WhenU.SaveNow

Popis: Adware
Úroveň rizika: Vysoké
Datum 1. výskytu: Monday, April 14, 2008
Poskytovatel Softwaru: WhenU.com, Inc.
Stručné informace: WhenU/SaveNow opens contextually targeted pop-ups on the desktop in response to user's web surfing.
Odstranění: Tento škodlivý software může být odstraněn pomocí "Spyware Terminatora"

ODSTRANIT SPYWARE »

Geogr. rozdělení softwaru "WhenU.SaveNow"

Info o škodlivém softwaru

Zobrazit vše

Detected Items

  1. Detected Files: %PROGRAMFILES%\Save\SaveUninst.exe MD5: 20EFC083CBFFD874C1E16A143A13D1AD Size:124852 MD5: 6B22AAE434B9E0395749C2C037D7EB80 Size:118200 MD5: 0AC19B03BE9748A946DEB2A849744F5C Size:32376 MD5: AA9F305228B39FBEF58DB805152E210A Size:24124 MD5: CF3576FF37CC70DA886F113E83BEBE19 Size:30336 MD5: 6718F420267F00ABBB8F109984185B50 Size:29312 MD5: E468A2D31824961A89888D2DFBDC552A Size:32376 MD5: 9B4ACDCE3789C3869C6E603D0EA0C465 Size:20540 %PROGRAMFILES%\SaveNow\Uninst.exe MD5: 4D1A762E58ADE94987FDB6C41C125AB2 Size:15416 MD5: 13FD93A68C959ED01128488F9B81287C Size:11776 MD5: C3B3713D4FAC019E6842F663BA861B2B Size:13368 %PROGRAMFILES%\SaveNow\SaveNow.exe MD5: 55C96B1BAA9C5481609346FC4AAA0B23 Size:194048 MD5: 6700E5FEB4A3AFB9FD1782A96DD24BB1 Size:139776 %PROGRAMFILES%\vvsn\VVSN.exe MD5: DE4E6AAF7285FF0B36C82FE7540A0975 Size:107592 MD5: A7F0A26EB76B808D6A4A124704566A7D Size:102400 MD5: 74CEE857A756191919F85EC7EB397174 Size:163840 %PROGRAMFILES%\Save\Inventrio\InventarioSave.dll MD5: A26B2C69026DC4DF28C10F87051F7620 Size:294980 MD5: B93DA0BF876ADF941D939AF5E1D07CB0 Size:270404 %PROGRAMFILES%\Save\ILRWindows\ILRPiloto.EXE MD5: 8F496C9106B666D09DAB020B23DF603B Size:94208 MD5: DE3A6C6B2EC41EDF9084FCFAC2020807 Size:94208 %PROGRAMFILES%\Save\ILRWindows\ILREstorno.dll MD5: 020B59658150211FE32EFD4478B0A108 Size:286720 MD5: D9E5A1FAEB5F6A615ADC78D34CEF0400 Size:286720 %PROGRAMFILES%\Save\ILRWindows\ILRBasic.dll MD5: 053BF66AC24B148E28FF3FE25C973BA1 Size:512000 MD5: E878CF6D57B265A00D6D8EFD0D108085 Size:512000 %PROGRAMFILES%\Save\ILRWindows\ILRAtuaRet.dll MD5: DB0136E96C986334B3DD9A93D8CAAC91 Size:1765376 MD5: 7F17E8952D2E68CFF37F901DA2B49147 Size:1761280 %PROGRAMFILES%\Save\ILRWindows\ILRAtuaLoja.dll MD5: 2A192EB57E64AACD7B38D8975CCC6B60 Size:3014656 MD5: 98D52990EA996663190605BA6928F427 Size:3014656 %PROGRAMFILES%\Save\ILRWindows\ILRAcesso.dll MD5: 08DC7F12B918A0A4B08C11E4DAFF09EB Size:32768 %PROGRAMFILES%\Save\Tabelas\Tabelas.EXE MD5: 8320D038ADCAA2F93E405B0BB82F4006 Size:1511424 %PROGRAMFILES%\Save\Produtos\Produtos.EXE MD5: 2CFEB8E1583671953046CFDD4A0129B3 Size:2072636 MD5: 67A63A12AA5EBB3F6A3733D1B5792896 Size:2068540 %PROGRAMFILES%\Save\Preos\Preos.EXE MD5: 52D20C2FD545AF1C6606CC2249628042 Size:2879488 %PROGRAMFILES%\Save\Pedidos\Pedidos.EXE MD5: 