saave on
What is saave on?
Distributed under the alias publisher picitup (Saveon), the Save On an adware browser extension that will deliver ads on web pages that are not affiliated with the ads or the extension. Ads will be injected as new ads that would not normally appear in whitespace on the page or displayed on top of banner advertisements that the underlying website is already providing. If a coupon is being displayed, clicking on any of the offers will result in a redirect that will drop affiliate cookies on to the end user computer and resolve the end user to the advertiser page/offer. Save On will communicate with a remote server in order to track the habits of the user including what URLs and domains the user visits, what pages they view and what advertisements are displayed and clicked on.
Overview
The most common release is 4.3.0.1718, with over 98% of all installations currently using this version. The primary executable is named 5cwR.exe. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 11 files and is usually about 680.09 KB (696,409 bytes).
- Malware detected in the program
- Typically distributed through a pay-per-install bundle
- Displays unwanted advertisements
- The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in saave on.
5cwR.exe (47b14be12d4e81c2dd00fb1b0aa4ba8f) has been flagged by the following 8 scanners: |
Anti-Virus software | Version | Detection |
AhnLab-V3 |
2014.06.13 |
Dropper/Win32.Preloader |
avast! |
2014.9-140620 |
Win32:MultiPlug-BC [PUP] |
AVG |
2015.0.3438 |
Generic5 |
Baidu-International |
4.0.3.14620 |
Adware.Win32.BHO.77 |
ESET-NOD32 |
8.9938 |
a variant of Win32/AdWare.MultiPlug.Y |
McAfee-GW-Edition |
7.7094 |
Heuristic.BehavesLike.Win32.Suspicious.H |
TrendMicro-HouseCall |
7.2.171 |
TROJ_GEN.F47V0604 |
VIPRE Antivirus |
30246 |
Trojan.Win32.Generic!BT |
LBJq7Pl.exe (a3a7122be69f78be5482b8d8108c99ea) has been flagged by the following 26 scanners: |
Anti-Virus software | Software version | Detection |
Lavasoft Ad-Aware |
12.0.163.0 |
Gen:Variant.Adware.Graftor.146103 |
Agnitum Outpost |
5.5.1.3 |
PUA.MultiPlug! |
AhnLab-V3 |
2014.07.28.00 |
Trojan/Win32.Preloader |
Avira AntiVir |
7.11.164.42 |
Adware/Graftor.146103.8 |
avast! |
8.0.1489.320 |
Win32:Dropper-gen [Drp] |
AVG |
14.0.0.3986 |
Generic5.AYTX |
Bitdefender |
7.2 |
Gen:Variant.Adware.Graftor.146103 |
Bkav FE |
1.3.0.4959 |
W32.MultiPlugCG.Adware |
Comodo Security |
18993 |
ApplicUnwnt |
Emsisoft Anti-Malware |
3.0.0.600 |
Gen:Variant.Adware.Graftor.146103 (B) |
ESET-NOD32 |
10160 |
Win32/AdWare.MultiPlug.AG |
Fortinet FortiGate |
5.1.152.0 |
Riskware/MultiPlug |
F-Secure |
11.0.19100.45 |
Gen:Variant.Adware.Graftor.146103 |
G Data |
24 |
Gen:Variant.Adware.Graftor.146103 |
K7 AntiVirus |
9.181.12846 |
Adware ( 0049c94b1 ) |
K7GW |
9.181.12846 |
Adware ( 0049c94b1 ) |
Malwarebytes |
1.75.0.1 |
PUP.Optional.MultiPlug |
McAfee |
6.0.4.564 |
RDN/Generic.bfr!hk |
McAfee-GW-Edition |
2013 |
RDN/Generic.bfr!hk |
MicroWorld-eScan |
12.0.250.0 |
Gen:Variant.Adware.Graftor.146103 |
Panda Antivirus |
10.0.3.5 |
Trj/CI.A |
Qihoo-360 |
1.0.0.1015 |
Win32/Trojan.Dropper.c9f |
Tencent |
1.0.0.1 |
Win32.Risk.Adware.Lmkl |
Trend Micro |
9.740.0.1012 |
TROJ_GEN.R0CBC0PGO14 |
TrendMicro-HouseCall |
9.700.0.1001 |
TROJ_GEN.R0CBC0PGO14 |
VIPRE Antivirus |
31654 |
Trojan.Win32.Generic!BT |
