BuyNsave
What is BuyNsave?
BuyNsave is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 63.11% of installations running this operating system. BuyNsave's installer is typically 1.00 MB in size and installs around 61 files.
BuyNsave is most popular in the United States with 19.54% of installations residing in this country.
About BuyNsave?
This browser extension, delivered through the WebPick (InstalleRex) download and install manager, is a cross-browser extension developed by JustPlug.It. It includes a Windows service, an auto-starting component, and a browser toolbar/plugin designed to inject various forms of advertisements, such as banner ads, hyper-text links, and pop-ups. Some versions may also hijack existing advertising on websites and inject affiliate codes as coupon offers. The program installs itself in a folder with a randomly generated name in the Program Files or ProgramData directory, with each included file also having a shared random name. The advertisements displayed in the browser may include deceptive malvertising ads for 'required' updates of common programs and unwanted pop-up advertisements. Additionally, if downloaded, the program installs bundled adware utilities and additional browser extensions, and modifies the browser's default security levels.
Multiple virus scanners have detected malware in BuyNsave.
| Scanner Software | Version | Result |
|---|---|---|
| Lavasoft Ad-Aware | 12.0.163.0 | Gen:Variant.Adware.Graftor.169592 |
| Agnitum Outpost | 5.5.1.3 | PUA.MultiPlug! |
| AhnLab-V3 | 2015.04.02.00 | PUP/Win32.Generic |
| ALYac | 1.0.1.4 | Gen:Variant.Adware.Graftor.169592 |
| Antiy-AVL | 1.0.0.1 | GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent |
| avast! | 8.0.1489.320 | Win32:MultiPlug-LV [PUP] |
| AVG | 15.0.0.4321 | Generic6.BGY |
| Avira | 3.6.1.96 | ADWARE/MultiPlug.Gen |
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.MultiPlug.Gen |
| Bitdefender | 7.2 | Gen:Variant.Adware.Graftor.169592 |
| CAT-QuickHeal | 14.00 | Browser.RestrictsControl.SL4 |
| Comodo Security | 21613 | Application.Win32.AdWare.MultiPlug.VB |
| Cyren | 5.4.16.7 | W32/S-71786d78!Eldorado |
| Dr.Web | 7.0.12.3050 | Trojan.Crossrider.49553 |
| Emsisoft Anti-Malware | 3.0.0.600 | Gen:Variant.Adware.Graftor.169592 (B) |
| ESET-NOD32 | 11411 | a variant of Win32/Adware.MultiPlug.EG |
| Fortinet FortiGate | 5.0.999.0 | Riskware/MultiPlug |
| F-Prot | 4.7.1.166 | W32/S-71786d78!Eldorado |
| F-Secure | 11.0.19100.45 | Gen:Variant.Adware.Graftor |
| G Data | 25 | Gen:Variant.Adware.Graftor.169592 |
| Jiangmin | 16.0.100 | Adware/Agent.akpb |
| K7 AntiVirus | 9.202.15452 | Adware ( 004a07251 ) |
| K7GW | 9.202.15453 | Adware ( 004a07251 ) |
| Malwarebytes | 1.75.0.1 | PUP.Optional.MultiPlug |
| McAfee | 6.0.5.614 | Multiplug-FRF |
| McAfee-GW-Edition | v2015 | BehavesLike.Win32.Downloader.bm |
| Microsoft Security Essentials | 1.1.11502.0 | BrowserModifier:Win32/CouponRuc |
| MicroWorld-eScan | 12.0.250.0 | Gen:Variant.Adware.Graftor.169592 |
| NANO AntiVirus | 0.30.8.659 | Riskware.Win32.MultiPlug.djsook |
| Panda Antivirus | 4.6.4.2 | Trj/Genetic.gen |
| Qihoo-360 | 1.0.0.1015 | HEUR/QVM30.1.Malware.Gen |
| Sophos | 4.98.0 | Generic PUA GH |
| SUPERAntiSpyware | 5.6.0.1032 | Adware.MultiPlug/Variant |
| Symantec | 20141.2.0.56 | Trojan.Gen.2 |
| Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.12 |
| Trend Micro | 9.740.0.1012 | TROJ_GEN.R0C1C0EA415 |
| TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R0C1C0EA415 |
| VIPRE Antivirus | 38964 | Trojan.Win32.Generic!BT |
| Zillya | 2.0.0.2123 | Adware.MultiPlug.Win32.133589 |
| Rising Antivirus | 25.0.0.17 | PE:Trojan.Win32.Generic.17BE2E95!398339733 |
| ViRobot | 2014.3.20.0 | Adware.Agent.767488.A[h] |
| Bkav FE | 1.3.0.6379 | W32.PmobeC.Trojan |
| Kaspersky | 15.0.1.10 | HEUR:Trojan.Win32.Generic |
| IKARUS anti.virus | T3.1.8.6.0 | Win32.SuspectCrc |
| Vba32 AntiVirus | 3.12.26.3 | AdWare.Win64.MultiPlug |
| Clam AntiVirus | 0.98.5.0 | Win.Adware.Agent-38486 |
| Norman | 7.04.04 | Agent.BLMHC |
| nProtect | 2015-04-10.01 | Adware.Agent.PKA |
| Scanner Software | Version | Result |
|---|---|---|
| Lavasoft Ad-Aware | 12.0.163.0 | Gen:Variant.Adware.Graftor.169592 |
| Agnitum Outpost | 5.5.1.3 | PUA.MultiPlug! |
| AhnLab-V3 | 2015.03.30.00 | PUP/Win32.Generic |
| ALYac | 1.0.1.4 | Gen:Variant.Adware.Graftor.169592 |
| Antiy-AVL | 1.0.0.1 | GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent |
| avast! | 8.0.1489.320 | Win32:MultiPlug-LV [PUP] |
| AVG | 15.0.0.4315 | Generic6.BJM |
| Avira | 3.6.1.96 | ADWARE/MultiPlug.Gen |
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.MultiPlug.bEG |
| Bitdefender | 7.2 | Gen:Variant.Adware.Graftor.169592 |
| CAT-QuickHeal | 14.00 | Browser.RestrictsControl.SL4 |
| Comodo Security | 21587 | Application.Win32.AdWare.MultiPlug.VB |
| Cyren | 5.4.16.7 | W32/S-71786d78!Eldorado |
| Emsisoft Anti-Malware | 3.0.0.600 | Gen:Variant.Adware.Graftor.169592 (B) |
| ESET-NOD32 | 11396 | a variant of Win32/Adware.MultiPlug.EG |
| Fortinet FortiGate | 5.0.999.0 | Riskware/MultiPlug |
| F-Prot | 4.7.1.166 | W32/S-71786d78!Eldorado |
| F-Secure | 11.0.19100.45 | Gen:Variant.Adware.Graftor |
| G Data | 25 | Gen:Variant.Adware.Graftor.169592 |
| K7 AntiVirus | 9.202.15418 | Adware ( 004a07251 ) |
| K7GW | 9.202.15419 | Adware ( 004a07251 ) |
| Malwarebytes | 1.75.0.1 | PUP.Optional.MultiPlug |
| McAfee | 6.0.5.614 | MultiPlug |
| McAfee-GW-Edition | v2015 | BehavesLike.Win32.Downloader.bm |
| Microsoft Security Essentials | 1.1.11502.0 | BrowserModifier:Win32/CouponRuc |
| MicroWorld-eScan | 12.0.250.0 | Gen:Variant.Adware.Graftor.169592 |
| NANO AntiVirus | 0.30.8.659 | Riskware.Win32.MultiPlug.djzuso |
| Panda Antivirus | 4.6.4.2 | Trj/Genetic.gen |
| Sophos | 4.98.0 | Generic PUA JH |
| SUPERAntiSpyware | 5.6.0.1032 | Adware.Graftor/Variant |
| Symantec | 20141.2.0.56 | Adware.Popuppers |
| Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.12 |
| Trend Micro | 9.740.0.1012 | TROJ_GEN.R02KC0EA415 |
| TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R02KC0EA415 |
| VIPRE Antivirus | 38892 | Trojan.Win32.Generic!BT |
| Zillya | 2.0.0.2121 | Backdoor.PePatch.Win32.55859 |
| Dr.Web | 7.0.12.3050 | Trojan.Crossrider.48329 |
| Qihoo-360 | 1.0.0.1015 | HEUR/QVM30.1.Malware.Gen |
| Kaspersky | 15.0.1.10 | not-a-virus:AdWare.Win32.MultiPlug.nbxh |
| Vba32 AntiVirus | 3.12.26.3 | AdWare.MultiPlug |
| IKARUS anti.virus | T3.1.8.6.0 | PUA.Generic |
| Jiangmin | 16.0.100 | Adware/Agent.ajop |
| Rising Antivirus | 25.0.0.17 | PE:Trojan.Win32.Generic.17DF78B9!400521401 |
| Clam AntiVirus | 0.98.5.0 | Win.Adware.Multiplug-33429 |
| Scanner Software | Version | Result |
|---|---|---|
| Lavasoft Ad-Aware | 12.0.163.0 | Gen:Variant.Adware.Graftor.169592 |
| Agnitum Outpost | 5.5.1.3 | PUA.MultiPlug! |
| AhnLab-V3 | 2015.04.07.02 | PUP/Win32.Generic |
| ALYac | 1.0.1.4 | Gen:Variant.Adware.Graftor.169592 |
| Antiy-AVL | 1.0.0.1 | GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent |
| avast! | 8.0.1489.320 | Win32:MultiPlug-LV [PUP] |
| AVG | 15.0.0.4321 | Generic6.DCB |
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.MultiPlug.Gen |
| Bitdefender | 7.2 | Gen:Variant.Adware.Graftor.169592 |
| CAT-QuickHeal | 14.00 | Browser.RestrictsControl.SL4 |
| Comodo Security | 21675 | Application.Win32.AdWare.MultiPlug.VB |
| Cyren | 5.4.16.7 | W32/S-71786d78!Eldorado |
| Dr.Web | 7.0.12.3050 | Trojan.Crossrider.47611 |
| Emsisoft Anti-Malware | 3.0.0.600 | Gen:Variant.Adware.Graftor.169592 (B) |
| ESET-NOD32 | 11434 | a variant of Win32/Adware.MultiPlug.EG |
| Fortinet FortiGate | 5.0.999.0 | Riskware/MultiPlug |
| F-Prot | 4.7.1.166 | W32/S-71786d78!Eldorado |
| F-Secure | 11.0.19100.45 | Gen:Variant.Adware.Graftor |
| G Data | 25 | Gen:Variant.Adware.Graftor.169592 |
| Jiangmin | 16.0.100 | Adware/Agent.akzc |
| K7 AntiVirus | 9.202.15502 | Adware ( 004a07251 ) |
| K7GW | 9.202.15503 | Adware ( 004a07251 ) |
| Kaspersky | 15.0.1.10 | not-a-virus:AdWare.Win32.MultiPlug.oaqj |
| Malwarebytes | 1.75.0.1 | PUP.Optional.MultiPlug |
| McAfee | 6.0.5.614 | MultiPlug |
| McAfee-GW-Edition | v2015 | BehavesLike.Win32.Downloader.bm |
| Microsoft Security Essentials | 1.1.11502.0 | BrowserModifier:Win32/CouponRuc |
| MicroWorld-eScan | 12.0.250.0 | Gen:Variant.Adware.Graftor.169592 |
| NANO AntiVirus | 0.30.10.952 | Riskware.Win32.MultiPlug.dkmioj |
| Panda Antivirus | 4.6.4.2 | Trj/Genetic.gen |
| Qihoo-360 | 1.0.0.1015 | HEUR/QVM30.1.Malware.Gen |
| Sophos | 4.98.0 | Generic PUA JF |
| SUPERAntiSpyware | 5.6.0.1032 | Adware.Graftor/Variant |
| Symantec | 20141.2.0.56 | Trojan.Gen.2 |
| Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.12 |
| Trend Micro | 9.740.0.1012 | TROJ_GEN.R0C1C0EA915 |
| TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R0C1C0EA915 |
| Vba32 AntiVirus | 3.12.26.3 | AdWare.MultiPlug |
| VIPRE Antivirus | 39128 | Trojan.Win32.Generic!BT |
| Zillya | 2.0.0.2128 | Adware.MultiPlug.Win32.97508 |
| Avira | 3.6.1.96 | ADWARE/MultiPlug.Gen |
| ViRobot | 2014.3.20.0 | Adware.Graftor.754176[h] |
| IKARUS anti.virus | T3.1.8.9.0 | Win32.SuspectCrc |
| Rising Antivirus | 25.0.0.17 | PE:Trojan.Win32.Generic.17BE300D!398340109 |
| Bkav FE | 1.3.0.6379 | W32.PmobeC.Trojan |
| Clam AntiVirus | 0.98.5.0 | Win.Adware.Agent-38486 |
