26923.zip (bandbrothers.exe)

26923.zip (bandbrothers.exe) is an adware bundler that installs other adware with itself like Adware-GAIN (Claria). The Adware that it installs with itself may download and displays advertisements.

General information:

Malware Name: 26923.zip (bandbrothers.exe)
Malware Type: Adware Bundler
Company Name: screensandthemes.com
Company URL: http://www.screensandthemes.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

screensandthemes.com provides you the software 26923.zip (bandbrothers.exe) that shows you 31 scenes from the TV drama series with sound.

Spyware Description:

26923.zip (bandbrothers.exe) is an adware bundler that installs other adware with itself like Adware-GAIN (Claria). The Adware that it installs with itself may download and displays advertisements.

Characteristics/Symptoms:

    -> It installs other adware with itself like Adware-GAIN (Claria). -> The Adware that it installs with itself may download and displays advertisements.

Additional information might be found here:

google Search at Google for 26923.zip (bandbrothers.exe)
bing Search at Bing for 26923.zip (bandbrothers.exe)
yahoo Search at Yahoo for 26923.zip (bandbrothers.exe)

Processes Running:

Band of Brothers Part01.scr

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\ScreensAndThemes\26923.zip\26923.zip 3620267 WinZip File
C:\Program Files\ScreensAndThemes\26923.zip\bonzi.exe 117511 Application
C:\WINDOWS\Band of Brothers Part01.scr 466944 Screen Saver

Folder information Created after Installation:

Folder Location
C:\Documents and Settings\[USER]\Start Menu\Programs\Band of Brothers Part0

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_CURRENT_USER \Software\Auralis\Wsst Screen Savers\Band of Brothers Part01
HKEY_CURRENT_USER \Software\Auralis\Wsst Screen Savers\Band of Brothers Part01\General EXESize
HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\26923.zip