Angel Art Screensaver 2.5a

Angel Art Screensaver 2.5a is an adware bundler that installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.

General information:

Malware Name: Angel Art Screensaver 2.5a
Malware Type: Adware Bundler
Company Name: Always Great Software, Inc
Company URL: http://www.alwaysgreat.com/
Threat Level: Elevated Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

Always Great Software, Inc provides you the software Angel Art Screensaver 2.5a that shows uplifting and inspiring images of angels portrayed in paintings from before the Renaissance to the 20th century. Let the cherubim charm and the seraphim inspire as they float on your screen.

Spyware Description:

Angel Art Screensaver 2.5a is an adware bundler that installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.

Characteristics/Symptoms:

    -> It installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). -> Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.

Additional information might be found here:

google Search at Google for Angel Art Screensaver 2.5a
bing Search at Bing for Angel Art Screensaver 2.5a
yahoo Search at Yahoo for Angel Art Screensaver 2.5a

Processes Running:

Angel Art.scr

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\NewDotNet\newdotnet7_48.dll 610304 Application Extension
C:\Program Files\NewDotNet\readme.html 6254 HTML Document
C:\WINDOWS\LastGood\INF\oem1.inf unknown Setup Information

Folder information Created after Installation:

Folder Location
C:\Program Files\Always Great Software\Angel Ar
C:\Program Files\Free Offers from Always Great Softwar

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\WhenUSave
HKEY_LOCAL_MACHINE \SOFTWARE\WhenUSave acm_rs
HKEY_LOCAL_MACHINE \SOFTWARE\WhenUSave extraver_url