| Norman | 7.04.04 | Agent.BLMHC |
| nProtect | 2015-04-10.01 | Adware.Agent.PKA |
| Scanner Software | Version | Result |
|---|---|---|
| Lavasoft Ad-Aware | 12.0.163.0 | Gen:Variant.Adware.Graftor.169592 |
| Agnitum Outpost | 5.5.1.3 | PUA.MultiPlug! |
| AhnLab-V3 | 2015.03.18.04 | PUP/Win32.Generic |
| ALYac | 1.0.1.4 | Gen:Variant.Adware.Graftor.169592 |
| Antiy-AVL | 1.0.0.1 | GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent |
| avast! | 8.0.1489.320 | Win32:MultiPlug-LV [PUP] |
| AVG | 15.0.0.4311 | Generic6.BKI |
| Avira | 7.11.218.38 | ADWARE/MultiPlug.Gen |
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.MultiPlug.Gen |
| Bitdefender | 7.2 | Gen:Variant.Adware.Graftor.169592 |
| CAT-QuickHeal | 14.00 | BrowserModifier.CouponRuc.r6 (Not a Virus) |
| Comodo Security | 21448 | Application.Win32.AdWare.MultiPlug.VB |
| Cyren | 5.4.16.7 | W32/S-71786d78!Eldorado |
| Dr.Web | 7.0.12.3050 | Trojan.Crossrider.48485 |
| Emsisoft Anti-Malware | 3.0.0.600 | Gen:Variant.Adware.Graftor.169592 (B) |
| ESET-NOD32 | 11337 | a variant of Win32/Adware.MultiPlug.EG |
| Fortinet FortiGate | 5.0.999.0 | Riskware/MultiPlug |
| F-Prot | 4.7.1.166 | W32/S-71786d78!Eldorado |
| F-Secure | 11.0.19100.45 | Gen:Variant.Adware.Graftor |
| G Data | 25 | Gen:Variant.Adware.Graftor.169592 |
| Jiangmin | 16.0.100 | Adware/Agent.agay |
| K7 AntiVirus | 9.201.15292 | Adware ( 004a07251 ) |
| K7GW | 9.201.15292 | Adware ( 004a07251 ) |
| Malwarebytes | 1.75.0.1 | PUP.Optional.MultiPlug |
| McAfee | 6.0.5.614 | Multiplug-FRF |
| McAfee-GW-Edition | v2014.2 | BehavesLike.Win32.Downloader.bm |
| Microsoft Security Essentials | 1.1.11400.0 | BrowserModifier:Win32/CouponRuc |
| MicroWorld-eScan | 12.0.250.0 | Gen:Variant.Adware.Graftor.169592 |
| NANO AntiVirus | 0.30.8.659 | Riskware.Win32.MultiPlug.djtcsa |
| Panda Antivirus | 4.6.4.2 | Trj/Genetic.gen |
| Qihoo-360 | 1.0.0.1015 | HEUR/QVM30.1.Malware.Gen |
| Sophos | 4.98.0 | Generic PUA GO |
| SUPERAntiSpyware | 5.6.0.1032 | Adware.MultiPlug/Variant |
| Symantec | 20141.2.0.56 | Trojan.Gen.2 |
| Trend Micro | 9.740.0.1012 | TROJ_GEN.R02KC0EA415 |
| TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R02KC0EA415 |
| VIPRE Antivirus | 38526 | Trojan.Win32.Generic!BT |
| Zillya | 2.0.0.2104 | Adware.MultiPlug.Win32.225346 |
| Rising Antivirus | 25.0.0.17 | PE:Trojan.Win32.Generic.17B6D06A!397856874 |
| Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.12 |
| ViRobot | 2014.3.20.0 | Adware.Graftor.769024[h] |
| Bkav FE | 1.3.0.6379 | W32.DropperAgentK.Trojan |
| IKARUS anti.virus | T3.1.8.9.0 | Trojan.SuspectCRC |
| Kaspersky | 15.0.1.10 | Trojan.Win32.Cosmu.csae |
| Norman | 7.04.04 | Agent.BLMHC |
| nProtect | 2015-04-10.01 | Adware.Agent.PKA |
| Vba32 AntiVirus | 3.12.26.3 | TrojanDropper.Agent |
| Clam AntiVirus | 0.98.5.0 | Win.Adware.Multiplug-33429 |
| Scanner Software | Version | Result |
|---|---|---|
| Lavasoft Ad-Aware | 12.0.163.0 | Gen:Variant.Adware.Graftor.169592 |
| Agnitum Outpost | 5.5.1.3 | PUA.MultiPlug! |
| AhnLab-V3 | 2015.03.17.00 | PUP/Win32.Generic |
