PUA

AdGateway Timesink Installer (PUA) removal guide

Malware Removal

The AdGateway Timesink Installer (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdGateway Timesink Installer (PUA) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Generates some ICMP traffic

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdGateway Timesink Installer (PUA)?


File Info:

crc32: E5B4E9CE
md5: 509eb63c9e0cfd381ff484f59d04b047
name: wcamvcr.exe
sha1: 1893c9da29157bd2d9d7ba6cece6936729865d3e
sha256: d406d3bf1e86b41241fc0e815bdd0dad63b0f439b337bdea9fe168513803c0e3
sha512: 9036220b2e3a23f7806b85a2076175ad71fd44166844208862e20cc8d8bdb33018e1246353bc4dc2647f3dba33f6f159e31cc0052423c757df5a2be0d5f74852
ssdeep: 49152:AepVFtj6NltcvylRtPTboNjXRRYJjI0F3u+:lMNlKqlLTboVX6++
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1999
InternalName: TSInstall
FileVersion: 4, 0, 0, 1
CompanyName: Conducent Technologies, Inc.
ProductName: Conducent Technologies, Inc. TSInstall
ProductVersion: 4, 0, 0, 1
FileDescription: TSInstall
OriginalFilename: TSInstall.exe
Translation: 0x0409 0x04b0

AdGateway Timesink Installer (PUA) also known as:

K7AntiVirusAdware ( 004a418a1 )
MicroWorld-eScanGen:Adware.Heur.nw3@Rydo5jfi
CMCAdWare.Win32!O
CAT-QuickHealSpyware.Conducent
McAfeeAdware-TSADB
CylanceUnsafe
TheHackerAdware/TimeSink
K7GWAdware ( 004a418a1 )
ArcabitAdware.Heur.E2B82F
Invinceaheuristic
CyrenW32/TSAdbot.CVHK-1288
SymantecAdware.TSAdBot
AvastWin32:Timesink-B [PUP]
ClamAVWin.Adware.Timesink-1
Kasperskynot-a-virus:AdWare.Win32.TimeSink
BitDefenderGen:Adware.Heur.nw3@Rydo5jfi
NANO-AntivirusRiskware.Win32.TimeSink.ridbu
Paloaltogeneric.ml
TencentWin32.Adware.Timesink.benu
Ad-AwareGen:Adware.Heur.nw3@Rydo5jfi
EmsisoftGen:Adware.Heur.nw3@Rydo5jfi (B)
ComodoApplication.Win32.Adware.TimeSink@39av
F-SecureGen:Adware.Heur.nw3@Rydo5jfi
DrWebAdware.TimeSink
ZillyaAdware.TimeSink.Win32.43
McAfee-GW-EditionAdware-TSADB
SophosAdGateway Timesink Installer (PUA)
F-ProtW32/TSAdbot.A
JiangminAdWare/TimeSink.a
WebrootSpyware:Win32/Conducent
Antiy-AVLGrayWare[AdWare]/Win32.TimeSink
Endgamemalicious (high confidence)
MicrosoftSpyware:Win32/Conducent
ZoneAlarmnot-a-virus:AdWare.Win32.TimeSink
GDataGen:Adware.Heur.nw3@Rydo5jfi
VBA32Adware.TimeSink
MAXmalware (ai score=69)
MalwarebytesAdware.TSAdBot
ESET-NOD32Win32/Adware.TimeSink
RisingSpyware.Conducent!8.254B (RDM+:cmRtazpJdkXo1xUoDSXg66cS0NAk)
YandexAdware.TimeSink!siI5CG3j3cw
FortinetAdware/TimeSink
AVGWin32:Timesink-B [PUP]
Cybereasonmalicious.c9e0cf
PandaSpyware/Conducent-Timesink

How to remove AdGateway Timesink Installer (PUA)?

AdGateway Timesink Installer (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment