Should I block it?

98%
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization

VersionsAdditional versions

1.1.151.35 20.00%
1.1.151.35 80.00%
(Note, Awesome Apps publishes each variation of this file with the same version, but the hashes are unique.)

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
GetSidSubAuthorityCount, RegCreateKeyExA, RegDeleteValueA, RegCloseKey, RegQueryValueExA, RegSetValueExA, RegQueryInfoKeyA, RegEnumKeyExA, RegQueryInfoKeyW, RegDeleteKeyA, GetTokenInformation, RegOpenKeyExA, GetSidSubAuthority, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegEnumValueA
gdiplus.dll
GdiplusShutdown
kernel32.dll
FreeLibrary, LoadLibraryA, CloseHandle, GetLastError, GetCurrentProcess, OpenProcess, Sleep, TerminateProcess, WaitForSingleObject, CreateThread, RaiseException, EnterCriticalSection, LeaveCriticalSection, FlushInstructionCache, SetLastError, WideCharToMultiByte, LocalFree, FormatMessageA, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, MultiByteToWideChar, UnmapViewOfFile, SetEvent, MapViewOfFile, OpenFileMappingA, CreateFileMappingA, CreateEventA, lstrcpyA, LocalAlloc, InitializeCriticalSection, WriteFile, ReadFile, SetFilePointer, GetFileSize, CreateFileA, lstrlenW, ReleaseMutex, lstrcmpiA, DisableThreadLibraryCalls, GetModuleFileNameA, GetModuleHandleW, IsDBCSLeadByte, SizeofResource, LoadResource, GetCurrentProcessId, LoadLibraryExA, OpenMutexA, lstrlenA, GetVersion, ExpandEnvironmentStringsA, FreeEnvironmentStringsW, GetStartupInfoW, GetFileType, SetHandleCount, FlushFileBuffers, GetConsoleMode, GetConsoleCP, GetTimeZoneInformation, HeapDestroy, HeapCreate, GetLocaleInfoW, GetModuleFileNameW, GetStdHandle, ExitProcess, HeapSize, GetStringTypeW, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, LCMapStringW, GetCommandLineA, VirtualQuery, GetSystemInfo, VirtualProtect, HeapReAlloc, GetLocalTime, GetSystemTimeAsFileTime, RtlUnwind, DecodePointer, EncodePointer, InterlockedExchange, GetCurrentThreadId, OutputDebugStringA, DebugBreak, InterlockedIncrement, FindResourceA, InterlockedDecrement, GetModuleHandleA, GetProcAddress, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetUserDefaultLCID, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, LoadLibraryW, SetStdHandle, WriteConsoleW, CreateFileW, SetEndOfFile, CompareStringW, SetEnvironmentVariableA, GetStringTypeExA, InterlockedPopEntrySList, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, HeapAlloc, GetProcessHeap, HeapFree, InterlockedPushEntrySList, InterlockedCompareExchange, LCMapStringA, CreateMutexA
ole32.dll
CoGetClassObject, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoCreateInstance, StringFromGUID2, CoCreateGuid, CLSIDFromProgID
oleacc.dll
AccessibleObjectFromWindow
shell32.dll
ShellExecuteA, SHGetFolderPathA, ShellExecuteExA
urlmon.dll
URLDownloadToCacheFileA, CoInternetGetSession
user32.dll
LoadStringA, CharNextA, PostMessageA, GetWindowThreadProcessId, EnumWindows, SetWindowLongA, GetClassInfoExA, LoadCursorA, DefWindowProcA, RegisterClassExA, CreateWindowExA, GetWindowLongA, CallWindowProcA, DestroyWindow, GetDesktopWindow, DestroyIcon, SendMessageA, GetWindowRect, wvsprintfA, SetWindowPos, GetParent, FindWindowExA, UnhookWindowsHookEx, SetTimer, KillTimer, CharNextW, MessageBoxA, CharLowerA, GetWindowTextA, IsWindowVisible, UnregisterClassA
wininet.dll
InternetSetOptionA, InternetReadFile, HttpQueryInfoA, InternetGetCookieA, InternetSetCookieA, HttpSendRequestA, HttpOpenRequestA, InternetConnectA, InternetCloseHandle, InternetCrackUrlA, InternetOpenA
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer

SavingsApp.dll

SavingsApp by Awesome Apps (Signed)

Remove SavingsApp.dll
Version:   1.1.151.35
MD5:   c422de9a493b242a51077ca504c84624
SHA1:   d25ab833aaa8f354bd0b92dba6dc9ad8cf776994
SHA256:   98f3fd6a7d05a1a3c45d28233ea9e753595f5ee2ffa7b4dbafe96d12c824cc25
Warning 9 antivirus scanners has detected malware.

What is SavingsApp.dll?

SavingsApp BHO (savingsapp.dll) is the Internet Explorer BHO add-in portion of SavingsApp. SavingsApp BHO installs a Browser Helper into IE that monitor browsing habits. SavingsApp is an adware type program that has causes serious performance issues to your PC by installing a number of plug-ins and add-ins to your web browser and Windows. It injects ads directly by modifying web pages based on your surfing habits.

About SavingsApp.dll (from Awesome Apps)

SavingsApp is a web tool that lists deals to help you save on retail sites while you shop. We provide a list of deals that you can access at anytime while shopping, allowing you to avoid having to mak

DetailsDetails

File name:savingsapp.dll
Publisher:215 Apps
Product name:SavingsApp
Description:SavingsApp BHO
Typical file path:C:\Program Files\savingsapp\savingsapp.dll
File version:1.1.151.35
Size:596.88 KB (611,200 bytes)
Certificate
Issued to:Awesome Apps
Authority (CA):Thawte
Effective date:Tuesday, August 28, 2012
Expiration date:Thursday, August 29, 2013
Digital DNA
PE subsystem:Windows GUI
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following program will install this file
215 Apps
  86% remove
215 SavingsApp (by 50onRed) is a web browser plugin that displays coupon deals and other advertisements when users visit various online shopping sites. When a user visits an online shopping site and the program has a pre-arranged affiliate relationship with a similar merchant it will alert the user that other deals or prices exist, or in many cases just shows adverts. It injects ads and affiliate codes in product links directly by modif...

BehaviorsBehaviors

Internet Explorer Browser Helper Object
Located in the registry at 'SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects'
  • BHO CLSID: {11111111-1111-1111-1111-110011461139}

MalwareMalware detections

Based on 40+ industry antivirus scanners, 9 of them detected the following malware.
Antivirus engineEngine versionDetection
AVG 2014.0.3629 Suspicion: unknown virus
CAT Quick Heal 4.13.12.00 Adware.Crossid (Not a Virus)
Dr.Web 7.0.4.09250 Adware.Plugin.14
ESET NOD32 7.7811 a variant of Win32/Toolbar.CrossRider.A
Malwarebytes 1.62.0.140 PUP.CrossFire.SA
Symantec 20121.2.1.2 Adware.Crossid
Trend Micro 9.561.0.1035 ADW_GAMEPLAYLABS
Trend Micro HouseCall 9.700.0.1001 ADW_GAMEPLAYLABS
VIPRE Antivirus 14542 GamePlayLabs (v)

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Ultimate N 100.00%

Distribution by countryDistribution by country

United States installs about 100.00% of SavingsApp.
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE