| Visit ThreatExpert web site | | | Close Report |
| What's been found | Severity Level |
| Contains characteristics of an identified security risk. | ![]() |
NOTICE: The content shown in the above window is captured automatically and is not controlled or endorsed by ThreatExpert.
Please contact us on this link should any material be offensive or inappropriate and we will ensure any such content is blocked from future viewers of the report.
![]() | Possible Security Risk |
| Security Risk | Description |
Adware.WhenU_SaveNow![]() |
SaveNow shows targeted pop-up advertisements and coupons based on user's Internet surfing habits. It is usually distributed with other third party software such as BearShare. |
![]() | File System Modifications |
| # | Filename(s) | File Size | File Hash |
| 1 | %Temp%\GLC1.tmp | 165,376 bytes | MD5: 0x8C97D8BB1470C6498E47B12C5A03CE39 SHA-1: 0x15D233B22F1C3D756DCA29BCC0021E6FB0B8CDF7 |
| 2 | %Temp%\GLF5.tmp | 814 bytes | MD5: 0xDEA7A85FA8D7AF805A373A1E97ACC16F SHA-1: 0xCA18D5809158C2BFF038DDF513650DA67BB3F301 |
| 3 |
%Temp%\GLF6.EXE
|
151,552 bytes | MD5: 0xF81D91509198204E31BCB3EF6103A8B7 SHA-1: 0x4EA28D7AFC9956C61863E9F30B11440C7EA0FC47 |
| 4 |
%Temp%\GLF6.tmp
%Windir%\Model.log |
0 bytes | MD5: 0xD41D8CD98F00B204E9800998ECF8427E SHA-1: 0xDA39A3EE5E6B4B0D3255BFEF95601890AFD80709 |
| 5 | %Temp%\GLF8.tmp | 15,239 bytes | MD5: 0x4A36EE288FE36271C1B2D5D64D6B6F16 SHA-1: 0xBA9636C97CAB42F1B0AB409B116BD83827A57F34 |
| 6 | %Temp%\GLG3.tmp | 538 bytes | MD5: 0xE0EC9EC2E95700053EB020EE60F3D389 SHA-1: 0x777FD7CCB1B6CDA37BB58CD2860123460FDF2309 |
| 7 | %Windir%\Model.txt | 35 bytes | MD5: 0xFD84D0C74CE9EC9FC6C9E607A62C1187 SHA-1: 0xB312493C2234CF61A2976980148F31BB2DF0AEDF |
| 8 | [file and pathname of the sample #1] | 2,193,597 bytes | MD5: 0xEF553BAFA2A5CC1F946E2AE3DA73713F SHA-1: 0x9F842BFF0096CBFEF41A7FEC1283AD2E5C604C25 |
![]() | Memory Modifications |
| Process Name | Process Filename | Main Module Size |
| [filename of the sample #1] | [file and pathname of the sample #1] | 28,672 bytes |
GLF6.EXE![]() | %Temp%\GLF6.EXE![]() | 163,840 bytes |
All content ("Information") contained in this report is the copyrighted work of Threat Expert Ltd and its associated companies ("ThreatExpert") and may not be copied without the express permission of ThreatExpert.
The Information is provided on an "as is" basis. ThreatExpert disclaims all warranties, whether express or implied, to the maximum extent permitted by law, including the implied warranties that the Information is merchantable, of satisfactory quality, accurate, fit for a particular purpose or need, or non-infringing, unless such implied warranties are legally incapable of exclusion. Further, ThreatExpert does not warrant or make any representations regarding the use or the results of the use of the Information in terms of their correctness, accuracy, reliability, or otherwise.
Copyright © 2013 ThreatExpert. All rights reserved.