SaveSense

By Domesticus in Adware

Threat Scorecard

Popularity Rank: 3,921
Threat Level: 20 % (Normal)
Infected Computers: 52,782
First Seen: December 18, 2013
Last Seen: February 25, 2026
OS(es) Affected: Windows

SaveSense is adware that may display random pop-up ads, discount coupons, offers and deals via a pop-up box in well-known online shopping websites and social networking websites that computer users are visiting. SaveSense may insert an adware supported add-on, plug-in or extension for Mozilla Firefox, Internet Explorer and Google Chrome that may show pop-up, pop-under, banner, search, and in-text link interstitial ads. SaveSense may propagate and enter the PC throughout the installation of possibly unprotected free software downloads. SaveSense may commonly be embedded in the web browser when the computer user installs other free applications that may have added into their installation SaveSense. When the PC user installs free programs, he may also install SaveSense on the computer system. Once installed, SaveSense may highlight words on the websites that PC users are visiting changing them into hyperlinks. The links of SaveSense may be inserted within the text, and they may come with a double underline to separate them from usual links. When the PC user rolls the mouse over the link, the pop-up ads of SaveSense may emerge on the desktop of the computer system. If the PC user clicks on the pop-up links of SaveSense, the makers of the browser plug-in may make a profit from the clicks.

Aliases

3 security vendors flagged this file as malicious.

Antivirus Vendor Detection
Avast Win32:Adware-gen [Adw]
AVG MalSign.Generic.81E
McAfee Artemis!6F2939B1EC17

SpyHunter Detects & Remove SaveSense

File System Details

SaveSense may create the following file(s):
# File Name MD5 Detections
1. SaveSenseLive.exe.vir c495d8665a32539660625182d23d5c59 9,791
2. upd.exe.vir 52da860708dc877b3c97c1bab8afeb72 1,273
3. upd.exe 3d8a76f376ec7a2c117bd4997fb933d3 747
4. UpdateTask.exe.vir ce969763d1753ecf9c05b199f280b252 311
5. SaveSense_p1v2.exe ed0d2ff9243af4c4021934ad7948981b 51
6. sas.exe d05cf41a2e1e01e7842e2b643a6f2370 7
7. SaveSense_p1v3.exe 307c7de8ad0df8f792bfab63e5dd7c39 4
8. XpersSaveSense.exe f078e6f3aaaf1bf2211587ab38d62666 2
9. SaveSenseLive.exe b776c0d6a72e29399ecfa6a54858d448 2
10. UpdateTask.exe 4bcd59216ce6a7fcb1bc77ff285afe59 1
More files

Registry Details

SaveSense may create the following registry entry or registry entries:
CLSID
{0EE6D408-6ED5-40C6-8C42-A041D5DE9AB0}
{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
{1070C156-160B-47A0-B7D9-1860396BAB57}
{13A42355-1F94-4459-B19E-F60B2C607C77}
{27CE191D-733B-4450-AFCD-096D105288C3}
{293DD661-C540-4AC4-9B4C-42E68369CE1B}
{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
{2EC58BDB-0694-4D54-80DD-A8F2AA0427A1}
{313B508D-596D-4BDF-B0B5-E41F224E184A}
{39A29266-D3E4-462D-AB05-F93B1053F6CF}
{3AF4400F-CDC5-4F2D-B3F1-74348E5D5CCC}
{422E1393-7A4C-44FF-A7E1-8B9D146E0666}
{44FC7A33-2E5C-48DC-B6F5-B81E8005D122}
{4807D6D8-ADC8-41AF-AB9D-AE1086D1E62F}
{6E1CD171-29C1-4D56-A223-E31C57A0A25A}
{70E96298-17FC-4020-A7CF-6F81ED8CF3AB}
{73192D81-6D24-4C40-BF7B-2507C6FA0B1A}
{84A81B7E-B8CD-4891-BEA0-548D65E9610A}
{867DF9A9-D013-4A1A-B685-DFF65D225ED4}
{889074FC-1456-4CE8-88F7-154264DC275F}
{88C606E7-BA26-41CB-8CC3-D1E313E34E75}
{91F4CF02-F675-4E6A-B4E8-C13DF09B9B1B}
{93D3100A-BBB6-456C-96FC-82CAC5F383AC}
{997E3BFB-F821-411C-8B96-D61D415EC8FA}
{998745A3-2AE4-488D-8092-B98FB20A00C2}
{99DCF141-03F9-4363-8D79-640FA646DEED}
{9E0546FF-D44F-4FE4-A324-995FCACB8D33}
{A18D16ED-27B2-4B83-B70C-15E73F099546}
{A2D3FB7A-6873-45E8-AF96-57092D721828}
{A902A36E-0C79-4BD7-B561-9C058BD60210}
{AB778974-218E-4734-90F0-731BE7E50E77}
{ADE6A9C0-12B3-457D-9A86-548FA87E04DB}
{B7C67027-15EB-489F-A9EA-286076CF7540}
{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
{C1424421-D274-491E-9D47-11C8D8CB5F9A}
{CDB98856-BEA3-4073-AF57-23A3583AE9E4}
{CDDAB3A4-E64D-4AE0-9E1D-F3132F5F913F}
{CDED8922-BB3D-4E3A-9C2C-89B1C927F48B}
{D79CBD8E-D857-4D05-B3AD-26F722CF5B6E}
{E66A759D-367F-433E-85C6-ED7F040BCC32}
{E7EA7058-B19B-4A27-B50A-87A1B8FC5F30}
{F4B8D46C-4EEE-401B-8607-DC03025F34B1}
Software\Microsoft\Internet Explorer\Approved Extensions\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Internet Explorer\Approved Extensions\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{71E129FF-6C2A-4984-818C-7E2C998B8D99}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E32CFE5-DF92-4AE5-B0BE-609ED0DF74A6}
Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{71E129FF-6C2A-4984-818C-7E2C998B8D99}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Software\SaveSense
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{2e32cfe5-df92-4ae5-b0be-609ed0df74a6}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{A18D16ED-27B2-4B83-B70C-15E73F099546}
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\Stats\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
SOFTWARE\Wow6432Node\SaveSense
SYSTEM\ControlSet001\Services\savesenselive
SYSTEM\ControlSet001\Services\savesenselivem
SYSTEM\ControlSet002\Services\savesenselive
SYSTEM\ControlSet002\Services\savesenselivem
SYSTEM\CurrentControlSet\Services\savesenselive
SYSTEM\CurrentControlSet\Services\savesenselivem

