35,598,033 programs installed

Should I remove savernet?

What percent of users and experts removed it?
83% remove it17% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Global Rank #41,936
United States Rank #37,217
Reach 0.0023%

savernet

What is savernet?

SaverNet is an adware extension that plugs into the user's web browser for IE, Chrome and Firefox and will display additional advertisements in search engines such as Bing and Google. It installs itself as an extension (BHO/plugin) and runs as a background process. This adware program creates an entry in Add or Remove Programs however removing this entry might stop the adware from running, but will not stop ads from displaying. Once installed, it displays ads by injecting new ads in search as well as various web pages that use 3rd party advertising and replaces these ads with its own. The program users the InstalleRex download manager from WebPicks Holdings to install itself on the user's PC. InstalleRex is known for distributing potentially unwanted applications including web browser toolbars and various ad-supported extensions. The software is a variant of a known adware (AKA SaveAs, SaveNShare, DownloadKeeper) but is re-branded to mask its origination although is includes many of the same components.

Overview

It adds a Browser Helper Object (BHO) to Internet Explorer. The main program executable is aHmbhLnI.exe. Typically most users end up uninstalling this just after a few days. The software installer includes 24 files and is usually about 906.53 KB (928,289 bytes).
  • Possible malware installed by this program
  • Loads into the web browser
  • Typically distributed through a pay-per-install bundle
  • Installs bundled adware using the WebPick InstalleRex
  • Lowers the security level of the web browser
  • Installs with little or no user consent as an 'optional' offer
  • Injects advertisements unassociated with the underlying web page
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in savernet.
kk.dll (6bdd2b931e45fa910c821a3beb07928c) has been flagged by the following 29 scanners:
Anti-Virus softwareVersionDetection
Lavasoft Ad-Aware 960 Application.Generic.604038
Agnitum Outpost 7.1.1 PUA.BHO
Antiy-AVL 1.0.0.1 Trojan/Win32.TGeneric
avast! 2014.9-140620 Win32:Dropper-gen [Drp]
AVG 2015.0.3438 Generic5
Baidu-International 4.0.3.14620 Adware.Win32.BHO.71
Bitdefender 1.0.20.855 Application.Generic.604038
Bkav FE 1.3.0.4959 W32.ToolbarEscort.Adware
CAT-QuickHeal 6.14.14.00 AdWare.BHO.r6 (Not a Virus)
Comodo Security 18598 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 8.9968 a variant of Win32/AdWare.MultiPlug.T
F-Secure 11.2014-20-06_6 Application.Generic.604038
G Data 14.6.24 Application.Generic.604038
IKARUS anti.virus t3scan.1.6.1.0 Win32.SuspectCrc
K7 AntiVirus 13.180.12463 Adware
K7GW 13.180.12463 Adware ( 004976341 )
Kaspersky 14.0.0.3683 not-a-virus:AdWare.Win32.BHO
Malwarebytes v2014.06.20.09 PUP.Optional.MultiPlug.A
McAfee 5600.7094 RDN/Generic PUP.x!cf3
McAfee-GW-Edition 7.7094 RDN/Generic PUP.x!cf3
MicroWorld-eScan 15.0.0.513 Application.Generic.604038
NANO AntiVirus 0.28.0.60253 Riskware.Win32.BHO.dbdfeq
Panda Antivirus 14.06.20.09 Trj/CI.A
Sophos 4.98 Generic PUA IO
Symantec 6/20/2014 rev. 6 Adware.BL
Trend Micro 10.465.20 ADW_MULTIPLUG
TrendMicro-HouseCall 7.2.171 ADW_MULTIPLUG
Vba32 AntiVirus 3.12.26.3 AdWare.BHO
VIPRE Antivirus 30454 Trojan.Win32.Generic!BT
I.exe (065a59096c5f1a6b3450f599141f13e8) has been flagged by the following 24 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.02.23.00 Trojan/Win32.Preloader
Antiy-AVL 0.1.0.1 GrayWare[AdWare:not-a-virus]/Win32.MegaSearch
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
AVG 13.0.0.3169 Generic_r.GV
Baidu-International 3.5.1.41473 Adware.Win32.MegaSearch.aX
CAT-QuickHeal 12.00 Adware.Megasearch.at (Not a Virus)
Comodo Security 17826 UnclassifiedMalware
ESET-NOD32 9457 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate 4 Adware/Megasearch
IKARUS anti.virus T3.1.5.6.0 Win32.AdWare
K7 AntiVirus 9.176.11239 Adware ( 00490ca81 )
K7GW 9.176.11226 Adware ( 00490ca81 )
Kaspersky 12.0.0.1225 not-a-virus:AdWare.Win32.MegaSearch.at
Kingsoft AntiVirus 2013.04.09.267 Win32.Troj.MegaSearch.at.(kcloud)
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
McAfee 6.0.4.564 PUP-FFY!065A59096C5F
NANO AntiVirus 0.28.0.57630 Riskware.Win32.MegaSearch.csukmc
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Qihoo-360 1.0.0.1015 HEUR/Malware.QVM10.Gen
Sophos 4.97.0 Generic PUA KI
Trend Micro 9.740-1012 TROJ_GEN.R0CBC0PBK14
TrendMicro-HouseCall 9.700-1001 TROJ_GEN.R0CBC0PBK14
Vba32 AntiVirus 3.12.24.3 BScope.Trojan.Agent
VIPRE Antivirus 26730 MegaSearch Toolbar
90.x64.dll (7b61be0d8ed2728570bf3b5a607620c6) has been flagged by the following 18 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Application.Generic.591097
AhnLab-V3 2014.03.04.00 Trojan/Win32.Preloader
AVG 13.0.0.3169 Generic_r.GX
Baidu-International 3.5.1.41473 Adware.Win64.MultiPlug.A
Bitdefender 7.2 Application.Generic.591097
Comodo Security 17878 ApplicUnwnt
ESET-NOD32 9495 a variant of Win64/Adware.MultiPlug.A
F-Secure 11.0.19100.45 Application.Generic.591097
G Data 24 Application.Generic.591097
IKARUS anti.virus T3.1.5.6.0 not-a-virus:AdWare.Win32.MegaSearch
K7 AntiVirus 9.176.11322 Adware ( 004922f61 )
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
McAfee 6.0.4.564 Artemis!7B61BE0D8ED2
McAfee-GW-Edition 2013 Artemis!7B61BE0D8ED2
MicroWorld-eScan 12.0.250.0 Application.Generic.591097
Norman 7.03.02 Multiplug.A
Qihoo-360 1.0.0.1015 ??????????L?????
VIPRE Antivirus 27044 Win64.Adware.MultiPlug
xlamk_R.dll (e49054ecb3ee417d69762aca6c900c61) has been flagged by the following 15 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Application.Generic.640894
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
AVG 14.0.0.3950 Generic_r.KL
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.81
Bitdefender 7.2 Application.Generic.640894
Comodo Security 18339 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 9853 a variant of Win32/AdWare.MultiPlug.T
F-Secure 11.0.19100.45 Application.Generic.640894
G Data 24 Application.Generic.640894
Kaspersky 12.0.0.1225 not-a-virus:AdWare.Win32.MultiPlug.bfs
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
MicroWorld-eScan 12.0.250.0 Application.Generic.640894
Trend Micro 9.740-1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700-1001 ADW_MULTIPLUG
