SavePass Smartbar Engine

SavePass Smartbar Engine

Known Toolbar

by Pinwid Ltd.

What is SavePass Smartbar Engine?

SavePass Smartbar Engine is software application developed by Pinwid Ltd.. It is most commonly found on computers running Windows 10 with nearly 45.83% of installations running this operating system. SavePass Smartbar Engine's installer is typically 1.00 MB in size and installs around 149 files.

SavePass Smartbar Engine is most popular in the United States with 99.55% of installations residing in this country.

SavePass Smartbar Engine adds 5 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, SavePass Smartbar Engine is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About SavePass Smartbar Engine?

This software program serves advertisements from its affiliate ad providers, including banner, inline text links, and popups. The ads are designed to promote the installation of additional content, such as web browser toolbars, optimization utilities, and other products. Common symptoms of infection include hyperlinked text on web pages, slow loading times due to ads, browser popups recommending fake updates or software, and the potential installation of additional unwanted adware programs without the user's consent.

Multiple virus scanners have detected malware in SavePass Smartbar Engine.

classicstartmenu.exe (MD5: 7e1b5c16183b6688b429f800fd588e42) has been flagged by 2 scanners:
Scanner Software Result
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0703
browserhelper.exe (MD5: 62deb1c0d3fa76e1ed82262c4f35477a) has been flagged by 4 scanners:
Scanner Software Result
AVG MalSign.Pindi.8CC
TrendMicro-HouseCall TROJ_GEN.F47V0305
VIPRE Antivirus Adware.Linkury (fs)
Symantec WS.Reputation.1
savepass.exe (MD5: a1e91428c80e6ca65171cf1426319b98) has been flagged by 4 scanners:
Scanner Software Result
AVG MalSign.Pindi
TrendMicro-HouseCall TROJ_GEN.F47V0305
VIPRE Antivirus Adware.Linkury (fs)
Symantec WS.Reputation.1

Software Behaviors

Services:
  • hpsupportsolutionsframeworkservice.exe runs as a service named 'HP Support Solutions Framework Service' (HPSupportSolutionsFrameworkService) "This service allows for the detection of HP products and enables identification of support solutions for detected products.".
  • skypec2cautoupdatesvc.exe runs as a service named 'Skype Click to Call Updater' (c2cautoupdatesvc) "Downloads and installs product updates.".
  • classicshellservice.exe runs as a service named 'Classic Shell Service' (ClassicShellService) "Launches the start button after logon".
  • hd-logrotatorservice.exe runs as a service named 'BlueStacks Log Rotator Service' (BstHdLogRotatorSvc).
  • hd-service.exe runs as a service named 'BlueStacks Android Service' (BstHdAndroidSvc).
Firewall:
  • hpwucli.exe is added as a firewall exception for 'C:\Program Files\HP\HP Software Update\HPWUCli.exe'.
  • hpdevicedetection3.exe is added as a firewall exception for 'C:\Program Files\HP\Common\HPDeviceDetection3.exe'.
Scheduled tasks:
  • hd-adb.exe is scheduled as a task with the class '{414B58D5-075E-4F20-A788-93CF9F140FAC}' (runs on registration).
  • hpwuschd2.exe is scheduled as a task named 'hpwuSchd2' (runs monthly on Sundays at 12:48).
  • hpwucli.exe is scheduled as a task with the class '{795727AE-CD28-4FE9-AF32-13A827361736}' (runs on registration).
  • hd-startlauncher.exe is scheduled as a task with the class '{B55D3525-8C6E-4B1F-BD28-695EDB23A31E}' (runs on registration).
  • hd-agent.exe is scheduled as a task with the class '{E1EB8FAB-6872-4465-89EF-FBAC0F92C660}' (runs on registration).

Startup Entries

Startup tasks:
  • hpwuschd2.exe is automatically launched at startup through a scheduled task named HP Software Update_Reg_HKLMWow6432Run.
Registry entries:
  • savepass.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Browser Infrastructure Helper' and executes as C:\users\user\appdata\Local\Smartbar\Application\SavePass.exe startup.
Registry entries (User):
  • hpwucli.exe is loaded once in the current user (HKCU) registry as a startup file name 'HPSoftwareUpdate' which loads as C:\Program Files\HP\HP Software Update\HPWUCli.exe.

Software Details

URL:
Support:
Installation path:
C:\Program Files\Smartbar
Uninstaller:
MsiExec.exe /X{5823C449-6868-4154-B496-21E40C5F09DA} /quiet ENGINE=1
Size:
1.00 MB
Language:
English

SavePass Smartbar Engine Executable Details

Primary executable:
savepass.exe
Name:
SavePass Smartbar Engine
Path:
C:\Program Files\Smartbar\savepass.exe
MD5:
a1e91428c80e6ca65171cf1426319b98
SHA-1:
SHA-256:
Files installed by SavePass Smartbar Engine
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
DLL
a565864517495112a6f2cbce6f169020
DLL
d7d36318347d46069d05ca434c2c9a62
EXE
651a780e5bfc91348d05504d03dfe724
DLL
d09c4309737caaa868c20deb2873504a
EXE
d505df0fde206cbc0fe43b8deb5fe2f4
EXE
a3752399845420a03c259f42ae5d720d
DLL
eb725212555516e7208b7e9c686e63c4
EXE
9d7b3e989aed3de53b13e514d3d3fdd2
DLL
419cae8a2b069263720044644c1fa7db