RoboSavEr

RoboSavEr

Known Toolbar

by InstalleRex-WebPick

What is RoboSavEr?

RoboSavEr is software application developed by InstalleRex-WebPick. It is most commonly found on computers running Windows 7 with nearly 85.19% of installations running this operating system. RoboSavEr's installer is typically 1.00 MB in size and installs around 34 files.

RoboSavEr is most popular in the United States with 28.13% of installations residing in this country.

About RoboSavEr?

RoboSaver is an adware program that is designed to serve additional advertisements to users while they are using popular search engines such as Bing and Google. This adware installs itself as a Chrome extension and as a process and Browser Helper Object in Internet Explorer, as well as adding itself as a Windows add-on. Although the program creates an entry in the Add or Remove Programs section of the Control Panel, removing this entry may not completely stop the adware from running or prevent ads from displaying. Once installed, RoboSaver injects or inserts additional ads into search results and various web pages that utilize third-party advertising when a user conducts searches using Bing or Google. The adware uses the InstalleRex download and install manager from WebPicks Holdings for distribution, which is typically used to distribute Pay Per Install monetized software such as unwanted toolbars and web browser extensions.

Multiple virus scanners have detected malware in RoboSavEr.

Q.dll (MD5: 5337ab32d06451b51b031fad03674a73) has been flagged by 17 scanners:
Scanner Software Result
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.81
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.T
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfk
Malwarebytes PUP.Optional.MultiPlug.A
Sophos Generic PUA GP
TrendMicro-HouseCall TROJ_GEN.R03WH07EQ14
VIPRE Antivirus Trojan.Win32.Generic!BT
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:Adware-gen [Adw]
McAfee Artemis!BD9FB537D3D3
McAfee-GW-Edition Artemis!BD9FB537D3D3
Symantec Trojan.Gen.2
Qihoo-360 HEUR/Malware.QVM10.Gen
Trend Micro ADW_MULTIPLUG
AhnLab-V3 Dropper/Win32.Preloader
p7.x64.dll (MD5: 2a05aaa383857ecbdd6100c34595b5df) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Trojan.Generic.11089445
AhnLab-V3 Trojan/Win32.Preloader
Avira AntiVir ADWARE/Adware.Gen
Antiy-AVL Trojan/Win32.SGeneric
avast! Win64:Adware-gen [Adw]
AVG Generic_r.GX
Baidu-International Adware.Win64.MultiPlug.A
Bitdefender Trojan.Generic.11089445
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11089445 (B)
ESET-NOD32 a variant of Win64/Adware.MultiPlug.A
F-Secure Trojan.Generic.11089445
G Data Trojan.Generic.11089445
IKARUS anti.virus AdWare.MultiPlug
K7 AntiVirus Adware ( 004922f61 )
K7GW Adware ( 004922f61 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Mplug!2A05AAA38385
McAfee-GW-Edition Mplug!2A05AAA38385
MicroWorld-eScan Trojan.Generic.11089445
Norman Multiplug.A
nProtect Trojan.Generic.11089445
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.273
Rising Antivirus PE:Adware.MultiPlug!6.166A
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.R0CBH06DC14
VIPRE Antivirus MPlug
ViRobot Adware.Agent.474112
Agnitum Outpost PUA.BHO!
Bkav FE W32.ToolbarEscort.Adware
CAT-QuickHeal AdWare.BHO.r6 (Not a Virus)
Kaspersky not-a-virus:AdWare.Win32.BHO.bdnc
NANO AntiVirus Riskware.Win32.BHO.dbdfeq
Trend Micro ADW_MULTIPLUG
Vba32 AntiVirus AdWare.BHO
Dr.Web Trojan.Crossrider.8290
Fortinet FortiGate Adware/Megasearch
Tencent Win32.Risk.Adware.Lmkl
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
AegisLab AdWare.Win64.MegaSearch
34v7yJwz.dll (MD5: 230c8ce3c37ae8b366d3d28ed9a56001) has been flagged by 40 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
avast! Win32:Adware-gen [Adw]
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
G Data Win32.Trojan.Multiplug.A
IKARUS anti.virus not-a-virus:AdWare.Win32.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
NANO AntiVirus Riskware.Win32.MultiPlug.cthsbt
Rising Antivirus PE:Malware.Adware!6.1293
