| Visit ThreatExpert web site | | | Close Report |
[PCTools]| What's been found | Severity Level |
| Creates a startup registry entry. | ![]() |
| Registers a 32-bit in-process server DLL. | ![]() |
| Contains characteristics of an identified security risk. | ![]() |
![]() | Possible Security Risk |
| Security Risk | Description |
Adware.WhenU_SaveNow![]() |
SaveNow shows targeted pop-up advertisements and coupons based on user's Internet surfing habits. It is usually distributed with other third party software such as BearShare. |
| Threat Category | Description |
![]() |
A potentially unwanted adware program designed to deliver various advertisements to the users' systems |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash | Alias |
| 1 |
%ProgramFiles%\AdVantage\AdVantage.exe
|
884,176 bytes | MD5: 0x7E857342986176D6864171E5643DB953 SHA-1: 0xED1570C83EE39FC61F87EF21BA9E3D7CCB007AF0 |
not-a-virus:AdTool.Win32.WhenU.t [Kaspersky Lab] |
| 2 | %ProgramFiles%\AdVantage\AdVantage.htm | 140,849 bytes | MD5: 0x4F431DA2840DCA976748D0C48630F982 SHA-1: 0x7EDAD9B2CC90CC58DC55D2EEA499699091FCA4D8 |
(not available) |
| 3 |
%ProgramFiles%\AdVantage\AdVUninst.exe
|
454,096 bytes | MD5: 0xB00E59202BF6F8FF8A8AFAB41926DF77 SHA-1: 0x6833E7F388BAAD5312B4A851F2495029D5F36F94 |
(not available) |
| 4 | %ProgramFiles%\AdVantage\ffext.mod | 17,625 bytes | MD5: 0x9F6818C62151C4F3634959D20E8C44A4 SHA-1: 0x23062BB72A27D283F2CE57EFD35C16EAC2575461 |
(not available) |
| 5 |
%ProgramFiles%\AdVantage\TR.dll
|
517,856 bytes | MD5: 0xC3D98DAC60F6F8A6AE60BAFA9E6745E6 SHA-1: 0xCA366F3D14E1B6DC9658EC5FE8A34899E59D6F4F |
not-a-virus:AdTool.Win32.WhenU.r [Kaspersky Lab]MeMedia [McAfee] |
| 6 | [file and pathname of the sample #1] | 1,050,584 bytes | MD5: 0xCAE0475C0D428C7C0E530EBC6C00FA22 SHA-1: 0xA345C8F173A611307199F155813E41B2F7B24C24 |
Adware.WhenU_SaveNow [PCTools]not-a-virus:AdTool.Win32.WhenU.t, not-a-virus:AdTool.Win32.WhenU.r [Kaspersky Lab] |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
AdVantage.exe![]() | %ProgramFiles%\AdVantage\AdVantage.exe![]() | 901,120 bytes |
| [filename of the sample #1] | [file and pathname of the sample #1] | 1,064,960 bytes |
![]() | Registry Modifications |
![]() | Other details |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.