fZHR.exe (bfc8248e4a46941c28971f7ace499154) has been flagged by the following 21 scanners: |
Anti-Virus software | Software version | Detection |
Lavasoft Ad-Aware |
12.0.163.0 |
Application.Generic.664610 |
AhnLab-V3 |
2014.07.08.02 |
Dropper/Win32.Preloader |
Avira AntiVir |
7.11.159.14 |
Adware/MultiPlug.Y.2 |
avast! |
8.0.1489.320 |
Win32:Dropper-gen [Drp] |
AVG |
14.0.0.3986 |
Generic5.AXOC |
Baidu-International |
3.5.1.41473 |
Adware.Win32.MultiPlug.BY |
Bitdefender |
7.2 |
Application.Generic.664610 |
Comodo Security |
18804 |
ApplicUnwnt |
ESET-NOD32 |
10062 |
a variant of Win32/AdWare.MultiPlug.Y |
Fortinet FortiGate |
5.1.152.0 |
Riskware/MultiPlug |
F-Secure |
11.0.19100.45 |
Application.Generic.664610 |
G Data |
24 |
Application.Generic.664610 |
Malwarebytes |
1.75.0.1 |
PUP.Optional.Multiplug |
McAfee |
6.0.4.564 |
RDN/Generic PUP.x!cgm |
McAfee-GW-Edition |
2013 |
Heuristic.BehavesLike.Win32.Suspicious.H |
MicroWorld-eScan |
12.0.250.0 |
Application.Generic.664610 |
Panda Antivirus |
10.0.3.5 |
Trj/CI.A |
Sophos |
4.98.0 |
Generic PUA EN |
Symantec |
20131.1.5.61 |
WS.Reputation.1 |
TrendMicro-HouseCall |
9.700.0.1001 |
TROJ_GEN.R0C1H06FT14 |
VIPRE Antivirus |
31082 |
Trojan.Win32.Generic!BT |
wcWS3.exe (c16252d1e226b9266c6ca054203f2e00) has been flagged by the following 21 scanners: |
Anti-Virus software | Software version | Detection |
Lavasoft Ad-Aware |
12.0.163.0 |
Application.Generic.679463 |
Agnitum Outpost |
5.5.1.3 |
PUA.MultiPlug! |
AhnLab-V3 |
2014.07.23.00 |
Trojan/Win32.Preloader |
avast! |
8.0.1489.320 |
Win32:Dropper-gen [Drp] |
AVG |
14.0.0.3986 |
Generic5.AYZO |
Baidu-International |
3.5.1.41473 |
Adware.Win32.MultiPlug.81 |
Bitdefender |
7.2 |
Application.Generic.679463 |
Comodo Security |
18944 |
ApplicUnwnt |
ESET-NOD32 |
10140 |
a variant of Win32/AdWare.MultiPlug.AG |
Fortinet FortiGate |
5.1.152.0 |
Riskware/MultiPlug |
F-Secure |
11.0.19100.45 |
Application.Generic.679463 |
G Data |
24 |
Application.Generic.679463 |
K7 AntiVirus |
9.181.12806 |
Adware ( 0049c94b1 ) |
K7GW |
9.181.12812 |
Adware ( 0049c94b1 ) |
Malwarebytes |
1.75.0.1 |
PUP.Optional.MultiPlug |
McAfee |
6.0.4.564 |
RDN/Generic.bfr!ho |
McAfee-GW-Edition |
2013 |
RDN/Generic.bfr!ho |
MicroWorld-eScan |
12.0.250.0 |
Application.Generic.679463 |
Sophos |
4.98.0 |
Generic PUA CC |
TrendMicro-HouseCall |
9.700.0.1001 |
TROJ_GEN.R0CBH06GI14 |
VIPRE Antivirus |
31520 |
Trojan.Win32.Generic!BT |
0jw.exe (ebc28e5d26d6526a25e5d641716e01ed) has been flagged by the following 18 scanners: |
Anti-Virus software | Software version | Detection |
Lavasoft Ad-Aware |
12.0.163.0 |
Application.Generic.654852 |
AhnLab-V3 |
2014.06.27.00 |
Dropper/Win32.Preloader |
avast! |
8.0.1489.320 |
Win32:Dropper-gen [Drp] |
AVG |
14.0.0.3972 |
Generic5.AXLN |
Baidu-International |
3.5.1.41473 |
Adware.Win32.MultiPlug.bY |
Bitdefender |
7.2 |
Application.Generic.654852 |
ESET-NOD32 |
10008 |
a variant of Win32/AdWare.MultiPlug.Y |
Fortinet FortiGate |
5.1.152.0 |
Riskware/MultiPlug |
F-Secure |
11.0.19100.45 |
Application.Generic.654852 |
G Data |
24 |
Application.Generic.654852 |
Malwarebytes |
1.75.0.1 |
PUP.Optional.MultiPlug.A |
McAfee |
6.0.4.564 |
RDN/Generic PUP.x!cg3 |
McAfee-GW-Edition |
2013 |
Heuristic.BehavesLike.Win32.Suspicious.H |
MicroWorld-eScan |
12.0.250.0 |
Application.Generic.654852 |
Qihoo-360 |
1.0.0.1015 |
Win32/Trojan.Dropper.c9f |
