84,488,480 programs installed

Should I remove Feven?

What percent of users and experts removed it?
84% remove it16% keep it
Overall Sentiment
Bad
What do people think about it?
(click star to rate)
How common is it?
Global Rank #20,944
United States Rank #20,621
Reach 0.0100%
Lifespan of installation (until removal)
< 7.79 days
229.79 days >
Average installed length: 120.73 days

Versions

VersionDistribution
1.33.153.1 4.06%
1.32.153.0 34.01%
1.31.153.4 1.52%
1.31.153.1 7.61%
1.31.153.0 7.61%
1.30.153.0 6.09%
1.29.153.3 4.06%
1.29.153.0 6.60%
1.28.153.6 1.52%
1.28.153.5 11.68%
1.28.153.4 0.51%
1.28.153.2 11.68%
1.28.153.1 3.05%

Feven 1.7

What is Feven?

Feven is a web browser extension that changes the browsers search and home pages as well as delivers. In order to provide search advertising revenue, the software is designed not only to modify the search provider but to protect it so that it remains the default browser search engine. It is typically installed via a bundled offer within a third-party software distribution.

What the toolbar does:
- Change of the default search engine, including the Browser's built-in search box, and address bar.
- Change of the default Home Page and/or New Tabs, and protect your search settings.
- Addition of alternative error page functionality, such as “Page Not Found”.

Overview

The most common release is 1.32.153.0, with over 98% of all installations currently using this version. During setup, the program registers itself to launch on boot through a Windows Schedule Task in order to automatically start-up (this is typically done to avoid any UAC prompts). It adds a Browser Helper Object (BHO) to Internet Explorer. A scheduled task is added to Windows Task Scheduler in order to launch the program at various scheduled times (the schedule varies depending on the version). The primary executable is named utils.exe. A majority of users end up uninstalling this less than a week of it being installed. The setup package generally installs about 15 files and is usually about 8.43 MB (8,840,914 bytes). The installed file Feven 1.7-updater.exe is the auto-update component of the program which is designed to check for software updates and notify and apply them when new versions are discovered.

