\HvWFhDYjQIo8bp.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

BuyNsave Executable Details

Primary executable:
HvWFhDYjQIo8bp.exe
Name:
BuyNsave
Path:
C:\Program Files\buynsave\HvWFhDYjQIo8bp.exe
MD5:
974ad54281862631c28e0c587bc49ce0
SHA-1:
–
SHA-256:
–
Files installed by BuyNsave
File Type Filename MD5
DLL
1556919ab5fa8e87a6501b11efe786fe
DLL
ab11ba1c7c01a2200b0361854a60159c
DLL
21c9e4674785f07246d7c1d2a8636bf9
DLL
8793d067cc40097f30ae3496a1666eb7
DLL
de3e803333347054a117544e42d8344f
DLL
d47ca1c20a10d913fa773f66c14e9edf
DLL
df7d0a67e09b23194245e0ec259b477f
DLL
ce718f87e9d438e99e0f3a976ecae549
DLL
4d05aab49d1ad9626e309ea81112d6ea
DLL
b66b2e804fa268572b55be0a4ee9ad7c