49A945650659367B6741C8515415BFF9 Size:8667136 MD5: 0F4BDC5AF7D213AA7D3A0D236D727BAD Size:8638464 %PROGRAMFILES%\Save\Movimentao Avulsa\Movimentao Avulsa.EXE MD5: 85D3583AC9FF6BB2154E8F14B3E3DE6C Size:1396736 %PROGRAMFILES%\Save\Metas de Vendas\Metas de Vendas.EXE MD5: 2ACBE0DF51B5FDEB0CB8567CBEC69EC1 Size:2056192 %PROGRAMFILES%\Save\Manager\Manager.EXE MD5: DCD676D3141F95880A406939E76A0833 Size:1503232 MD5: 8EFC3927F39AEAA1701DC84D680FB857 Size:1744896 MD5: 7F2A9CFFAC8C4DF0A9AE7CAB0002193D Size:1744896 %PROGRAMFILES%\Save\Inventrio\Inventrio.EXE MD5: 4057D1D5C9E2B2BD96398BDA15E443EE Size:2506752 MD5: E188BE4C2D2D29965FDB084AA9599EDF Size:2494464 %PROGRAMFILES%\Save\Gerencial\Gerencial.EXE MD5: 02750BCD68531EAD1B23AC2789FE7CF9 Size:3940414 %PROGRAMFILES%\Save\Clientes\Clientes.EXE MD5: 24587500F90F7DB988241AAFFE7C93D2 Size:1511424 %PROGRAMFILES%\Save\Batimento\Batimento.EXE MD5: 88615D219F1758D7E10564A5716A6CB3 Size:1310720 %PROGRAMFILES%\Save\Auditoria\Auditoria.EXE MD5: 7ED63D39A31967B5F73984A09599F0A4 Size:1298432 %PROGRAMFILES%\Save\ILRWindows\ILRWindows.EXE MD5: 471F94450D885455A2DBD57EB44EB751 Size:2609152 MD5: 11D77E4CD98AC15CAA9AA59E567F117A Size:2609152 %PROGRAMFILES%\Save\extra.exe MD5: 116D68CB72A86B1D6A2A4F6E581C954C Size:336248 MD5: 49F299343AC24D499D3EBD0E072A6FDD Size:277048 %PROGRAMFILES%\Save\Save.exe MD5: 43F84B1C5108A4FBFED88DB69CD446B6 Size:646600 MD5: 583FBDD19453175C97255761D9D6C491 Size:478320 MD5: DF954293E614C7363CB82D15109518D8 Size:315904 MD5: C2B301245BA652D14B278B4684BA34BB Size:827904 MD5: F546BC617D80CA36D4BB50C5845EA6E3 Size:343616 MD5: 7E7713E0069159031A232D0A560E545D Size:221184 MD5: 20AF9BD458CEA0B837A2D7A5E149EDF9 Size:881008 %PROGRAMFILES%\Save\saveupdate.exe MD5: E9BC4F03B8058EEFDB8896F42E064FB2 Size:560184 MD5: 45610EC74627069EEAC07D6D1E844B39 Size:713080 %PROGRAMFILES%\Save\ACM.dll MD5: 694A3416BDB2B246D9A270645D799CA1 Size:517688 %PROGRAMFILES%\DAEMON Tools\SetupDTSB.exe MD5: FCAB18D4E3DBC8C51FA1F4FB4B474D27 Size:143416 MD5: 938B7E14C6ADDA8125FD1A88881F5650 Size:156584 MD5: 0D8C6ABF24EFF55EA951492F40E28268 Size:203176 MD5: 564E646A200D6068C54E886442E7C8C2 Size:175328 %PROGRAMFILES%\Save\temp.exe MD5: 4B0B3267DA160BA7BE83B2B82B0B0869 Size:416768 %PROGRAMFILES%\Save\SaveNowupdate.exe MD5: 7187984E68068997476596837101C1FE Size:246848 MD5: 7AFF16BAF7BC2D9CB780D4D975383968 Size:3696504 f:\PORTABLE IBM\Bureau Mootez\VVSNI_LOFS120501Inst.exe MD5: FBBED9813267000B6A8F7FF75B4F51B1 Size:107064 %PROGRAMFILES%\Save\Gerenciador de Relatorios\TabelasNET.msi MD5: 92768B5215C4F9C400991537D46432D1 Size:190976 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Quadrant - ILR - Atualizacao.msi MD5: D92E6319DEF908C17D1C8291FE8D624C Size:105984 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.VBRUN.dll