Sm23mS

Sm23mS

Known Adware

by Robokid Technologies

What is Sm23mS?

Sm23mS is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 64.29% of installations running this operating system. Sm23mS's installer is typically 14.00 MB in size and installs around 206 files. The most common release is 1.36.01.22 with 35.71% of all installations currently using this version.

Sm23mS is most popular in the United States with 44.1% of installations residing in this country.

About Sm23mS?

The Smart-SaverPlus application is an adware that is often bundled with third-party download managers, using misleading advertising tactics to install the software. It is known for modifying browser settings, including altering security configurations, changing the home page, and manipulating the search provider, leading to web browser hijacking. Additionally, the extension sends analytics data to a remote server, capturing user internet activity, visited URLs, displayed advertisements, and clicked links. Smart-SaverPlus is typically included in third-party download manager packages alongside various potentially unwanted programs.

Multiple virus scanners have detected malware in Sm23mS.

utils.exe (MD5: 9be2289c42c19b17ea989369c61d954c) has been flagged by 48 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MulDrop
Bkav FE HW32.CDB
Dr.Web Trojan.Crossrider.27467
G Data NSIS.Adware.Crossrider
IKARUS anti.virus PUA.PlusHD
Malwarebytes PUP.Optional.CrossRider.A
McAfee Artemis!9BE2289C42C1
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious-PKR.O
Rising Antivirus PE:Malware.Obscure!1.9C59
TrendMicro-HouseCall Suspicious_GEN.F47V0803
Lavasoft Ad-Aware Gen:Application.Heur.6v1@mqIxPymO
Antiy-AVL Trojan/NSIS.GoogUpdate.dq
avast! Win32:Crossrider-BR [Adw]
AVG Generic.B92
Avira ADWARE/CrossRider.Gen7
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.AX
Bitdefender Gen:Application.Heur.6v1@mqIxPymO
CAT-QuickHeal PUA.BrightCircle.OD6
Clam AntiVirus Win.Adware.Agent-29337
Comodo Security Application.Win32.Plush.GRI
Cyren W32/A-6583813c!Eldorado
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AX potentially unwanted
Fortinet FortiGate W32/GoogUpdate.AX!tr
F-Prot W32/A-6583813c!Eldorado
F-Secure Gen:Application.Heur.6v1@mqIxPymO
Jiangmin Trojan/NSIS.ahj
K7 AntiVirus Unwanted-Program ( 004afadd1 )
K7GW Unwanted-Program ( 004afadd1 )
Kaspersky Trojan.NSIS.GoogUpdate.dq
MicroWorld-eScan Gen:Application.Heur.6v1@mqIxPymO
NANO AntiVirus Trojan.Win32.GoogUpdate.diimaw
nProtect Trojan/W32.Agent.2004384
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos Generic PUA KD
Symantec PUA.Gen.2
Tencent Trojan.Win32.Qudamah.Gen.6
Trend Micro TROJ_SPNR.11KE14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.4283
ALYac Adware.Crossrider.BW
Emsisoft Anti-Malware Adware.Crossrider.BW (B)
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Agnitum Outpost PUA.Toolbar.CrossRider!
Avira AntiVir ADWARE/CrossRider.Gen2
527a0c99-6959-49e2-b875-a47b92c9fb15-6.exe (MD5: d110a28e311da64db032e46ad9b44cac) has been flagged by 22 scanners:
Scanner Software Result
AVG Berta.0DE
Avira ADWARE/CrossRider.Gen4
AVware Crossrider (fs)
Baidu-International Adware.Win32.CrossAd.77
Clam AntiVirus Win.Trojan.Googupdate-20
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
G Data Win32.Adware.Crossrider.R
Malwarebytes PUP.Optional.SmartSaver.A
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.3292
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
McAfee Artemis!83D8598563A9
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
AhnLab-V3 PUP/Win32.Toolbar
Avira AntiVir ADWARE/CrossRider.Gen2
Sophos AppRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
avast! Win32:Adware-gen [Adw]
Dr.Web Trojan.Crossrider.33433
527a0c99-6959-49e2-b875-a47b92c9fb15-5.exe (MD5: b766f2237403c255b3c963d45f05b1c6) has been flagged by 23 scanners:
Scanner Software Result
AVG Berta.0DE
AVware Crossrider (fs)
Clam AntiVirus Win.Trojan.Googupdate-19
Dr.Web Trojan.Crossrider.35624
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
G Data Win32.Adware.Crossrider.L
Malwarebytes PUP.Optional.SmartSaver.A
NANO AntiVirus Trojan.Win32.Crossrider.dgnkon
Rising Antivirus PE:Malware.Obscure!1.9C59
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.3377
Avira ADWARE/CrossRider.Gen4
Baidu-International Adware.Win32.CrossAd.77
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
McAfee Artemis!83D8598563A9
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
AhnLab-V3 PUP/Win32.Toolbar
Avira AntiVir ADWARE/CrossRider.Gen2
Sophos AppRider
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
avast! Win32:Adware-gen [Adw]
527a0c99-6959-49e2-b875-a47b92c9fb15-11.exe (MD5: 793c842a79e8963c8ee8e15a2c34fbad) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AhnLab-V3 PUP/Win32.CrossRider
AVG Berta.0DE
Avira Adware/CrossRider.gr
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAV
Bitdefender Gen:Variant.Adware.Plush.1
Clam AntiVirus Win.Adware.Agent-14079
Dr.Web Trojan.Crossrider.33790
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
F-Prot W32/A-fe3c301b!Eldorado
F-Secure Gen:Variant.Adware.Plush.1
G Data Gen:Variant.Adware.Plush.1
IKARUS anti.virus Trojan.GoogUpdate
Malwarebytes PUP.Optional.SmartSaver.A
MicroWorld-eScan Gen:Variant.Adware.Plush.1
NANO AntiVirus Trojan.Win32.Crossrider.dfrnkt
Qihoo-360 Win32/Virus.Adware.0f5
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.173
K7 AntiVirus Unwanted-Program ( 004a9d0d1 )
K7GW Unwanted-Program ( 004a9d0d1 )
Kaspersky not-a-virus:AdWare.NSIS.Adwapper.ai
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
nProtect Trojan-Clicker/W32.Agent.599400
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
Symantec Adware.Crossid
Vba32 AntiVirus Trojan.GoogUpdate
Avira AntiVir ADWARE/CrossRider.Gen2
avast! Win32:Adware-gen [Adw]
Rising Antivirus PE:Malware.Obscure!1.9C59
Fortinet FortiGate Riskware/CrossRider
McAfee Artemis!F5952BC356C8
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Comodo Security ApplicUnwnt
4e36f811-8543-4121-a99a-83d66e982f08-7.exe (MD5: 97b05a95259ae351b105175d5b73fa74) has been flagged by 17 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
AVG Generic.332
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAG
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AG
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.SmartSaver.A
Panda Antivirus Trj/Genetic.gen
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Rising Antivirus PE:Malware.Obscure!1.9C59
avast! Win32:Adware-gen [Adw]
G Data Win32.Adware.Crossrider.L
Qihoo-360 HEUR/QVM10.1.Malware.Gen
AhnLab-V3 PUP/Win32.CrossRider
Dr.Web Trojan.Crossrider.33433
Zillya Trojan.GoogUpdate.Win32.3136

