SaveUninst.exe

WhenU Save

WHENU.COM INC

The application SaveUninst.exe, “WhenU Save Uninstall” by WHENU.COM INC has been detected as adware by 25 anti-malware scanners.
Publisher:
WhenU.com, Inc.  (signed by WHENU.COM INC)

Product:
WhenU Save

Description:
WhenU Save Uninstall

Version:
4, 2, 2, 2

MD5:
7aadcb4eb4b8ebda8be77548754427da

SHA-1:
c5610cd5ac119e395e843fe1c0893acd1141ebe1

Scanner detections:
25 / 68

Status:
Adware

Analysis date:
4/27/2024 2:49:41 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Adware.Heur.hq1@RKi5tpoi
671

Agnitum Outpost
Adware.WhenU
7.1.1

AhnLab V3 Security
Unwanted/Win32.Xema
2015.03.12

Avira AntiVirus
TR/Spy.113664.14
7.11.216.60

AVG
Generic
2016.0.3149

Bitdefender
Gen:Adware.Heur.hq1@RKi5tpoi
1.0.20.475

Clam AntiVirus
Win.Adware.Whenu-7
0.98/21511

Comodo Security
Application.Win32.Adware.SaveNow.~A
21378

Emsisoft Anti-Malware
Gen:Adware.Heur.hq1@RKi5tpoi
8.15.04.05.05

Fortinet FortiGate
Adware/SaveNow
4/5/2015

F-Prot
W32/SaveNow.A.gen
v6.4.7.1.166

F-Secure
Gen:Adware.Heur.hq1@RKi5tpoi
11.2015-05-04_1

G Data
Gen:Adware.Heur.hq1@RKi5tpoi
15.4.25

Malwarebytes
Adware.WhenU
v2015.04.05.05

McAfee
Adware-SaveNow
5600.6805

MicroWorld eScan
Gen:Adware.Heur.hq1@RKi5tpoi
16.0.0.285

NANO AntiVirus
Trojan.Win32.113664.qliwg
0.30.0.296

Reason Heuristics
PUP.WHENUCOM
15.4.5.5

Sophos
WhenU
4.98

SUPERAntiSpyware
Adware.WhenU
9955

Total Defense
Win32/WhenU
37.0.11489

Trend Micro House Call
ADW_SAVENOW.BZ
7.2.95

Trend Micro
ADW_SAVENOW.BZ
10.465.05

VIPRE Antivirus
WhenU.Save
38344

ViRobot
Adware.Whenusearch.118200[h]
2014.3.20.0

File size:
115.4 KB (118,200 bytes)

Product version:
4, 2, 2, 2

Copyright:
Copyright 2001-2006

Original file name:
SaveUninst.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\save\saveuninst.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
2/7/2006 4:00:00 PM

Valid to:
4/8/2007 4:59:59 PM

Subject:
CN=WHENU.COM INC, OU=Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WHENU.COM INC, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3961E82457D32F54A770A098673031F5

File PE Metadata
Compilation timestamp:
9/6/2006 2:14:56 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:R0+eC6a00ZIIwEo7xNhrfSTElwgyAQWG5ruAkGlp4UQYazt:R07buZIE2jhrSTElwgylTuAvrQn

Entry address:
0x5DFF

Entry point:
55, 8B, EC, 6A, FF, 68, D8, B3, 40, 00, 68, A4, 75, 40, 00, 64, A1, 00, 00, 00, 00, 50, 64, 89, 25, 00, 00, 00, 00, 83, EC, 58, 53, 56, 57, 89, 65, E8, FF, 15, 58, B1, 40, 00, 33, D2, 8A, D4, 89, 15, 98, 02, 41, 00, 8B, C8, 81, E1, FF, 00, 00, 00, 89, 0D, 94, 02, 41, 00, C1, E1, 08, 03, CA, 89, 0D, 90, 02, 41, 00, C1, E8, 10, A3, 8C, 02, 41, 00, 33, F6, 56, E8, 47, 15, 00, 00, 59, 85, C0, 75, 08, 6A, 1C, E8, B0, 00, 00, 00, 59, 89, 75, FC, E8, EF, 11, 00, 00, FF, 15, 28, B0, 40, 00, A3, 88, 07, 41, 00, E8...
 
[+]

Entropy:
5.5884

Developed / compiled with:
Microsoft Visual C++ v6.0

Code size:
36.5 KB (37,376 bytes)

Remove SaveUninst.exe - Powered by Reason Core Security