NeWSavver

NeWSavver

Known Toolbar

by InstalleRex-WebPick

What is NeWSavver?

NeWSavver is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 50.00% of installations running this operating system. NeWSavver's installer is typically 1.00 MB in size and installs around 15 files.

NeWSavver is most popular in the United States with 55.44% of installations residing in this country.

About NeWSavver?

Introducing New Saver, a browser extension designed to enhance the user's online experience by displaying additional advertisements in popular search engines such as Bing and Google. Compatible with Internet Explorer, Chrome, and Firefox, this adware program seamlessly integrates as a background process and creates an entry in Add or Remove Programs for easy management. Although removing the program may halt its operation, advertisements may still persist. New Saver utilizes the InstalleRex download manager from WebPicks Holdings for installation, a known distributor of potentially unwanted applications and ad-supported extensions. With its ability to inject new ads into search results and web pages, New Saver aims to provide users with targeted and relevant advertising content.

Multiple virus scanners have detected malware in NeWSavver.

4.exe (MD5: f5bff621c4c58358b36f8526dec8a264) has been flagged by 39 scanners:
Scanner Software Result
Agnitum Outpost Adware.MegaSearch
AhnLab-V3 Trojan/Win32.Preloader
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Adware-gen [Adw]
AVG Generic5
Baidu-International Adware.Win32.MegaSearch.aBc
Bkav FE W32.Clod3fd.Trojan
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate Adware/Megasearch
IKARUS anti.virus Win32.AdWare
K7 AntiVirus Adware
K7GW Adware ( 00490ca81 )
Kaspersky not-a-virus:AdWare.Win32.MegaSearch
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Malwarebytes PUP.Optional.CRXDrop.A
McAfee Artemis!F5BFF621C4C5
McAfee-GW-Edition Artemis!F5BFF621C4C5
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA BJ
Symantec Trojan.Gen
Trend Micro TROJ_GEN.F0C2C00A414
TrendMicro-HouseCall TROJ_GEN.F0C2C00A414
Vba32 AntiVirus BScope.Trojan.Agent
VIPRE Antivirus Trojan.Win32.Generic!BT
Lavasoft Ad-Aware Gen:Variant.Adware.Graftor.146103
Avira AntiVir Adware/Graftor.146103
AVware Trojan.Win32.Generic!BT
Bitdefender Gen:Variant.Adware.Graftor.146103
CAT-QuickHeal AdWare.MultiPlug.r5 (Not a Virus)
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.146103 (B)
F-Secure Gen:Variant.Adware.Graftor.146103
G Data Gen:Variant.Adware.Graftor.146103
MicroWorld-eScan Gen:Variant.Adware.Graftor.146103
NANO AntiVirus Riskware.Win32.Graftor.dcodwf
Tencent Win32.Risk.Adware.Dzkd
Qihoo-360 Win32/Trojan.Adware.814
Rising Antivirus PE:Malware.Adware!6.1293
SUPERAntiSpyware Adware.Multiplug/Variant
gunJkOem.dll (MD5: 98e78357d0a423420fb17dc09212e741) has been flagged by 24 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
G Data Win32.Trojan.Multiplug.A
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
Qihoo-360 Malware.QVM30.Gen
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
VIPRE Antivirus JustPlugIt (fs)
AVware Trojan.Win32.Generic!BT
Fortinet FortiGate Riskware/MultiPlug
TrendMicro-HouseCall TROJ_GEN.R0C9H06GB14
avast! Win64:Malware-gen
IKARUS anti.virus PUA.Multiplug
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
4.x64.dll (MD5: 9e0383fb82ce83bd785951c20f3fe959) has been flagged by 4 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win32.Preloader
Baidu-International Adware.Win64.MultiPlug.A
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
Malwarebytes PUP.Optional.MultiPlug.A
4.dll (MD5: 1550537f5aee53fec3b74eb4605f8483) has been flagged by 18 scanners:
Scanner Software Result
Avira AntiVir ADWARE/Adware.Gen
AVG Generic5.ALFJ
Baidu-International Adware.Win32.MultiPlug.40
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
Rising Antivirus PE:Malware.Adware!6.1293
TrendMicro-HouseCall TROJ_GEN.F47V1230
VIPRE Antivirus JustPlugIt (fs)
AhnLab-V3 Trojan/Win32.Preloader
Fortinet FortiGate Riskware/MultiPlug
McAfee RDN/Generic PUP.x!c2a
McAfee-GW-Edition RDN/Generic PUP.x!c2a
Sophos Generic PUA AO
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
IKARUS anti.virus PUA.Multiplug
xA3zGfJWm4.x64.dll (MD5: 9b44cf590f064eaf267c2fe11a2f6d7a) has been flagged by 9 scanners:
Scanner Software Result
AhnLab-V3 Trojan/Win64.Preloader
AVG Generic_r.QB
Baidu-International Trojan.Win64.MultiPlug.BD
ESET-NOD32 a variant of Win64/Adware.MultiPlug.D
IKARUS anti.virus PUA.Multiplug
Malwarebytes PUP.Optional.Preload
McAfee Artemis!9B44CF590F06
McAfee-GW-Edition Artemis!9B44CF590F06
TrendMicro-HouseCall Suspicious_GEN.F47V0702

Software Details

URL:
https://justplug.it
Support:
–
Installation path:
C:\ProgramData\newsavver
Uninstaller:
"C:\ProgramData\NeWSavver\4.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

NeWSavver Executable Details

Primary executable:
4.exe
Name:
NeWSavver
Path:
C:\ProgramData\newsavver\4.exe
MD5:
f5bff621c4c58358b36f8526dec8a264
SHA-1:
–
SHA-256:
–
Files installed by NeWSavver
File Type Filename MD5
EXE
4.exe
Adware
f5bff621c4c58358b36f8526dec8a264
DLL
583063fa9e8cbafbf965f918efda7e3a
DLL
98e78357d0a423420fb17dc09212e741
DLL
4.x64.dll
Malware
9e0383fb82ce83bd785951c20f3fe959
DLL
4.dll
Malware
1550537f5aee53fec3b74eb4605f8483
DLL
9b44cf590f064eaf267c2fe11a2f6d7a
DLL
1305e75a5e77ece0845806814d753836
EXE
83c728a3d4b56127985b096478a943f8
DLL
1fa387fdb51a2204bdc2bbf808b583d5
EXE
1b63b4e4fe4be0d8607d362c3d2f2677