Safe Saver

Safe Saver Description

Safe Saver is an adware application that shows pop-up advertisements, sponsored links and coupons via a pop-up box on Amazon, Walmart, Ebay and other shopping websites that are visited by web users. Safe Saver pop-up advertisements will be shwon as boxes, which include a variety of coupons that are available or as underlined keywords, which when clicked will illustrate a pop-up advertisement that declares it is sent to the PC user by Safe Saver. Safe Saver is an add-on for Internet Explorer, Mozilla Firefox and Google Chrome that is usually inserted when Internet users install other free software products, such as download-managers, video recording/streaming or PDF creators, that had packaged into their installation Safe Saver. When Internet users install these free applications, they will also install Safe Saver. While being installed, whenever the PC user will visit Expedia, Best Buy, Facebook or any other similar websites, Safe Saver will show a 'See Similar' button on product images, which when clicked will deliver pop-up ads by Safe Saver. Safe Saver may also display advertising banners on the websites visited by computer users, and as they surf the Internet, Safe Saver will show coupons and other deals available on various websites.
Aliases: a variant of Win32/Toolbar.CrossRider.H [ESET-NOD32], a variant of Win32/Toolbar.CrossRider.I [ESET-NOD32], a variant of Win32/Toolbar.CrossRider.J [ESET-NOD32], Artemis!780958166D99 [McAfee], Artemis!F75B89C57D58 [McAfee], Crossrider (fs) [VIPRE], Generic_r.GS [AVG], probably a variant of Win32/Toolbar.CrossRider.I [ESET-NOD32], Riskware [K7AntiVirus], TROJ_GEN.F47V0925 [TrendMicro-HouseCall], TROJ_GEN.F47V1015 [TrendMicro-HouseCall] and Win32.Troj.Generic.a.(kcloud) [Kingsoft].

Infected with Safe Saver? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect Safe Saver

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of Safe Saver outbreaks and other threats from global to local level.

File System Details

Safe Saver creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\Safe Saver\Safe Saver-codedownloader.exe 478,568 ed4d6b9412cefdb13c7d05c7cd32eddd 803
2 %PROGRAMFILES(x86)%\Safe Saver\Safe Saver-chromeinstaller.exe 464,232 86e74f9f3e742f1d7cb2b776c98d6fb0 724
3 %PROGRAMFILES(x86)%\Safe Saver\Safe Saver-updater.exe 364,392 9d74a2dd342ed0df85eb50af43737cca 710
4 %PROGRAMFILES%\Safe Saver\Safe Saver-firefoxinstaller.exe 725,352 0767b0d339b36bceaff7490b5febcab4 557
5 %PROGRAMFILES%\Safe Saver\Safe Saver-enabler.exe 345,960 f1dc13b88a159a77f7c1081a06cd8342 444
6 %PROGRAMFILES(x86)%\safe saver\safe saver-bg.exe 898,408 f6f0d4b88c9bc35d5424de4977fb806f 244
7 %PROGRAMFILES(x86)%\Safe Saver\Uninstall.exe 120,168 ed421b6c602225c31dcfac61a7381c08 139
8 %PROGRAMFILES%\Safe Saver\Safe Saver-bho.dll 750,952 eab52450ba8469a61bef37c0ec0b34dd 101
9 %TEMP%\is1852162411\safe-saver.exe 4,936,984 a9198d21f5dacafa274b14dca257ea12 72
10 %PROGRAMFILES(x86)%\Safe-Saver App\Safe-Saver App-enabler.exe 348,520 94e89d6f36bda940c0ed106072dacc20 2
11 %PROGRAMFILES(x86)%\Safe-Saver App\Safe-Saver App-firefoxinstaller.exe 891,240 b843e61005fbd81f1aa9c14d489ba15b 2
12 %PROGRAMFILES(x86)%\Safe-Saver App\Safe-Saver App-updater.exe 358,760 9d5c3a5275b31cfdde7fcb7ebd65c4d0 2
13 %PROGRAMFILES(x86)%\Safe-Saver Generic\Safe-Saver Generic-enabler.exe 345,960 1c8a607404c53127cea0219c05037b80 2
14 %PROGRAMFILES(x86)%\Safe-Saver Generic\Safe-Saver Generic-firefoxinstaller.exe 725,352 57943334cf81f3fe0959101d904633eb 2
15 %PROGRAMFILES(x86)%\Safe-Saver Generic\Safe-Saver Generic-updater.exe 364,392 9c122de35a491f00c4615be581b04738 2

