SaveSense

SaveSense Description

SaveSense is adware that may display random pop-up ads, discount coupons, offers and deals via a pop-up box in well-known online shopping websites and social networking websites that computer users are visiting. SaveSense may insert an adware supported add-on, plug-in or extension for Mozilla Firefox, Internet Explorer and Google Chrome that may show pop-up, pop-under, banner, search, and in-text link interstitial ads. SaveSense may propagate and enter the PC throughout the installation of possibly unprotected free software downloads. SaveSense may commonly be embedded in the web browser when the computer user installs other free applications that may have added into their installation SaveSense. When the PC user installs free programs, he may also install SaveSense on the computer system. Once installed, SaveSense may highlight words on the websites that PC users are visiting changing them into hyperlinks. The links of SaveSense may be inserted within the text, and they may come with a double underline to separate them from usual links. When the PC user rolls the mouse over the link, the pop-up ads of SaveSense may emerge on the desktop of the computer system. If the PC user clicks on the pop-up links of SaveSense, the makers of the browser plug-in may make a profit from the clicks.

Aliases: Adware.SaveSense (fs), Adware.SaveSense.1 [DrWeb], Win32:Adware-gen [Adw] [Avast], TROJ_GEN.F47V0205, PUP.Optional.SaveSence.A, MalSign.Generic.81E [AVG], a variant of Win32/DealPly.M, PUP.Optional.SaveSense.A and Artemis!6F2939B1EC17 [McAfee].

Technical Information

File System Details

SaveSense creates the following file(s):
# File Name Size MD5 Detection Count
1 %PROGRAMFILES%\SaveSenseLive\Update\SaveSenseLive.exe 146,920 dc54e25a36d1a2650d38333ee95134a0 75
2 %APPDATA%\OpenCandy\61CBB1694CA041C5B80F3FEBB7744C35\SaveSense_p1v2.exe 1,341,680 ed0d2ff9243af4c4021934ad7948981b 32
3 sas.exe 870,512 d05cf41a2e1e01e7842e2b643a6f2370 7
4 %APPDATA%\SaveSense\UpdateProc\UpdateTask.exe 199,176 b0a38576188bac6bfa30cc35c4669038 2
5 %APPDATA%\SaveSense\XpersSaveSense.exe 315,904 f078e6f3aaaf1bf2211587ab38d62666 2
6 %APPDATA%\OpenCandy\987A2EF0C594436C86F1B8937B315D54\SaveSense_p1v3.exe 1,341,696 307c7de8ad0df8f792bfab63e5dd7c39 1
More files

