Snapshots of Ronald Reagan Screensaver 2.5a
Snapshots of Ronald Reagan Screensaver 2.5a is an adware bundler that installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response
to users web browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.
General information:
Malware Name: |
Snapshots of Ronald Reagan Screensaver 2.5a |
Malware Type: |
Adware Bundler |
Company Name: |
Always Great Software, Inc |
Company URL: |
http://www.alwaysgreat.com/
|
Threat Level: |
Elevated Risk |
Operating System: |
WIN XP |
Installation Type: |
Installed through EXE |
Operation: |
Time of After Installation |
Company Description:
Always Great Software, Inc provides you the software Snapshots of Ronald Reagan Screensaver 2.5a that honors the Gipper and the conservative principles he fought for. Ronald Reagan, one of this nation s finest presidents, strengthened the nation s
economy, increased our freedoms, and brought democracy to many millions around the world. The screensaver shows 25 classic images of President Reagan next to quotes that epitomize the man and his principles.
Spyware Description:
Snapshots of Ronald Reagan Screensaver 2.5a is an adware bundler that installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response
to users web browsing and Adware.NDotNet is an adware program that associates non-existent domain names with sponsored content.
Characteristics/Symptoms:
-> It installs other adware with itself like Adware-SaveNow (WhenU), Adware-Url.gen and NDotNet (New.net). -> Adware-SaveNow (WhenU) may displays pop-up advertising on the desktop in response to users web browsing and Adware.NDotNet
is an adware program that associates non-existent domain names with sponsored content.
Additional information might be found here:
Processes Running:
Snapshots of Ronald Reagan.scr
File information Created after Installation:
File Location |
Size (Bytes) |
Type |
C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\74BFD122C0875EC75DBE5C6DB4C59019 |
410133 |
System file |
C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\Content\7735880A01E3F94F763761958A7A8191 |
1219 |
System file |
C:\Documents and Settings\[USER]\Application Data\Microsoft\CryptnetUrlCache\MetaData\486CC6AFD08942336C61FCD401C4A1D1 |
120 |
System file |
Folder information Created after Installation:
Folder Location |
C:\Program Files\Sav |
C:\WINDOWS\LastGood\IN |
Registry information Created after Installation:
Main Registry Key |
Sub Registry Key |
Key Value Name |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WhenUSave |
|
HKEY_LOCAL_MACHINE |
\SOFTWARE\WhenUSave |
acm_rs |
HKEY_LOCAL_MACHINE |
\SOFTWARE\WhenUSave |
brandskin_url |