MD5: 57D24CDCAC51D3060AAFC64540E606BB Size:49152 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.VBA.dll MD5: 5B9EA036B2C2985F7D17E34B62BBD9CC Size:10752 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.StdFormat.dll MD5: 8B6F1CF7F529EE9A0C07F10F5C1A7C26 Size:12800 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.GRExcel.dll MD5: 196D412EE1815F0428B8C7B18A1A1D59 Size:32768 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.CRPEAuto.dll MD5: F1D06D55C08439BB967C1C71A7F5C564 Size:233472 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.axViewData.dll MD5: 4B3ED95771DF81858A0508D9EEF40902 Size:262144 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Interop.ADODB.dll MD5: 82ED508609B013407D3D8701EA152965 Size:102400 %PROGRAMFILES%\Save\Gerenciador de Relatorios\GerenciadorRelatoriosUI.dll MD5: 47A3D83CA54F475029B010F38E93BA85 Size:282624 %PROGRAMFILES%\Save\Gerenciador de Relatorios\GerenciadorRelatorios.dll MD5: EE0078A0E4296A164CDF8619B0E203D1 Size:212992 %PROGRAMFILES%\Save\Gerenciador de Relatorios\AxInterop.axViewData.dll MD5: 76569179A50942EBD33A3D08B1854E79 Size:81920 %PROGRAMFILES%\Save\Gerenciador de Relatorios\AuditoriaNET.msi MD5: C0928F9F127ACFB750C4367AA6784D5C Size:76288 %PROGRAMFILES%\Save\Gerenciador de Relatorios\adodb.dll MD5: 17E9B16AA9EEF97178EB30A77FDBD737 Size:110592 %PROGRAMFILES%\Save\Gerenciador de Relatorios\AcessoNET.msi MD5: 85766A3A96ECBC4837B91244CF810D0E Size:93696 %PROGRAMFILES%\Save\Fluxo de Caixa\Interop.VBRUN.dll MD5: 6A50348D4EE24A34923F932A8C207C14 Size:49152 %PROGRAMFILES%\Save\Fluxo de Caixa\Interop.VBA.dll MD5: 58F3B07F34682D4A5FAC3F47FF6CAE63 Size:10752 %PROGRAMFILES%\Save\Fluxo de Caixa\Interop.GRExcel.dll MD5: B7444F7322801FB07681C8B04824029D Size:32768 %PROGRAMFILES%\Save\Fluxo de Caixa\Interop.CRPEAuto.dll MD5: BFB3F91F6E4B53E74BBC95091DF1FAA5 Size:233472 %PROGRAMFILES%\Save\Fluxo de Caixa\Interop.axViewData.dll MD5: BA9054624E54675A848EAA147E31C7B1 Size:262144 %PROGRAMFILES%\Save\Fluxo de Caixa\Interop.ADODB.dll MD5: 7C781798224A8B49EBE7480FCBD647B6 Size:102400 %PROGRAMFILES%\Save\Fluxo de Caixa\FluxoCaixaUI.dll MD5: 84B98C13C8A3A2D50649E209774F8671 Size:102400 %PROGRAMFILES%\Save\Fluxo de Caixa\FluxoCaixa.msi MD5: 97AAF9E1A0797A141F4E339682DA2DE5 Size:148480 %PROGRAMFILES%\Save\Fluxo de Caixa\AxInterop.axViewData.dll MD5: 1C0184754D5A48577B4B7DE1EA072839 Size:81920 %PROGRAMFILES%\Save\Controle dos Caixas das Lojas\Interop.Quadrant.dll MD5: 863FBB65242BB5814BE25C3A7D80957B Size:6144 %PROGRAMFILES%\Save\Controle dos Caixas das Lojas\Interop.QdtZip.dll MD5: F49597BF8C539B0E9FBD28482426E614 Size:10240 %PROGRAMFILES%\Save\Controle dos Caixas das Lojas\ControleCaixasLojasUI.DLL MD5: 41BCC08C58C33A0D434209FFE40F8B63 