Sophos Generic PUA NC
Symantec Trojan.Gen.2
Trend Micro ADW_MULTIPLG
TrendMicro-HouseCall ADW_MULTIPLG
VIPRE Antivirus JustPlugIt (fs)
Lavasoft Ad-Aware Application.Generic.626740
Agnitum Outpost PUA.MultiPlug!
Antiy-AVL Trojan/Win32.SGeneric
Bitdefender Application.Generic.626740
F-Secure Application.Generic.626740
MicroWorld-eScan Application.Generic.626740
Panda Antivirus Trj/CI.A
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Bkav FE W32.MultiPlugCP.Adware
Norman Multiplug.A
SUPERAntiSpyware Adware.Multiplug/Variant
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
2O7CdzQyJ.dll (MD5: ed9ba7584b23695e86a2a0ff897ac751) has been flagged by 34 scanners:
Scanner Software Result
AhnLab-V3 Adware/Win32.Graftor
AVG Generic_r.GU
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
Baidu-International Adware.Win32.MultiPlug.N
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
G Data Win32.Trojan.Multiplug.A
IKARUS anti.virus PUA.Multiplug
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition BehavesLike.Win32.Adware.gm
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM30.Gen
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
Symantec WS.Reputation.1
VIPRE Antivirus JustPlugIt (fs)
Lavasoft Ad-Aware Application.Generic.649799
Avira AntiVir SPR/Tool.643072.7
Bitdefender Application.Generic.649799
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.649799
MicroWorld-eScan Application.Generic.649799
TrendMicro-HouseCall Suspicious_GEN.F47V0611
avast! Win32:Dropper-gen [Drp]
K7 AntiVirus Adware ( 0049c94b1 )
K7GW Adware ( 0049c94b1 )
Trend Micro ADW_MULTIPLUG
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)
Antiy-AVL Trojan/Win32.TGeneric
0gSMxHHH.dll (MD5: ea89a5cfcf37d160e1b20b40e5111e89) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Application.Generic.607493
Agnitum Outpost PUA.MultiPlug!
AhnLab-V3 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Bitdefender Application.Generic.607493
Comodo Security ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 a variant of Win32/AdWare.MultiPlug.N
Fortinet FortiGate Riskware/MultiPlug
F-Secure Application.Generic.607493
G Data Application.Generic.607493
IKARUS anti.virus AdWare.MegaSearch
K7 AntiVirus Adware ( 004923a41 )
K7GW Adware ( 004923a41 )
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Adware-FHP
McAfee-GW-Edition Adware-FHP
MicroWorld-eScan Application.Generic.607493
NANO AntiVirus Riskware.Win32.MultiPlug.cvyxyu
Panda Antivirus Trj/CI.A
Rising Antivirus PE:Malware.Adware!6.1293
Sophos MultiPlug
SUPERAntiSpyware Adware.Multiplug/Variant
TrendMicro-HouseCall TROJ_GEN.R047H06CO14
VIPRE Antivirus JustPlugIt (fs)
Antiy-AVL AdWare/Win32.MegaSearch
avast! Win32:Adware-gen [Adw]
Bkav FE W32.Clod3fd.Trojan.2240
Kaspersky not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus Win32.Troj.MegaSearch.at.(kcloud)
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.F0C2C00A414
Vba32 AntiVirus BScope.Trojan.Agent
Qihoo-360 Win32/Trojan.Adware.814
Tencent Win64.Adware.Multiplug.Hqlt
Norman Multiplug.A
Avira ADWARE/Adware.Gen
AVware JustPlugIt (fs)
AegisLab AdWare.Win64.MegaSearch
Emsisoft Anti-Malware Gen:Variant.Adware.Strictor.61989 (B)

Software Details

URL:
https://justplug.it
Support:
–
Installation path:
C:\ProgramData\robosaver
Uninstaller:
"C:\ProgramData\RoboSavEr\f_ZsRWwX.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Size:
1.00 MB
Language:
English

RoboSavEr Executable Details

Primary executable:
f_ZsRWwX.exe
Name:
RoboSavEr
Path:
C:\ProgramData\robosaver\f_ZsRWwX.exe
MD5:
ea4934cc3e962e4df8b41d334f6ea65e
SHA-1:
–
SHA-256:
–
Files installed by RoboSavEr
File Type Filename MD5
EXE
1b63b4e4fe4be0d8607d362c3d2f2677
DLL
938a58a18228d9c556965deb4f74e494
EXE
0i.exe
Malware
692b15082eeaa2006c68b39d78f49dbf
DLL
e22959dc8202d1244affe010955ade60
DLL
2399176cdc9056ed5fc364c12b555b23
EXE
5ad0db10a1d770b464f6e800a61dc564
EXE
ea4934cc3e962e4df8b41d334f6ea65e
EXE
c68ba5a3fefd398e25a2f3eb282fc56e
EXE
f5bff621c4c58358b36f8526dec8a264
EXE
19e5eb31641597fa245deb887aa25817