Startup Entries

Startup tasks:
  • e0895c50-b38e-4f5f-980e-c515788dbc7e-7.exe is automatically launched at startup through a scheduled task named e0895c50-b38e-4f5f-980e-c515788dbc7e-7.
  • e0895c50-b38e-4f5f-980e-c515788dbc7e-6.exe is automatically launched at startup through a scheduled task named e0895c50-b38e-4f5f-980e-c515788dbc7e-6.
  • e0895c50-b38e-4f5f-980e-c515788dbc7e-10.exe is automatically launched at startup through a scheduled task named e0895c50-b38e-4f5f-980e-c515788dbc7e-10_user.
  • 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-5.exe is automatically launched at startup through a scheduled task named 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-5_user.
  • 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-1-6.exe is automatically launched at startup through a scheduled task named 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-14.
  • 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-1-7.exe is automatically launched at startup through a scheduled task named 9d37329e-ca9a-42c2-b7f4-aa3749cebe1f-13.

Software Details

URL:
https://crossrider.com/install/48914-smartsaver+-23
Support:
–
Installation path:
C:\Program Files\sm23ms
Uninstaller:
C:\Program Files\Sm23mS\Uninstall.exe /fcp=1
Size:
14.00 MB
Language:
English

Sm23mS Executable Details

Primary executable:
utils.exe
Name:
Sm23mS
Path:
C:\Program Files\sm23ms\utils.exe
MD5:
9be2289c42c19b17ea989369c61d954c
SHA-1:
–
SHA-256:
–
Files installed by Sm23mS
File Type Filename MD5
EXE
7b00d48011e02353f56ab68061e266e6
EXE
097521bbfcc13245238f4257de23a920
EXE
025993179c74e1ccb538bee971ff1281
EXE
eeca096d5a6a45da7f25ebf09fd4390d
EXE
a336ea3f43d5e781de9ed9cca6a331f8
EXE
404cb57a897ba82ed41b89be811dd2ac
EXE
2b9af2edd3755e34bd922277268108e6
EXE
8872596480740471562b230600eaedbd
EXE
bb39877329843e8cd14ee5836877e0eb
EXE
b3d7ac6e369f70de96ea4d6426d3304b