SavePass 1.1

SavePass 1.1

Known Generic

by Morgan Enter Mode

What is SavePass 1.1?

SavePass 1.1 is software application developed by Morgan Enter Mode. It is most commonly found on computers running Windows 7 with nearly 61.41% of installations running this operating system. SavePass 1.1's installer is typically 12.00 MB in size and installs around 704 files. The most common release is 1.36.01.22 with 66.15% of all installations currently using this version.

SavePass 1.1 is most popular in the United States with 11.15% of installations residing in this country.

SavePass 1.1 adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About SavePass 1.1?

SavePass, developed by Brightcircle, is a browser extension designed to provide display advertising within the user's web browser experience. The extension showcases ads in the form of banners and contextual text-links, strategically placed within the white space areas of the HTML page or overlaying existing ads on the visited website. These advertisements commonly promote PC optimization utilities, bundled malware, and other forms of malvertising. SavePass is constructed using the CrossRider framework, ensuring its robust performance and compatibility with various web browsers.

Multiple virus scanners have detected malware in SavePass 1.1.

utils.exe (MD5: f537709f5588f2dfb92f953233146615) has been flagged by 51 scanners:
Scanner Software Result
AegisLab AdWare.NSIS.Indirect
Baidu-International PUA.Win32.VMDetector.BI
Bkav FE HW32.Packed
G Data NSIS.Adware.Crossrider
Malwarebytes PUP.Optional.CrossRider.A
Qihoo-360 HEUR/QVM20.1.Malware.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Gen:Application.Heur.cv1@mej4XpmO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL Trojan/NSIS.GoogUpdate.dq
Arcabit Application.Heur.EBD1FD7
avast! Win32:Crossrider-AI [PUP]
AVG Crossrider.EMR
Avira ADWARE/CrossRider.Gen
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.cv1@mej4XpmO
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security ApplicUnwnt
Cyren W32/A-1a27c920!Eldorado
Dr.Web Trojan.Crossrider1.26059
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/A-1a27c920!Eldorado
F-Secure Gen:Application.Heur.cv1@mej4XpmO
IKARUS anti.virus Trojan.GoogUpdate
Jiangmin Trojan/NSIS.aow
K7 AntiVirus Unwanted-Program ( 004afae01 )
K7GW Unwanted-Program ( 004afae01 )
Kaspersky Trojan.NSIS.GoogUpdate.dq
McAfee Artemis!1EA0693DF275
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.cv1@mej4XpmO
NANO AntiVirus Trojan.Win32.Crossrider.dhzall
nProtect Trojan/W32.Agent.1092512
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA NC
SUPERAntiSpyware Adware.SavePass/Variant
Symantec Trojan.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.4
Trend Micro TROJ_GEN.R0C1C0EA115
TrendMicro-HouseCall TROJ_GEN.R0C1C0EA115
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.4254
Agnitum Outpost PUA.Adwapper!
Clam AntiVirus Win.Adware.Agent-47082
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
ALYac Gen:Variant.Adware.Kazy.133003
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
ViRobot Adware.CrossRider.1192928[h]
Kingsoft AntiVirus Win32.Troj.Advert.ac.(kcloud)
1f97e74e-77ab-4fc7-94ee-fdc979e77ee7-7.exe (MD5: 521de5d0d86e6fb3e01b1c6d0f264c6a) has been flagged by 48 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.ev1@m4lioZkO
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.EDDE9E
avast! Win32:Crossrider-CB [PUP]
AVG Generic.619
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.CD
Bitdefender Gen:Application.Heur.ev1@m4lioZkO
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security Application.Win32.CrossRider.CK
Cyren W32/S-dbad4651!Eldorado
Dr.Web Trojan.Crossrider1.23051
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-dbad4651!Eldorado
F-Secure Gen:Application.Heur.ev1@m4lioZkO
G Data Gen:Application.Heur.ev1@m4lioZkO
K7 AntiVirus Trojan ( 004afbb41 )
K7GW Trojan ( 004afbb41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!521DE5D0D86E
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.ev1@m4lioZkO
NANO AntiVirus Riskware.Win32.CrossRider.dtmouf
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Application.c20
Rising Antivirus PE:Trojan.GoogUpdate!6.1E39
SUPERAntiSpyware Adware.SavePass/Variant
Symantec Adware.Crossid
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AE15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.1611
Clam AntiVirus Win.Adware.Crossrider-140
Jiangmin AdWare/NSIS.dvt
Sophos Generic PUA DD
TrendMicro-HouseCall TROJ_GEN.R047C0EC315
Vba32 AntiVirus AdWare.Adwapper
IKARUS anti.virus AdWare.CrossRider
Bkav FE W32.HfsAdware.4389
nProtect Trojan-Clicker/W32.Agent.1112024
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
1f97e74e-77ab-4fc7-94ee-fdc979e77ee7-6.exe (MD5: a1efeae0f73f32f6f7f49f6161340dc0) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.133003
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
ALYac Gen:Variant.Adware.Kazy.133003
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Trojan.Adware.Kazy.D2078B
avast! Win32:Crossrider-CB [PUP]
AVG Generic.619
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.BM
Bitdefender Gen:Variant.Adware.Kazy.133003
Bkav FE W32.HfsAdware.52D8
CAT-QuickHeal PUA.BrightCircle.OD6
Clam AntiVirus Win.Adware.Crossrider-217
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.23051
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.133003 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CD potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Variant.Adware.Kazy
G Data Gen:Variant.Adware.Kazy.133003
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!A1EFEAE0F73F
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Variant.Adware.Kazy.133003
NANO AntiVirus Trojan.Win32.Crossrider1.dmfdfb
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Malware.Adwapper!6.23ED
Sophos AppRider
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen.2
Trend Micro TROJ_GEN.R0C2C0EC715
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.1578
Comodo Security Application.Win32.CrossRider.KS
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Tencent Win32.Adware.Bp-browser.Luqs
Jiangmin Trojan/NSIS.geu
Vba32 AntiVirus AdWare.Adwapper
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
nProtect Trojan-Clicker/W32.Agent.517480
TrendMicro-HouseCall TROJ_GEN.R0C1C0EK314
ViRobot Adware.CrossRider.1418728[h]
IKARUS anti.virus AdWare.CrossRider
1f97e74e-77ab-4fc7-94ee-fdc979e77ee7-5.exe (MD5: 0779017c9f3b2447ad5c7e054d390da4) has been flagged by 45 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.av1@mKQKkAnO
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.E2F340
avast! Win32:Crossrider-CB [PUP]
AVG Crossrider.GFK
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.BM
Bitdefender Gen:Application.Heur.av1@mKQKkAnO
CAT-QuickHeal PUA.BrightCircle.OD6
Cyren W32/CrossRider.H.gen!Eldorado
Dr.Web Trojan.Crossrider1.23051
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CC potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/CrossRider.H.gen!Eldorado
F-Secure Gen:Application.Heur.av1@mKQKkAnO
G Data Gen:Application.Heur.av1@mKQKkAnO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
Malwarebytes PUP.Optional.SavePass.A
MicroWorld-eScan Gen:Application.Heur.av1@mKQKkAnO
NANO AntiVirus Trojan.Win32.Crossrider1.dmflos
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.1606
Bkav FE W32.HfsAdware.B84E
McAfee Artemis!572BFA50CFAB
Rising Antivirus PE:Malware.Adwapper!6.2370
Sophos AppRider
TrendMicro-HouseCall TROJ_GEN.F0C2C00AA15
Jiangmin Trojan/NSIS.cea
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Vba32 AntiVirus AdWare.Adwapper
Comodo Security ApplicUnwnt
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
IKARUS anti.virus Trojan.GoogUpdate
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
1f97e74e-77ab-4fc7-94ee-fdc979e77ee7-2.exe (MD5: 69558397be4e6b936774e2ae0fd6e6f2) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.1u1@maFWWXgO
Agnitum Outpost PUA.Toolbar.CrossRider!
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.E11F21
avast! Win32:IeEnablerC-B [Adw]
AVG Crossrider_r.BL
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.BM
Bitdefender Gen:Application.Heur.1u1@maFWWXgO
Bkav FE W32.HfsAdware.52D8
CAT-QuickHeal PUA.BrightCircle.OD6
Comodo Security Application.Win32.CrossRider.KS
Cyren W32/S-95be3f30!Eldorado
Dr.Web Trojan.Crossrider1.23051
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.CK potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/S-95be3f30!Eldorado
F-Secure Gen:Application.Heur.1u1@maFWWXgO
G Data Gen:Application.Heur.1u1@maFWWXgO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
Malwarebytes PUP.Optional.SavePass.A
McAfee Artemis!69558397BE4E
McAfee-GW-Edition Artemis!PUP
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
MicroWorld-eScan Gen:Application.Heur.1u1@maFWWXgO
NANO AntiVirus Riskware.Win32.CrossRider.dmesrj
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Trojan.Gen
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.F0C2C00AF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.1589
Emsisoft Anti-Malware Gen:Variant.Adware.Graftor.171733 (B)
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos AppRider (PUA)
ViRobot Adware.Agent.1358824[h]
Jiangmin AdWare/NSIS.eno
Vba32 AntiVirus AdWare.Adwapper
TrendMicro-HouseCall TROJ_GEN.R0C2C0EC815
Clam AntiVirus Win.Adware.Crossrider-273
IKARUS anti.virus BHO.Win32.IeEnablerCby
nProtect Trojan-Clicker/W32.Agent.363944
ALYac Gen:Variant.Adware.Kazy.133003
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)

Software Behaviors

Scheduled tasks:
  • 26dd6979-8d64-4730-9d96-7deb2c10d974-10.exe is scheduled as a task named 'temp_26dd6979-8d64-4730-9d96-7deb2c10d974-10_user'.
  • b1c53fee-8726-444e-88b0-ee36f5a8ba6e-10.exe is scheduled as a task named 'temp_b1c53fee-8726-444e-88b0-ee36f5a8ba6e-10_user'.
  • d54ab9aa-c630-4be0-ab82-415d3adaaa4b-10.exe is scheduled as a task named 'd54ab9aa-c630-4be0-ab82-415d3adaaa4b-10_user'.
  • 2baf08be-a43a-44ab-950f-a58cdf6142a1-6.exe is scheduled as a task named 'temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-6'.
  • 2baf08be-a43a-44ab-950f-a58cdf6142a1-10.exe is scheduled as a task named 'temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-10_user'.
  • 2baf08be-a43a-44ab-950f-a58cdf6142a1-1-6.exe is scheduled as a task named 'temp_2baf08be-a43a-44ab-950f-a58cdf6142a1-1-6'.

Startup Entries

Startup tasks:
  • abb3bee3-0cfe-42f4-bc0d-20164cc70f4d-7.exe is automatically launched at startup through a scheduled task named abb3bee3-0cfe-42f4-bc0d-20164cc70f4d-1.
  • 7f75cb8c-a37f-48b2-99e3-0e9c6011327b-1-7.exe is automatically launched at startup through a scheduled task named 7f75cb8c-a37f-48b2-99e3-0e9c6011327b-7.
  • 7f75cb8c-a37f-48b2-99e3-0e9c6011327b-10.exe is automatically launched at startup through a scheduled task named 7f75cb8c-a37f-48b2-99e3-0e9c6011327b-10_user.
  • 988cc88a-23c4-45bb-8db9-777989a6658f-1-7.exe is automatically launched at startup through a scheduled task named 988cc88a-23c4-45bb-8db9-777989a6658f-7.
  • 988cc88a-23c4-45bb-8db9-777989a6658f-10.exe is automatically launched at startup through a scheduled task named 988cc88a-23c4-45bb-8db9-777989a6658f-10_user.
  • b1c53fee-8726-444e-88b0-ee36f5a8ba6e-1-7.exe is automatically launched at startup through a scheduled task named b1c53fee-8726-444e-88b0-ee36f5a8ba6e-7.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\savepass 1.1
Uninstaller:
C:\Program Files\SavePass 1.1\Uninstall.exe /fcp=1
Size:
12.00 MB
Language:
English

SavePass 1.1 Executable Details

Primary executable:
utils.exe
Name:
SavePass 1.1
Path:
C:\Program Files\savepass 1.1\utils.exe
MD5:
f537709f5588f2dfb92f953233146615
SHA-1:
–
SHA-256:
–
Files installed by SavePass 1.1
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
utils.exe
Malware
f537709f5588f2dfb92f953233146615
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
521de5d0d86e6fb3e01b1c6d0f264c6a
EXE
a1efeae0f73f32f6f7f49f6161340dc0