Safe Saver

Safe Saver Description

Safe Saver is an adware application that shows pop-up advertisements, sponsored links and coupons via a pop-up box on Amazon, Walmart, Ebay and other shopping websites that are visited by web users. Safe Saver pop-up advertisements will be shwon as boxes, which include a variety of coupons that are available or as underlined keywords, which when clicked will illustrate a pop-up advertisement that declares it is sent to the PC user by Safe Saver. Safe Saver is an add-on for Internet Explorer, Mozilla Firefox and Google Chrome that is usually inserted when Internet users install other free software products, such as download-managers, video recording/streaming or PDF creators, that had packaged into their installation Safe Saver. When Internet users install these free applications, they will also install Safe Saver. While being installed, whenever the PC user will visit Expedia, Best Buy, Facebook or any other similar websites, Safe Saver will show a 'See Similar' button on product images, which when clicked will deliver pop-up ads by Safe Saver. Safe Saver may also display advertising banners on the websites visited by computer users, and as they surf the Internet, Safe Saver will show coupons and other deals available on various websites.

Infected with Safe Saver? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect Safe Saver

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.
Aliases: a variant of Win32/Toolbar.CrossRider.H [ESET-NOD32], a variant of Win32/Toolbar.CrossRider.I [ESET-NOD32], a variant of Win32/Toolbar.CrossRider.J [ESET-NOD32], Artemis!780958166D99 [McAfee], Artemis!F75B89C57D58 [McAfee], Crossrider (fs) [VIPRE], Generic_r.GS [AVG], probably a variant of Win32/Toolbar.CrossRider.I [ESET-NOD32], Riskware [K7AntiVirus], TROJ_GEN.F47V0925 [TrendMicro-HouseCall], TROJ_GEN.F47V1015 [TrendMicro-HouseCall] and Win32.Troj.Generic.a.(kcloud) [Kingsoft].

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of Safe Saver outbreaks and other threats from global to local level.

File System Details

Safe Saver creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES(x86)%\safe saver\safe saver-bg.exe 898,408 f6f0d4b88c9bc35d5424de4977fb806f 571
2 %PROGRAMFILES(x86)%\Safe Saver\Uninstall.exe 120,168 ed421b6c602225c31dcfac61a7381c08 326
3 %PROGRAMFILES%\Safe-Saver App 300
4 %APPDATA%\Safe-Saver App 297
5 %USERPROFILE%\AppData\LocalLow\Safe-Saver App 294
6 %USERPROFILE%\Local Settings\Application Data\Google\Chrome\User Data\Default\Local Extension Settings\gdecomoeoinffmfpcihlmacjmlnjfbgm 290
7 %LOCALAPPDATA%\Google\Chrome\User Data\Default\Local Extension Settings\gdecomoeoinffmfpcihlmacjmlnjfbgm 287
8 %PROGRAMFILES%\Safe Saver\Safe Saver-bho.dll 750,952 eab52450ba8469a61bef37c0ec0b34dd 237
9 %TEMP%\is1852162411\safe-saver.exe 4,936,984 a9198d21f5dacafa274b14dca257ea12 225
10 %ALLUSERSPROFILE%\Application Data\SafeSaver 175
11 %PROGRAMFILES%\Safe Saver\Safe Saver-codedownloader.exe 478,568 ed4d6b9412cefdb13c7d05c7cd32eddd 1,881
12 %PROGRAMFILES(x86)%\Safe Saver\Safe Saver-chromeinstaller.exe 464,232 86e74f9f3e742f1d7cb2b776c98d6fb0 1,696
13 %PROGRAMFILES(x86)%\Safe Saver\Safe Saver-updater.exe 364,392 9d74a2dd342ed0df85eb50af43737cca 1,663
14 %PROGRAMFILES%\Safe Saver\Safe Saver-firefoxinstaller.exe 725,352 0767b0d339b36bceaff7490b5febcab4 1,305
15 %PROGRAMFILES%\Safe Saver\Safe Saver-enabler.exe 345,960 f1dc13b88a159a77f7c1081a06cd8342 1,040

More files

Registry Details

Safe Saver creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
CrossriderApp0033986.BHO.1
CrossriderApp0033986.Sandbox
CrossriderApp0033986.Sandbox.1
Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Safe-Saver App
Software\AppDataLow\Software\Crossrider\onBeforeNavigate, value: 33986
Software\AppDataLow\Software\Crossrider\onRequest, value: 33986
Software\AppDataLow\Software\Safe-Saver App
Software\AppDataLow\Software\Safe-Saver Generic
SOFTWARE\Classes\CrossriderApp0033986.BHO
SOFTWARE\Classes\CrossriderApp0033986.BHO.1
SOFTWARE\Classes\CrossriderApp0033986.Sandbox
SOFTWARE\Classes\CrossriderApp0033986.Sandbox.1
Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\windows_ie_ac_001\Software\Safe-Saver App
SOFTWARE\Google\Chrome\Extensions\jmeknddjppjlpinebglbobfkilooocmn
Software\InstalledBrowserExtensions\Safe Saver
Software\Microsoft\Internet Explorer\Approved Extensions, value: {11111111-1111-1111-1111-110311391186}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0312b94b-64d7-4c7f-b9e0-655433f680ef}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2BF368B4-F66D-459D-8AC1-4DE6C199569}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2D49E934-3559-471F-ADB9-66F586144D73}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{459aa3cf-13e8-4689-96c3-2fc5daa0660f}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A33445DC-D4E5-44C3-AE28-D6AB4CCDD44C}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b92280a8-ca3f-4f4c-a144-6b65b7f118c4}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ec7310bd-0746-4544-9447-f13b79929c18}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{edcc3289-cb95-483e-a933-9e5378cdfb80}
Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F808742B-E236-453B-A05D-4B43DE3E94FF}
SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION, value: Safe-Saver Generic-bg.exe
SOFTWARE\Microsoft\Tracing\SafeSaver_RASAPI32
SOFTWARE\Microsoft\Tracing\SafeSaver_RASMANCS
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110311391186}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311391186}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110311391186}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110311391186}
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Safe-Saver App
SOFTWARE\Safe-Saver App
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0312b94b-64d7-4c7f-b9e0-655433f680ef}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{354e33cb-c492-4da6-9962-723814146918}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{50f8a9d0-e033-49e5-8208-c7994f396162}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7134e9ea-9cca-4fca-a1f0-a2912b0accdc}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{750d0e2c-fbdb-46fa-b1d4-bac41d2ec6fd}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8280c7d0-0f49-4231-97f5-e20c34422eec}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{b92280a8-ca3f-4f4c-a144-6b65b7f118c4}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ec7310bd-0746-4544-9447-f13b79929c18}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION, value: Safe-Saver Generic-bg.exe
SOFTWARE\Wow6432Node\Microsoft\Tracing\SafeSaver_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\SafeSaver_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110311391186}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E1CD9321-6EBD-4166-A38D-269F3A2EB1D7}
SOFTWARE\Wow6432Node\Safe-Saver Generic
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
SafeSaver
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{22222222-2222-2222-2222-220322392286}
{11111111-1111-1111-1111-110311391186}
{E22CFB3A-860D-64D7-DE03-7F338DAC5C73}
{E1CD9321-6EBD-4166-A38D-269F3A2EB1D7}
{9BC1C7D4-6E74-F49C-FC3B-0C159553235E}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 14 + 15 ?