Adware

How to remove “Adware.Agent.TWY”?

Malware Removal

The Adware.Agent.TWY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Agent.TWY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Uses suspicious command line tools or Windows utilities

How to determine Adware.Agent.TWY?


File Info:

name: EFA1B1C6238FCDD87136.mlw
path: /opt/CAPEv2/storage/binaries/8c24a60f5faf8af08b7cabd86e34688dd6071eb8c6b82019ec3c981c2123ac3d
crc32: 309B995C
md5: efa1b1c6238fcdd8713685e04c952e43
sha1: cd10cf4d45bd50fda75a7a28926a34f18440d179
sha256: 8c24a60f5faf8af08b7cabd86e34688dd6071eb8c6b82019ec3c981c2123ac3d
sha512: 40291800d2792e0fc55554cef585129ce6e3b1c65c997e3fae05de475962e7ed76c11c4251308c73f2a0bc079306ec10966d2addc1b85b0d62bf89fdb4258760
ssdeep: 196608:/QvrOOEGzFcGk34FEhoiPjCSRNbHbv3/0Ak9D4yoZhgQoGnVrq:/UOTqF3k34FEWQVNbHjsxl4yofgRGZq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16686339B93989832E67D143D1E59C5B9AB3F12C1F8B22D1531B5B8AD0066F87058F3E3
sha3_384: fa77b07328d5afa3fa14a39a86b0d8b8aeb3109e2ecd0b7a0415e48f41affc6f98f0a29f429e20563a3161411147192b
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: LaCie Private, Inc.
FileDescription: LaCie Private Public Setup
FileVersion:
LegalCopyright:
ProductName: LaCie Private Public
ProductVersion: 1.1
Translation: 0x0000 0x04b0

Adware.Agent.TWY also known as:

LionicTrojan.Win32.Miner.4!c
DrWebTrojan.BtcMine.1810
MicroWorld-eScanAdware.Agent.TWY
FireEyeAdware.Agent.TWY
ALYacApplication.BitCoinMiner.WD
CylanceUnsafe
ZillyaTrojan.Agentb.Win32.18326
SangforTrojan.Win64.Miner.axg
K7AntiVirusUnwanted-Program ( 004d38111 )
AlibabaTrojan:Win64/Miner.5076266f
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.6238fc
SymantecTrojan.Gen.2
ESET-NOD32multiple detections
APEXMalicious
KasperskyTrojan.Win32.Miner.bal
BitDefenderAdware.Agent.TWY
NANO-AntivirusTrojan.Win32.BtcMine.ewznkx
AvastWin32:CoinMiner-AH [Miner]
SophosMal/Generic-S
ComodoMalware@#1u4m10w4g4ecq
VIPRETrojan.Win32.Generic!BT
EmsisoftAdware.Agent.TWY (B)
IkarusTrojan.Win32.Miner
JiangminAdWare.FileTour.eqt
AviraHEUR/AGEN.1112841
Antiy-AVLTrojan/Generic.ASMalwS.23FBE95
GridinsoftRansom.Win32.Gen.sa
ArcabitAdware.Agent.TWY
GDataWin32.Application.CoinMiner.AG
VBA32Trojan.BtcMine
MAXmalware (ai score=98)
MalwarebytesTrojan.Agent
TencentWin32.Trojan.Miner.Aosv
YandexTrojan.GenAsa!VyACLv3P9cY
eGambitUnsafe.AI_Score_99%
FortinetRiskware/BitMiner
WebrootW32.Malware.Gen
AVGWin32:CoinMiner-AH [Miner]
PandaTrj/CI.A

How to remove Adware.Agent.TWY?

Adware.Agent.TWY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment