SaveSense is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 10/10/2013.

0_Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– A toolbar is an additional internet browser bar.
– An Adware is a program that adds other programs without the knowledge of the user.
– Vendor : PUP.Optional

0_Main_Actions

– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a process launched at startup of the system (RP),
– It installs as a service to be launched each time the system (O23),(SS/SR),
– It starts a task planned in automatic (O39),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),
– It creates registry keys Tracing (O100),

0_Zhpdiag

O2 – BHO: SaveSense

[64Bits] – {0F21B1E5-5AFC-43C9-9C66-515046E92EC2} . (.SaveSense – SaveSense for IE.) — C:\Program Files (x86)\SaveSense\SaveSenseIE.dll
O23 – Service: SaveSenseLive Service (savesenselive) (savesenselive) . (.SaveSense – SaveSenseLive Update.) – C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
O23 – Service: SaveSenseLive Service (savesenselivem) (savesenselivem) . (.SaveSense – SaveSenseLive Update.) – C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
O39 – APT:Automatic Planified Task – C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job [938] O39 – APT:Automatic Planified Task – C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job [942] O39 – APT:Automatic Planified Task – C:\Windows\Tasks\SaveSense.job [292] [MD5.6F2939B1EC17A6631106CFD013A9CD77] [APT] [SaveSense] (…) — C:\Users\Coolman\AppData\Roaming\SAVESE~1\UPDATE~1\UPDATE~1.exe [199176] [MD5.C495D8665A32539660625182D23D5C59] [APT] [SaveSenseLiveUpdateTaskMachineCore] (.SaveSense.) — C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920] [MD5.C495D8665A32539660625182D23D5C59] [APT] [SaveSenseLiveUpdateTaskMachineUA] (.SaveSense.) — C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe [146920] O42 – Logiciel: SaveSense (remove only) – (.SaveSense.) [HKLM][64Bits] — SaveSense
O42 – Logiciel: SaveSense – (…) [HKCU][64Bits] — SaveSense
O42 – Logiciel: Google Update Helper – (.SaveSense.) [HKLM][64Bits] — {A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}[HKCU\Software\SaveSenseLive] [HKLM\Software\Wow6432Node\SaveSenseLive] O43 – CFD: 19/11/2013 – 20:51:33 – [1,262] —-D C:\Program Files (x86)\SaveSense
O43 – CFD: 19/11/2013 – 20:51:46 – [3,431] —-D C:\Program Files (x86)\SaveSenseLive
O43 – CFD: 19/11/2013 – 20:51:46 – [0,143] —-D C:\ProgramData\SaveSenseLive
O43 – CFD: 19/11/2013 – 20:51:44 – [0,190] —-D C:\Users\Coolman\AppData\Roaming\SaveSense
O43 – CFD: 19/11/2013 – 20:51:33 – [0,001] —-D C:\Users\Coolman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense
SS – | Auto 19/11/2013 146920 | (savesenselive) . (.SaveSense.) – C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
SS – | Demand 19/11/2013 146920 | (savesenselivem) . (.SaveSense.) – C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SaveSense] [HKLM\SYSTEM\CurrentControlSet\Services\savesenselive] [HKLM\SYSTEM\CurrentControlSet\Services\savesenselivem] [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F21B1E5-5AFC-43C9-9C66-515046E92EC2}] [HKLM\Software\Classes\CLSID\{0F21B1E5-5AFC-43C9-9C66-515046E92EC2}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0F21B1E5-5AFC-43C9-9C66-515046E92EC2}] [HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0F21B1E5-5AFC-43C9-9C66-515046E92EC2}] [HKCU\Software\SaveSenseLive] [HKLM\Software\Wow6432Node\SaveSenseLive] O45 – LFCP:[MD5.89B1CB430FE0FE6BD568A9AF0B25C75E] 12/11/2015 A — C:\windows\Prefetch\SAVESENSELIVE.EXE-A927BDEE.pf
O45 – LFCP:[MD5.8334184CDFC5A88C345FEA83C91E80ED] 12/11/2015 A — C:\windows\Prefetch\SAVESENSELIVEHANDLER.EXE-887EC19F.pf
C:\Program Files (x86)\SaveSense
C:\Program Files (x86)\SaveSenseLive
C:\Program Files (x86)\SaveSense\SaveSenseIE.dll
C:\Users\Coolman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SaveSense
C:\Program Files (x86)\SaveSenseLive\Update\SaveSenseLive.exe
C:\ProgramData\SaveSenseLive
C:\Users\Coolman\AppData\Roaming\SaveSense
C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineUA.job
C:\Windows\Tasks\SaveSenseLiveUpdateTaskMachineCore.job

0_Alias

PUP.Optional.SaveSense.A [ Malwarebytes Antimalware ] Adware.Shopper
Adware Bundle [Dr.Web]

Remove_Software

– Remove software in Windows Configuration Panel,
0_ZHPcleaner
Remove with ZHPcleaner
ZHPCleaner_EN2
0_Zhpdiag
Diagnose with ZHPDiag
ZHPDiag_2-300x220

2016-12-30T07:34:15+00:00 Categories: Adware, Polluteware, PUP, Toolbar|Tags: , , , |Comments Off on PUP.Optional.SaveSense