SaveShare

SaveShare Description

SaveShare is an adware application that shows a variety of irritating pop-up advertisements on the compromised PC while the target Internet user is surfing the Internet. SaveShare can access Internet Explorer, Mozilla Firefox and Google Chrome Internet browsers. When SaveShare corrupts the contaminated computer system, it will show random pop-up advertisements while the PC user is surfing mostly shopping websites, such as Amazon, eBay or some other well-known websites, such as Facebook, Youtube, and other. If the victimized PC user clicks on these pop-up advertisements, he/she will be rerouted to some unidentified advertisement websites. The main goal of SaveShare is to raise traffic of these doubtful advertisement websites. Saveshare penetrates into corrupted PCs packaged with other applications. Computer users can evade this if they are attentive enough while installing other applications and unmarking all options to install extra unidentified tools. However, many computer users often skip the steps of installation simply because of a rush. SaveShare can grab information about the victimized PC user's browsing habits. SaveShare can then transmit this data to the third parties and use it for a variety of marketing associated aims.
Aliases: a variant of Win32/Adware.MultiPlug.I [ESET-NOD32], Adware.Win32.MultiPlug.I [Baidu-International], AdWare.Win32.Plugie.a [Rising], ApplicUnwnt [Comodo], Artemis!E9B27306A18F [McAfee], Generic5.AFXS [AVG], HW32.Laneul.tesi [Bkav], PUP.Optional.MultiPlug.A [Malwarebytes], Trojan.Win32.Generic!BT [VIPRE], Win32.Troj.Generic.a.(kcloud) [Kingsoft] and Win32:BHO-AML [Spy] [Avast].

Infected with SaveShare? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect SaveShare

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of SaveShare outbreaks and other threats from global to local level.

File System Details

SaveShare creates the following file(s):
# File Name Size MD5 Detection Count
1 %ALLUSERSPROFILE%\Application Data\saveanShaare 91
2 %ALLUSERSPROFILE%\Application Data\saveaNshare 83
3 %ALLUSERSPROFILE%\Siaveensharee\O1.dll 227,328 e9b27306a18f18b88945cdf066de2fc9 63
4 %ALLUSERSPROFILE%\Application Data\saveeNshare 56
5 %ALLUSERSPROFILE%\Application Data\saevenshAre 54
6 %ALLUSERSPROFILE%\Application Data\saavenishare 52
7 %ALLUSERSPROFILE%\Application Data\savensharre 47
8 %ALLUSERSPROFILE%\Application Data\saVeensshare 27
9 %ALLUSERSPROFILE%\Application Data\SavennsHaRe 23
10 %ALLUSERSPROFILE%\Application Data\sauveeNshiare 16
11 %ALLUSERSPROFILE%\Application Data\Microsoft\Windows\Start Menu\Programs\sauveeNshiare 14
12 %ALLUSERSPROFILE%\Application Data\sAvenshhaaree 7
13 %AllUsersProfile%\Application Data\saVenshaare! 6
14 %AllUsersProfile%\Application Data\savenshare 4
15 %ALLUSERSPROFILE%\saveNshaaarE.\KWqYQ4M.exe 342,016 8300c91b40229b42301aebc6d8859907 2

More files

Registry Details

SaveShare creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
Classes\saviENshare..saviENshare..5.10
i.ssaivenshare
saVensshare.saVensshare
saVensshare.saVensshare.5.10
saviENshare..saviENshare.
savueinshare.savueinshare
savueinshare.savueinshare.5.10
SOFTWARE\Classes\i.ssaivenshare
SOFTWARE\Classes\saavensuharE.saavensuharE.5.10
SOFTWARE\Classes\saveanshaare.saveanshaare
SOFTWARE\Classes\saveanshaare.saveanshaare.5.10
SOFTWARE\Classes\saveenshare.saveenshare
SOFTWARE\Classes\saveenshare.saveenshare.5.10
SOFTWARE\Classes\saVensshare.saVensshare
SOFTWARE\Classes\saVensshare.saVensshare.5.10
SOFTWARE\Classes\savueinshare.savueinshare
SOFTWARE\Classes\savueinshare.savueinshare.5.10
Software\Microsoft\Internet Explorer\Approved Extensions, value: {5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration\{5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1993DC35-823E-1989-1DC7-3924AAF12C42}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2044E087-C17A-6E4C-45FD-35650A67A2C6}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2C40E766-EAC3-3031-2134-913A70B30BCB}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3C081C04-E1A7-BE90-9F9A-9B5C41C054EC}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5A7EE4D9-D365-B41A-7C58-42097F19E9E3
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{869B536E-874E-DD39-3132-C5CEE5DC1699}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8E3F38F6-D331-1651-97D1-F195176F2922}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AA8DFEC9-9B34-4F4C-8E2B-796D96302798}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1993DC35-823E-1989-1DC7-3924AAF12C42}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2044E087-C17A-6E4C-45FD-35650A67A2C6}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3C081C04-E1A7-BE90-9F9A-9B5C41C054EC}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3C081C04-E1A7-BE90-9F9A-9B5C41C054EC}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {3C081C04-E1A7-BE90-9F9A-9B5C41C054EC}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {1993DC35-823E-1989-1DC7-3924AAF12C42}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{1993DC35-823E-1989-1DC7-3924AAF12C42}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2C40E766-EAC3-3031-2134-913A70B30BCB}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3C081C04-E1A7-BE90-9F9A-9B5C41C054EC}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5A7EE4D9-D365-B41A-7C58-42097F19E9E3
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{869B536E-874E-DD39-3132-C5CEE5DC1699}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{8E3F38F6-D331-1651-97D1-F195176F2922}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AA8DFEC9-9B34-4F4C-8E2B-796D96302798}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1993DC35-823E-1989-1DC7-3924AAF12C42}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2044E087-C17A-6E4C-45FD-35650A67A2C6}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID, value: {1993DC35-823E-1989-1DC7-3924AAF12C42}
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{5B5E60F5-7778-D8BF-4529-4EC3D2069A6A}
{2044E087-C17A-6E4C-45FD-35650A67A2C6}
{869B536E-874E-DD39-3132-C5CEE5DC1699}
{63E95A0E-83F3-DFAB-5C0F-D9B381ABAAE4}
{1993DC35-823E-1989-1DC7-3924AAF12C42}
{8E3F38F6-D331-1651-97D1-F195176F2922}
{AA8DFEC9-9B34-4F4C-8E2B-796D96302798}
{5A7EE4D9-D365-B41A-7C58-42097F19E9E3}
{62D82EC1-0D3A-DF54-8E3E-07E1337A5311}
{3C081C04-E1A7-BE90-9F9A-9B5C41C054EC}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 13 + 4 ?