Sm23mS

Sm23mS

Known Adware

by Robokid Technologies

What is Sm23mS?

Sm23mS is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 64.29% of installations running this operating system. Sm23mS's installer is typically 14.00 MB in size and installs around 206 files. The most common release is 1.36.01.22 with 35.71% of all installations currently using this version.

Sm23mS is most popular in the United States with 44.1% of installations residing in this country.

About Sm23mS?

The Smart-SaverPlus application is an adware that is often bundled with third-party download managers, using misleading advertising tactics to install the software. It is known for modifying browser settings, including altering security configurations, changing the home page, and manipulating the search provider, leading to web browser hijacking. Additionally, the extension sends analytics data to a remote server, capturing user internet activity, visited URLs, displayed advertisements, and clicked links. Smart-SaverPlus is typically included in third-party download manager packages alongside various potentially unwanted programs.

Multiple virus scanners have detected malware in Sm23mS.

utils.exe (MD5: 9be2289c42c19b17ea989369c61d954c) has been flagged by 48 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MulDrop
Bkav FE HW32.CDB
Dr.Web Trojan.Crossrider.27467
G Data NSIS.Adware.Crossrider
IKARUS anti.virus PUA.PlusHD
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!9BE2289C42C1
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-PKR.O
Rising Antivirus PE:Malware.Obscure!1.9C59
TrendMicro-HouseCall Suspicious_GEN.F47V0803
Lavasoft Ad-Aware Gen:Application.Heur.6v1@mqIxPymO
Antiy-AVL Trojan/NSIS.GoogUpdate.dq
avast! Win32:Crossrider-BR [Adw]
AVG Generic.B92
Avira ADWARE/CrossRider.Gen7
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AX
Bitdefender Gen:Application.Heur.6v1@mqIxPymO
CAT-QuickHeal PUA.BrightCircle.OD6
Clam AntiVirus Win.Adware.Agent-29337
Comodo Security Application.Win32.Plush.GRI
Cyren W32/A-6583813c!Eldorado
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AX potentially unwanted
Fortinet FortiGate W32/GoogUpdate.AX!tr
F-Prot W32/A-6583813c!Eldorado
F-Secure Gen:Application.Heur.6v1@mqIxPymO
Jiangmin Trojan/NSIS.ahj
K7 AntiVirus Unwanted-Program ( 004afadd1 )
K7GW Unwanted-Program ( 004afadd1 )
Kaspersky Trojan.NSIS.GoogUpdate.dq
MicroWorld-eScan Gen:Application.Heur.6v1@mqIxPymO
NANO AntiVirus Trojan.Win32.GoogUpdate.diimaw
nProtect Trojan/W32.Agent.2004384
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos Generic PUA KD
Symantec PUA.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.6
Trend Micro TROJ_SPNR.11KE14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.4283
ALYac Adware.Crossrider.BW
Emsisoft Anti-Malware Adware.Crossrider.BW (B)
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Agnitum Outpost PUA.Toolbar.CrossRider!
Avira AntiVir ADWARE/CrossRider.Gen2
527a0c99-6959-49e2-b875-a47b92c9fb15-6.exe (MD5: d110a28e311da64db032e46ad9b44cac) has been flagged by 22 scanners:
Scanner Software Result
AVG Berta.0DE
Avira ADWARE/CrossRider.Gen4
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.77
Clam AntiVirus Win.Trojan.Googupdate-20
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
G Data Win32.Adware.Crossrider.R
Malwarebytes PUP.Optional.SmartSaver.A
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.3292
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
McAfee Artemis!83D8598563A9
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
AhnLab-V3 PUP/Win32.Toolbar
Avira AntiVir ADWARE/CrossRider.Gen2
Sophos AppRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
avast! Win32:Adware-gen [Adw]
Dr.Web Trojan.Crossrider.33433
527a0c99-6959-49e2-b875-a47b92c9fb15-5.exe (MD5: b766f2237403c255b3c963d45f05b1c6) has been flagged by 23 scanners:
Scanner Software Result
AVG Berta.0DE
AVware Crossrider (fs)
Clam AntiVirus Win.Trojan.Googupdate-19
Dr.Web Trojan.Crossrider.35624
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
G Data Win32.Adware.Crossrider.L
Malwarebytes PUP.Optional.SmartSaver.A
NANO AntiVirus Trojan.Win32.Crossrider.dgnkon
Rising Antivirus PE:Malware.Obscure!1.9C59
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.3377
Avira ADWARE/CrossRider.Gen4
Baidu-International Adware.Win32.CrossAd.77
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
McAfee Artemis!83D8598563A9
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
AhnLab-V3 PUP/Win32.Toolbar
Avira AntiVir ADWARE/CrossRider.Gen2
Sophos AppRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
avast! Win32:Adware-gen [Adw]
527a0c99-6959-49e2-b875-a47b92c9fb15-11.exe (MD5: 793c842a79e8963c8ee8e15a2c34fbad) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AhnLab-V3 PUP/Win32.CrossRider
AVG Berta.0DE
Avira Adware/CrossRider.gr
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAV
Bitdefender Gen:Variant.Adware.Plush.1
Clam AntiVirus Win.Adware.Agent-14079
Dr.Web Trojan.Crossrider.33790
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
F-Prot W32/A-fe3c301b!Eldorado
F-Secure Gen:Variant.Adware.Plush.1
G Data Gen:Variant.Adware.Plush.1
IKARUS anti.virus Trojan.GoogUpdate
Malwarebytes PUP.Optional.SmartSaver.A
MicroWorld-eScan Gen:Variant.Adware.Plush.1
NANO AntiVirus Trojan.Win32.Crossrider.dfrnkt
Qihoo-360 Win32/Virus.Adware.0f5
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.173
K7 AntiVirus Unwanted-Program ( 004a9d0d1 )
K7GW Unwanted-Program ( 004a9d0d1 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
nProtect Trojan-Clicker/W32.Agent.599400
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec Adware.Crossid
Vba32 AntiVirus Trojan.GoogUpdate
Avira AntiVir ADWARE/CrossRider.Gen2
avast! Win32:Adware-gen [Adw]
Rising Antivirus PE:Malware.Obscure!1.9C59
Fortinet FortiGate Riskware/CrossRider
McAfee Artemis!F5952BC356C8
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Comodo Security ApplicUnwnt
4e36f811-8543-4121-a99a-83d66e982f08-7.exe (MD5: 97b05a95259ae351b105175d5b73fa74) has been flagged by 17 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAG
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.SmartSaver.A
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Rising Antivirus PE:Malware.Obscure!1.9C59
avast! Win32:Adware-gen [Adw]
G Data Win32.Adware.Crossrider.L
Qihoo-360 HEUR/QVM10.1.Malware.Gen
AhnLab-V3 PUP/Win32.CrossRider
Dr.Web Trojan.Crossrider.33433
Zillya Trojan.GoogUpdate.Win32.3136