This browser extension utilizes Crossrider framework, a cross-browser toolbar/plugin platform used to develop, deploy and monetize web browser toolbars for Internet Explorer, Chrome and Firefox. Crossrider extension provide monetization options, mostly potentially unwanted apps, for toolbars including coupons, search assistant (home page and search hijacking) and in-text contextual advertising. Many adware programs (defined by a number of anti-virus vendors) are built using Crossrider as it provides a quick an easy way to deploy ad-supported features that will assist in browser search hijacking.
  • Malware detected in the program
  • Automatically starts with Windows
  • Integrates into the web browser
  • Uses the Crossrider toolbar framework
  • During install it may hijack/modify the browser's homepage and search provider
  • Runs disconnected from the browser as a background process
  • Known to reinstall itself
  • Typically distributed through a pay-per-install bundle
  • Hijacks the web browser's home page
  • Hijacks the browser's default search provider
  • Most users and experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in Feven.
utils.exe (ed09b4f73e08c3a41a9eb49659f7b17e) has been flagged by the following 5 scanners:
Anti-Virus softwareVersionDetection
Baidu-International 4.0.3.131024 Trojan.Win32.Packed.ScrambleWrapper.C
Bkav FE 1.3.0.4246 HW32.CDB
ESET-NOD32 7.8870 Win32/Packed.ScrambleWrapper.C
Kingsoft AntiVirus 331020.49267 Win32.Troj.Generic.a.(kcloud)
TrendMicro-HouseCall 7.2.297 TROJ_GEN.F47V0825
Feven 1.7-enabler.exe (8e1cc90006c32a0ed9cd72b3eed7950a) has been flagged by the following 40 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.vu1@mS@yIabO
Agnitum Outpost 5.5.1.3 PUA.Agent!
AhnLab-V3 2015.08.12.01 PUP/Win32.Addlyrics
Arcabit 1.0.0.425 Application.Heur.EA19E9
avast! 8.0.1489.320 Win32:IeEnablerC-G [Adw]
AVG 15.0.0.4392 Generic5.ANHA
Avira 8.3.1.6 ADWARE/CrossRider.Gen2
AVware 1.5.0.21 Crossrider (fs)
Baidu-International 3.5.1.41473 Adware.Win32.CrossAd.45
Bitdefender 7.2 Gen:Application.Heur.vu1@mS@yIabO
Bkav FE 1.3.0.7062 W32.HfsAdware.A7F9
CAT-QuickHeal 14.00 PUA.Feven.A6
Clam AntiVirus 0.98.5.0 Win.Adware.Plush-29
Comodo Security 22986 ApplicUnwnt
Cyren 5.4.16.7 W32/S-a64d6097!Eldorado
Dr.Web 7.0.13.5270 Trojan.Crossrider1.23864
ESET-NOD32 12079 a variant of Win32/Toolbar.CrossRider.T potentially unwanted
Fortinet FortiGate 5.1.220.0 Riskware/Toolbar_CrossRider
F-Prot 4.7.1.166 W32/S-a64d6097!Eldorado
F-Secure 11.0.19100.45 Gen:Application.Heur.vu1@mS@yIabO
G Data 25 Gen:Application.Heur.vu1@mS@yIabO
IKARUS anti.virus T3.1.9.5.0 AdWare.CrossRider
Jiangmin 16.0.100 AdWare/Lyckriks.ki
K7 AntiVirus 9.207.16857 Adware ( 004bbf581 )
K7GW 9.207.16851 Adware ( 004bbf581 )
Kaspersky 15.0.1.10 not-a-virus:HEUR:AdWare.Win32.Agent.heur
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
Malwarebytes 2.1.1.1115 PUP.Optional.Feven.A
McAfee 6.0.5.614 Adware-AddLyrics
McAfee-GW-Edition v2015 Adware-AddLyrics
Microsoft Security Essentials 1.1.11903.0 BrowserModifier:Win32/IeEnablerCby
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.vu1@mS@yIabO
NANO AntiVirus 0.30.24.3079 Trojan.Win32.Toolbar.ctsoci
Rising Antivirus 25.0.0.17 PE:Malware.Adload!6.1D39
Sophos 4.98.0 AppRider (PUA)
SUPERAntiSpyware 5.6.0.1032 Adware.CrossRider/Variant
Symantec 20141.2.0.56 Adware.Crossid
Trend Micro 9.740.0.1012 TROJ_GEN.R047C0EFG15
VIPRE Antivirus 42800 Crossrider (fs)
Zillya 2.0.0.2348 Adware.Agent.Win32.9493
Feven 1.7-codedownloader.exe (734a9de172e84812b5dcd91929209a32) has been flagged by the following 34 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.Gu1@mS2ECkmO
Agnitum Outpost 5.5.1.3 PUA.Agent!
AhnLab-V3 2015.07.28.00 PUP/Win32.Addlyrics
Arcabit 1.0.0.425 Application.Heur.E8AAAA
avast! 8.0.1489.320 Win32:Crossrider-AI [PUP]
AVG 15.0.0.4392 Crossrider.OF
Avira 8.3.1.6 ADWARE/CrossRider.Gen2
AVware 1.5.0.21 Crossrider (fs)
Bitdefender 7.2 Gen:Application.Heur.Gu1@mS2ECkmO
CAT-QuickHeal 14.00 PUA.Feven.A6
Comodo Security 22876 ApplicUnwnt
Cyren 5.4.16.7 W32/A-eb9ef301!Eldorado
Dr.Web 7.0.13.5270 Trojan.Crossrider1.23864
ESET-NOD32 12003 a variant of Win32/Toolbar.CrossRider.T potentially unwanted
Fortinet FortiGate 5.1.220.0 Riskware/Toolbar_CrossRider
F-Prot 4.7.1.166 W32/A-eb9ef301!Eldorado
F-Secure 11.0.19100.45 Gen:Application.Heur.Gu1@mS2ECkmO
G Data 25 Gen:Application.Heur.Gu1@mS2ECkmO
IKARUS anti.virus T3.1.9.5.0 AdWare.CrossRider
Jiangmin 16.0.100 Adware/Agent.apqp
K7 AntiVirus 9.207.16698 Trojan ( 004a08ef1 )
K7GW 9.207.16699 Trojan ( 004a08ef1 )
Kaspersky 15.0.1.10 not-a-virus:HEUR:AdWare.Win32.Agent.heur
McAfee 6.0.5.614 Adware-AddLyrics
McAfee-GW-Edition v2015 Adware-AddLyrics
Microsoft Security Essentials 1.1.11903.0 Adware:Win32/Feven
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.Gu1@mS2ECkmO
NANO AntiVirus 0.30.24.2668 Riskware.Win32.Downware.cynnrj
Sophos 4.98.0 AppRider
SUPERAntiSpyware 5.6.0.1032 Adware.CrossRider/Variant
Symantec 20141.2.0.56 Adware.Crossid
Trend Micro 9.740.0.1012 TROJ_GEN.R047C0CFG15
VIPRE Antivirus 42394 Crossrider (fs)
Zillya 2.0.0.2318 Backdoor.PePatch.Win32.37980
Feven 1.7-chromeinstaller.exe (dae355a6fd6182e95576e36218bb5e1a) has been flagged by the following 27 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.Yu1@mmJPZgiO
AhnLab-V3 2015.04.10.00 PUP/Win32.Addlyrics
avast! 8.0.1489.320 Win32:Crossrider-AI [PUP]
AVG 15.0.0.4328 Crossrider.MF
AVware 1.5.0.21 Crossrider (fs)
Bitdefender 7.2 Gen:Application.Heur.Yu1@mmJPZgiO
Bkav FE 1.3.0.6379 W32.HfsAdware.A7F9
Comodo Security 21715 ApplicUnwnt
Cyren 5.4.16.7 W32/S-721e1cba!Eldorado
Dr.Web 7.0.12.3050 Trojan.Crossrider1.23864
ESET-NOD32 11454 a variant of Win32/Toolbar.CrossRider.S potentially unwanted
Fortinet FortiGate 5.0.999.0 Riskware/Toolbar_CrossRider
F-Prot 4.7.1.166 W32/S-721e1cba!Eldorado
F-Secure 11.0.19100.45 Gen:Application.Heur.Yu1@mmJPZgiO
G Data 25 Gen:Application.Heur.Yu1@mmJPZgiO
K7 AntiVirus 9.202.15552 Trojan ( 004b5c281 )
K7GW 9.202.15551 Trojan ( 004b5c281 )
Malwarebytes 1.75.0.1 PUP.Optional.Feven.A
McAfee 6.0.5.614 Adware-AddLyrics
McAfee-GW-Edition v2015 Adware-AddLyrics
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.Yu1@mmJPZgiO
NANO AntiVirus 0.30.10.952 Riskware.Win32.Toolbar.daeteq
Sophos 4.98.0 Generic PUA IC
Symantec 20141.2.0.56 Trojan.Gen.2
Trend Micro 9.740.0.1012 TROJ_GEN.R0CBC0EBJ15
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R0CBC0EBJ15
VIPRE Antivirus 39216 Crossrider (fs)
Feven 1.7-firefoxinstaller.exe (f23cbb54a7a79f5f5d522a7948754726) has been flagged by the following 26 scanners:
Anti-Virus softwareSoftware versionDetection
Lavasoft Ad-Aware 12.0.163.0 Gen:Application.Heur.2u1@mKdf!qpO
Agnitum Outpost 5.5.1.3 PUA.Toolbar.CrossRider!
AhnLab-V3 2015.04.11.00 PUP/Win32.Addlyrics
avast! 8.0.1489.320 Win32:Crossrider-AI [PUP]
AVG 15.0.0.4328 Toolbar.UD
AVware 1.5.0.21 Crossrider (fs)
Bitdefender 7.2 Gen:Application.Heur.2u1@mKdf!qpO
Bkav FE 1.3.0.6379 W32.HfsAdware.A7F9
Comodo Security 21717 ApplicUnwnt
Cyren 5.4.16.7 W32/A-6583813c!Eldorado
Dr.Web 7.0.12.3050 Trojan.Crossrider1.23864
ESET-NOD32 11455 Win32/Toolbar.CrossRider.S potentially unwanted
Fortinet FortiGate 5.0.999.0 Riskware/Toolbar_CrossRider
F-Prot 4.7.1.166 W32/A-6583813c!Eldorado
F-Secure 11.0.19100.45 Gen:Application.Heur.2u1@mKdf!qpO
G Data 25 Gen:Application.Heur.2u1@mKdf!qpO
Malwarebytes 1.75.0.1 PUP.Optional.Feven.A
McAfee 6.0.5.614 Adware-AddLyrics
McAfee-GW-Edition v2015 Adware-AddLyrics
MicroWorld-eScan 12.0.250.0 Gen:Application.Heur.2u1@mKdf!qpO
NANO AntiVirus 0.30.10.952 Riskware.Win32.Toolbar.czjdfd
Symantec 20141.2.0.56 Adware.Crossid
Trend Micro 9.740.0.1012 TROJ_GEN.R0C1C0EJB14
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.R0C1C0EJB14
VIPRE Antivirus 39222 Crossrider (fs)
Zillya 2.0.0.2134 Adware.CroRi.Win32.137
Feven 1.7-bho.dll (355aa1ff3f6d918840a37a782bc7f99a) has been flagged by the following 13 scanners:
Anti-Virus softwareSoftware versionDetection
AVG 13.0.0.3169 Generic5.AIKL
Dr.Web Trojan.Crossrider.7
ESET-NOD32 8976 a variant of Win32/Toolbar.CrossRider.H
Jiangmin 16.0.100 AdWare/Lyckriks.cu
K7 AntiVirus 9.173.10014 Riskware
K7GW 12.7.0.14 Riskware
Kingsoft AntiVirus 2013.4.9.267 Win32.Troj.Generic.a.(kcloud)
McAfee 5.600.0.1067 Artemis!355AA1FF3F6D
McAfee-GW-Edition 2013 Artemis!355AA1FF3F6D
Symantec 20131.1.5.61 WS.Reputation.1
TrendMicro-HouseCall 9.700.0.1001 TROJ_GEN.F47V1025
Vba32 AntiVirus 3.12.24.3 AdWare.Lyckriks
VIPRE Antivirus 22806 Crossrider (fs)
Feven 1.7-bho64.dll (3df3e703b6f78c1cd2e1c4fd5f71946c) has been flagged by the following 4 scanners:
Anti-Virus softwareSoftware versionDetection
ESET-NOD32 9393 a variant of Win64/Toolbar.Crossrider.A
Malwarebytes 1.75.0001 PUP.Optional.Feven.A
Symantec 20131.1.5.61 WS.Reputation.1
VIPRE Antivirus 26224 Crossrider (fs)
Feven 1.7-updater.exe (ddd109d17ff832503060b9a7c2c6ea05) has been flagged by the following 3 scanners:
Anti-Virus softwareSoftware versionDetection
ESET-NOD32 9161 a variant of Win32/Toolbar.CrossRider.K
Malwarebytes 1.75.0001 PUP.Optional.Feven.A
VIPRE Antivirus 24256 Crossrider (fs)
       View all 152 all detections
Feven has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

Program detailsProgram details

Displayed publisher: Feven
URL: crossrider.com
Installation folder: C:\Program Files\feven 1.7
Uninstaller: C:\Program Files\Feven 1.7\Uninstall.exe /fromcontrolpanel=1
Estimated size: 8.43 MB

Program filesFiles installed by Feven 1.7

Program executable:utils.exe (Malware detected)
Name:Feven 1.7
Feven 1.7 Installer
Path:C:\Program Files\feven 1.7\utils.exe
MD5:ed09b4f73e08c3a41a9eb49659f7b17e
Additional files:
  • Feven 1.7-bg.exe - Feven 1.7 (Feven 1.7 exe)
  • Feven 1.7-bho.dll - Feven 1.7 BHO
  • Feven 1.7-bho64.dll
  • Feven 1.7-buttonutil.exe
  • Feven 1.7-buttonutil64.exe
  • (Malware detected) Feven 1.7-chromeinstaller.exe
  • (Malware detected) Feven 1.7-codedownloader.exe
  • (Malware detected) Feven 1.7-enabler.exe
  • (Malware detected) Feven 1.7-firefoxinstaller.exe
  • Feven 1.7-updater.exe
  • Feven 1.7-buttonutil.dll
  • Feven 1.7-buttonutil64.dll
  • Feven 1.7-helper.exe
  • Uninstall.exe

Program behaviorsBehaviors exhibited

2 Internet Explorer BHOs
  • Feven 1.7-bho64.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Feven 1.7' with the class of {11111111-1111-1111-1111-110411051194} (CrossriderApp0040594).
  • Feven 1.7-bho.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'Feven 1.7' with the class of {11111111-1111-1111-1111-110411051194} (CrossriderApp0040594).
Scheduled Task
  • Feven 1.7-firefoxinstaller.exe is scheduled as a task named 'Feven 1.7-firefoxinstaller'.
5 Scheduled Tasks (Boot/Login)
  • Feven 1.7-updater.exe is automatically launched at startup through a scheduled task named Feven 1.7-updater.
  • Feven 1.7-enabler.exe is automatically launched at startup through a scheduled task named Feven 1.7-enabler.
  • Feven 1.7-codedownloader.exe is automatically launched at startup through a scheduled task named Feven 1.7-codedownloader.
  • Feven 1.7-firefoxinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.7-firefoxinstaller.
  • Feven 1.7-chromeinstaller.exe is automatically launched at startup through a scheduled task named Feven 1.7-chromeinstaller.

How do I remove Feven?

You can uninstall Feven from your computer by using the Add/Remove Program feature in the Window's Control Panel.
  1. On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
    • Windows Vista/7/8/10: Click Uninstall a Program.
    • Windows XP: Click Add or Remove Programs.
  2. When you find the program Feven 1.7, click it, and then do one of the following:
    • Windows Vista/7/8/10: Click Uninstall.
    • Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
  3. Follow the prompts. A progress bar shows you how long it will take to remove Feven.
  4. If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.

How do I reset my web browser?

If your web browser homepage and search settings have been modfied by Feven 1.7 you can restore them to their previous default settings.
Microsoft Internet Explorer
Mozilla Firefox
Google Chrome

OS VERSIONS
Win 7 (SP1) 58%
Win XP 1%
 
HOW IT STARTS
Scheduled task? Yes
(Runs on Windows boot)
 
USER ACTIONS
Uninstall it 84%
Keep it 16%

Windows OS versionsWindows

Which Windows OS versions does it run on?
Windows 7 61.93%
Windows 10 22.84%
Windows XP 8.12%
Windows Vista 7.11%
Which OS releases does it run on?
Windows 7 Home Premium 41.62%
Windows 8 13.20%
Windows 7 Ultimate 9.14%
Windows 7 Professional 8.12%
Microsoft Windows XP 8.12%
Windows Vista Home Premiu... 6.60%

Distribution by countryGeography

44.29% of installs come from the United States
Which countries install it?
  United States 44.29%
  France 13.24%
  United Kingdom 10.96%
  Canada 8.68%
  Italy 7.76%
  Israel 1.83%
  Australia 1.37%
  Mexico 1.37%
  Iran 1.37%
  Malaysia 1.37%
  DZ 1.37%
  TN 0.91%
  Greece 0.91%
  IQ 0.46%

OEM distributionPC manufacturers

What PC manufacturers (OEMs) have it installed?
Hewlett-Packard 29.29%
Acer 20.00%
Dell 16.43%
Toshiba 12.14%
ASUS 10.00%
Samsung 4.29%
Intel 2.14%
Lenovo 2.14%
Sahara 1.43%
Sony 1.43%
GIGABYTE 0.71%
Common models
HP Pavilion dv6 Notebook ... 4.39%
HP Pavilion g6 Notebook P... 2.63%
HP ProBook 4540s 2.63%
HP Pavilion dv7 Notebook ... 2.63%
Samsung 300E4A/300E5A/300... 2.63%
LENOVO 20182 1.75%

commentsComments

user comment
No one has commented yet. Help others learn more about this software, share your comments.