Exterminate It! Antimalware

malpedia

Known threats:699,742 Last Update:November 20, 22:46

Testimonials

exterminate it remove the agent.nbo files without restart. i let it scan again, nothing found! great job!

now i surf since 5 minutes, no popups, it looks like the problem is solved!

big thanks to you and your team, you are the only company that give me response and realy help to remove this bad worm/malware!

i will place now links to our network to your homepage and email my friends and business partners that they know that there is a realy good company with a great tool and good programmers.

thanks.

regards,

m. s.

SaveSense- Registry Keys List

This is a complete list of SaveSense registry keys collected by Exterminate It!. If you find any of these registry keys on your PC, your computer is very likely to be infected with the SaveSense - pua.

IMPORTANT: Because the registry is a core component of your Windows system, it is strongly recommended that you back up the registry before you begin deleting keys and values. For information about backing up the Windows registry, refer to the Registry Editor online help.
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\SaveSenseLive
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\SaveSense
  • HKEY_CURRENT_USER\SOFTWARE\SaveSenseLive
  • HKEY_CLASSES_ROOT\AppID\SaveSenseLive.exe
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3WebSvc.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3WebSvc
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3COMClassService.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3COMClassService
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.OnDemandCOMClassSvc.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.OnDemandCOMClassSvc
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CoreClass.1
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CoreClass
  • HKEY_CLASSES_ROOT\WOW6432Node\AppID\SaveSenseLive.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\SaveSenseLive
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3WebMachineFallback.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3WebMachineFallback
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3WebMachine.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.Update3WebMachine
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.ProcessLauncher.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.ProcessLauncher
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.OnDemandCOMClassMachineFallback
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.OnDemandCOMClassMachine.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.OnDemandCOMClassMachine
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CredentialDialogMachine.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CredentialDialogMachine
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CoreMachineClass.1
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CoreMachineClass
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CoCreateAsync.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLiveUpdate.CoCreateAsync
  • HKEY_CLASSES_ROOT\SaveSenseLive.Update3WebControl.3
  • HKEY_CLASSES_ROOT\SaveSenseLive.OneClickProcessLauncherMachine.1.0
  • HKEY_CLASSES_ROOT\SaveSenseLive.OneClickProcessLauncherMachine
  • HKEY_CLASSES_ROOT\SaveSenseLive.OneClickCtrl.9
  • HKEY_CURRENT_USER\SOFTWARE\SaveSense
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineUA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSenseLiveUpdateTaskMachineCore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SaveSense
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C681613B-5540-4AAD-B47F-AE1950AA4666}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B90A047-CFB0-4D82-9091-B74E19D07826}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47433CC6-8AEC-4832-AA9F-B5CF02036D4E}
  • HKEY_CLASSES_ROOT\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
  • HKEY_CLASSES_ROOT\WOW6432Node\CLSID\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{94266681-2C1A-4084-8983-F4A7002AA4BE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4775A96-7245-4F42-9EC6-2E8164256932}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
  • HKEY_LOCAL_MACHINE\SOFTWARE\SaveSense
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{71e129ff-6c2a-4984-818c-7e2c998b8d99}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\savesenselivem
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\savesenselive
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9474468B-BA82-437E-B312-99DA01D38D77}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{37E2F884-C748-4F4E-9D8D-CA8EE46C0DEB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A4F8DA4-9943-47AD-B7FD-2429C9C18E5A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F7F10E4-2ED2-494E-8EA4-622CED13FAE3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26271909-B19C-40CE-A0F8-63426F06DA1D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB986FF2-4D8E-4044-8F0D-5132E0007996}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FD428F17-1B85-4599-A2B7-0756D5E82305}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4223E7C-E6F0-4C2A-A310-6D6A3D7B0565}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ABB5B450-1148-49A2-8373-E31BEFBF8C20}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEA21FD1-C1A5-4A6D-95D7-B644A76D4350}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DC36542-0C83-43AE-A26F-77A8702B10E5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAE11698-98A9-4D0D-9571-7153B9E8813D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1669E007-B386-4630-A12F-55E135878E89}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{98EB56B1-A330-4F1F-92B1-148DA17F6CDF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{84EFFCE8-B93C-4844-B615-5FEBD193182C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{73078EEF-7759-4C9C-ABED-3CA9E618051F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3619497-BE6F-4BFD-AEDC-8C3515AC2991}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A80BF6D-6DD5-40BE-AD26-F68AC890FFEF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17139208-A16B-4CB0-8E12-86B2059357D9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E8488CCA-816F-4242-B51C-6A3ACC177AD2}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28B052E7-0D8E-477D-B72E-862C7294AA4E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04108E09-8693-4D4D-A08E-6AB3F4727493}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40BDFA94-51A7-4B0D-8D93-DA65A63DA388}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C964A986-C82C-4F37-AD5C-FB0178F4CFB5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A970AB0-1B94-403A-9192-E2042CFA4080}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01C14620-96C8-4038-88C2-58D2EE2A317C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{981726F6-32BB-49E6-97D0-4C5C1CF9F91B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{602E400C-C450-4A57-BA23-77D0DCDA85F7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{19E9A930-B188-490A-8C50-FA1DE5918D49}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2A5E8E5-3CBF-4796-9527-EF3DCC2224CA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8B63A22C-2312-4BF9-B9C1-5825F47B73A9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{466CABC4-3C02-45AA-8251-F58461571F7B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08516C1B-1E4F-4A94-A328-3CDB107F883B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A91423A5-A50E-470A-8921-940B2EE5680C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8DBBEF8-65CA-4B0F-A6CD-C5225B66CB09}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{925DE90A-0F59-4AA7-A475-082AE228A28E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04775957-E76D-4671-845C-FEBE5587C25A}
  • HKEY_CLASSES_ROOT\CLSID\{0f21b1e5-5afc-43c9-9c66-515046e92ec2}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F2174EC2-54A9-45A5-86BC-F001715FAEE7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{462443F4-7BF1-473D-9568-E113EB4C8F8E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{03D5D0FC-5DFA-48EB-AD66-42C077AF8A99}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D68858A7-59F5-40AD-BD1D-D92EFB1D5FD1}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ECFE867F-DF34-45E7-AD97-0B956C7D6741}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D737B0F2-D187-433A-8E45-F23E00C84788}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{32E9A749-A211-4283-A70B-AD2D1039715C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EAFF9DCD-790F-4B8B-8EF5-74372FFA12D5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9E39DB0D-63CC-4130-BFE2-04AB83074D19}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{846248B3-CFA1-42B0-99F6-554243DC67F9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C00D4F5-4F6C-4868-8B04-1313A19B0EA3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0BFD20A0-73DB-4750-84ED-DBD0338D1C8D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{04CA4667-CE46-4B87-B9B2-AAC7B65BD5F5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9FD4B09B-0532-4EDB-B88A-197B7C2513DF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3BD84089-4188-46E1-B494-3F07EE2C221B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D28A84DB-4FDE-460F-8A76-AA77435BAD5D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{37562892-6AEB-405F-A9D3-41CE2C271CFC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{08D290B1-BC1D-4798-B1F9-F1070385AA69}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{31CACC7E-69A9-4383-BB98-7269EAAD6829}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2D80CF9C-209E-4758-B0CE-E5B850D8767A}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\savesenselive1cf30bbc98645d5