Threat Search: 

ThreatExpert's Statistics for Adware:Win32/WhenU.A [Microsoft]:

Adware:Win32/WhenU.A [Microsoft] is also known as:
Threat AliasNumber of Incidents
Adware-SaveNow [McAfee]1,217
Adware.Savenow [Symantec]1,124
Adware.WhenU_SaveNow [PC Tools]1,055
not-a-virus:WebToolbar.Win32.WhenU.a [Kaspersky Lab]486
not-a-virus:AdWare.Win32.SaveNow.bo [Ikarus]462
not-a-virus:AdTool.Win32.WhenU.i [Ikarus]313
not-a-virus:AdTool.Win32.WhenU.i [Kaspersky Lab]171
not-a-virus:WebToolbar.Win32.WhenU.y [Kaspersky Lab]169
Virus.Win32.Trojan [Ikarus]156
not-a-virus:AdTool.Win32.WhenU.a [Kaspersky Lab]141
Generic.dx [McAfee]55
not-a-virus:AdWare.Win32.SaveNow.z [Ikarus]49
not-a-virus:AdWare.Win32.SaveNow.z [Kaspersky Lab]49
Adware.SaveNow!sd6 [PC Tools]26
not-a-virus:AdWare.Win32.SaveNow.bc [Kaspersky Lab]25
not-a-virus:WebToolbar.Win32.WhenU.i [Kaspersky Lab]24
AdWare.Win32.WhenU [Ikarus]23
Adware.WhenU!sd5 [PC Tools]12
not-a-virus:AdWare.Win32.SaveNow.bi [Kaspersky Lab]4
Adware-xplus [McAfee]3
not-a-virus:AdWare.Win32.SaveNow [Ikarus]3
not-a-virus:AdWare.Win32.SaveNow.af [Kaspersky Lab]3
not-a-virus:AdWare.Win32.SaveNow.ar [Kaspersky Lab]3
not-a-virus:AdWare.WhenU [Ikarus]2
not-a-virus:AdWare.Win32.SaveNow.ap [Ikarus]2
not-a-virus:AdWare.Win32.SaveNow.cb [Kaspersky Lab]2
Win-Trojan/Xema.variant [AhnLab]2
Adware.generic!ct [PC Tools]1
Adware.SaveNow.AD [PC Tools]1
Adware.SaveNow.BJ [PC Tools]1
not-a-virus:.WebToolbar [Ikarus]1
not-a-virus:AdWare.Win32.SaveNow.ae [Kaspersky Lab]1
not-a-virus:AdWare.Win32.SaveNow.by [Ikarus]1
not-a-virus:AdWare.Win32.SaveNow.by [Kaspersky Lab]1
not-a-virus:AdWare.Win32.SaveNow.c [Kaspersky Lab]1
not-a-virus:WebToolbar.Win32.WhenU.b [Kaspersky Lab]1
not-a-virus:WebToolbar.Win32.WhenU.d [Kaspersky Lab]1

Adware:Win32/WhenU.A [Microsoft] is known to be created as:
%ProgramFiles%\bearshare\installer\saveinstwm.exe
%ProgramFiles%\filesubmit\hllewchter.zip\vvsninst.exe
%ProgramFiles%\save\acm.dll
%ProgramFiles%\save\save.exe
%ProgramFiles%\save\saveuninst.exe
%ProgramFiles%\save\saveupdate.exe
%ProgramFiles%\savenow\savenow.exe
%ProgramFiles%\sky fire\vvsninst.exe
%ProgramFiles%\vvsn\vvsn.exe
%System%\saveupdate.exe
%Temp%\vvsninst.exe
Notes:
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).