SmartSaver+ 15

SmartSaver+ 15

Known Adware

by Robokid Technologies

What is SmartSaver+ 15?

SmartSaver+ 15 is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 48.86% of installations running this operating system. SmartSaver+ 15's installer is typically 10.00 MB in size and installs around 765 files. The most common release is 1.35.9.29 with 22.35% of all installations currently using this version.

SmartSaver+ 15 is most popular in United Kingdom with 23.53% of installations residing in this country.

SmartSaver+ 15 adds 6 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About SmartSaver+ 15?

This software is designed to inject adware into various web browsers, including Internet Explorer, Chrome, and Firefox. Once installed, it presents out-of-context advertisements on websites unrelated to the software or its partners. These advertisements come in various forms such as banners, video ads, search-related ads, transitional and in-text ads, and links. Additionally, the software is designed to regularly update itself and reach out to a central server for further instructions, additional ad content, and reporting the user's interactions and visited domains and web pages.

Multiple virus scanners have detected malware in SmartSaver+ 15.

243b4397-7faa-44d1-8490-96b781d845c2-4.exe (MD5: 20790fcc116b59ef46f6f8fdd946c8c7) has been flagged by 27 scanners:
Scanner Software Result
AVG Generic.614
AVware Crossrider (fs)
Dr.Web Trojan.Crossrider.27830
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Kaspersky Trojan.NSIS.GoogUpdate.cq
Malwarebytes PUP.Optional.SmartSaver.A
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Symantec WS.Reputation.1
Tencent Nsis.Trojan.Googupdate.Hoon
VIPRE Antivirus Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAR
G Data Win32.Adware.Crossrider.L
McAfee Artemis!3AFE809AD173
McAfee-GW-Edition BehavesLike.Win32.BadFile.dh
Rising Antivirus PE:Malware.Obscure!1.9C59
AhnLab-V3 PUP/Win32.CrossRider
Avira Adware/CrossRider.pm
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
F-Prot W32/A-9e906728!Eldorado
Avira AntiVir Adware/CrossRider.A.20561
IKARUS anti.virus AdWare.Adload
TrendMicro-HouseCall Suspicious_GEN.F47V0716
Clam AntiVirus Win.Adware.Agent-7722
NANO AntiVirus Riskware.Win32.AdLoad.dbotua
avast! Win32:Crossrider-AI [PUP]
Sophos AppRider
243b4397-7faa-44d1-8490-96b781d845c2-2.exe (MD5: 76f0227d4944f8ab2ab0325e43222d7c) has been flagged by 44 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL Trojan/NSIS.GoogUpdate
avast! Win32:Crossrider-AG [PUP]
AVG Generic.614
Avira Adware/CrossRider.pm
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAJ
CAT-QuickHeal Trojan.NSIS.r5
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27656
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate W32/GoogUpdate.AJ!tr
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.L
K7 AntiVirus Unwanted-Program ( 004a9d051 )
K7GW Unwanted-Program ( 004a9d051 )
Kaspersky Trojan.NSIS.GoogUpdate.cq
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!76F0227D4944
McAfee-GW-Edition BehavesLike.Win32.BadFile.fh
NANO AntiVirus Trojan.Win32.Crossrider.ddpegn
nProtect Trojan/W32.Agent.367472
Qihoo-360 HEUR/Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA KI
Symantec Adware.Crossid!gen1
Tencent Nsis.Trojan.Googupdate.Akpc
Trend Micro TROJ_SPNV.03HR14
TrendMicro-HouseCall TROJ_SPNV.03HR14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.99
Clam AntiVirus Win.Trojan.Crossrider-92
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
Bitdefender Gen:Variant.Adware.Plush.1
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Secure Gen:Variant.Adware.Plush.1
IKARUS anti.virus Trojan.GoogUpdate
MicroWorld-eScan Gen:Variant.Adware.Plush.1
Panda Antivirus Trj/Genetic.gen
Jiangmin AdWare/NSIS.cnw
Avira AntiVir ADWARE/CrossRider.Gen2
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
243b4397-7faa-44d1-8490-96b781d845c2-11.exe (MD5: ac75f7e292409b16504022dc71a12142) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AP [PUP]
AVG Generic.614
Avira Adware/CrossRider.pm
AVware Crossrider (fs)
Baidu-International Adware.Win32.GoogUpdate.aGk
Bitdefender Gen:Variant.Adware.Plush.1
CAT-QuickHeal Trojan.NSIS.g5
Clam AntiVirus Win.Adware.Agent-8243
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.27650
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/A-36036ca5!Eldorado
F-Secure Gen:Variant.Adware.Plush.1
G Data Gen:Variant.Adware.Plush.1
IKARUS anti.virus not-a-virus:AdWare.Adwapper
K7 AntiVirus Trojan ( 0049ee4a1 )
K7GW Unwanted-Program ( 004a9d0c1 )
Kaspersky Trojan.NSIS.GoogUpdate.cq
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!AC75F7E29240
McAfee-GW-Edition BehavesLike.Win32.PUP.th
MicroWorld-eScan Gen:Variant.Adware.Plush.1
NANO AntiVirus Trojan.Win32.GoogUpdate.ddylsi
nProtect Trojan/W32.Agent.1920368
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos Generic PUA DO
Symantec Adware.BL
Tencent Nsis.Trojan.Googupdate.Lorl
Trend Micro TROJ_SPNV.03HR14
TrendMicro-HouseCall TROJ_SPNV.03HR14
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.76
Agnitum Outpost PUA.Adwapper!
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/NSIS.Adwapper.df
Arcabit Application.Heur.EFD1C6
Bkav FE W32.HfsAdware.422B
Cyren W32/AdLoad.AK2.gen!Eldorado
Jiangmin AdWare/NSIS.dhb
Panda Antivirus Trj/Genetic.gen
SUPERAntiSpyware Adware.CrossRider/Variant
Rising Antivirus PE:Malware.Adwapper!6.214C
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
ALYac Gen:Variant.Adware.Kazy.133004
Avira AntiVir ADWARE/CrossRider.Gen2
241d9d1f-59c6-4bf2-af54-60b6bdd388dc-11.exe (MD5: 6cef64b372336a8fcc1aa3e0821280d2) has been flagged by 50 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.3v0@mm6sBVcO
AhnLab-V3 PUP/Win32.CrossRider
Antiy-AVL RiskWare[WebToolbar]/Win32.CrossRider.agq
Arcabit Application.Heur.EBC173
avast! Win32:Crossrider-AP [PUP]
AVG Crossrider.TT
Avira ADWARE/CrossRider.gr
Baidu-International Adware.Win32.CrossAd.AK
Bitdefender Gen:Application.Heur.3v0@mm6sBVcO
CAT-QuickHeal PUA.GoogleUpdate.A5
Comodo Security Application.Win32.CrossRider.KVA
Cyren W32/AdLoad.AK2.gen!Eldorado
Dr.Web Trojan.Crossrider.28208
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK potentially unwanted
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/AdLoad.AK2.gen!Eldorado
F-Secure Gen:Application.Heur.3v0@mm6sBVcO
G Data Gen:Application.Heur.3v0@mm6sBVcO
IKARUS anti.virus AdWare.Adwapper
Jiangmin Adware/Adload.dsu
K7 AntiVirus Trojan ( 0049c2a41 )
K7GW Trojan ( 0049c2a41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.agq
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!6CEF64B37233
McAfee-GW-Edition BehavesLike.Win32.AdwareCross.th
MicroWorld-eScan Gen:Application.Heur.3v0@mm6sBVcO
NANO AntiVirus Riskware.Win32.AdLoad.dcajje
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Rising Antivirus PE:Malware.Adwapper!6.23CE
SUPERAntiSpyware Adware.CrossRider/Variant
Symantec Adware.Crossid
Tencent Win32.Adware.Bp-browser.Luqs
Trend Micro TROJ_GEN.R047C0OA815
VIPRE Antivirus Crossrider (fs)
Agnitum Outpost PUA.Toolbar.CrossRider!
AVware Crossrider (fs)
Bkav FE W32.HfsAdware.BDE5
Sophos Generic PUA LJ
TrendMicro-HouseCall TROJ_GEN.R047C0OB915
Zillya Adware.CrossRider.Win32.2389
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.132996 (B)
ALYac Gen:Variant.Adware.Kazy.133004
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Clam AntiVirus Win.Adware.Agent-11250
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
nProtect Trojan-Clicker/W32.Agent.2004448
Vba32 AntiVirus Trojan.GoogUpdate
Avira AntiVir ADWARE/CrossRider.Gen2
23410e8c-686e-4faa-a947-5bcd9b352a53-7.exe (MD5: 30afb362e469a3bb3a97acf1265411fa) has been flagged by 43 scanners:
Scanner Software Result
Antiy-AVL Trojan/Win32.TGeneric
avast! Win32:Crossrider-AI [PUP]
AVG Generic.B92
Avira ADWARE/CrossRider.Gen
Baidu-International Adware.Win32.CrossAd.77
Comodo Security ApplicUnwnt
Dr.Web Trojan.Crossrider.37589
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AY
Fortinet FortiGate Riskware/CrossRider
F-Prot W32/A-1a27c920!Eldorado
G Data Win32.Adware.Crossrider.R
IKARUS anti.virus Trojan.GoogUpdate
K7GW Unwanted-Program ( 004afae01 )
Kaspersky Trojan.NSIS.GoogUpdate.dq
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!30AFB362E469
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
NANO AntiVirus Trojan.Win32.Crossrider.dhzlub
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Sophos Generic PUA PM
Symantec WS.Reputation.1
Tencent Nsis.Trojan.Googupdate.Liqx
TrendMicro-HouseCall Suspicious_GEN.F47V1109
Vba32 AntiVirus Trojan.GoogUpdate
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.403
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.1
AVware Crossrider (fs)
Bitdefender Gen:Variant.Adware.Plush.1
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Secure Gen:Variant.Adware.Plush.1
K7 AntiVirus Trojan ( 004af2de1 )
MicroWorld-eScan Gen:Variant.Adware.Plush.1
Clam AntiVirus Win.Adware.Plush-58
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Rising Antivirus PE:Trojan.Win32.Generic.1709D60A!386520586
CAT-QuickHeal Trojan.NSIS.r5
nProtect Trojan/W32.Agent.1129376
Microsoft Security Essentials BrowserModifier:Win32/IeEnablerCby
Trend Micro TROJ_GEN.R0C1C0OJV14

Software Behaviors

Scheduled tasks:
  • 8a438fca-7602-431b-861e-b7fcf29ba3bd.exe is scheduled as a task named 'temp_8a438fca-7602-431b-861e-b7fcf29ba3bd'.
  • 1fa9923d-ab7b-43e7-aee9-2ade727b6b97-11.exe is scheduled as a task named '1fa9923d-ab7b-43e7-aee9-2ade727b6b97-3'.
  • 916a028c-c71c-498c-8bc0-ff59580dd93d-6.exe is scheduled as a task named 'temp_916a028c-c71c-498c-8bc0-ff59580dd93d-6'.
  • 916a028c-c71c-498c-8bc0-ff59580dd93d-1-6.exe is scheduled as a task named 'temp_916a028c-c71c-498c-8bc0-ff59580dd93d-1-6'.
  • dfe99f8c-192d-47d0-96e7-675488880cca-6.exe is scheduled as a task named 'temp_dfe99f8c-192d-47d0-96e7-675488880cca-6'.
  • dfe99f8c-192d-47d0-96e7-675488880cca-4.exe is scheduled as a task named 'dfe99f8c-192d-47d0-96e7-675488880cca-4'.

Startup Entries

Startup tasks:
  • c8a24c07-fdd9-4ee1-83c0-59cad257aa8f-7.exe is automatically launched at startup through a scheduled task named c8a24c07-fdd9-4ee1-83c0-59cad257aa8f-1.
  • c8a24c07-fdd9-4ee1-83c0-59cad257aa8f-11.exe is automatically launched at startup through a scheduled task named c8a24c07-fdd9-4ee1-83c0-59cad257aa8f-3.
  • bb165547-2994-4803-9ab8-5816e270d924-7.exe is automatically launched at startup through a scheduled task named bb165547-2994-4803-9ab8-5816e270d924-1.
  • bb165547-2994-4803-9ab8-5816e270d924-6.exe is automatically launched at startup through a scheduled task named bb165547-2994-4803-9ab8-5816e270d924-6.
  • bb165547-2994-4803-9ab8-5816e270d924-5.exe is automatically launched at startup through a scheduled task named bb165547-2994-4803-9ab8-5816e270d924-5_user.
  • bb165547-2994-4803-9ab8-5816e270d924-11.exe is automatically launched at startup through a scheduled task named bb165547-2994-4803-9ab8-5816e270d924-11.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\smartsaver+ 15
Uninstaller:
C:\Program Files\SmartSaver+ 15\Uninstall.exe /fcp=1
Size:
10.00 MB
Language:
English

SmartSaver+ 15 Executable Details

Primary executable:
utils.exe
Name:
SmartSaver+ 15
Path:
C:\Program Files\smartsaver+ 15\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by SmartSaver+ 15
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
a0bdc8051a740904d9e5f24d697f6875
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
20790fcc116b59ef46f6f8fdd946c8c7
EXE
76f0227d4944f8ab2ab0325e43222d7c