Size:77824 %PROGRAMFILES%\Save\Controle dos Caixas das Lojas\ControleCaixasLojas.DLL MD5: 41D27EF407498C620FFC5CC62A654AA7 Size:40960 %PROGRAMFILES%\Save\Contas Correntes\ContasCorrentesUI.dll MD5: C90937C75BEAF985C4FA11593C4922C5 Size:303104 %PROGRAMFILES%\Save\Contas Correntes\ContasCorrentes.msi MD5: B41B89689D4303BAC2A1962EACE5E665 Size:112128 %PROGRAMFILES%\Save\Contas a Pagar\ContasPagarUI.dll MD5: 1CBE13B43D37D3D75BAC920DB653FA03 Size:831488 %PROGRAMFILES%\Save\Contas a Pagar\ContasPagar.msi MD5: 0DBD00E0642D93A5A605F695B3CE64C3 Size:179200 %PROGRAMFILES%\Save\Cheques\Interop.VBRUN.dll MD5: 7DB1FAFF3DF16C4BE94385EBB5C6AB6F Size:49152 %PROGRAMFILES%\Save\Cheques\Interop.VBA.dll MD5: 0EE0BBD4F1CF4E5FA95DA08B46E06BAA Size:10752 %PROGRAMFILES%\Save\Cheques\Interop.QBASICO.dll MD5: 5F65E788E1DDE95ADCBC7AAAC51A98E8 Size:32768 %PROGRAMFILES%\Save\Cheques\Interop.GRExcel.dll MD5: 44B12B5749C53BBFC8DCAA148D8EFB2F Size:32768 %PROGRAMFILES%\Save\Cheques\Interop.CRPEAuto.dll MD5: 08223F31AAF562F32D041821F6C2E779 Size:233472 %PROGRAMFILES%\Save\Cheques\Interop.axViewData.dll MD5: F932CE85224C47A398E46DECB3D46C95 Size:262144 %PROGRAMFILES%\Save\Cheques\Interop.ADODB.dll MD5: 119F53A2C5C87AF6D028E68946BBACC1 Size:102400 %PROGRAMFILES%\Save\Cheques\ChequesUI.DLL MD5: 2BDEF33A521B798B084715EEC373F87F Size:688128 %PROGRAMFILES%\Save\Cheques\Cheques.msi MD5: 446A9B2B86904BC052C713B01AFBAC9F Size:182272 %PROGRAMFILES%\Save\Cheques\AxInterop.axViewData.dll MD5: CE325288A8A0EDE5C08EEC668237CF38 Size:81920 %PROGRAMFILES%\Save\Cartoes de Debito\CartaoDebitoUI.dll MD5: AF949269C5CCFAD4A13E57EB3A927E99 Size:327680 %PROGRAMFILES%\Save\Cartoes de Debito\CartaoDebito.msi MD5: 61D579C13A39C5C1683B4FA6F9B72D7E Size:157184 %PROGRAMFILES%\Save\Cartoes de Credito\CartaoCreditoUI.DLL MD5: 42F48B0E0013BFEA299D6D176E05D2F4 Size:733184 %PROGRAMFILES%\Save\Cartoes de Credito\CartaoCredito.msi MD5: F2CDC91707FC264757720CF3FCB3525D Size:233984 %PROGRAMFILES%\Save\Apuracao de Resultados\ApuracaoResultadosUI.dll MD5: F3A0223EBCDB94D1F8D03112805A09FC Size:294912 %PROGRAMFILES%\Save\Apuracao de Resultados\ApuracaoResultados.dll MD5: F2D9A333BAB1688DDB764F64C2138F3E Size:376832 %PROGRAMFILES%\Save\Gerenciador de Relatorios\Gerenciador de Relatorios.exe MD5: 7E2B3915358E04EBDE9F61AB9DD709DC Size:155648 %PROGRAMFILES%\Save\Fluxo de Caixa\Fluxo de Caixa.EXE MD5: F4502E0B55C97E6CA4672C8B9847A333 Size:163840 %PROGRAMFILES%\Save\Controle dos Caixas das Lojas\Controle dos Caixas das Lojas.EXE MD5: CB0D6834A2925A3462B91077494B64A7 Size:192512 %PROGRAMFILES%\Save\Contas Correntes\Contas Correntes.EXE MD5: AB76387004904907BED12CCA46BF9265 Size:163840 %PROGRAMFILES%\Save\Contas a Pagar\Contas a Pagar.EXE MD5: DFD92CA936236662AD0E76A39C31DFE7 