SmartSaver+ 3

SmartSaver+ 3

Known Adware

by Robokid Technologies

What is SmartSaver+ 3?

SmartSaver+ 3 is software application developed by Robokid Technologies. It is most commonly found on computers running Windows 7 with nearly 46.02% of installations running this operating system. SmartSaver+ 3's installer is typically 9.00 MB in size and installs around 507 files. The most common release is 1.36.01.22 with 43.81% of all installations currently using this version.

SmartSaver+ 3 is most popular in France with 38.29% of installations residing in this country.

SmartSaver+ 3 adds 2 scheduled tasks to the Windows Task Scheduler launching the program at randomly scheduled times.

About SmartSaver+ 3?

This software serves as an adware that integrates into various web browsers, including Internet Explorer, Chrome, and Firefox, to showcase out-of-context advertising on websites unrelated to the software or its affiliate partners. The displayed advertisements encompass banner and video ads, search-related ads, transitional and in-text ads, and links. The software is programmed to perform periodic self-updates and communicate with a central server for further instructions, additional ad feeds, and user interaction reports, including tracking the user's visited domains and web pages.

Multiple virus scanners have detected malware in SmartSaver+ 3.

utils.exe (MD5: cebffb7feac91f3e86d2d88339744ad2) has been flagged by 48 scanners:
Scanner Software Result
AhnLab-V3 PUP/Win32.MulDrop
avast! Win32:Dropper-gen [Drp]
Baidu-International PUA.Win32.VMDetector.bE
Bkav FE HW32.CDB
ESET-NOD32 a variant of Win32/Packed.VMDetector.E
Malwarebytes PUP.Optional.CrossRider.A
Symantec WS.Reputation
TrendMicro-HouseCall TROJ_GE.969B5901
Lavasoft Ad-Aware Gen:Application.Heur.@u1@muLGWWjO
Agnitum Outpost PUA.Toolbar.CrossRider!
Antiy-AVL GrayWare[WebToolbar:not-a-virus]/Win32.CrossRider.kyc
Arcabit Application.Heur.EC2F6E
AVG Generic.619
Avira ADWARE/CrossRid.bqyp
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.@u1@muLGWWjO
CAT-QuickHeal PUA.BrightCircle.OD6
Clam AntiVirus Win.Trojan.Crossrider-194
Comodo Security ApplicUnwnt
Cyren W32/Application.BVPV-0268
Dr.Web Trojan.Crossrider1.23051
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.@u1@muLGWWjO
G Data Gen:Application.Heur.@u1@muLGWWjO
K7 AntiVirus Unwanted-Program ( 0040f9e41 )
K7GW Unwanted-Program ( 0040f9e41 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kyc
McAfee Artemis!2398D219E37A
McAfee-GW-Edition Artemis!PUP
MicroWorld-eScan Gen:Application.Heur.@u1@muLGWWjO
NANO AntiVirus Trojan.Win32.Crossrider1.dmewph
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Win32/Virus.WebToolbar.44b
Rising Antivirus PE:Malware.Adwapper!6.2370
Sophos AppRider
SUPERAntiSpyware Adware.CrossRider/Variant
Tencent Trojan.Win32.Qudamah.Gen.5
Trend Micro TROJ_GEN.F0C2C00AF15
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.1610
F-Prot W32/S-dbad4651!Eldorado
IKARUS anti.virus Trojan.GoogUpdate
Jiangmin AdWare/NSIS.cuh
nProtect Trojan/W32.Agent.1512864
Vba32 AntiVirus Trojan.GoogUpdate
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Avira AntiVir ADWARE/CrossRider.Gen2
105f1336-109e-4df6-817a-b3fe6a9dc2e5-7.exe (MD5: cf609cb69f7c94f244edf72b56b6ad3f) has been flagged by 41 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Application.Heur.bv1@mqIWJddO
AhnLab-V3 PUP/Win32.Solimba
AVG Generic.95F
Avira ADWARE/CrossRider.Gen4
AVware Crossrider (fs)
Bitdefender Gen:Application.Heur.bv1@mqIWJddO
Dr.Web Trojan.Crossrider.49654
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.BM
Fortinet FortiGate Riskware/CrossRider
F-Secure Gen:Application.Heur.bv1@mqIWJddO
G Data Gen:Application.Heur.bv1@mqIWJddO
K7 AntiVirus Unwanted-Program ( 0040f9a31 )
K7GW Unwanted-Program ( 0040f9a31 )
Kaspersky not-a-virus:WebToolbar.Win32.CrossRider.kti
Malwarebytes PUP.Optional.SmartSaver.A
McAfee Artemis!CF609CB69F7C
McAfee-GW-Edition Artemis
MicroWorld-eScan Gen:Application.Heur.bv1@mqIWJddO
NANO AntiVirus Trojan.Win32.Crossrider.dlljre
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.Malware.Gen
Symantec Trojan.Gen
VIPRE Antivirus Crossrider (fs)
Zillya Adware.CrossRider.Win32.1061
Antiy-AVL Trojan/NSIS.GoogUpdate.dx
avast! Win32:Crossrider-AI [PUP]
F-Prot W32/A-865d81b8!Eldorado
IKARUS anti.virus Trojan.GoogUpdate
