Winter Sports Screen Saver

Winter Sports Screen Saver is an adware bundler that installs other adware with itself like Adware-Ezula. It can alter Web pages viewed in Internet Explorer and can add extra links to certain keywords that are targeted by advertisers.

General information:

Malware Name: Winter Sports Screen Saver
Malware Type: Adware Bundler
Company Name: 3D Screensaver Jam
Company URL: http://www.3d-screensaver-jam.com/
Threat Level: Low Risk
Operating System: WIN XP
Installation Type: Installed through EXE
Operation: Time of After Installation

Company Description:

3D Screensaver Jam provides you the software Winter Sports Screen Saver that shows you Snowboarding, tubing, and much more. Get ready for all those fun winter activities with this saver.

Spyware Description:

Winter Sports Screen Saver is an adware bundler that installs other adware with itself like Adware-Ezula. It can alter Web pages viewed in Internet Explorer and can add extra links to certain keywords that are targeted by advertisers.

Characteristics/Symptoms:

    -> It installs other adware with itself like Adware-Ezula. -> It can alter Web pages viewed in Internet Explorer and can add extra links to certain keywords that are targeted by advertisers.

Additional information might be found here:

google Search at Google for Winter Sports Screen Saver
bing Search at Bing for Winter Sports Screen Saver
yahoo Search at Yahoo for Winter Sports Screen Saver

Processes Running:

Winter Sports.scr

File information Created after Installation:

File Location Size (Bytes) Type
C:\Program Files\SaveNow\SaveNow.exe 166400 Application
C:\Program Files\SaveNow\Uninst.exe 13368 Application
C:\Program Files\SaveNow\savenow.htm 31729 HTML Document

Folder information Created after Installation:

Folder Location
C:\WINDOWS\LastGoo
C:\WINDOWS\LastGood\IN

Registry information Created after Installation:

Main Registry Key Sub Registry Key Key Value Name
HKEY_LOCAL_MACHINE \SOFTWARE\WhenU\SaveNow InstallDir
HKEY_LOCAL_MACHINE \SOFTWARE\WhenU\SaveNow db_local_update
HKEY_LOCAL_MACHINE \SOFTWARE\WhenU\SaveNow db_script_update