RoboSavEr

RoboSavEr

Known Toolbar

by InstalleRex-WebPick

What is RoboSavEr?

RoboSavEr is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 85.19% of installations running this operating system. RoboSavEr's installer is typically 1.00 MB in size and installs around 34 files.

RoboSavEr is most popular in the United States with 28.13% of installations residing in this country.

About RoboSavEr?

RoboSaver is an adware program that is designed to serve additional advertisements to users while they are using popular search engines such as Bing and Google. This adware installs itself as a Chrome extension and as a process and Browser Helper Object in Internet Explorer, as well as adding itself as a Windows add-on. Although the program creates an entry in the Add or Remove Programs section of the Control Panel, removing this entry may not completely stop the adware from running or prevent ads from displaying. Once installed, RoboSaver injects or inserts additional ads into search results and various web pages that utilize third-party advertising when a user conducts searches using Bing or Google. The adware uses the InstalleRex download and install manager from WebPicks Holdings for distribution, which is typically used to distribute Pay Per Install monetized software such as unwanted toolbars and web browser extensions.

Multiple virus scanners have detected malware in RoboSavEr.

Q.dll (MD5: 5337ab32d06451b51b031fad03674a73) has been flagged by 17 scanners:
Scanner Software Result
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.81
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Malwarebytes PUP.Optional.MultiPlug.A
Sophos Generic PUA GP
TrendMicro-HouseCall TROJ_GEN.R03WH07EQ14
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:Adware-gen [Adw]
McAfee Artemis!BD9FB537D3D3
McAfee-GW-Edition Artemis!BD9FB537D3D3
Symantec Trojan.Gen.2
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG
AhnLab-V3 Dropper/Win32.Preloader
p7.x64.dll (MD5: 2a05aaa383857ecbdd6100c34595b5df) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11089445
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
Antiy-AVL Trojan/Win32.SGeneric
avast! Win64:Adware-gen [Adw]
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.A
Bitdefender Trojan.Generic.11089445
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11089445 (B)
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
F-Secure Trojan.Generic.11089445
G Data Trojan.Generic.11089445
IKARUS anti.virus AdWare.MultiPlug
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Mplug!2A05AAA38385
McAfee-GW-Edition Mplug!2A05AAA38385
MicroWorld-eScan Trojan.Generic.11089445
Norman Multiplug.A
nProtect Trojan.Generic.11089445
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.273
Rising Antivirus PE:Adware.MultiPlug!6.166A
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.R0CBH06DC14
VIPRE Antivirus MPlug
ViRobot Adware.Agent.474112
Agnitum Outpost PUA.BHO!
Bkav FE W32.ToolbarEscort.Adware
CAT-QuickHeal AdWare.BHO.r6 (Not a Virus)
Kaspersky not-a-virus:AdWare.Win32.BHO.bdnc
NANO AntiVirus Riskware.Win32.BHO.dbdfeq
Trend Micro ADW_MULTIPLUG
Vba32 AntiVirus AdWare.BHO
Dr.Web Trojan.Crossrider.8290
Fortinet FortiGate Adware/Megasearch
Tencent Win32.Risk.Adware.Lmkl
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
AegisLab AdWare.Win64.MegaSearch
34v7yJwz.dll (MD5: 230c8ce3c37ae8b366d3d28ed9a56001) has been flagged by 40 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
avast! Win32:Adware-gen [Adw]
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
G Data Win32.Trojan.Multiplug.A
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
NANO AntiVirus Riskware.Win32.MultiPlug.cthsbt
Rising Antivirus PE:Malware.Adware!6.1293
Sophos Generic PUA NC
Symantec Trojan.Gen.2
Trend Micro ADW_MULTIPLG
TrendMicro-HouseCall ADW_MULTIPLG
VIPRE Antivirus JustPlugIt (fs)
Lavasoft Ad-Aware Application.Generic.626740
Agnitum Outpost PUA.MultiPlug!
Antiy-AVL Trojan/Win32.SGeneric
Bitdefender Application.Generic.626740
F-Secure Application.Generic.626740
MicroWorld-eScan Application.Generic.626740
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Bkav FE W32.MultiPlugCP.Adware
Norman Multiplug.A
SUPERAntiSpyware Adware.Multiplug/Variant
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
2O7CdzQyJ.dll (MD5: ed9ba7584b23695e86a2a0ff897ac751) has been flagged by 34 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Graftor
AVG Generic_r.GU
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
Baidu-International Adware.Win32.MultiPlug.N
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
G Data Win32.Trojan.Multiplug.A
IKARUS anti.virus PUA.Multiplug
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition BehavesLike.Win32.Adware.gm
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM30.Gen
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
VIPRE Antivirus JustPlugIt (fs)
Lavasoft Ad-Aware Application.Generic.649799
Avira AntiVir SPR/Tool.643072.7
Bitdefender Application.Generic.649799
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.649799
MicroWorld-eScan Application.Generic.649799
TrendMicro-HouseCall Suspicious_GEN.F47V0611
avast! Win32:Dropper-gen [Drp]
K7 AntiVirus Adware ( 0049c94b1 )
K7GW Adware ( 0049c94b1 )
Trend Micro ADW_MULTIPLUG
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
Antiy-AVL Trojan/Win32.TGeneric
0gSMxHHH.dll (MD5: ea89a5cfcf37d160e1b20b40e5111e89) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.607493
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Bitdefender Application.Generic.607493
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.607493
G Data Application.Generic.607493
IKARUS anti.virus AdWare.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
MicroWorld-eScan Application.Generic.607493
NANO AntiVirus Riskware.Win32.MultiPlug.cvyxyu
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
TrendMicro-HouseCall TROJ_GEN.R047H06CO14
VIPRE Antivirus JustPlugIt (fs)
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Adware-gen [Adw]
Bkav FE W32.Clod3fd.Trojan.2240
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.F0C2C00A414
Vba32 AntiVirus BScope.Trojan.Agent
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Norman Multiplug.A
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)

Software Details

URL:
https://justplug.it
Support:
–
Installation path:
C:\ProgramData\robosaver
Uninstaller:
"C:\ProgramData\RoboSavEr\f_ZsRWwX.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

RoboSavEr Executable Details

Primary executable:
f_ZsRWwX.exe
Name:
RoboSavEr
Path:
C:\ProgramData\robosaver\f_ZsRWwX.exe
MD5:
ea4934cc3e962e4df8b41d334f6ea65e
SHA-1:
–
SHA-256:
–
Files installed by RoboSavEr
File Type Filename MD5
DLL
Q.dll
Malware
5337ab32d06451b51b031fad03674a73
DLL
2a05aaa383857ecbdd6100c34595b5df
DLL
90a4b6a58d9a1ebecd0e5fd5fec7390b
DLL
6548ba7d77ed36e85d1fc39cd5b103f6
DLL
690eb006638487f5989f5da48ce81e94
DLL
230c8ce3c37ae8b366d3d28ed9a56001
DLL
7855352e4100f76237ce3bb4d5fe1133
DLL
ed9ba7584b23695e86a2a0ff897ac751
DLL
ea89a5cfcf37d160e1b20b40e5111e89
DLL
bab49b61943c026b825a714d2175635a