Giant Savings.exe

Giant Savings

Amazing Apps

This is part of a distribution package that is classified as adware distributed by 50onRed. This adware is used to interact with the installed web browsers and inject ads and modify the default search and homepages. The application Giant Savings.exe, “Giant Savings exe” by Amazing Apps has been detected as adware by 19 anti-malware scanners. This file is typically installed with the program Giant Savings by 215 Apps which is a potentially unwanted software program. This web browser addon will display additional advertisements in the user's browser including popup, banner, contextual hyperlinks as well as affiliate links.
Publisher:
215 Apps  (signed by Amazing Apps)

Product:
Giant Savings

Description:
Giant Savings exe

Version:
1.1.149.12

MD5:
3cf145ced22b25174f02b4ae33a4e9c3

SHA-1:
a5e6b97ec8e5faa68dbaf3ba08e9e674fe2b0be3

SHA-256:
3e7a644581cf17abf3cfa922e9038f38b383ebf1b5647fd73f3e59e1a0d16587

Scanner detections:
19 / 68

Status:
Adware

Explanation:
Browser extension that injects additional advertisements (banner and text links) on web pages.

Analysis date:
4/25/2024 5:14:08 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Adware.Generic.554623
361

Agnitum Outpost
PUA.Toolbar.CrossRider
7.1.1

Baidu Antivirus
Trojan.Win32.Toolbar
4.0.3.1628

Bitdefender
Adware.Generic.554623
1.0.20.195

Dr.Web
Adware.Plugin.24
9.0.1.039

Emsisoft Anti-Malware
Adware.Generic.554623
8.16.02.08.05

ESET NOD32
Win32/Toolbar.CrossRider (variant)
10.9010

F-Secure
Adware.Generic.554623
11.2016-08-02_2

G Data
Adware.Generic.554623
16.2.22

K7 AntiVirus
Unwanted-Program
13.174.10656

Malwarebytes
PUP.GamePlayLabs
v2016.02.08.05

MicroWorld eScan
Adware.Generic.554623
17.0.0.117

Quick Heal
Adware.Crossid (Not a Virus)
2.16.12.00

Reason Heuristics
PUP.50OnRed.AmazingApps (M)
16.2.8.17

Sophos
AppRider
4.94

SUPERAntiSpyware
Trojan.Agent/Gen-Crossid
9336

Trend Micro House Call
TROJ_GEN.R0CBC0OL813
7.2.39

Trend Micro
TROJ_GEN.R0CBC0OL813
10.465.08

VIPRE Antivirus
GamePlayLabs
23084

File size:
430.9 KB (441,216 bytes)

Product version:
1.1.149.12

Copyright:
Copyright 2011

Original file name:
Giant Savings.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\giant savings\giant savings.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
5/1/2012 2:00:00 AM

Valid to:
5/2/2013 1:59:59 AM

Subject:
CN=Amazing Apps, O=Amazing Apps, L=Philadelphia, S=Pennsylvania, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
2E307885017928B61D4F2CEF5EB10A05

File PE Metadata
Compilation timestamp:
3/20/2012 11:43:16 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
12288:R4k3ViprBlWaQBDrIrUgbVDgmb33cEfpjUb15R9xrdfu:R4kWg0URXdG

Entry address:
0x41D23

Entry point:
E8, BA, 90, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, 74, D0, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 40, 96, 46, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, 44, A0, 45, 00...
 
[+]

Code size:
352.5 KB (360,960 bytes)

The file Giant Savings.exe has been discovered within the following program.

Giant Savings  by 215 Apps
Giant Savings from 215 Apps (Amazing Apps/50onRed) installs a web browser extension (Internet Explorer Browser Helper Object) to view web pages loaded and looks for affiliated merchants in order to possibly provide better pricing or alternative deals on a given product or merchant.
giant-savings.com
85% remove it
 
Powered by Should I Remove It?

Remove Giant Savings.exe - Powered by Reason Core Security