34,539,225 programs installed

Should I remove savernet?

What percent of users and experts removed it?
83% remove it17% keep it
Overall Sentiment
What do people think about it?
(click star to rate)
How common is it?
United States Rank #47,135
Reach 0.0013%


What is savernet?

SaverNet is an adware extension that plugs into the user's web browser for IE, Chrome and Firefox and will display additional advertisements in search engines such as Bing and Google. It installs itself as an extension (BHO/plugin) and runs as a background process. This adware program creates an entry in Add or Remove Programs however removing this entry might stop the adware from running, but will not stop ads from displaying. Once installed, it displays ads by injecting new ads in search as well as various web pages that use 3rd party advertising and replaces these ads with its own. The program users the InstalleRex download manager from WebPicks Holdings to install itself on the user's PC. InstalleRex is known for distributing potentially unwanted applications including web browser toolbars and various ad-supported extensions. The software is a variant of a known adware (AKA SaveAs, SaveNShare, DownloadKeeper) but is re-branded to mask its origination although is includes many of the same components.


It adds a Browser Helper Object (BHO) to Internet Explorer. The main program executable is aHmbhLnI.exe. Typically most users end up uninstalling this just after a few days. The software installer includes 15 files and is usually about 906.53 KB (928,289 bytes).
  • Possible malware installed by this program
  • Loads into the web browser
  • Typically distributed through a pay-per-install bundle
  • Injects advertisements unassociated with the underlying web page
  • The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in savernet.
I.exe (065a59096c5f1a6b3450f599141f13e8) has been flagged by the following 24 scanners:
Anti-Virus softwareVersionDetection
AhnLab-V3 2014.02.23 Trojan/Win32.Preloader
Antiy-AVL GrayWare[AdWare:not-a-virus]/Win32.MegaSearch
avast! 2014.9-140304 Win32:Adware-gen [Adw]
AVG 2015.0.3546 Generic_r
Baidu-International Adware.Win32.MegaSearch.aX
CAT-QuickHeal Adware.Megasearch.at (Not a Virus)
Comodo Security 17826 UnclassifiedMalware
ESET-NOD32 8.9457 a variant of Win32/AdWare.MultiPlug.K.gen
Fortinet FortiGate 3/4/2014 Adware/Megasearch
IKARUS anti.virus t3scan.2.2.29 Win32.AdWare
K7 AntiVirus 13.176.11239 Adware
K7GW 13.176.11226 Adware ( 00490ca81 )
Kaspersky not-a-virus:AdWare.Win32.MegaSearch
Kingsoft AntiVirus 331020.49267 Win32.Troj.MegaSearch.at.(kcloud)
Malwarebytes v2014.03.04.12 PUP.Optional.MultiPlug.A
McAfee 5600.7202 PUP-FFY!065A59096C5F
NANO AntiVirus Riskware.Win32.MegaSearch.csukmc
Panda Antivirus Trj/Genetic.gen
Qihoo-360 HEUR/Malware.QVM10.Gen
Sophos 4.97 Generic PUA KI
Trend Micro 10.465.04 TROJ_GEN.R0CBC0PBK14
TrendMicro-HouseCall 7.2.63 TROJ_GEN.R0CBC0PBK14
Vba32 AntiVirus BScope.Trojan.Agent
VIPRE Antivirus 26730 MegaSearch Toolbar
xlamk_R.dll (e49054ecb3ee417d69762aca6c900c61) has been flagged by the following 15 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Application.Generic.640894
avast! 8.0.1489.320 Win32:Adware-gen [Adw]
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender 7.2 Application.Generic.640894
Comodo Security 18339 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 9853 a variant of Win32/AdWare.MultiPlug.T
F-Secure 11.0.19100.45 Application.Generic.640894
G Data 24 Application.Generic.640894
Kaspersky not-a-virus:AdWare.Win32.MultiPlug.bfs
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.640894
Trend Micro 9.740-1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700-1001 ADW_MULTIPLUG
VIPRE Antivirus 29652 Trojan.Win32.Generic!BT
qNtPMRvlG.exe (15138ff3390b4687fc3dd3f4acef85ab) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Application.Generic.638264
AhnLab-V3 2014.05.24.00 Dropper/Win32.Preloader
AVG Generic_r.JW
Baidu-International Adware.Win32.MultiPlug.81
Bitdefender 7.2 Application.Generic.638264
ESET-NOD32 9841 a variant of Win32/AdWare.MultiPlug.T
G Data 24 Application.Generic.638264
Malwarebytes 1.75.0001 PUP.Optional.MultiPlug.A
MicroWorld-eScan Application.Generic.638264
Panda Antivirus Trj/Genetic.gen
Trend Micro 9.740-1012 ADW_MULTIPLUG
TrendMicro-HouseCall 9.700-1001 ADW_MULTIPLUG
VIPRE Antivirus 29530 Trojan.Win32.Generic!BT
j.exe (b0ee8864d103a51fc19984285099e53a) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware Application.Generic.649344
AhnLab-V3 2014.06.19.00 Dropper/Win32.Preloader
AVG Generic5.AVMA
Baidu-International Trojan.Win32.Dropper.77
Bitdefender 7.2 Application.Generic.649344
ESET-NOD32 9963 a variant of Win32/AdWare.MultiPlug.Y
F-Secure 11.0.19100.45 Application.Generic.649344
G Data 24 Application.Generic.649344
K7 AntiVirus 9.180.12449 Adware ( 0049b4c51 )
K7GW 9.180.12449 Adware ( 0049b4c51 )
McAfee Artemis!B0EE8864D103
McAfee-GW-Edition 2013 Artemis!B0EE8864D103
MicroWorld-eScan Application.Generic.649344
I.dll (957e832f7e5a3d97cdaef6354c247135) has been flagged by the following 11 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.01.25.00 Adware/Win32.Graftor
Avira AntiVir ADWARE/Adware.Gen
AVG Generic_r.GU
Baidu-International Adware.Win32.MultiPlug.N
Comodo Security 17671 ApplicUnwnt.Win32.InstallRex.ALC
ESET-NOD32 9336 a variant of Win32/AdWare.MultiPlug.N
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes PUP.Optional.MultiPlug.A
Qihoo-360 HEUR/Malware.QVM30.Gen
Rising Antivirus PE:Malware.Adware!6.1293
VIPRE Antivirus 25784 JustPlugIt (fs)
u.exe (c2f76b2a4784ce0f8b5d1fbb149de768) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
AhnLab-V3 2014.06.18.00 Dropper/Win32.Preloader
AVG Generic5.AWSD
Baidu-International Adware.Win32.MultiPlug.77
ESET-NOD32 9962 a variant of Win32/AdWare.MultiPlug.Y
Malwarebytes PUP.Optional.MultiPlug.A
McAfee Artemis!C2F76B2A4784
McAfee-GW-Edition 2013 Heuristic.BehavesLike.Win32.Suspicious.H
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0614
j.dll (5e82b06c849c657098025e7d43bad579) has been flagged by the following 8 scanners:
Anti-Virus softwareSoftware versionDetection
AVG Generic_r.KL
Baidu-International Adware.Win32.MultiPlug.bT
ESET-NOD32 9968 a variant of Win32/AdWare.MultiPlug.Y
McAfee RDN/Generic PUP.z!dw
McAfee-GW-Edition 2013 RDN/Generic PUP.z!dw
Sophos 4.98.0 Generic PUA PA
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.F47V0605
VIPRE Antivirus 30454 Trojan.Win32.Generic!BT
u.dll (9f712f660d2538ba5fd12cfc496b33c0) has been flagged by the following 5 scanners:
Anti-Virus softwareSoftware versionDetection
AVG Generic5.AWSC
Baidu-International Adware.Win32.MultiPlug.BT
Comodo Security 18568 ApplicUnwnt
ESET-NOD32 9952 a variant of Win32/AdWare.MultiPlug.Y
TrendMicro-HouseCall 9.700.0.1001 Suspicious_GEN.F47V0615
       View all 97 all detections
savernet has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.
Find out how to remove savernet.

Program detailsProgram details

Displayed publisher: Savernet
URL: justplug.it
Installation folder: C:\Documents and Settings\user\Application data\savernet
Uninstaller: "C:\Documents and Settings\user\Application Data\savernet\aHmbhLnI.exe" /s /n /C:"ExecuteCommands;UninstallCommands" ""
Estimated size: 906.53 KB

Program filesFiles installed by savernet

Program executable:aHmbhLnI.exe
Path:C:\Documents and Settings\user\Application data\savernet\aHmbhLnI.exe
Additional files:
  • aHmbhLnI.exe (by Setup)
  • (Malware detected) I.exe (by Setup)
  • aHmbhLnI.dll
  • (Malware detected) I.dll
  • (Malware detected) j.dll (by data mobile one) - data mobile one (of DBMS inputting of Physically)
  • (Malware detected) j.exe (by interactions in) - interactions in (applications term the information)
  • j.x64.dll (by data mobile one)
  • (Malware detected) qNtPMRvlG.exe (by only RAID database Administration technology) - only RAID database Administration technology (they or)
  • Qpo7uQV.exe
  • Qpo7uQV.x64.dll
  • (Malware detected) u.dll (by or into database) - or into database (software plans)
  • (Malware detected) u.exe (by arrays of the) - arrays of the (DBMS Defining often)
  • u.x64.dll (by or into database)
  • (Malware detected) xlamk_R.dll (by storage a) - storage a (DBMS any computers)
  • xlamk_R.x64.dll (by storage a)

Program behaviorsBehaviors exhibited

4 Internet Explorer BHOs
  • xlamk_R.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'SaverParo' with the class of {8FF15B2F-A7D0-2CCB-D41A-F231126A5C51}.
  • j.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'RoyaloSHoppperApp' with the class of {9590B1B2-F115-0EBF-6788-F25AF16E5C90}.
  • u.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'savernet' with the class of {AC17A36C-A1C0-DE1B-06AB-49BFF9C84DAA}.
  • I.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'surfkeepit' with the class of {106319D7-5E31-B58E-2677-7F577941E24E}.

How do I remove savernet?

Quickly and completely remove savernet from your computer by downloading "Should I Remove It?", its 100% FREE and installs in seconds (click the button below).
Download "Should I Remove It?", it's FREE!Remove savernet from your computer.
Or, you can uninstall savernet from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program savernet, click it, and then do one of the following:
    • Windows Vista/7/8: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove savernet.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by savernet you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome
Scan your PC for malware
If you do not have a good anti-virus program, please consider installing one. Below are some we highly recommend.

Win 7 (SP1) 71%
Win XP 29%
Uninstall it 83%
Keep it 17%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 71.43%
Windows XP 28.57%
Which OS releases does it run on?
Windows 7 Home Premium 57.14%
Microsoft Windows XP 28.57%
Windows 7 Starter 14.29%

Distribution by countryGeography

58.33% of installs come from the United States
Which countries install it?
  United States 58.33%
  Canada 16.67%
  France 16.67%
  Brazil 8.33%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Dell 28.57%
ASUS 14.29%
Sony 14.29%
Samsung 14.29%
Hewlett-Packard 14.29%
Common models
Sony VPCYB35AB 14.29%
Samsung RV415/RV515 14.29%
HP Pavilion dv6 Notebook ... 14.29%
Gigabyte G31M-ES2L 14.29%
Dell Inspiron M5040 14.29%
Dell Computer Dimension 2... 14.29%

comments1 comment

user comment
user comment
Brooke5 months ago
My computer has had trouble Uninstalling it, I've downloaded the Microsoft Uninstall Fixer but it requires the Product Code. Could you please tell me the code? Cheers