Threat Database Adware Adware.SaveSense

Adware.SaveSense

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 3,737
Threat Level: 20 % (Normal)
Infected Computers: 52,824
First Seen: December 18, 2013
Last Seen: April 13, 2026
OS(es) Affected: Windows

Aliases

3 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Avast Win32:Adware-gen [Adw]
AVG MalSign.Generic.81E
McAfee Artemis!6F2939B1EC17

SpyHunter Detects & Remove Adware.SaveSense

File System Details

Adware.SaveSense may create the following file(s):
# File Name MD5 Detections
1. SaveSenseLive.exe.vir c495d8665a32539660625182d23d5c59 9,798
2. upd.exe.vir 52da860708dc877b3c97c1bab8afeb72 1,273
3. upd.exe 3d8a76f376ec7a2c117bd4997fb933d3 747
4. UpdateTask.exe.vir ce969763d1753ecf9c05b199f280b252 311
5. SaveSense_p1v2.exe ed0d2ff9243af4c4021934ad7948981b 51
6. sas.exe d05cf41a2e1e01e7842e2b643a6f2370 7
7. SaveSense_p1v3.exe 307c7de8ad0df8f792bfab63e5dd7c39 4
8. XpersSaveSense.exe f078e6f3aaaf1bf2211587ab38d62666 2
9. SaveSenseLive.exe b776c0d6a72e29399ecfa6a54858d448 2
10. UpdateTask.exe 4bcd59216ce6a7fcb1bc77ff285afe59 1
More files

Registry Details

Adware.SaveSense may create the following registry entry or registry entries:
CLSID
{0EE6D408-6ED5-40C6-8C42-A041D5DE9AB0}
{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
{1070C156-160B-47A0-B7D9-1860396BAB57}
{13A42355-1F94-4459-B19E-F60B2C607C77}
{27CE191D-733B-4450-AFCD-096D105288C3}
{293DD661-C540-4AC4-9B4C-42E68369CE1B}
{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
{2EC58BDB-0694-4D54-80DD-A8F2AA0427A1}
{313B508D-596D-4BDF-B0B5-E41F224E184A}
{39A29266-D3E4-462D-AB05-F93B1053F6CF}
{3AF4400F-CDC5-4F2D-B3F1-74348E5D5CCC}
{422E1393-7A4C-44FF-A7E1-8B9D146E0666}
{44FC7A33-2E5C-48DC-B6F5-B81E8005D122}
{4807D6D8-ADC8-41AF-AB9D-AE1086D1E62F}
{6E1CD171-29C1-4D56-A223-E31C57A0A25A}
{70E96298-17FC-4020-A7CF-6F81ED8CF3AB}
{73192D81-6D24-4C40-BF7B-2507C6FA0B1A}
{84A81B7E-B8CD-4891-BEA0-548D65E9610A}
{867DF9A9-D013-4A1A-B685-DFF65D225ED4}
{889074FC-1456-4CE8-88F7-154264DC275F}
{88C606E7-BA26-41CB-8CC3-D1E313E34E75}
{91F4CF02-F675-4E6A-B4E8-C13DF09B9B1B}
{93D3100A-BBB6-456C-96FC-82CAC5F383AC}
{997E3BFB-F821-411C-8B96-D61D415EC8FA}
{998745A3-2AE4-488D-8092-B98FB20A00C2}
{99DCF141-03F9-4363-8D79-640FA646DEED}
{9E0546FF-D44F-4FE4-A324-995FCACB8D33}
{A18D16ED-27B2-4B83-B70C-15E73F099546}
{A2D3FB7A-6873-45E8-AF96-57092D721828}
{A902A36E-0C79-4BD7-B561-9C058BD60210}
{AB778974-218E-4734-90F0-731BE7E50E77}
{ADE6A9C0-12B3-457D-9A86-548FA87E04DB}
{B7C67027-15EB-489F-A9EA-286076CF7540}
{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
{C1424421-D274-491E-9D47-11C8D8CB5F9A}
{CDB98856-BEA3-4073-AF57-23A3583AE9E4}
{CDDAB3A4-E64D-4AE0-9E1D-F3132F5F913F}
{CDED8922-BB3D-4E3A-9C2C-89B1C927F48B}
{D79CBD8E-D857-4D05-B3AD-26F722CF5B6E}
{E66A759D-367F-433E-85C6-ED7F040BCC32}
{E7EA7058-B19B-4A27-B50A-87A1B8FC5F30}
{F4B8D46C-4EEE-401B-8607-DC03025F34B1}
Software\Microsoft\Internet Explorer\Approved Extensions\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Internet Explorer\Approved Extensions\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71E129FF-6C2A-4984-818C-7E2C998B8D99}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71E129FF-6C2A-4984-818C-7E2C998B8D99}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Software\SaveSense
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\SaveSense
SYSTEM\ControlSet001\Services\savesenselive
SYSTEM\ControlSet001\Services\savesenselivem
SYSTEM\ControlSet002\Services\savesenselive
SYSTEM\ControlSet002\Services\savesenselivem
SYSTEM\CurrentControlSet\Services\savesenselive
SYSTEM\CurrentControlSet\Services\savesenselivem

Directories

Adware.SaveSense may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\SaveSenseLive
%ALLUSERSPROFILE%\SaveSenseLive
%APPDATA%\Microsoft\Windows\Start Menu\Programs\SaveSense
%APPDATA%\SaveSense
%LOCALAPPDATA%\SaveSense
%LOCALAPPDATA%\SaveSenseLive
%PROGRAMFILES%\SaveSense
%PROGRAMFILES%\SaveSenseLive
%PROGRAMFILES(x86)%\SaveSense
%PROGRAMFILES(x86)%\SaveSenseLive
%USERPROFILE%\Start Menu\Programs\SaveSense
%UserProfile%\Local Settings\Application Data\SaveSense

URLs

Adware.SaveSense may call the following URLs:

SaveSense

Analysis Report

General information

Family Name: Adware.SaveSense
Signature status: Hash Mismatch

Known Samples

MD5: f07dfac1550f64fd46eac390a16c5821
SHA1: bb805d7fd4c7670f29007f54c728c048edf16ca3
SHA256: D95FA17EFFC48756DD358A915DB3946C04AD2B7B747D81CEF12AEFD539962865
File Size: 1.45 MB, 1452296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name SaveSense
File Description SaveSense
File Version 6.4.0.0
Internal Name sas.exe
Legal Copyright Copyright © 2014 SaveSense
Legal Trademarks [4BB806A] [default:default] SaveSense and SaveSense.com trademarks or registered trademarks in the U.S. and/or other countries.
Original Filename sas.exe
Product Name SaveSense
Product Version 6.4.0.0

Digital Signatures

Signer Root Status
SaveSense UTN-USERFirst-Object Hash Mismatch

Block Information

Total Blocks: 1,074
Potentially Malicious Blocks: 306
Whitelisted Blocks: 751
Unknown Blocks: 17

Visual Map

1 0 1 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 0 x x 0 x x 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 x x x x 0 x 0 x x 0 x x x x ? x 0 0 0 0 0 0 x 1 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x 0 x x 0 x 0 x 0 0 x 0 x 0 x 0 0 x x 0 0 0 0 x 0 0 x 0 x 0 0 0 1 0 0 x x 0 0 0 x x 0 0 0 1 x 0 0 0 0 x x x x x 0 0 0 0 x x x x x x x x x x 0 x 0 x 0 x 0 1 x x 0 x x 0 x x x x x 0 x x 0 0 0 0 x ? x x 0 0 0 0 0 x 0 0 x x 0 0 x x x x 1 0 x 0 0 x x x x x 1 x x x x x x 0 x x x x x ? 0 ? x x 0 x x x 0 x x x x x x 0 x x 0 x x 0 0 0 1 x x 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 1 x 0 0 0 0 x 0 x x x 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? 0 0 0 0 0 0 0 x 0 x x x x 0 x x 0 0 x 0 x 0 0 0 x x x x x x x 0 0 0 0 x x 0 0 x x x x x 0 0 0 0 0 x 0 x x x 0 x x 0 0 0 0 x x 0 x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x x x x 0 0 x x x 0 x 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x x x x x 0 x x 0 x 0 x 0 x 0 0 0 0 x x 0 1 x 1 0 0 0 0 0 1 x 0 0 0 x 0 x x 0 x x x x 0 0 0 x 0 x x x x x 0 x x x x 0 0 1 0 0 x x x x x x 0 x x 0 x x 0 0 x 1 x 1 x 0 0 0 x x x x 0 x x x x x 0 x x 0 x x x x x x x x 0 0 0 0 0 0 x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x x ? 0 0 0 x 1 2 0 0 1 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 1 0 1 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 2 2 1 0 1 0 0 0 0 0 0 1 1 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 3 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 ? ? ? ? ? ? 0 ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • PriceMeter.A

Trending

Most Viewed

Loading...