WHENU.COM INC

Publisher Information

WHENU.COM INC is a software developer located in New York, United States*. The company is a primary distributor of unwanted software. Thre are 3 additional code signing certificates issued to this publisher.
Authority:
VeriSign, Inc.

Valid from:
2/8/2006 1:00:00 AM

Valid to:
4/9/2007 1:59:59 AM

Subject:
CN=WHENU.COM INC, OU=Department, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=WHENU.COM INC, L=New York, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3961e82457d32f54a770a098673031f5

Scanner detections:
Detections  (100% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.Installer.WHENUCOMINC.J, PUP.Startup.WHENUCOM, PUP.WHENUCOM, PUP.WHENUCOM.Installer (M), PUP.WHENUCOM (M)
100.00%

McAfee
Adware-SaveNow, Generic.dx!9669E660BE9C
38.46%

Malwarebytes
Adware.WhenU
38.46%

NANO AntiVirus
Riskware.Win32.WhenUSave.gbrh, Riskware.Win32.WhenU.croqkb, Trojan.Win32.Whenu.idrhm, Trojan.Win32.113664.qliwg
38.46%

F-Prot
W32/SaveNow.D, W32/HackToolX.WE, W32/HackTool.BBQ, W32/SaveNow.A.gen
38.46%

Total Defense
Win32/WhenU
38.46%

Trend Micro House Call
ADW_SAVENOW.BD, Adware_SaveNow, Adware_whenu, ADW_SAVENOW.BH, ADW_SAVENOW.BZ
38.46%

Bitdefender
Adware.Generic.59338, Gen:Adware.Heur.hq1@Rm!VmBji, Gen:Adware.Heur.Xq1@ROmjo4ki, Gen:Adware.Heur.Fu9@RmWJe9ii, Gen:Adware.Heur.hq1@RKi5tpoi
38.46%

Agnitum Outpost
Adware.WhenU, Adware.Savenow.BU
38.46%

SUPERAntiSpyware
Adware.WhenU
38.46%

1 / 68      (Adware)
Search.exe (WhenUSearch by WhenU.com)  (221156db6e7d827428e859e3cb79cb2c)

1 / 68      (Adware)
UInstall.exe (Universal Installer by WhenU.com, Inc)  (275ef5a3a1cebe59b9d92e86dca63033)

1 / 68      (Adware)
dtPlugin.dll (dtPlugin by WhenU)  (4b91bb49d57e6eb2153c536d85d7a5cc)

1 / 68      (Adware)
tmp0000005467f66556d094b5d5 (dtPlugin by WhenU)  (e044c59a9b7609749c575ee52035eb5c)

1 / 68      (Adware)

1 / 68      (Adware)
SaveUninst.exe (WhenU Save by WhenU.com)  (db0b256467d61a17c9ed665b33c8fdd0)

1 / 68      (Adware)
extra.exe (Universal Installer by WhenU.com, Inc)  (997bbba77968f9054f76fd285068315c)

1 / 68      (Adware)
savenowupdate.exe (Universal Installer by WhenU.com, Inc)  (10f9c395bf459897d24a92f8bc1712e5)

28 / 68    (Adware)
SaveUninst.exe (WhenU Save by WhenU.com)  (7aadcb4eb4b8ebda8be77548754427da)

35 / 68    (Adware)
Acm.dll (WhenU Acm.dll by WhenU.com)  (ad616a7e4a5306582e0f7363e36e0e75)

38 / 68    (Adware)
Save.exe (WhenU Save by WhenU.com)  (47754bf98fd5a4bc05c3b08221d6426a)

35 / 68    (Adware)
setupdtsb.exe (Universal Installer by WhenU.com, Inc)  (9669e660be9c5f1ec78f0355f3713257)

37 / 68    (Adware)
setupdtsb.exe (Universal Installer by WhenU.com, Inc)  (cef5a6707caf709dc606c1daa61eb06f)

The certificates below are also signed by WHENU.COM INC.

14553E9DBDEAA7C5D2E5D12E3C96B561  (Mar 14, 2005 to Apr 09, 2006)

7C0FDD14AFF33B9E05AD4A6AE79E6F04  (Mar 18, 2004 to Apr 09, 2005)

5FBDD3BD7047BB143A8B113CF0999DF6  (Mar 31, 2002 to Apr 01, 2003)

* Note, the details and description above are based on the code signing digital signature issued to WHENU.COM INC by VeriSign, Inc. on February 08, 2006 with the serial number '3961e82457d32f54a770a098673031f5'.