| ALYac | 1.0.1.4 | Gen:Variant.Adware.Graftor.169592 |
| Antiy-AVL | 1.0.0.1 | GrayWare[AdWare:not-a-virus,HEUR]/Win32.Agent |
| avast! | 8.0.1489.320 | Win32:MultiPlug-LV [PUP] |
| AVG | 15.0.0.4306 | Generic6.BBT |
| Avira | 7.11.217.176 | ADWARE/MultiPlug.Gen |
| AVware | 1.5.0.21 | Trojan.Win32.Generic!BT |
| Baidu-International | 3.5.1.41473 | Adware.Win32.MultiPlug.EG |
| Bitdefender | 7.2 | Gen:Variant.Adware.Graftor.169592 |
| CAT-QuickHeal | 14.00 | BrowserModifier.CouponRuc.r6 (Not a Virus) |
| Comodo Security | 21434 | Application.Win32.AdWare.MultiPlug.VB |
| Cyren | 5.4.16.7 | W32/S-350365ee!Eldorado |
| Dr.Web | 7.0.12.3050 | Trojan.Crossrider.47681 |
| Emsisoft Anti-Malware | 3.0.0.600 | Gen:Variant.Adware.Graftor.169592 (B) |
| ESET-NOD32 | 11327 | a variant of Win32/Adware.MultiPlug.EG |
| Fortinet FortiGate | 5.0.999.0 | Riskware/MultiPlug |
| F-Prot | 4.7.1.166 | W32/S-350365ee!Eldorado |
| F-Secure | 11.0.19100.45 | Gen:Variant.Adware.Graftor |
| G Data | 25 | Gen:Variant.Adware.Graftor.169592 |
| Jiangmin | 16.0.100 | Adware/Agent.akts |
| K7 AntiVirus | 9.201.15274 | Adware ( 004a07251 ) |
| K7GW | 9.201.15274 | Adware ( 004a07251 ) |
| Malwarebytes | 1.75.0.1 | PUP.Optional.MultiPlug |
| McAfee | 6.0.5.614 | MultiPlug |
| McAfee-GW-Edition | v2014.2 | BehavesLike.Win32.Downloader.bm |
| Microsoft Security Essentials | 1.1.11400.0 | BrowserModifier:Win32/CouponRuc |
| MicroWorld-eScan | 12.0.250.0 | Gen:Variant.Adware.Graftor.169592 |
| NANO AntiVirus | 0.30.0.296 | Riskware.Win32.Agent.djssoa |
| Panda Antivirus | 4.6.4.2 | Trj/Genetic.gen |
| Qihoo-360 | 1.0.0.1015 | Win32/Virus.Adware.5c6 |
| Sophos | 4.98.0 | Generic PUA NI |
| SUPERAntiSpyware | 5.6.0.1032 | Adware.Graftor/Variant |
| Symantec | 20141.2.0.56 | Trojan.Gen.2 |
| Trend Micro | 9.740.0.1012 | TROJ_GEN.R01TC0EA215 |
| TrendMicro-HouseCall | 9.700.0.1001 | TROJ_GEN.R01TC0EA215 |
| VIPRE Antivirus | 38474 | Trojan.Win32.Generic!BT |
| Zillya | 2.0.0.2101 | Adware.MultiPlug.Win32.127917 |
| IKARUS anti.virus | T3.1.8.6.0 | Win32.SuspectCrc |
| Vba32 AntiVirus | 3.12.26.3 | AdWare.Win64.MultiPlug |
| Tencent | 1.0.0.1 | Trojan.Win32.Qudamah.Gen.12 |
| Clam AntiVirus | 0.98.5.0 | Win.Adware.Agent-38486 |
| Rising Antivirus | 25.0.0.17 | PE:Trojan.Win32.Generic.17B6D06A!397856874 |
| ViRobot | 2014.3.20.0 | Adware.Graftor.769024[h] |
| Bkav FE | 1.3.0.6379 | W32.DropperAgentK.Trojan |
| Kaspersky | 15.0.1.10 | Trojan.Win32.Cosmu.csae |
| Norman | 7.04.04 | Agent.BLMHC |
| nProtect | 2015-04-10.01 | Adware.Agent.PKA |
Software Details
- URL:
- –
- Support:
- –
- Installation path:
- C:\Program Files\buynsave
- Uninstaller:
- "C:\Program Files\BuyNsave\HvWFhDYjQIo8bp.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
- Size:
- 1.00 MB
- Language:
- English
BuyNsave Executable Details
- Primary executable:
- HvWFhDYjQIo8bp.exe
- Name:
- BuyNsave
- Path:
- C:\Program Files\buynsave\HvWFhDYjQIo8bp.exe
- MD5:
- 974ad54281862631c28e0c587bc49ce0
- SHA-1:
- –
- SHA-256:
- –
| File Type | Filename | MD5 |
|---|---|---|
|
EXE
|
HvWFhDYjQIo8bp.exe
Adware
|
974ad54281862631c28e0c587bc49ce0 |