SavePass Smartbar Engine

SavePass Smartbar Engine

Known Toolbar

by Pinwid Ltd.

What is SavePass Smartbar Engine?

SavePass Smartbar Engine is software application developed by Pinwid Ltd.. It is most commonly found on computers running Windows 10 with nearly 45.83% of installations running this operating system. SavePass Smartbar Engine's installer is typically 1.00 MB in size and installs around 149 files.

SavePass Smartbar Engine is most popular in the United States with 99.55% of installations residing in this country.

SavePass Smartbar Engine adds 5 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, SavePass Smartbar Engine is known to create 2 firewall exceptions to allow inbound and outbound connectivity.

About SavePass Smartbar Engine?

This software program serves advertisements from its affiliate ad providers, including banner, inline text links, and popups. The ads are designed to promote the installation of additional content, such as web browser toolbars, optimization utilities, and other products. Common symptoms of infection include hyperlinked text on web pages, slow loading times due to ads, browser popups recommending fake updates or software, and the potential installation of additional unwanted adware programs without the user's consent.

Multiple virus scanners have detected malware in SavePass Smartbar Engine.

classicstartmenu.exe (MD5: 7e1b5c16183b6688b429f800fd588e42) has been flagged by 2 scanners:
Scanner Software Result
Symantec WS.Reputation.1
TrendMicro-HouseCall TROJ_GEN.F47V0703
browserhelper.exe (MD5: 62deb1c0d3fa76e1ed82262c4f35477a) has been flagged by 4 scanners:
Scanner Software Result
AVG MalSign.Pindi.8CC
TrendMicro-HouseCall TROJ_GEN.F47V0305
VIPRE Antivirus Adware.Linkury (fs)
Symantec WS.Reputation.1
savepass.exe (MD5: a1e91428c80e6ca65171cf1426319b98) has been flagged by 4 scanners:
Scanner Software Result
AVG MalSign.Pindi
TrendMicro-HouseCall TROJ_GEN.F47V0305
VIPRE Antivirus Adware.Linkury (fs)
Symantec WS.Reputation.1

Software Behaviors

Services:
  • hpsupportsolutionsframeworkservice.exe runs as a service named 'HP Support Solutions Framework Service' (HPSupportSolutionsFrameworkService) "This service allows for the detection of HP products and enables identification of support solutions for detected products.".
  • skypec2cautoupdatesvc.exe runs as a service named 'Skype Click to Call Updater' (c2cautoupdatesvc) "Downloads and installs product updates.".
  • classicshellservice.exe runs as a service named 'Classic Shell Service' (ClassicShellService) "Launches the start button after logon".
  • hd-logrotatorservice.exe runs as a service named 'BlueStacks Log Rotator Service' (BstHdLogRotatorSvc).
  • hd-service.exe runs as a service named 'BlueStacks Android Service' (BstHdAndroidSvc).
Firewall:
  • hpwucli.exe is added as a firewall exception for 'C:\Program Files\HP\HP Software Update\HPWUCli.exe'.
  • hpdevicedetection3.exe is added as a firewall exception for 'C:\Program Files\HP\Common\HPDeviceDetection3.exe'.
Scheduled tasks:
  • hd-adb.exe is scheduled as a task with the class '{414B58D5-075E-4F20-A788-93CF9F140FAC}' (runs on registration).
  • hpwuschd2.exe is scheduled as a task named 'hpwuSchd2' (runs monthly on Sundays at 12:48).
  • hpwucli.exe is scheduled as a task with the class '{795727AE-CD28-4FE9-AF32-13A827361736}' (runs on registration).
  • hd-startlauncher.exe is scheduled as a task with the class '{B55D3525-8C6E-4B1F-BD28-695EDB23A31E}' (runs on registration).
  • hd-agent.exe is scheduled as a task with the class '{E1EB8FAB-6872-4465-89EF-FBAC0F92C660}' (runs on registration).

Startup Entries

Startup tasks:
  • hpwuschd2.exe is automatically launched at startup through a scheduled task named HP Software Update_Reg_HKLMWow6432Run.
Registry entries:
  • savepass.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Browser Infrastructure Helper' and executes as C:\users\user\appdata\Local\Smartbar\Application\SavePass.exe startup.
Registry entries (User):
  • hpwucli.exe is loaded once in the current user (HKCU) registry as a startup file name 'HPSoftwareUpdate' which loads as C:\Program Files\HP\HP Software Update\HPWUCli.exe.

Software Details

URL:
Support:
Installation path:
C:\Program Files\Smartbar
Uninstaller:
MsiExec.exe /X{5823C449-6868-4154-B496-21E40C5F09DA} /quiet ENGINE=1
Size:
1.00 MB
Language:
English

SavePass Smartbar Engine Executable Details

Primary executable:
savepass.exe
Name:
SavePass Smartbar Engine
Path:
C:\Program Files\Smartbar\savepass.exe
MD5:
a1e91428c80e6ca65171cf1426319b98
SHA-1:
SHA-256:
Files installed by SavePass Smartbar Engine
File Type Filename MD5
EXE
42b550f71d32d64f8fff3d2b39bfb5a2
EXE
5d011161691ddd4cc9c60f92cddb960b
EXE
4b24f4ec38a6631145c6961d252c7a19
EXE
c0c276653fec02aba22e7ec83375739a
EXE
a3a72e188cb78ce630cd70c9612cf81a
EXE
44ee39b34c74ce28454ac9d876db3ce1
DLL
7a8bec3c1cfddc55e67265f93512b8f4
DLL
5cc1c7385c7978a71a0177b870ec0ebf
DLL
6b1249e09335230996b0b27543f59b04
DLL
0dc5321a03057a824e1ce00045b69ec9