Ocean Life Screensaver 2.5a
Ocean Life Screensaver 2.5a is an adware bundler that installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web
browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.
General information:
Malware Name: |
Ocean Life Screensaver 2.5a |
Malware Type: |
Adware Bundler |
Company Name: |
Always Great Software, Inc |
Company URL: |
http://www.alwaysgreat.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
Always Great Software, Inc provides you the software Ocean Life Screensaver 2.5a that shows beautiful images from our planet s living seas. Enjoy colorful underwater life from all over the world: Hawaii, Kiribati and Palau in the Pacific; the Gulf
of Aqaba in the Red Sea; the Caribbean; and the Tropical Atlantic Ocean. See many different forms of life from corals and sponges to clown fish and angelfish to eels. Experience Earth s amazing oceans. Includes 30 images.
Spyware Description:
Ocean Life Screensaver 2.5a is an adware bundler that installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web
browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.
Characteristics/Symptoms:
-> It installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). -> Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web browsing and Adware.NDotNet
is an adware program that associates non-existent domain names with sponsored content.
Additional information might be found here:
Processes Running:
Ocean Life.scr
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Documents and Settings\[USER]\Start Menu\Programs\WhenU\Customer Support.lnk |
1400 |
Shortcut |
C:\Program Files\NewDotNet\uninstall5_64.exe |
49664 |
Application |
C:\Program Files\NewDotNet\uninstall7_48.exe |
183808 |
Application |
Folder information Created after Installation:
Folder Location |
C:\Program Files\Free Offers from Always Great Softwar |
C:\WINDOWS\LastGood\IN |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WhenUSave |
brandskin_url |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WhenUSave |
brandstrip_rs |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WhenUSave |
brandstrip_url |