Should I block it?
Yes, 98% block recommendation.
Possible reasons:
Multiple malware detections
Performance resource utilization
Additional versions
Relationships
luckysave.exe
Smartbar by Smartbar
Version: | 1.6.1.708 |
MD5: | 87aebfb8fe2b8792dc905707a7214836 |
SHA1: | 9c75af417c451b9d0c8f7b14dd33b5594374ae9c |
SHA256: | 3e7b75708961a68c0bf249c962ab03478b2d9cbc49a36a87a8d461305d6730cf |
Warning 5 antivirus scanners has detected malware.
What is luckysave.exe?
Smartbar (Snap.Do) is a web browser addin/toolbar with Internet Explorer, Chrome and Firefox. Snap.Do provides social integration features for Facebook and Twitter. Privacy Policy: In order to facilitate, refine, personalize and match the identification and presentation of our products results to your browsing preferences and habits, we collect information regarding your use of our Product including URL and information of websites you browse while Smartbar is installed.
About luckysave.exe (from Smartbar)
“Snap.do works on all 3 major web browsers – Google Chrome, Mozilla Firefox and Internet Explorer. Simply get it now to start snapping! Snap.do will always be there when you need it. Once you got it yo”
Details
File name: | luckysave.exe |
Publisher: | Smartbar |
Product name: | Smartbar |
Typical file path: | C:\users\user\appdata\local\smartbar\application\luckysave.exe |
Original name: | Smartbar.exe |
File version: | 1.6.1.708 |
Size: | 13.5 KB (13,824 bytes) |
Digital DNA |
PE subsystem: | Windows GUI |
File packed: | No |
Code language: | Microsoft Visual C# / Basic .NET |
.NET CLR: | Yes |
.NET NGENed: | No |
More details
Behaviors
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
- 'Browser Infrastructure Helper' → C:\users\user\appdata\Local\Smartbar\Application\Luckysave.exe startup
Malware detections
Based on 40+ industry antivirus scanners, 5 of them detected the following malware.
Antivirus engine | Engine version | Detection |
ESET NOD32 |
7.7969 |
a variant of Win32/Toolbar.Linkury.A |
Fortinet |
5.0.26.0 |
Adware/MSIL_Agent |
Kaspersky |
9.0.0.837 |
not-a-virus:AdWare.MSIL.Agent.af |
Panda Antivirus |
10.0.3.5 |
Suspicious file |
Trend Micro HouseCall |
9.700.0.1001 |
TROJ_GEN.RCBH1B3 |
Resource utilization
(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
CPU |
Total CPU: | 0.00313587% | |
Kernel CPU: | 0.00167021% | |
User CPU: | 0.00146566% | |
Kernel CPU time: | 78,906 ms/min | |
CPU cycles: | 34,249,869/sec | |
Context switches: | 67/sec | |
Memory |
Private memory: | 70.98 MB | |
Private (maximum): | 82.23 MB | |
Private (minimum): | 6.23 MB | |
Non-paged memory: | 70.98 MB | |
Virtual memory: | 410.04 MB | |
Virtual memory (peak): | 447.11 MB | |
Working set: | 24.42 MB | |
Working set (peak): | 82.43 MB | |
Page faults: | 2,967,908/min | |
I/O |
I/O read transfer: | 2.91 MB/sec | |
I/O read operations: | 4,310/sec | |
I/O write transfer: | 2.66 KB/sec | |
I/O write operations: | 1/sec | |
I/O other transfer: | 36.73 KB/sec | |
I/O other operations: | 1,278/sec | |
Resource allocations |
Threads: | 30 | |
Handles: | 1086 | |
GUI GDI count: | 71 | |
GUI GDI peak: | 74 | |
GUI USER count: | 132 | |
GUI USER peak: | 138 | |
Process properties
Distribution by Windows OS
OS version | distribution |
Windows 8 |
66.67% |
|
Windows Vista Home Premium |
33.33% |
|
Distribution by country
United States installs about 100.00% of Smartbar.
Distribution by PC manufacturer
PC Manufacturer | distribution |
ASUS |
66.67% |
|
Acer |
33.33% |
|