Tencent Nsis.Trojan.Googupdate.Piua
Clam AntiVirus Win.Adware.Agent-17584
Emsisoft Anti-Malware Gen:Variant.Adware.Plush.1 (B)
Sophos Generic PUA JN
Baidu-International PUA.Win32.CrossRider.bBN
Comodo Security Application.Win32.Plush.GRI
Vba32 AntiVirus AdWare.Adwapper
Avira AntiVir Adware/CrossRider.A.18728
TrendMicro-HouseCall Suspicious_GEN.F47V0711
Rising Antivirus PE:Malware.Obscure!1.9C59
Kingsoft AntiVirus Win32.Troj.NSIS.ck.(kcloud)
Bkav FE W32.HfsAdware.16D7
Agnitum Outpost PUA.Toolbar.CrossRider!
0d5e438e-eb9f-4ae3-b34b-343a750e00ef-5.exe (MD5: 8f7505c949c55096079ac959b5233705) has been flagged by 37 scanners:
Scanner Software Result
Lavasoft Ad-Aware Gen:Variant.Adware.Kazy.374109
AhnLab-V3 PUP/Win32.CrossRider
Avira AntiVir ADWARE/CrossRider.Gen2
Bitdefender Gen:Variant.Adware.Kazy.374109
Emsisoft Anti-Malware Gen:Variant.Adware.Kazy.374109 (B)
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AH
F-Secure Gen:Variant.Adware.Kazy.374109
G Data Gen:Variant.Adware.Kazy.374109
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Kingsoft AntiVirus Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.SmartSaver.A
MicroWorld-eScan Gen:Variant.Adware.Kazy.374109
Panda Antivirus Trj/Genetic.gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos Generic PUA JF
VIPRE Antivirus Crossrider (fs)
AVG Generic.614
Kaspersky Trojan.NSIS.GoogUpdate.cq
Tencent Nsis.Trojan.Googupdate.Hren
Avira Adware/CrossRider.gr
AVware Crossrider (fs)
McAfee Artemis!98741DAF5663
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Dr.Web Trojan.Crossrider.28285
Fortinet FortiGate W32/GoogUpdate.AJ!tr
F-Prot W32/A-04c00d5a!Eldorado
Qihoo-360 Win32/Trojan.Multi.daf
Bkav FE W32.HfsAdware.16D7
Symantec Trojan.ADH.2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
Baidu-International PUA.Win32.CrossRider.bAK
TrendMicro-HouseCall Suspicious_GEN.F47V0725
Comodo Security ApplicUnwnt
NANO AntiVirus Riskware.Win32.AdLoad.dbtdxq
avast! Win32:Crossrider-AI [PUP]
Agnitum Outpost PUA.Toolbar.CrossRider!
Zillya Adware.AdLoad.Win32.86
0d5e438e-eb9f-4ae3-b34b-343a750e00ef-4.exe (MD5: 3126aa4d7bb9ee656bc57f2f0612afe5) has been flagged by 37 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
Antiy-AVL RiskWare[WebToolbar:not-a-virus]/Win32.CrossRider
AVG Generic.16F
AVware Crossrider (fs)
Baidu-International PUA.Win32.CrossRider.bAK
Dr.Web Trojan.Crossrider.17413
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AK
Fortinet FortiGate Riskware/Toolbar_CrossRider
IKARUS anti.virus AdWare.Adload
Malwarebytes PUP.Optional.SmartSaver.A
Panda Antivirus Trj/Genetic.gen
Sophos Generic PUA HI
Symantec Trojan.ADH.2
TrendMicro-HouseCall Suspicious_GEN.F47V0725
Lavasoft Ad-Aware Trojan.Generic.11445155
Bitdefender Trojan.Generic.11445155
Comodo Security ApplicUnwnt
Emsisoft Anti-Malware Trojan.Generic.11445155 (B)
F-Secure Trojan.Generic.11445155
G Data Trojan.Generic.11445155
MicroWorld-eScan Trojan.Generic.11445155
NANO AntiVirus Riskware.Win32.AdLoad.dbtdxq
VIPRE Antivirus Crossrider (fs)
AhnLab-V3 PUP/Win32.Solimba
avast! Win32:Crossrider-AI [PUP]
Avira ADWARE/CrossRider.Gen4
F-Prot W32/A-73a7935c!Eldorado
Kaspersky Trojan.NSIS.GoogUpdate.dx
Agnitum Outpost PUA.Toolbar.CrossRider!
Qihoo-360 Win32/Virus.Adware.c6c
Kingsoft AntiVirus Win32.Troj.NSIS.cq.(kcloud)
Rising Antivirus PE:Malware.Obscure!1.9C59
Tencent Nsis.Trojan.Googupdate.Pjdo
Bkav FE W32.HfsAdware.4A10
McAfee Artemis!E846B209F6D4
McAfee-GW-Edition BehavesLike.Win32.BadFile.th
Zillya Adware.AdLoad.Win32.86
0d5e438e-eb9f-4ae3-b34b-343a750e00ef-2.exe (MD5: b7bc37e10e715418e96b41d8578e26c7) has been flagged by 18 scanners:
Scanner Software Result
Avira AntiVir ADWARE/CrossRider.Gen2
ESET-NOD32 a variant of Win32/Toolbar.CrossRider.AJ
F-Prot W32/A-eb9ef301!Eldorado
IKARUS anti.virus not-a-virus:WebToolbar.CrossRider
Malwarebytes PUP.Optional.SmartSaver.A
Panda Antivirus Trj/Genetic.gen
Qihoo-360 Malware.QVM10.Gen
Rising Antivirus PE:Malware.Obscure!1.9C59
Sophos AppRider
VIPRE Antivirus Crossrider (fs)
Baidu-International Adware.Win32.CrossRider.BAK
NANO AntiVirus Riskware.Win32.AdLoad.dcasvk
Symantec WS.Reputation.1
Kingsoft AntiVirus Win32.Troj.Generic.v.(kcloud)
Zillya Adware.AdLoad.Win32.86
McAfee Artemis!ABCCB4A7B797
McAfee-GW-Edition Artemis!ABCCB4A7B797
TrendMicro-HouseCall TROJ_GEN.F47V0318

