SavePass

SavePass

Known Adware

by Kimahri Software inc.

What is SavePass?

SavePass is software application developed by Kimahri Software inc.. It is most commonly found on computers running Windows 7 with nearly 64.07% of installations running this operating system. SavePass's installer is typically 6.00 MB in size and installs around 232 files. The most common release is 1.34.7.1 with 45.24% of all installations currently using this version.

SavePass is most popular in the United States with 12.36% of installations residing in this country.

SavePass adds 4 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About SavePass?

SavePass is an adware application designed for web browsers, including Internet Explorer, Firefox, and Chrome. It injects banner ads and contextual link ads onto web pages, regardless of the site's affiliation with the publisher. The software may display up to 10 intext ads, 4 banner ads, and/or a transitional ad on web pages. Typically, SavePass is bundled with deceptive 3rd-party download managers and may be installed without users' knowledge or consent. Once installed, the program can modify the browser settings, including lowering security settings, changing the home page, and altering the default search provider, a process known as web browser hijacking. In addition to displaying ads, SavePass may also collect user data and report back to a controlling server, potentially including user behavior on the internet, visited URLs, clicked advertisements, and more. This adware is often bundled with multiple potentially unwanted programs offered by 3rd-party download managers.

Multiple virus scanners have detected malware in SavePass.

utils.exe (MD5: 0a52aa3e26ed14909e73901152593b80) has been flagged by 43 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MulDrop
Antiy-AVL Trojan[Downloader:not-a-virus]/Win32.Solimba.a
Bkav FE HW32.CDB
Malwarebytes PUP.Optional.crossRider.A
McAfee Artemis!0A52AA3E26ED
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-PKR.O
Qihoo-360 HEUR/Malware.QVM20.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec WS.Reputation
TrendMicro-HouseCall Suspicious_GEN.F47V0627
Lavasoft Ad-Aware Trojan.Generic.11378568
Agnitum Outpost PUA.Toolbar.CrossRider!
Avira AntiVir Adware/CrossRider.A.6260
avast! Win32:Adware-gen [Adw]
AVG Generic_r.OE
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.45
Bitdefender Trojan.Generic.11378568
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11378568 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
F-Secure Trojan.Generic.11378568
G Data Trojan.Generic.11378568
K7 AntiVirus Trojan ( 004985a61 )
K7GW Trojan ( 004985a61 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.aga
MicroWorld-eScan Trojan.Generic.11378568
nProtect Trojan.Generic.11378568
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Trend Micro TROJ_GEN.R002C0EH314
VIPRE Antivirus Crossrider (fs)
Dr.Web Trojan.Crossrider.17413
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
NANO AntiVirus Trojan.Win32.GoogUpdate.dditte
Norman Troj_Generic.UDQYJ
Clam AntiVirus Win.Adware.Plush-33
Jiangmin Adware/Adload.axm
Vba32 AntiVirus AdWare.AdLoad
Zillya Adware.AdLoad.Win32.89
6398f4bd-1925-4d06-936d-98ac9df2049e-10.exe (MD5: 4baeefee25dcdb2d191695614d556e16) has been flagged by 38 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.A.19244
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAG
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus AdWare.Adload
K7 AntiVirus Trojan ( 0049b45e1 )
K7GW Trojan ( 0049b45e1 )
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!4BAEEFEE25DC
McAfee-GW-Edition Artemis!4BAEEFEE25DC
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA MP
Symantec WS.Reputation.1
TrendMicro-HouseCall Suspicious_GEN.F47V0713
VIPRE Antivirus Crossrider (fs)
AVware Crossrider (fs)
G Data Win32.Application.Plush.A
NANO AntiVirus Riskware.Win32.AdLoad.dbqhel
Qihoo-360 HEUR/Malware.QVM10.Gen
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
F-Prot W32/A-eb9ef301!Eldorado
Rising Antivirus PE:Malware.Obscure!1.9C59
Vba32 AntiVirus AdWare.AdLoad
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
Kingsoft AntiVirus Win32.Troj.NSIS.br.(kcloud)
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Antiy-AVL Trojan/Win32.TSGeneric
Dr.Web Trojan.Crossrider.17413
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.oz
Clam AntiVirus Win.Adware.Agent-7235
Jiangmin Adware/Adload.avv
Zillya Adware.AdLoad.Win32.89
638b4bbf-879c-44e9-931e-7183c0d5a8c6-5.exe (MD5: 430a4e1651459ead0ddaf72e83f5479f) has been flagged by 38 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAH
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
K7 AntiVirus Trojan ( 0049b6e01 )
K7GW Trojan ( 0049b6e01 )
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!430A4E165145
McAfee-GW-Edition Artemis!430A4E165145
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA LJ
TrendMicro-HouseCall Suspicious_GEN.F47V0718
VIPRE Antivirus Crossrider (fs)
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
avast! Win32:Adware-gen [Adw]
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
NANO AntiVirus Riskware.Win32.AdLoad.dbeken
Qihoo-360 Win32/Virus.Adware.a29
Symantec Trojan.ADH.2
Clam AntiVirus Win.Adware.Agent-7640
F-Prot W32/A-eb9ef301!Eldorado
AVware Crossrider (fs)
Vba32 AntiVirus AdWare.AdLoad
Antiy-AVL Trojan/Win32.TSGeneric
Dr.Web Trojan.Crossrider.17413
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.oz
Jiangmin Adware/Adload.avv
Zillya Adware.AdLoad.Win32.89
638b4bbf-879c-44e9-931e-7183c0d5a8c6-4.exe (MD5: 4f0c84ff50d7ac98830db6b1551bf0c2) has been flagged by 40 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL Trojan/Win32.SGeneric
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.BAK
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
K7 AntiVirus Trojan ( 0049c2ce1 )
K7GW Trojan ( 0049c2ce1 )
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!4F0C84FF50D7
McAfee-GW-Edition Artemis!4F0C84FF50D7
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA IA
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0718
VIPRE Antivirus Crossrider (fs)
AVware Crossrider (fs)
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.oy
NANO AntiVirus Riskware.Win32.AdLoad.dchxwa
Lavasoft Ad-Aware Adware.Crossrider.V
Agnitum Outpost PUA.Toolbar.CroRi!
Bitdefender Adware.Crossrider.V
Emsisoft Anti-Malware Adware.Crossrider.V (B)
F-Secure Adware.Crossrider.V
G Data Adware.Crossrider.V
MicroWorld-eScan Adware.Crossrider.V
nProtect Adware.Crossrider.V
F-Prot W32/A-eb9ef301!Eldorado
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Malware.Obscure!1.9C59
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
Qihoo-360 Win32/Virus.Adware.a29
Clam AntiVirus Win.Adware.Agent-7640
Vba32 AntiVirus AdWare.AdLoad
Dr.Web Trojan.Crossrider.17413
Jiangmin Adware/Adload.avv
Zillya Adware.AdLoad.Win32.89
638b4bbf-879c-44e9-931e-7183c0d5a8c6-2.exe (MD5: 862e8b06a677aeb1aa2a0f6ba3878da6) has been flagged by 40 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
Baidu-International Adware.Win32.CrossRider.bAJ
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate Riskware/Toolbar_CrossRider
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
K7 AntiVirus Trojan ( 0049bec01 )
K7GW Trojan ( 0049bec01 )
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!862E8B06A677
McAfee-GW-Edition Artemis!862E8B06A677
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0718
VIPRE Antivirus Crossrider (fs)
Clam AntiVirus Win.Adware.Agent-7545
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
NANO AntiVirus Riskware.Win32.AdLoad.dbyhwj
Qihoo-360 HEUR/Malware.QVM10.Gen
Antiy-AVL Trojan/Win32.TSGeneric
AhnLab-V3 PUP/Win32.CrossRider
AVware Crossrider (fs)
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.oy
Lavasoft Ad-Aware Adware.Crossrider.V
Agnitum Outpost PUA.Toolbar.CroRi!
Bitdefender Adware.Crossrider.V
Emsisoft Anti-Malware Adware.Crossrider.V (B)
F-Secure Adware.Crossrider.V
G Data Adware.Crossrider.V
MicroWorld-eScan Adware.Crossrider.V
nProtect Adware.Crossrider.V
avast! Win32:Adware-gen [Adw]
Vba32 AntiVirus AdWare.AdLoad
Dr.Web Trojan.Crossrider.17413
Jiangmin Adware/Adload.avv
Zillya Adware.AdLoad.Win32.89