Size:352256 %PROGRAMFILES%\Save\Cheques\Cheques.EXE MD5: F8936E034F1A16740225556CADD01E21 Size:282624 %PROGRAMFILES%\Save\Cartoes de Debito\Cartoes de Debito.EXE MD5: A565DCE763A130C41E5EBAC63FAA88C1 Size:212992 %PROGRAMFILES%\Save\Cartoes de Credito\Cartoes de Credito.EXE MD5: 58D4097C2ED05F269E8FAFC251114CA8 Size:290816 %PROGRAMFILES%\Save\Apuracao de Resultados\Apuracao de Resultados.exe MD5: 61008D8A59BD918BC8EEA291F262F86F Size:155648 %PROGRAMFILES%\Save\Planejamento e gesto de categorias\Planejamento e gesto de categorias.EXE MD5: 2CC8EDBF63FBD4FC283CC371C631250A Size:3358720 %PROGRAMFILES%\Save\Delivery\Delivery.EXE MD5: 7C0939A142948D78FA92F1B1983D181B Size:7311428 %PROGRAMFILES%\Save\CRM\CRM.exe MD5: 0BEAC28E8DE1463D16ED060F0123AF41 Size:2367488 %PROGRAMFILES%\vvsn\URL2\WUSVInst.exe MD5: 56DD5208F7A432ACB4A3DD3A6FAA6247 Size:9698 %PROGRAMFILES%\VVSN\VVSN.exe MD5: B1EEAB9A3461607B7DC12DFE22356A42 Size:177152 MD5: 6D5FCEE8EB3730E678A5DE25C0A50BB1 Size:113288
  2. Detected Files with variable Filenames: MD5: 7AADCB4EB4B8EBDA8BE77548754427DA Size: 118200 %PROGRAMFILES%\Save\SaveUninst.exe %PROGRAMFILES%\Save\saveuninst.exe.ren MD5: B4FAAAD7FB17366A801D5658690D1925 Size: 128000 %PROGRAMFILES%\Save\Tabelas\UNWISE.EXE %PROGRAMFILES%\Save\Produtos\UNWISE.EXE %PROGRAMFILES%\Save\Preos\UNWISE.EXE %PROGRAMFILES%\Save\Pedidos\UNWISE.EXE %PROGRAMFILES%\Save\Movimentao Avulsa\UNWISE.EXE %PROGRAMFILES%\Save\Metas de Vendas\UNWISE.EXE %PROGRAMFILES%\Save\Manager\UNWISE.EXE %PROGRAMFILES%\Save\Inventrio\UNWISE.EXE %PROGRAMFILES%\Save\ILRWindows\UNWISE.EXE %PROGRAMFILES%\Save\Gerencial\UNWISE.EXE %PROGRAMFILES%\Save\Clientes\UNWISE.EXE and next 13 variations. MD5: 10F9C395BF459897D24A92F8BC1712E5 Size: 847736 %PROGRAMFILES%\Save\Saveupdate.exe %PROGRAMFILES%\Save\SaveNowupdate.exe %PROGRAMFILES%\Save\saveupdate.exe.ren MD5: AA9F305228B39FBEF58DB805152E210A Size: 24124 %PROGRAMFILES%\Save\SaveUninst.exe %PROGRAMFILES%\Save\saveuninst.exe.ren

Detecting items list:

  1. Files by Name %PROGRAMFILES%\Save\Save.exe %PROGRAMFILES%\Save\Saveuninst.exe %PROGRAMFILES%\vvsn.exe %ProgramFiles%\VVSN\VVSN.exe %ProgramFiles%\SaveNow\SaveNow.exe %PROGRAMFILES%\VICMAN_WHENUSAVE_INSTALLER\VICMAN_WHENUSAVE_INSTALLER.EXE %programfiles%\DAEMON Tools\SetupDTSB.exe
  2. Files by MD5 MD5: B9688D2FCE7508CD4C4CA64D39437465 Size: 959327
  3. Files by Directories %PROGRAMFILES%\Save %START_PROGRAMSALL%\WhenU %START_PROGRAMS%\WhenU %PROGRAMFILES%\vvsn %ProgramFiles%\VVSN %ProgramFiles%\SaveNow
  4. Registry Keys HKLM\SOFTWARE\WhenUSave
  5. Registry Values HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ ValueName=WhenUSave HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ValueName=WhenUSearchWHSE

« Jít do Databáze softwaru