Startup Entries

Startup tasks:
  • e0895c50-b38e-4f5f-980e-c515788dbc7e-7.exe is automatically launched at startup through a scheduled task named e0895c50-b38e-4f5f-980e-c515788dbc7e-7.
  • e0895c50-b38e-4f5f-980e-c515788dbc7e-6.exe is automatically launched at startup through a scheduled task named e0895c50-b38e-4f5f-980e-c515788dbc7e-6.
  • e0895c50-b38e-4f5f-980e-c515788dbc7e-10.exe is automatically launched at startup through a scheduled task named e0895c50-b38e-4f5f-980e-c515788dbc7e-10_user.
  • 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-5.exe is automatically launched at startup through a scheduled task named 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-5_user.
  • 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-1-6.exe is automatically launched at startup through a scheduled task named 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-14.
  • 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-1-7.exe is automatically launched at startup through a scheduled task named 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-13.

Software Details

URL:
https://crossrider.com/install/48914-smartsaver+-23
Support:
–
Installation path:
C:\Program Files\sm23ms
Uninstaller:
C:\Program Files\Sm23mS\Uninstall.exe /fcp=1
Size:
14.00 MB
Language:
English

Sm23mS Executable Details

Primary executable:
utils.exe
Name:
Sm23mS
Path:
C:\Program Files\sm23ms\utils.exe
MD5:
9be2289c42c19b17ea989369c61d954c
SHA-1:
–
SHA-256:
–
Files installed by Sm23mS
File Type Filename MD5
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
EXE
9be2289c42c19b17ea989369c61d954c
EXE
e55abe718c872d0b912f64456b3dcdea
EXE
d110a28e311da64db032e46ad9b44cac
EXE
b766f2237403c255b3c963d45f05b1c6
EXE
793c842a79e8963c8ee8e15a2c34fbad
EXE
97b05a95259ae351b105175d5b73fa74
EXE
0d9c95e3d7ee4ea9be15f717b7e83432
EXE
851a58447246b013a655970e8e4fe8ba
EXE
6fe3958421d504695de7ccd82b69e191