Software Behaviors

Scheduled tasks:
  • 453efbf3-0c1e-4620-97d4-1d97a78d7f40-10.exe is scheduled as a task named 'temp_453efbf3-0c1e-4620-97d4-1d97a78d7f40-10_user'.
  • 8d5b34af-b068-4d01-81b9-d5ad47309383-2.exe is scheduled as a task named '8d5b34af-b068-4d01-81b9-d5ad47309383-2'.

Startup Entries

Startup tasks:
  • cb5904bb-0e1e-4bad-b812-c7ccf4a4e566-5.exe is automatically launched at startup through a scheduled task named cb5904bb-0e1e-4bad-b812-c7ccf4a4e566-5_user.
  • cb5904bb-0e1e-4bad-b812-c7ccf4a4e566-10.exe is automatically launched at startup through a scheduled task named cb5904bb-0e1e-4bad-b812-c7ccf4a4e566-10_user.
  • 592682d2-b084-4dba-aed2-39efe0ee7e54-1-7.exe is automatically launched at startup through a scheduled task named 592682d2-b084-4dba-aed2-39efe0ee7e54-7.
  • 592682d2-b084-4dba-aed2-39efe0ee7e54-6.exe is automatically launched at startup through a scheduled task named 592682d2-b084-4dba-aed2-39efe0ee7e54-6.
  • 592682d2-b084-4dba-aed2-39efe0ee7e54-5.exe is automatically launched at startup through a scheduled task named 592682d2-b084-4dba-aed2-39efe0ee7e54-5_user.
  • 592682d2-b084-4dba-aed2-39efe0ee7e54-11.exe is automatically launched at startup through a scheduled task named 592682d2-b084-4dba-aed2-39efe0ee7e54-3.

Software Details

URL:
–
Support:
–
Installation path:
C:\Program Files\smartsaver+ 3
Uninstaller:
C:\Program Files\SmartSaver+ 3\Uninstall.exe /fcp=1
Size:
9.00 MB
Language:
English

SmartSaver+ 3 Executable Details

Primary executable:
utils.exe
Name:
SmartSaver+ 3
Path:
C:\Program Files\smartsaver+ 3\utils.exe
MD5:
cebffb7feac91f3e86d2d88339744ad2
SHA-1:
–
SHA-256:
–
Files installed by SmartSaver+ 3
File Type Filename MD5
DLL
0900b6c72905788aca613f89fe739bd3
EXE
ab91a7350a5fddcdf0a7b0c60e8e4e71
DLL
5e8e81170731f5521bf540e5e374b011
DLL
06bef001533cc9b2aee78e0315432f94
EXE
cebffb7feac91f3e86d2d88339744ad2
DLL
054eb97126c57f5476abc3c6f8586eab
DLL
55bbde7f48a5ef7a8254bfeb3a5a39d7
DLL
9161b2db6facc5aa59f5eae689ec05af
EXE
adae93314878c5832d4565147c99043b
EXE
6bedc4cf989ebec003eceefb5359715c