SmartSaver+ 21

SmartSaver+ 21

Known Adware

by Robokid Technologies

What is SmartSaver+ 21?

SmartSaver+ 21 is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 48.44% of installations running this operating system. SmartSaver+ 21's installer is typically 12.00 MB in size and installs around 549 files. The most common release is 1.36.01.22 with 35.16% of all installations currently using this version.

SmartSaver+ 21 is most popular in the United States with 59.76% of installations residing in this country.

SmartSaver+ 21 adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About SmartSaver+ 21?

This ad-supported software integrates with the user's web browsers (including IE, Chrome, and Firefox) and presents advertisements that are unrelated to the software or its affiliates on various websites. The advertisements may manifest as banner and video ads, search-related ads, transitional and in-text ads, as well as links. Additionally, the software will regularly update itself and communicate with a central server to receive instructions, deliver additional ad content, and report user interactions with the software, including the domains and web pages visited.

Multiple virus scanners have detected malware in SmartSaver+ 21.

1742240a-11bc-4595-b4b1-9d1197b9d0bb-7.exe (MD5: 26d6235ece9626add794e458b2a3925f) has been flagged by 40 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pm
Antiy-AVL Trojan/NSIS.GoogUpdate
AVG Generic.614
AVware Crossrider (fs)
Baidu-International Adware.Win32.GoogUpdate.ApO
Dr.Web Trojan.Crossrider.29515
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate W32/GoogUpdate.AJ!tr
IKARUS anti.virus AdWare.Adload
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!26D6235ECE96
NANO AntiVirus Trojan.Win32.Crossrider.debuln
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.cf5
Sophos Generic PUA JM
Tencent Nsis.Trojan.Googupdate.Htco
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.555
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374062
Bitdefender Gen:Variant.Adware.Kazy.374062
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374062 (B)
F-Secure Gen:Variant.Adware.Kazy.374062
G Data Gen:Variant.Adware.Kazy.374062
Kaspersky Trojan.NSIS.GoogUpdate.cq
MicroWorld-eScan Gen:Variant.Adware.Kazy.374062
Symantec PUA.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Avira Adware/CrossRider.pm
Clam AntiVirus Win.Trojan.Crossrider-49
K7 AntiVirus Unwanted-Program ( 004a9d061 )
K7GW Unwanted-Program ( 004a9d061 )
Vba32 AntiVirus Trojan.GoogUpdate
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Adware-gen [Adw]
McAfee-GW-Edition Artemis!EAEA2B7F4B92
Comodo Security Application.Win32.Plush.GRI
F-Prot W32/S-95be3f30!Eldorado
TrendMicro-HouseCall Suspicious_GEN.F47V0818
ALYac Gen:Variant.Adware.Kazy.133003
1742240a-11bc-4595-b4b1-9d1197b9d0bb-6.exe (MD5: 5eafb94edd965afbb4237fffea12c19e) has been flagged by 44 scanners:
Scanner Software Result
AhnLab-V3 Win-PUP/CrossRider
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
avast! Win32:Crossrider-AM [PUP]
AVG Generic.614
Avira Adware/CrossRider.pm
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.BAJ
CAT-QuickHeal Trojan.NSIS.r6
Comodo Security ApplicUnwnt
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AV
Fortinet FortiGate W32/GoogUpdate.AJ!tr
F-Prot W32/A-04c00d5a!Eldorado
G Data Win32.Adware.Crossrider.N
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Unwanted-Program ( 004a9d061 )
Kaspersky Trojan.NSIS.GoogUpdate.cq
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!5EAFB94EDD96
McAfee-GW-Edition BehavesLike.Win32.Trojan.jh
NANO AntiVirus Riskware.Win32.Crossrider.dejvwu
Qihoo-360 Win32/Trojan.cf5
Sophos AppRider
Symantec Trojan.Gen.2
Tencent Nsis.Trojan.Googupdate.Szvz
Trend Micro TROJ_GEN.R0C1C0EJO14
TrendMicro-HouseCall TROJ_GEN.R0C1C0EJO14
Vba32 AntiVirus AdWare.Adwapper
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.561
Dr.Web Trojan.Crossrider.32873
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Trojan.Win32.Generic.1754885B!391415899
Lavasoft Ad-Aware Gen:Application.Heur.8u1@myxTQRiO
Bitdefender Gen:Application.Heur.8u1@myxTQRiO
Cyren W32/Application.XBTO-6597
F-Secure Gen:Application.Heur.8u1@myxTQRiO
MicroWorld-eScan Gen:Application.Heur.8u1@myxTQRiO
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
IKARUS anti.virus Trojan.GoogUpdate
nProtect Trojan/W32.Agent.388464.D
Avira AntiVir Adware/CrossRider.pm
Clam AntiVirus Win.Adware.Agent-11250
ALYac Gen:Variant.Adware.Kazy.133003
1742240a-11bc-4595-b4b1-9d1197b9d0bb-5.exe (MD5: e4173c13c61fcf1d99df3748ab005b47) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.2
Avira AntiVir Adware/CrossRider.pm
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
AVG Generic.614
AVware Crossrider (fs)
Baidu-International Adware.Win32.GoogUpdate.AX
Bitdefender Gen:Variant.Adware.Plush.2
Dr.Web Trojan.Crossrider.29496
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
Fortinet FortiGate W32/GoogUpdate.AH!tr
F-Secure Gen:Variant.Adware.Plush.2
G Data Gen:Variant.Adware.Plush.2
IKARUS anti.virus AdWare.Adload
Kaspersky Trojan.NSIS.GoogUpdate.cq
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!E4173C13C61F
MicroWorld-eScan Gen:Variant.Adware.Plush.2
NANO AntiVirus Trojan.Win32.GoogUpdate.debbyh
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.48c
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA MK
Tencent Nsis.Trojan.Googupdate.Ahed
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.573
Avira Adware/CrossRider.pm
Comodo Security ApplicUnwnt
F-Prot W32/S-9ad4719b!Eldorado
K7 AntiVirus Trojan ( 0049ee4f1 )
K7GW Trojan ( 0049ee4f1 )
McAfee-GW-Edition BehavesLike.Win32.BadFile.hh
Symantec WS.Reputation.1
Vba32 AntiVirus AdWare.Adwapper
AhnLab-V3 PUP/Win32.CrossRider
TrendMicro-HouseCall Suspicious_GEN.F47V0818
Clam AntiVirus Win.Adware.Agent-11250
avast! Win32:Crossrider-AP [PUP]
nProtect Trojan/W32.Agent.623984
ALYac Gen:Variant.Adware.Kazy.133003
1742240a-11bc-4595-b4b1-9d1197b9d0bb-4.exe (MD5: a8b388862643c4fac3368cff1ab15c3f) has been flagged by 40 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pm
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
AVG Generic.614
AVware Crossrider (fs)
Baidu-International Adware.Win32.GoogUpdate.Ayr
Dr.Web Trojan.Crossrider.29508
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate W32/GoogUpdate.AK!tr
IKARUS anti.virus AdWare.Adload
Kaspersky Trojan.NSIS.GoogUpdate.cq
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!A8B388862643
McAfee-GW-Edition Artemis!A8B388862643
NANO AntiVirus Riskware.Win32.Crossrider.dechyc
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.48c
Sophos Generic PUA II
Tencent Nsis.Trojan.Googupdate.Lorj
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.553
avast! Win32:Crossrider-N [PUP]
Avira ADWARE/CrossRider.Gen2
F-Prot W32/S-9ad4719b!Eldorado
G Data Win32.Adware.Crossrider.L
K7 AntiVirus Unwanted-Program ( 004a9d051 )
K7GW Unwanted-Program ( 004a9d051 )
Rising Antivirus PE:Malware.Obscure!1.9C59
Symantec Trojan.ADH.2
Vba32 AntiVirus Trojan.GoogUpdate
Lavasoft Ad-Aware Gen:Variant.Adware.Plush.2
Bitdefender Gen:Variant.Adware.Plush.2
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.2 (B)
F-Secure Gen:Variant.Adware.Plush.2
MicroWorld-eScan Gen:Variant.Adware.Plush.2
AhnLab-V3 PUP/Win32.CrossRider
TrendMicro-HouseCall Suspicious_GEN.F47V0818
Clam AntiVirus Win.Trojan.Crossrider-49
Comodo Security Application.Win32.Plush.GRI
ALYac Gen:Variant.Adware.Kazy.133003
1742240a-11bc-4595-b4b1-9d1197b9d0bb-2.exe (MD5: 366e0ba7131b57a834d665617a8eb665) has been flagged by 41 scanners:
Scanner Software Result
Avira AntiVir Adware/CrossRider.pm
Antiy-AVL GrayWare[AdWare:not-a-virus]/NSIS.Adwapper
AVG Generic.614
AVware Crossrider (fs)
Baidu-International Adware.Win32.GoogUpdate.aMp
Dr.Web Trojan.Crossrider.29569
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
Fortinet FortiGate W32/GoogUpdate.AJ!tr
G Data Win32.Trojan.Agent.MX8JCV
IKARUS anti.virus AdWare.Adload
Kaspersky Trojan.NSIS.GoogUpdate.cq
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!366E0BA7131B
NANO AntiVirus Trojan.Win32.Crossrider.debuqj
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Trojan.cf5
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA PE
Symantec Adware.Crossid!gen1
Tencent Nsis.Trojan.Googupdate.Ljko
VIPRE Antivirus Crossrider (fs)
Zillya Trojan.GoogUpdate.Win32.556
Lavasoft Ad-Aware Gen:Application.Heur.cv1@kyl5t5jO
AhnLab-V3 PUP/Win32.CrossRider
avast! Win32:Crossrider-AH [PUP]
Avira Adware/CrossRider.KI
Bitdefender Gen:Application.Heur.cv1@kyl5t5jO
Clam AntiVirus Win.Adware.Agent-32777
F-Secure Gen:Application.Heur.cv1@kyl5t5jO
K7 AntiVirus Unwanted-Program ( 0040f9ae1 )
K7GW Unwanted-Program ( 0040f9ae1 )
MicroWorld-eScan Gen:Application.Heur.cv1@kyl5t5jO
Comodo Security Application.Win32.Plush.GRI
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
F-Prot W32/A-1a27c920!Eldorado
McAfee-GW-Edition BehavesLike.Win32.Dropper.th
nProtect Trojan/W32.Agent.623984
Vba32 AntiVirus AdWare.Adwapper
TrendMicro-HouseCall Suspicious_GEN.F47V0115
ALYac Gen:Variant.Adware.Kazy.133003