VIPRE Antivirus 29652 Trojan.Win32.Generic!BT
j.exe (b0ee8864d103a51fc19984285099e53a) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Application.Generic.649344
AhnLab-V3 2014.06.19.00 Dropper/Win32.Preloader
AVG 14.0.0.3972 Generic5.AVMA
Baidu-International 3.5.1.41473 Trojan.Win32.Dropper.77
Bitdefender 7.2 Application.Generic.649344
ESET-NOD32 9963 a variant of Win32/AdWare.MultiPlug.Y
F-Secure 11.0.19100.45 Application.Generic.649344
G Data 24 Application.Generic.649344
K7 AntiVirus 9.180.12449 Adware ( 0049b4c51 )
K7GW 9.180.12449 Adware ( 0049b4c51 )
McAfee 6.0.4.564 Artemis!B0EE8864D103
McAfee-GW-Edition 2013 Artemis!B0EE8864D103
MicroWorld-eScan 12.0.250.0 Application.Generic.649344
qNtPMRvlG.exe (15138ff3390b4687fc3dd3f4acef85ab) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Application.Generic.638264
AhnLab-V3 2014.05.24.00 Dropper/Win32.Preloader
AVG 14.0.0.3950 Generic_r.JW
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.81
Bitdefender 7.2 Application.Generic.638264
ESET-NOD32 9841 a variant of Win32/AdWare.MultiPlug.T
G Data 24 Application.Generic.638264
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
MicroWorld-eScan 12.0.250.0 Application.Generic.638264
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Trend Micro 9.740-1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700-1001 ADW_MULTIPLUG
VIPRE Antivirus 29530 Trojan.Win32.Generic!BT
g.x64.dll (600ff6994d8cddce04773e8c738d303d) has been flagged by the following 12 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.06.11.00 Trojan/Win64.Preloader
Baidu-International 3.5.1.41473 Adware.Win64.MultiPlug.81
Comodo Security 18507 ApplicUnwnt
ESET-NOD32 9926 a variant of Win64/Adware.MultiPlug.C
G Data 24 Win64.Adware.Megasearch.C
IKARUS anti.virus T3.1.6.1.0 AdWare.MultiPlug
Malwarebytes 1.75.0.1 PUP.Optional.MultiPlug.A
McAfee 6.0.4.564 RDN/Generic PUP.x!c2k
McAfee-GW-Edition 2013 RDN/Generic PUP.x!c2k
Symantec 20131.1.5.61 Adware.BL
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R0E6H05EU14
VIPRE Antivirus 30178 Trojan.Win32.Generic!BT
xlamk_R.x64.dll (35eb114bc1702df83ee6e23a56b4df0e) has been flagged by the following 11 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 None Trojan/Win64.Preloader
Baidu-International 3.5.1.41473 Adware.Win64.MultiPlug.C
Bitdefender 7.2 Adware.Generic.939645
Emsisoft Anti-Malware 3.0.0.599 Adware.Generic.939645 (B)
G Data 24 Adware.Generic.939645
K7 AntiVirus 9.177.12128 Adware ( 004997a51 )
K7GW 9.177.12128 Adware ( 004997a51 )
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
MicroWorld-eScan 12.0.250.0 Adware.Generic.939645
Qihoo-360 1.0.0.1015 Win32/Trojan.Adware.453
Tencent 1.0.0.1 Win64.Adware.Multiplug.Lmbj
I.dll (957e832f7e5a3d97cdaef6354c247135) has been flagged by the following 11 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.01.25.00 Adware/Win32.Graftor
Avira AntiVir 7.11.126.244 ADWARE/Adware.Gen
AVG 13.0.0.3169 Generic_r.GU
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.N
Comodo Security 17671 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 9336 a variant of Win32/AdWare.MultiPlug.N
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 1.75.0.1 PUP.Optional.MultiPlug.A
Qihoo-360 1.0.0.1015 HEUR/Malware.QVM30.Gen
Rising Antivirus 25.0.0.11 PE:Malware.Adware!6.1293
VIPRE Antivirus 25784 JustPlugIt (fs)
90.exe (ad486a650cecae834ee3f9c96eac02d5) has been flagged by the following 11 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.01.29.00 Trojan/Win32.Preloader
AVG 13.0.0.3169 Generic_r.GV
Baidu-International 3.5.1.41473 Adware.Win32.MegaSearch.AzvV
ESET-NOD32 9350 a variant of Win32/AdWare.MultiPlug.K.gen
IKARUS anti.virus T3.1.5.6.0 AdWare.SuspectCRC
Kaspersky 12.0.0.1221 not-a-virus:AdWare.Win32.MegaSearch.at
Malwarebytes 1.75.0.1 PUP.Optional.MultiPlug.A
McAfee 5.600.0.1067 PUP-FFY!AD486A650CEC
McAfee-GW-Edition 2013 PUP-FFY!AD486A650CEC
Panda Antivirus 10.0.3.5 Trj/Genetic.gen
Vba32 AntiVirus 3.12.24.3 BScope.Trojan.Agent
90.dll (d179d3e0822cb96bcbeb882fe9599a97) has been flagged by the following 9 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.01.29.00 Adware/Win32.Graftor
Avira AntiVir 7.11.127.172 ADWARE/Adware.Gen
AVG 13.0.0.3169 Generic_r.GU
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.N
Comodo Security 17693 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 9350 a variant of Win32/AdWare.MultiPlug.N
Malwarebytes 1.75.0.1 PUP.Optional.MultiPlug.A
Rising Antivirus 25.0.0.11 PE:Malware.Adware!6.1293
VIPRE Antivirus 25922 JustPlugIt (fs)
u.exe (c2f76b2a4784ce0f8b5d1fbb149de768) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.06.18.00 Dropper/Win32.Preloader
AVG 14.0.0.3972 Generic5.AWSD
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.77
ESET-NOD32 9962 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes 1.75.0.1 PUP.Optional.MultiPlug.A
McAfee 6.0.4.564 Artemis!C2F76B2A4784
McAfee-GW-Edition 2013 Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0614
j.dll (5e82b06c849c657098025e7d43bad579) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
AVG 14.0.0.3972 Generic_r.KL
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.bT
ESET-NOD32 9968 a variant of Win32/AdWare.MultiPlug.Y
McAfee 6.0.4.564 RDN/Generic PUP.z!dw
McAfee-GW-Edition 2013 RDN/Generic PUP.z!dw
Sophos 4.98.0 Generic PUA PA
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.F47V0605
VIPRE Antivirus 30454 Trojan.Win32.Generic!BT
kk.exe (ef38514253e4dafb6823f236bc47bb5f) has been flagged by the following 7 scanners:
Anti-Virus softwareSoftware versionDetection
AVG 13.0.0.3169 Generic5.AOBP
Comodo Security 17878 ApplicUnwnt
ESET-NOD32 9495 a variant of Win32/AdWare.MultiPlug.S
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
Qihoo-360 1.0.0.1015 HEUR/Malware.QVM10.Gen
Trend Micro 9.740-1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700-1001 ADW_MULTIPLUG
u.dll (9f712f660d2538ba5fd12cfc496b33c0) has been flagged by the following 5 scanners:
Anti-Virus softwareSoftware versionDetection
AVG 14.0.0.3964 Generic5.AWSC
Baidu-International 3.5.1.41473 Adware.Win32.MultiPlug.BT
Comodo Security 18568 ApplicUnwnt
ESET-NOD32 9952 a variant of Win32/AdWare.MultiPlug.Y
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0615
       View all 194 all detections
savernet has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.
Find out how to remove savernet.