More files

Registry Details

Safe Saver creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E1CD9321-6EBD-4166-A38D-269F3A2EB1D7}
SOFTWARE\Wow6432Node\Microsoft\Tracing\SafeSaver_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\SafeSaver_RASMANCS
SOFTWARE\Microsoft\Tracing\SafeSaver_RASAPI32
SOFTWARE\Microsoft\Tracing\SafeSaver_RASMANCS
SOFTWARE\Google\Chrome\Extensions\jmeknddjppjlpinebglbobfkilooocmn
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION, value: Safe-Saver Generic-bg.exe
SOFTWARE\Wow6432Node\Safe-Saver Generic
SOFTWARE\Classes\CrossriderApp0033986.BHO
CrossriderApp0033986.BHO.1
SOFTWARE\Classes\CrossriderApp0033986.BHO.1
CrossriderApp0033986.Sandbox
SOFTWARE\Classes\CrossriderApp0033986.Sandbox
CrossriderApp0033986.Sandbox.1
SOFTWARE\Classes\CrossriderApp0033986.Sandbox.1
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{459aa3cf-13e8-4689-96c3-2fc5daa0660f}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b92280a8-ca3f-4f4c-a144-6b65b7f118c4}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ec7310bd-0746-4544-9447-f13b79929c18}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391186}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391186}
Software\Microsoft\Internet Explorer\Approved Extensions, value: {11111111-1111-1111-1111-110311391186}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311391186}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311391186}
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311391186}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50f8a9d0-e033-49e5-8208-c7994f396162}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{750d0e2c-fbdb-46fa-b1d4-bac41d2ec6fd}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b92280a8-ca3f-4f4c-a144-6b65b7f118c4}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ec7310bd-0746-4544-9447-f13b79929c18}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION, value: Safe-Saver Generic-bg.exe
Software\AppDataLow\Software\Safe-Saver Generic
Software\InstalledBrowserExtensions\Safe Saver
Software\AppDataLow\Software\Crossrider\onBeforeNavigate, value: 33986
Software\AppDataLow\Software\Crossrider\onRequest, value: 33986
Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Safe-Saver App
Software\AppDataLow\Software\Safe-Saver App
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Safe-Saver App
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0312b94b-64d7-4c7f-b9e0-655433f680ef}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BF368B4-F66D-459D-8AC1-4DE6C199569}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D49E934-3559-471F-ADB9-66F586144D73}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A33445DC-D4E5-44C3-AE28-D6AB4CCDD44C}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{edcc3289-cb95-483e-a933-9e5378cdfb80}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F808742B-E236-453B-A05D-4B43DE3E94FF}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0312b94b-64d7-4c7f-b9e0-655433f680ef}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354e33cb-c492-4da6-9962-723814146918}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7134e9ea-9cca-4fca-a1f0-a2912b0accdc}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8280c7d0-0f49-4231-97f5-e20c34422eec}
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Safe-Saver App
SOFTWARE\Safe-Saver App
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9E2F489B-8C31-ECB0-1462-656F1DDDA1A2}
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
SafeSaver
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{11111111-1111-1111-1111-110311391186}
{22222222-2222-2222-2222-220322392286}
{9E2F489B-8C31-ECB0-1462-656F1DDDA1A2}
{E1CD9321-6EBD-4166-A38D-269F3A2EB1D7}
{E22CFB3A-860D-64D7-DE03-7F338DAC5C73}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 13 + 5 ?