Software Behaviors

Scheduled tasks:
  • 93f3155b-b7c5-49a8-96ec-2babd72e7947-1-7.exe is scheduled as a task named '93f3155b-b7c5-49a8-96ec-2babd72e7947-1-7'.
  • db15ed2f-870f-45cc-bdc9-aee6504fbc9d-6.exe is scheduled as a task named 'temp_db15ed2f-870f-45cc-bdc9-aee6504fbc9d-6'.

Startup Entries

Startup tasks:
  • e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-1-7.exe is automatically launched at startup through a scheduled task named e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-7.
  • e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-6.exe is automatically launched at startup through a scheduled task named e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-6.
  • e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-5.exe is automatically launched at startup through a scheduled task named e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-5_user.
  • e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-4.exe is automatically launched at startup through a scheduled task named e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-4.
  • e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-10.exe is automatically launched at startup through a scheduled task named e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-10_user.
  • e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-1-6.exe is automatically launched at startup through a scheduled task named e21b96d5-08da-4d05-aebd-f64b4a4dcf0a-1-6.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\smartsaver+ 21
Uninstaller:
C:\Program Files\SmartSaver+ 21\Uninstall.exe /fcp=1
Size:
12.00 MB
Language:
English

SmartSaver+ 21 Executable Details

Primary executable:
utils.exe
Name:
SmartSaver+ 21
Path:
C:\Program Files\smartsaver+ 21\utils.exe
MD5:
–
SHA-1:
–
SHA-256:
–
Files installed by SmartSaver+ 21
File Type Filename MD5
EXE
cd43c24cdafc4aed47511e42e6e98938
EXE
c5250f89bfac37aaac85dea1444edc16
EXE
6254fa55afe1141502c8b0a23c6ae0b2
EXE
c721a9b40d1890ba0dd4f143b145b99a
EXE
0d06c14b4c93c8967b8e17ed9b15597a
EXE
5e85b0fcefbc07371aee2f36c4f21d76
EXE
bbfaf2efc3f35766d17e25440b2b0946
EXE
18f527e3d687e86b059a5d9e9b0c142e
EXE
500e5138e2f8e570b68213d6648b152e
EXE
2f2d06f76ed867d0b4a73331666d6981