Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Relationships
giant savings-bg.exe
Giant Savings by Awesome Apps (Signed)
Version: | 1.1.151.36 |
MD5: | c5af2f30e7c4abf18a132d78f8f05403 |
SHA1: | eb4569f308cbfd1c2e521851de318e458b16acc0 |
SHA256: | b474f516176d716004e037a3bc9f864119fd4fdf3e01b5109f977a2aa6d2e76a |
Warning 15 antivirus scanners has detected malware.
What is giant savings-bg.exe?
Giant Savings exe (giant savings-bg.exe) is a background process that is loaded with Internet Explorer via the Giant Savings BHO. Giant Savings is an adware type program that has causes serious performance issues to your PC by installing a number of plug-ins and add-ins to your web browser and Windows. It injects ads directly by modifying web pages based on your surfing habits.
About giant savings-bg.exe (from Awesome Apps)
“Giant Savings takes couponing to the next level by providing users with an easy to use coupon list they can use to save as they browse. Savings in a single click. The sad truth about online shopping i”
Details
File name: | giant savings-bg.exe |
Publisher: | 215 Apps |
Product name: | Giant Savings |
Description: | Giant Savings exe |
Typical file path: | C:\Program Files\giant savings\giant savings-bg.exe |
Original name: | Giant Savings.exe |
File version: | 1.1.151.36 |
Size: | 886.38 KB (907,648 bytes) |
Certificate |
Issued to: | Awesome Apps |
Authority (CA): | Thawte |
Effective date: | Tuesday, August 28, 2012 |
Expiration date: | Thursday, August 29, 2013 |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
.NET CLR: | No |
More details
Programs
The following program will install this file
Giant Savings from 215 Apps (Amazing Apps/50onRed) installs a web browser extension (Internet Explorer Browser Helper Object) to view web pages loaded and looks for affiliated merchants in order to possibly provide better pricing or alternative deals on a given product or merchant. Basically if Giant Savings (215 Apps) has a pre-arranged affiliate relationship with a similar merchant it will alert you when you visit through your web bro...
Network connections
[UDP] listens on port 49883
Malware detections
Based on 40+ industry antivirus scanners, 15 of them detected the following malware.
Antivirus engine | Engine version | Detection |
AVG |
2014.0.3629 |
Suspicion: unknown virus |
BitDefender |
7.2 |
Adware.Agent.NNP |
Dr.Web |
7.0.4.09250 |
Adware.Plugin.14 |
F-Secure |
11.0.19020.35 |
Adware.Agent.NNP |
G Data |
13.4.22 |
Adware.Agent.NNP |
Ikarus |
T3.1.3.5.0 |
AdWare.Agent |
Kingsoft |
2013.1.8.219 |
Win32.Troj.Agent.tq.(kcloud) |
eScan by MicroWorld |
12.0.250.0 |
Adware.Agent.NNP |
NANO AntiVirus |
0.22.8.49711 |
Trojan.Win32.Plugin.batpwq |
nProtect |
2013-01-22.01 |
Trojan/W32.Agent.907648.B |
Sophos |
4.85.0 |
AppRider |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.RCBH1J3 |
Vba32 AntiVirus |
3.12.18.4 |
Trojan.Agent.aidw |
VIPRE Antivirus |
15164 |
GamePlayLabs (v) |
ViRobot |
2011.4.7.4223 |
Trojan.Win32.A.Agent.907648 |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.73203113% | |
Kernel CPU: | 0.62075604% | |
User CPU: | 0.11127509% | |
Kernel CPU time: | 821 ms/min | |
Memory |
Private memory: | 6.05 MB | |
Private (maximum): | 12.28 MB | |
Private (minimum): | 12.27 MB | |
Non-paged memory: | 6.05 MB | |
Virtual memory: | 80.86 MB | |
Virtual memory (peak): | 82.86 MB | |
Working set: | 12.28 MB | |
Working set (peak): | 14.74 MB | |
Resource allocations |
Threads: | 14 | |
Handles: | 255 | |
GUI GDI count: | 9 | |
GUI GDI peak: | 11 | |
GUI USER count: | 8 | |
GUI USER peak: | 11 | |
Process properties
Integrety level: | Low |
Platform: | 32-bit |
Command line: | "C:\Program Files\giant savings\giant savings-bg.exe" /createbg |
Owner: | User |
Parent process: | iexplore.exe (by Microsoft) |
Threads
Averages
giant savings-bg.exe (main module) |
Total CPU: | 0.71141086% | |
Kernel CPU: | 0.59788785% | |
User CPU: | 0.11352301% | |
CPU cycles: | 19,739,756/sec | |
Context switches: | 20/sec | |
Memory: | 904 KB | |
ntdll.dll |
Total CPU: | 0.00758228% | |
Kernel CPU: | 0.00758228% | |
User CPU: | 0.00000000% | |
CPU cycles: | 97,024/sec | |
Memory: | 1.23 MB | |
WININET.dll |
Total CPU: | 0.00758205% | |
Kernel CPU: | 0.00758205% | |
User CPU: | 0.00000000% | |
CPU cycles: | 116,327/sec | |
Memory: | 980 KB | |
Distribution by Windows OS
OS version | distribution |
Windows 7 Ultimate N |
100.00% |
|