BuyNsave

BuyNsave

Known Toolbar

by InstalleRex-WebPick

What is BuyNsave?

BuyNsave is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 63.11% of installations running this operating system. BuyNsave's installer is typically 1.00 MB in size and installs around 61 files.

BuyNsave is most popular in the United States with 19.54% of installations residing in this country.

About BuyNsave?

This browser extension, delivered through the WebPick (InstalleRex) download and install manager, is a cross-browser extension developed by JustPlug.It. It includes a Windows service, an auto-starting component, and a browser toolbar/plugin designed to inject various forms of advertisements, such as banner ads, hyper-text links, and pop-ups. Some versions may also hijack existing advertising on websites and inject affiliate codes as coupon offers. The program installs itself in a folder with a randomly generated name in the Program Files or ProgramData directory, with each included file also having a shared random name. The advertisements displayed in the browser may include deceptive malvertising ads for 'required' updates of common programs and unwanted pop-up advertisements. Additionally, if downloaded, the program installs bundled adware utilities and additional browser extensions, and modifies the browser's default security levels.

Multiple virus scanners have detected malware in BuyNsave.

vWXJtcKwwhTZH3.dll (MD5: 21c9e4674785f07246d7c1d2a8636bf9) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BGY
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.49553
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.akpb
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee Multiplug-FRF
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.djsook
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA GH
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R0C1C0EA415
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA415
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.133589
Rising Antivirus PE:Trojan.Win32.Generic.17BE2E95!398339733
ViRobot Adware.Agent.767488.A[h]
Bkav FE W32.PmobeC.Trojan
Kaspersky HEUR:Trojan.Win32.Generic
IKARUS anti.virus Win32.SuspectCrc
Vba32 AntiVirus AdWare.Win64.MultiPlug
Clam AntiVirus Win.Adware.Agent-38486
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
dSglJ4trCitQiJ.dll (MD5: de3e803333347054a117544e42d8344f) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BJM
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.bEG
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.djzuso
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA JH
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Adware.Popuppers
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R02KC0EA415
TrendMicro-HouseCall TROJ_GEN.R02KC0EA415
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Backdoor.PePatch.Win32.55859
Dr.Web Trojan.Crossrider.48329
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.nbxh
Vba32 AntiVirus AdWare.MultiPlug
IKARUS anti.virus PUA.Generic
Jiangmin Adware/Agent.ajop
Rising Antivirus PE:Trojan.Win32.Generic.17DF78B9!400521401
Clam AntiVirus Win.Adware.Multiplug-33429
c6K16WCycvd7vk.dll (MD5: df7d0a67e09b23194245e0ec259b477f) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.DCB
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal Browser.RestrictsControl.SL4
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.47611
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.akzc
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.oaqj
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.dkmioj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA JF
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.12
Trend Micro TROJ_GEN.R0C1C0EA915
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA915
Vba32 AntiVirus AdWare.MultiPlug
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.97508
Avira ADWARE/MultiPlug.Gen
ViRobot Adware.Graftor.754176[h]
IKARUS anti.virus Win32.SuspectCrc
Rising Antivirus PE:Trojan.Win32.Generic.17BE300D!398340109
Bkav FE W32.PmobeC.Trojan
Clam AntiVirus Win.Adware.Agent-38486
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
vusP0mwRImz81b.dll (MD5: 4d05aab49d1ad9626e309ea81112d6ea) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BKI
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.Gen
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal BrowserModifier.CouponRuc.r6 (Not a Virus)
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-71786d78!Eldorado
Dr.Web Trojan.Crossrider.48485
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-71786d78!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.agay
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee Multiplug-FRF
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.MultiPlug.djtcsa
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM30.1.Malware.Gen
Sophos Generic PUA GO
SUPERAntiSpyware Adware.MultiPlug/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R02KC0EA415
TrendMicro-HouseCall TROJ_GEN.R02KC0EA415
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.225346
Rising Antivirus PE:Trojan.Win32.Generic.17B6D06A!397856874
Tencent Trojan.Win32.Qudamah.Gen.12
ViRobot Adware.Graftor.769024[h]
Bkav FE W32.DropperAgentK.Trojan
IKARUS anti.virus Trojan.SuspectCRC
Kaspersky Trojan.Win32.Cosmu.csae
Norman Agent.BLMHC
nProtect Adware.Agent.PKA
Vba32 AntiVirus TrojanDropper.Agent
Clam AntiVirus Win.Adware.Multiplug-33429
Rnipxo6wRyXk5I.dll (MD5: b999bb8773d171b35115d736624bd32a) has been flagged by 49 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.169592
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 PUP/Win32.Generic
ALYac Gen:Variant.Adware.Graftor.169592
Antiy-AVL GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent
avast! Win32:MultiPlug-LV [PUP]
AVG Generic6.BBT
Avira ADWARE/MultiPlug.Gen
AVware Trojan.Win32.Generic!BT
Baidu-International Adware.Win32.MultiPlug.EG
Bitdefender Gen:Variant.Adware.Graftor.169592
CAT-QuickHeal BrowserModifier.CouponRuc.r6 (Not a Virus)
Comodo Security Application.Win32.AdWare.MultiPlug.VB
Cyren W32/S-350365ee!Eldorado
Dr.Web Trojan.Crossrider.47681
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.169592 (B)
ESET-NOD32 a variant of Win32/Adware.MultiPlug.EG
Fortinet FortiGate Riskware/MultiPlug
F-Prot W32/S-350365ee!Eldorado
F-Secure Gen:Variant.Adware.Graftor
G Data Gen:Variant.Adware.Graftor.169592
Jiangmin Adware/Agent.akts
K7 AntiVirus Adware ( 004a07251 )
K7GW Adware ( 004a07251 )
Malwarebytes PUP.Optional.MultiPlug
McAfee MultiPlug
McAfee-GW-Edition BehavesLike.Win32.Downloader.bm
Microsoft Security Essentials BrowserModifier:Win32/CouponRuc
MicroWorld-eScan Gen:Variant.Adware.Graftor.169592
NANO AntiVirus Riskware.Win32.Agent.djssoa
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.Adware.5c6
Sophos Generic PUA NI
SUPERAntiSpyware Adware.Graftor/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R01TC0EA215
TrendMicro-HouseCall TROJ_GEN.R01TC0EA215
VIPRE Antivirus Trojan.Win32.Generic!BT
Zillya Adware.MultiPlug.Win32.127917
IKARUS anti.virus Win32.SuspectCrc
Vba32 AntiVirus AdWare.Win64.MultiPlug
Tencent Trojan.Win32.Qudamah.Gen.12
Clam AntiVirus Win.Adware.Agent-38486
Rising Antivirus PE:Trojan.Win32.Generic.17B6D06A!397856874
ViRobot Adware.Graftor.769024[h]
Bkav FE W32.DropperAgentK.Trojan
Kaspersky Trojan.Win32.Cosmu.csae
Norman Agent.BLMHC
nProtect Adware.Agent.PKA

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\buynsave
Uninstaller:
"C:\Program Files\BuyNsave\HvWFhDYjQIo8bp.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

BuyNsave Executable Details

Primary executable:
HvWFhDYjQIo8bp.exe
Name:
BuyNsave
Path:
C:\Program Files\buynsave\HvWFhDYjQIo8bp.exe
MD5:
974ad54281862631c28e0c587bc49ce0
SHA-1:
–
SHA-256:
–
Files installed by BuyNsave
File Type Filename MD5
DLL
de4e962a88347979e7fc5777d71a90f3
DLL
34368e05cf8e5224521bec728cfc66f6
DLL
c0449e17280694a22cbd4c23631cd3e6
DLL
ff37fff194f43cb6cb80d8918cc650b1
DLL
15c2ee3e61aaf0129c425b89b2fa5ee6
DLL
6bacbafd4efeb54adac2f3235539a3cf
DLL
295e5dd3d12d16601aa4d5d3ed1373c4
DLL
1cd4345e074bf4390ff99bfae815acae
DLL
00e2ad752b281e372d6340417824e9ed
DLL
6c128d64d53086931fb08a4c24cf3f7d