Software Behaviors

Scheduled tasks:
  • SavePass-nova.exe is scheduled as a task named '731b28ed-138e-45a5-af8b-7ef590e61293-6'.
  • 36fddb18-1802-47ec-a031-2c0ef9f4c2fe-2.exe is scheduled as a task named 'temp_36fddb18-1802-47ec-a031-2c0ef9f4c2fe-2'.
  • 05484c50-24d6-4764-a40a-64e9fab6f83e-10.exe is scheduled as a task named 'temp_05484c50-24d6-4764-a40a-64e9fab6f83e-10'.
  • 5aa3d933-32c7-4b03-9bcf-13d56020c4b9-2.exe is scheduled as a task named 'temp_5aa3d933-32c7-4b03-9bcf-13d56020c4b9-2'.

Startup Entries

Startup tasks:
  • SavePass-nova.exe is automatically launched at startup through a scheduled task named 5d2076bc-d559-4c68-aca0-29a2e5982b96-7.
  • SavePass-codedownloader.exe is automatically launched at startup through a scheduled task named 1b5a7fb7-4f63-4d4d-b216-cc71fe1136d3-6.
  • 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-5.exe is automatically launched at startup through a scheduled task named 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-5_user.
  • 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-4.exe is automatically launched at startup through a scheduled task named 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-4.
  • 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-2.exe is automatically launched at startup through a scheduled task named 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-2.
  • 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-10.exe is automatically launched at startup through a scheduled task named 7fd6b5bd-5a09-47eb-ba10-4dbd4c635226-10.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\SavePass
Uninstaller:
C:\Program Files\SavePass\Uninstall.exe /fcp=1
Size:
6.00 MB
Language:
English

SavePass Executable Details

Primary executable:
utils.exe
Name:
SavePass
Path:
C:\Program Files\SavePass\utils.exe
MD5:
0a52aa3e26ed14909e73901152593b80
SHA-1:
–
SHA-256:
–
Files installed by SavePass
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
0a52aa3e26ed14909e73901152593b80
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
4baeefee25dcdb2d191695614d556e16
EXE
430a4e1651459ead0ddaf72e83f5479f