Sophos |
4.98.0 |
Generic PUA II |
TrendMicro-HouseCall |
9.700.0.1001 |
Suspicious_GEN.F47V0620 |
VIPRE Antivirus |
30700 |
Trojan.Win32.Generic!BT |
RC.exe (f82dc144bfd813a8d5389171d9ce92f0) has been flagged by the following 18 scanners: |
Anti-Virus software | Software version | Detection |
Lavasoft Ad-Aware |
12.0.163.0 |
Application.Generic.648917 |
AhnLab-V3 |
2014.06.17.00 |
Dropper/Win32.Preloader |
Avira AntiVir |
7.11.155.38 |
SPR/Tool.694272.1 |
avast! |
8.0.1489.320 |
Win32:Malware-gen |
AVG |
14.0.0.3964 |
Generic5.AVMG |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AdBlocker.81 |
Bitdefender |
7.2 |
Application.Generic.648917 |
ESET-NOD32 |
9952 |
a variant of Win32/AdWare.MultiPlug.Y |
Fortinet FortiGate |
5.1.152.0 |
Riskware/MultiPlug |
F-Secure |
11.0.19100.45 |
Application.Generic.648917 |
G Data |
24 |
Application.Generic.648917 |
Malwarebytes |
1.75.0.1 |
PUP.Optional.MultiPlug.A |
McAfee |
6.0.4.564 |
Artemis!F82DC144BFD8 |
McAfee-GW-Edition |
2013 |
Heuristic.BehavesLike.Win32.Suspicious.H |
MicroWorld-eScan |
12.0.250.0 |
Application.Generic.648917 |
Trend Micro |
9.740.0.1012 |
ADW_MULTIPLUG |
TrendMicro-HouseCall |
9.700.0.1001 |
ADW_MULTIPLUG |
VIPRE Antivirus |
30344 |
Trojan.Win32.Generic!BT |
MZ.exe (dd659ac85fad1370a5969577de786e3e) has been flagged by the following 15 scanners: |
Anti-Virus software | Software version | Detection |
AhnLab-V3 |
2014.06.28.00 |
Dropper/Win32.Preloader |
Antiy-AVL |
1.0.0.1 |
Trojan/Win32.TSGeneric |
avast! |
8.0.1489.320 |
Win32:Adware-gen [Adw] |
AVG |
14.0.0.3972 |
Generic5.AXXO |
Baidu-International |
3.5.1.41473 |
Adware.Win32.MultiPlug.BY |
Comodo Security |
18687 |
ApplicUnwnt |
ESET-NOD32 |
10011 |
a variant of Win32/AdWare.MultiPlug.Y |
Fortinet FortiGate |
5.1.152.0 |
Riskware/MultiPlug |
K7 AntiVirus |
9.180.12553 |
Adware ( 0049b4c51 ) |
K7GW |
9.180.12553 |
Adware ( 0049b4c51 ) |
Malwarebytes |
1.75.0.1 |
PUP.Optional.Multiplug |
McAfee |
6.0.4.564 |
RDN/Generic.bfr!hk |
McAfee-GW-Edition |
2013 |
Heuristic.BehavesLike.Win32.Suspicious.H |
TrendMicro-HouseCall |
9.700.0.1001 |
Suspicious_GEN.F47V0625 |
VIPRE Antivirus |
30712 |
Trojan.Win32.Generic!BT |
SXWC1b_qLJ.exe (e700a7c75654a3b567bb34106c4e9d52) has been flagged by the following 8 scanners: |
Anti-Virus software | Software version | Detection |
AhnLab-V3 |
2014.06.25.02 |
Dropper/Win32.Preloader |
AVG |
14.0.0.3972 |
Generic5.AXES |
Baidu-International |
3.5.1.41473 |
Adware.Win32.MultiPlug.BY |
ESET-NOD32 |
9996 |
a variant of Win32/AdWare.MultiPlug.Y |
McAfee-GW-Edition |
2013 |
Heuristic.BehavesLike.Win32.Suspicious.H |
Symantec |
20131.1.5.61 |
WS.Reputation.1 |
TrendMicro-HouseCall |
9.700.0.1001 |
Suspicious_GEN.F47V0618 |
VIPRE Antivirus |
30634 |
Trojan.Win32.Generic!BT |
xlPamJs.exe (ef38514253e4dafb6823f236bc47bb5f) has been flagged by the following 7 scanners: |
Anti-Virus software | Software version | Detection |
AVG |
13.0.0.3169 |
Generic5.AOBP |
Comodo Security |
17878 |
ApplicUnwnt |
ESET-NOD32 |
9495 |
a variant of Win32/AdWare.MultiPlug.S |
Malwarebytes |
1.75.0001 |
PUP.Optional.MultiPlug.A |
Qihoo-360 |
1.0.0.1015 |
HEUR/Malware.QVM10.Gen |
Trend Micro |
9.740-1012 |
ADW_MULTIPLUG |
TrendMicro-HouseCall |
9.700-1001 |
ADW_MULTIPLUG |
View all 142 all detections
saave on has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.