Registry Details

SaveSense creates the following registry entry or registry entries:
Directory
%ALLUSERSPROFILE%\Application Data\SaveSenseLive
%ALLUSERSPROFILE%\SaveSenseLive
%APPDATA%\Microsoft\Windows\Start Menu\Programs\SaveSense
%APPDATA%\SaveSense
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\doeiiacdhfmpdeckdaifnjaemmkkdlkf
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\khcceooakamlehbimaepcldnnlnkcmfk
%LOCALAPPDATA%\SaveSense
%LOCALAPPDATA%\SaveSenseLive
%PROGRAMFILES%\SaveSense
%PROGRAMFILES%\SaveSenseLive
%PROGRAMFILES(x86)%\SaveSense
%PROGRAMFILES(x86)%\SaveSenseLive
%UserProfile%\Local Settings\Application Data\SaveSense
%USERPROFILE%\Start Menu\Programs\SaveSense
Registry key
Software\Microsoft\Internet Explorer\Approved Extensions\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Internet Explorer\Approved Extensions\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71E129FF-6C2A-4984-818C-7E2C998B8D99}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71E129FF-6C2A-4984-818C-7E2C998B8D99}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Software\SaveSense
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\doeiiacdhfmpdeckdaifnjaemmkkdlkf
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\SaveSense
SYSTEM\ControlSet001\Services\savesenselive
SYSTEM\ControlSet001\Services\savesenselivem
SYSTEM\ControlSet002\Services\savesenselive
SYSTEM\ControlSet002\Services\savesenselivem
SYSTEM\CurrentControlSet\Services\savesenselive
SYSTEM\CurrentControlSet\Services\savesenselivem
Uninstaller
Save Sense
SaveSense
CLSID
{0EE6D408-6ED5-40C6-8C42-A041D5DE9AB0}
{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
{1070C156-160B-47A0-B7D9-1860396BAB57}
{13A42355-1F94-4459-B19E-F60B2C607C77}
{27CE191D-733B-4450-AFCD-096D105288C3}
{293DD661-C540-4AC4-9B4C-42E68369CE1B}
{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
{2EC58BDB-0694-4D54-80DD-A8F2AA0427A1}
{313B508D-596D-4BDF-B0B5-E41F224E184A}
{39A29266-D3E4-462D-AB05-F93B1053F6CF}
{3AF4400F-CDC5-4F2D-B3F1-74348E5D5CCC}
{422E1393-7A4C-44FF-A7E1-8B9D146E0666}
{44FC7A33-2E5C-48DC-B6F5-B81E8005D122}
{4807D6D8-ADC8-41AF-AB9D-AE1086D1E62F}
{6E1CD171-29C1-4D56-A223-E31C57A0A25A}
{70E96298-17FC-4020-A7CF-6F81ED8CF3AB}
{73192D81-6D24-4C40-BF7B-2507C6FA0B1A}
{84A81B7E-B8CD-4891-BEA0-548D65E9610A}
{867DF9A9-D013-4A1A-B685-DFF65D225ED4}
{889074FC-1456-4CE8-88F7-154264DC275F}
{88C606E7-BA26-41CB-8CC3-D1E313E34E75}
{91F4CF02-F675-4E6A-B4E8-C13DF09B9B1B}
{93D3100A-BBB6-456C-96FC-82CAC5F383AC}
{997E3BFB-F821-411C-8B96-D61D415EC8FA}
{998745A3-2AE4-488D-8092-B98FB20A00C2}
{99DCF141-03F9-4363-8D79-640FA646DEED}
{9E0546FF-D44F-4FE4-A324-995FCACB8D33}
{A18D16ED-27B2-4B83-B70C-15E73F099546}
{A2D3FB7A-6873-45E8-AF96-57092D721828}
{A902A36E-0C79-4BD7-B561-9C058BD60210}
{AB778974-218E-4734-90F0-731BE7E50E77}
{ADE6A9C0-12B3-457D-9A86-548FA87E04DB}
{B7C67027-15EB-489F-A9EA-286076CF7540}
{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
{C1424421-D274-491E-9D47-11C8D8CB5F9A}
{CDB98856-BEA3-4073-AF57-23A3583AE9E4}
{CDDAB3A4-E64D-4AE0-9E1D-F3132F5F913F}
{CDED8922-BB3D-4E3A-9C2C-89B1C927F48B}
{D79CBD8E-D857-4D05-B3AD-26F722CF5B6E}
{E66A759D-367F-433E-85C6-ED7F040BCC32}
{E7EA7058-B19B-4A27-B50A-87A1B8FC5F30}
{F4B8D46C-4EEE-401B-8607-DC03025F34B1}
File name without path
chrome-extension_doeiiacdhfmpdeckdaifnjaemmkkdlkf_0.localstorage
chrome-extension_doeiiacdhfmpdeckdaifnjaemmkkdlkf_0.localstorage-journal

Related Posts

Site Disclaimer

Enigmasoftware.com is not associated, affiliated, sponsored or owned by the malware creators or distributors mentioned on this article. This article should NOT be mistaken or confused in being associated in any way with the promotion or endorsement of malware. Our intent is to provide information that will educate computer users on how to detect, and ultimately remove, malware from their computer with the help of SpyHunter and/or manual removal instructions provided on this article.

This article is provided "as is" and to be used for educational information purposes only. By following any instructions on this article, you agree to be bound by the disclaimer. We make no guarantees that this article will help you completely remove the malware threats on your computer. Spyware changes regularly; therefore, it is difficult to fully clean an infected machine through manual means.

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.