Program detailsProgram details

Displayed publisher: Savernet
URL: justplug.it
Installation folder: C:\Documents and Settings\user\Application data\savernet
Uninstaller: "C:\Documents and Settings\user\Application Data\savernet\aHmbhLnI.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Estimated size: 906.53 KB

Program filesFiles installed by savernet

Program executable:aHmbhLnI.exe
Path:C:\Documents and Settings\user\Application data\savernet\aHmbhLnI.exe
MD5:a6cd76c90259c1c3edab363ec2ddb952
Additional files:
  • aHmbhLnI.exe (by Setup)
  • (Malware detected) I.exe (by Setup)
  • aHmbhLnI.dll
  • (Malware detected) I.dll
  • (Malware detected) 90.dll
  • (Malware detected) 90.exe
  • (Malware detected) 90.x64.dll
  • B7Xh6.dll
  • B7Xh6.exe
  • B7Xh6.x64.dll
  • (Malware detected) g.x64.dll (by large) - large (Obtaining operating database with)
  • (Malware detected) j.dll (by data mobile one) - data mobile one (of DBMS inputting of Physically)
  • (Malware detected) j.exe (by interactions in) - interactions in (applications term the information)
  • j.x64.dll (by data mobile one)
  • (Malware detected) kk.dll (by large)
  • (Malware detected) kk.exe (by system Retrieval cluster) - system Retrieval cluster (often)
  • (Malware detected) qNtPMRvlG.exe (by only RAID database Administration technology) - only RAID database Administration technology (they or)
  • Qpo7uQV.exe
  • Qpo7uQV.x64.dll
  • (Malware detected) u.dll (by or into database) - or into database (software plans)
  • (Malware detected) u.exe (by arrays of the) - arrays of the (DBMS Defining often)
  • u.x64.dll (by or into database)
  • (Malware detected) xlamk_R.dll (by storage a) - storage a (DBMS any computers)
  • (Malware detected) xlamk_R.x64.dll (by storage a)

Program behaviorsBehaviors exhibited

10 Internet Explorer BHOs
  • kk.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'toapbeuyer' with the class of {91C8F1A6-2C68-CB17-B2F1-2769F84C977B}.
  • I.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'DiscountLoacauteor' with the class of {D46DC9B5-E648-22C4-6F43-8D4107F50C60}.
  • xlamk_R.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'PdfMMaeker' with the class of {570F373A-B031-00FE-1B64-A04111BB8C03}.
  • g.x64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'grreeatsAvingu' with the class of {9CA5086A-B001-B572-0398-A5581270BDA1}.
  • B7Xh6.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'savernet' with the class of {19F374BA-C195-36DE-152F-9059E6A12AE2}.
  • u.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'SaveNieewaAppz' with the class of {7D171A6D-9CE5-CAB1-E4BE-8F20C9119BEA}.
  • Plus 4 more

How do I remove savernet?

Quickly and completely remove savernet from your computer by downloading "Should I Remove It?", its 100% FREE and installs in seconds (click the button below).
Download "Should I Remove It?", it's FREE!Remove savernet from your computer.
Or, you can uninstall savernet from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program savernet, click it, and then do one of the following:
    • Windows Vista/7/8: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove savernet.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by savernet you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome
Scan your PC for malware
If you do not have a good anti-virus program, please consider installing one. Below are some we highly recommend.

OS VERSIONS
Win 7 (SP1) 67%
Win XP 13%
 
USER ACTIONS
Uninstall it 83%
Keep it 17%
 
GLOBAL RANK
#41,936

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 66.67%
Windows 8 20.00%
Windows XP 13.33%
Which OS releases does it run on?
Windows 7 Home Premium 46.67%
Microsoft Windows XP 13.33%
Windows 7 Starter 13.33%
Windows 8.1 13.33%
Windows 7 Professional 6.67%
Windows 8 Pro 6.67%

Distribution by countryGeography

61.54% of installs come from the United States
Which countries install it?
  United States 61.54%
  Australia 11.54%
  Canada 7.69%
  France 7.69%
  Brazil 3.85%
  United Kingdom 3.85%
  PF 3.85%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 33.33%
Dell 26.67%
Samsung 13.33%
Sony 6.67%
GIGABYTE 6.67%
Acer 6.67%
ASUS 6.67%
Common models
Sony VPCYB35AB 6.67%
Samsung RV415/RV515 6.67%
Samsung N145P/N250P/N260P... 6.67%
HP Split 13 x2 PC 6.67%
HP Pavilion g6 Notebook P... 6.67%
HP Pavilion dv6 Notebook ... 6.67%

comments1 comment

user comment
user comment
Brooke6 months ago
My computer has had trouble Uninstalling it, I've downloaded the Microsoft Uninstall Fixer but it requires the Product Code. Could you please tell me the code? Cheers