Directories

SaveSense may create the following directory or directories:

%ALLUSERSPROFILE%\Application Data\SaveSenseLive
%ALLUSERSPROFILE%\SaveSenseLive
%APPDATA%\Microsoft\Windows\Start Menu\Programs\SaveSense
%APPDATA%\SaveSense
%LOCALAPPDATA%\SaveSense
%LOCALAPPDATA%\SaveSenseLive
%PROGRAMFILES%\SaveSense
%PROGRAMFILES%\SaveSenseLive
%PROGRAMFILES(x86)%\SaveSense
%PROGRAMFILES(x86)%\SaveSenseLive
%USERPROFILE%\Start Menu\Programs\SaveSense
%UserProfile%\Local Settings\Application Data\SaveSense

URLs

SaveSense may call the following URLs:

SaveSense

Analysis Report

General information

Family Name: Adware.SaveSense
Signature status: Hash Mismatch

Known Samples

MD5: f07dfac1550f64fd46eac390a16c5821
SHA1: bb805d7fd4c7670f29007f54c728c048edf16ca3
SHA256: D95FA17EFFC48756DD358A915DB3946C04AD2B7B747D81CEF12AEFD539962865
File Size: 1.45 MB, 1452296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name SaveSense
File Description SaveSense
File Version 6.4.0.0
Internal Name sas.exe
Legal Copyright Copyright © 2014 SaveSense
Legal Trademarks [4BB806A] [default:default] SaveSense and SaveSense.com trademarks or registered trademarks in the U.S. and/or other countries.
Original Filename sas.exe
Product Name SaveSense
Product Version 6.4.0.0

Digital Signatures

Signer Root Status
SaveSense UTN-USERFirst-Object Hash Mismatch

Block Information

Total Blocks: 1,074
Potentially Malicious Blocks: 306
Whitelisted Blocks: 751
Unknown Blocks: 17

Visual Map

1 0 1 x 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 0 x x 0 x x 0 x 0 0 0 0 x x 0 x 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 x x x x 0 x 0 0 0 0 0 0 0 0 0 0 1 1 1 1 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x 0 x x x x 0 x 0 x x 0 x x x x ? x 0 0 0 0 0 0 x 1 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x 0 x x 0 x 0 x 0 0 x 0 x 0 x 0 0 x x 0 0 0 0 x 0 0 x 0 x 0 0 0 1 0 0 x x 0 0 0 x x 0 0 0 1 x 0 0 0 0 x x x x x 0 0 0 0 x x x x x x x x x x 0 x 0 x 0 x 0 1 x x 0 x x 0 x x x x x 0 x x 0 0 0 0 x ? x x 0 0 0 0 0 x 0 0 x x 0 0 x x x x 1 0 x 0 0 x x x x x 1 x x x x x x 0 x x x x x ? 0 ? x x 0 x x x 0 x x x x x x 0 x x 0 x x 0 0 0 1 x x 0 x 0 0 x 0 x 0 0 0 x 0 0 0 0 1 x 0 0 0 0 x 0 x x x 0 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x ? 0 0 0 0 0 0 0 x 0 x x x x 0 x x 0 0 x 0 x 0 0 0 x x x x x x x 0 0 0 0 x x 0 0 x x x x x 0 0 0 0 0 x 0 x x x 0 x x 0 0 0 0 x x 0 x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x x x x x 0 0 x x x 0 x 0 x x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x 0 0 0 x x x x x 0 x x 0 x 0 x 0 x 0 0 0 0 x x 0 1 x 1 0 0 0 0 0 1 x 0 0 0 x 0 x x 0 x x x x 0 0 0 x 0 x x x x x 0 x x x x 0 0 1 0 0 x x x x x x 0 x x 0 x x 0 0 x 1 x 1 x 0 0 0 x x x x 0 x x x x x 0 x x 0 x x x x x x x x 0 0 0 0 0 0 x x x x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x 0 0 0 0 x 0 0 0 x x x x x 0 0 x x x x x 0 x 0 x 0 x x x 0 x 0 x 0 0 0 0 0 0 0 0 x x x x 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x x x ? 0 0 0 x 1 2 0 0 1 0 0 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 1 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 1 0 0 1 0 1 0 0 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 0 2 2 1 0 1 0 0 0 0 0 0 1 1 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 3 1 1 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 ? ? ? ? ? ? 0 ? ? ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • PriceMeter.A

Related Posts

Trending

Most Viewed

Loading...