Program details
Displayed publisher: save oN
URL: saveonapp.info
Installation folder: C:\ProgramData\saave on
Uninstaller: "C:\ProgramData\saave on\5cwR.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Estimated size: 680.09 KB
Files installed by saave on
Program executable: | 5cwR.exe (Malware detected) |
Name: | vendors |
| management term |
Path: | C:\ProgramData\saave on\5cwR.exe |
MD5: | 47b14be12d4e81c2dd00fb1b0aa4ba8f |
Additional files:
-
(Malware detected) MZ.exe (by use functions technology maintaining) - use functions technology maintaining (a may existing)
-
(Malware detected) fZHR.exe (by security technology for if) - security technology for if (technology such)
-
(Malware detected) xlPamJs.exe (by system Retrieval cluster) - system Retrieval cluster (often)
-
(Malware detected) RC.exe (by databases Inserting) - databases Inserting (DBMSs Outside used)
-
(Malware detected) ZXuI1W.exe (by databases Inserting)
-
(Malware detected) 0jw.exe (by the size) - the size (fall are)
-
(Malware detected) qnTLvKkErvd.exe (by the size)
-
(Malware detected) 5cwR.exe (by vendors) - vendors (management term)
-
(Malware detected) wcWS3.exe (by related) - related (fails modern for)
-
(Malware detected) LBJq7Pl.exe (by use) - use (important concurrency time)
-
(Malware detected) SXWC1b_qLJ.exe (by of) - of (comprise)
How do I remove saave on?
You can uninstall saave on from your computer by using the Add/Remove Program feature in the Window's Control Panel.
- On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
- Windows Vista/7/8/10: Click Uninstall a Program.
- Windows XP: Click Add or Remove Programs.
- When you find the program saave on, click it, and then do one of the following:
- Windows Vista/7/8/10: Click Uninstall.
- Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
- Follow the prompts. A progress bar shows you how long it will take to remove saave on.
- If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.
OS VERSIONS
Win 7 (SP1) 75%
Win 7 8%
|
|
USER ACTIONS
|
Uninstall it 86%
Keep it 14%
|
|
|
COUNTRY POPULARITY
43.75%
United States
|
Windows
Which Windows OS versions does it run on?
Windows 7 |
83.33% |
|
Windows 10 |
16.67% |
|
Which OS releases does it run on? |
Windows 7 Ultimate |
41.67% |
|
Windows 7 Home Premium |
25.00% |
|
Windows 7 Professional |
16.67% |
|
Windows 8.1 |
8.33% |
|
Windows 8.1 Pro Preview |
8.33% |
|
Geography
43.75% of installs come from the United States
Which countries install it?
United States |
43.75% |
Austria |
6.25% |
Belgium |
6.25% |
France |
6.25% |
Nicaragua |
6.25% |
Slovenia |
6.25% |
Brazil |
6.25% |
Italy |
6.25% |
Venezuela |
6.25% |
TN |
6.25% |
PC manufacturers
What PC manufacturers (OEMs) have it installed?
Acer |
25.00% |
|
GIGABYTE |
16.67% |
|
ASUS |
16.67% |
|
Hewlett-Packard |
16.67% |
|
Medion |
8.33% |
|
Lenovo |
8.33% |
|
Samsung |
8.33% |
|
Common models |
Samsung RV411 |
10.00% |
|
MEDIONPC MS-7646 |
10.00% |
|
HP Compaq nx6325 (EY355EA... |
10.00% |
|
HP Compaq dc7700 Converti... |
10.00% |
|
LENOVO 96362AU |
10.00% |
|
Gigabyte GA-MA74GM-S2 |
10.00% |
|
About (from WebPick Internet Holdings Ltd.)
The InstalleReX pay per install platform will help you promote your applications.
Publisher URL: installerex.com