Adware

What is “Adware.Agent.TVU (B)”?

Malware Removal

The Adware.Agent.TVU (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Agent.TVU (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

Related domains:

live.windowchannel.bid
gool.eventhammer.bid

How to determine Adware.Agent.TVU (B)?


File Info:

name: CFF67F862A5099A32BB9.mlw
path: /opt/CAPEv2/storage/binaries/0d1b66cd28f3f5da895778b3bd5c38b372e4e4a862edc93edcac5482bdde630e
crc32: 1EAC5B8B
md5: cff67f862a5099a32bb90861cdb5439c
sha1: effced9b390ae5a596cfd0589ce02cc27a22bd02
sha256: 0d1b66cd28f3f5da895778b3bd5c38b372e4e4a862edc93edcac5482bdde630e
sha512: e6153e4514f5cc8a587109b132c8920ed3fcff6f1e556f7bebd8d9a4528597defa392850f881e2231bbc7c98fcab503effc531e88da8e562c9d883da318d9c00
ssdeep: 12288:M7VG/Hw26VFxEdc5ecOSHdwmA95ygSU//8GTmRfc:M7VG/Hz6/nOSqv5BUV
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T16505E030B6C4E126C12754738801E5B91528FFA40A618A6F3F9C6E2F7FB5491F732A76
sha3_384: 0eeb9e38c39604cfc3195e6d264d47c52571226614c38c6b272a3b3e43108ef7dd9ada1a89e023a4ac2ca25060296a3a
ep_bytes: e820040000e987feffff558becf64508
timestamp: 2017-12-10 10:42:10

Version Info:

FileVersion: 1.0.0.1
LegalCopyright: Copyright (C) 2017
OriginalFilename: Template.exe
ProductVersion: 1.0.0.7
Translation: 0x0419 0x04b0

Adware.Agent.TVU (B) also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.Generic.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.Agent.TVU
FireEyeGeneric.mg.cff67f862a5099a3
CAT-QuickHealAdware.StartSurf.ZZ5
ALYacAdware.Agent.TVU
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.3631412
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00526e411 )
AlibabaAdWare:Win32/Kryptik.95b6c26a
K7GWTrojan ( 0051707e1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/S-94e15fbb!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FWQG
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderAdware.Agent.TVU
NANO-AntivirusRiskware.Win32.StartSurf.evxqpr
SUPERAntiSpywareAdware.StartSurf/Variant
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b2f2f8
Ad-AwareAdware.Agent.TVU
SophosGeneric PUA OP (PUA)
ComodoApplicUnwnt@#19eth5s59p0xm
DrWebTrojan.Vittalia.13827
VIPREAdware.Win32.StartSurf
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
EmsisoftAdware.Agent.TVU (B)
Ikarusnot-a-virus:AdWare.StartSurf
GDataAdware.Agent.TVU
JiangminAdWare.StartSurf.ajp
AviraHEUR/AGEN.1103313
Antiy-AVLTrojan/Generic.ASMalwS.231B26E
GridinsoftRansom.Win32.Wacatac.sa
ArcabitAdware.Agent.TVU
ViRobotAdware.Startsurf.815104.AIL
MicrosoftTrojan:Win32/Wacatac.A!rfn
CynetMalicious (score: 100)
AhnLab-V3Adware/Win32.StartSurf.R215484
Acronissuspicious
McAfeePacked-VV!CFF67F862A50
MAXmalware (ai score=100)
VBA32AdWare.StartSurf
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
RisingTrojan.Kryptik!1.AE0C (CLASSIC)
YandexTrojan.GenAsa!ZDC1h0fTc40
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Adware
FortinetW32/Kryptik.FWQG!tr
BitDefenderThetaGen:NN.ZexaF.34084.Xu0@aeCBWZai
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.62a509
PandaTrj/Genetic.gen

How to remove Adware.Agent.TVU (B)?

Adware.Agent.TVU (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment