Adware

Adware.WhenU removal

Malware Removal

The Adware.WhenU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.WhenU virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Adware.WhenU?


File Info:

name: 751D83AB92EDBFD9655F.mlw
path: /opt/CAPEv2/storage/binaries/c206feacd71fa5814a82703edb8d3874d6d2a67807905790205744f51b1f5fbf
crc32: EE4EDC9D
md5: 751d83ab92edbfd9655f42f3f931f824
sha1: 283ec6f88fead1b1bd3807e277667292542c6a31
sha256: c206feacd71fa5814a82703edb8d3874d6d2a67807905790205744f51b1f5fbf
sha512: 2bde82f734a101118676bd9f15c37262b4a75a5fe5dc85c8a7995cf66cae5657e96bd107d72bfd8602c802ae61e663806514fbe49c1d7b2b8a3094547a89d3c3
ssdeep: 6144:vVd0gMQuY1dBsHB+uq1slognqDHrJcvKnChG+iHv:vVWi1dShFpognaLJcvG+i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD3412E209D641E3DCDB0931A4E08F517BAF2FA61D44C903DD90D21A6DA87F1A2B8377
sha3_384: e209116a3292dccc5ed1cf44d1b40de30cdaac1839c2831b601020dfa863339219b952be7880d5f968477ef8a18e78a0
ep_bytes: 558bec83ec4456ff15445040008bf085
timestamp: 2003-03-14 21:23:26

Version Info:

Comments:
CompanyName: WhenU.com, Inc.
FileDescription: Save! Setup
FileVersion: 2, 1, 3, 1
InternalName: SaveInstCm
LegalCopyright: Copyright 2000
LegalTrademarks:
OriginalFilename: SaveInstCm.exe
PrivateBuild:
ProductName: Save! Setup
ProductVersion: 2, 1, 3, 1
SpecialBuild: Includes mandatory ClockSync
Translation: 0x0409 0x04b0

Adware.WhenU also known as:

LionicAdware.Win32.SaveNow.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Adware.Heur.pq0@R4VKYiii
FireEyeGeneric.mg.751d83ab92edbfd9
ALYacGen:Adware.Heur.pq0@R4VKYiii
CylanceUnsafe
ZillyaAdware.SaveNow.Win32.377
SangforTrojan.Win32.Heuristic.rg
AlibabaAdWare:Win32/SaveNow.71a8dcea
CyrenW32/SaveNow.A.gen!Eldorado
SymantecAdware.Savenow
ESET-NOD32a variant of Win32/Adware.SaveNow.A
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Adware.SaveNow-2
Kasperskynot-a-virus:AdWare.Win32.SaveNow.ae
BitDefenderGen:Adware.Heur.pq0@R4VKYiii
NANO-AntivirusRiskware.Win32.SaveNow.gmojq
SUPERAntiSpywareAdware.WhenU
AvastWin32:PUP-gen [PUP]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareGen:Adware.Heur.pq0@R4VKYiii
ComodoApplication.Win32.Adware.Savenow.~OSA@1xn0r8
DrWebAdware.SaveNow
VIPRETrojan.Win32.Generic!BT
TrendMicroADWARE_WHENU
EmsisoftGen:Adware.Heur.pq0@R4VKYiii (B)
SentinelOneStatic AI – Suspicious PE
WebrootAdware:Win32/WhenU.F
AviraADSPY/SaveNow.1
MAXmalware (ai score=99)
Antiy-AVLTrojan/Generic.ASMalwS.73EFD
MicrosoftTrojan:Win32/Ymacco.ABC2
ViRobotAdware.SaveNow.247296
GDataGen:Adware.Heur.pq0@R4VKYiii
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C100632
McAfeeArtemis!751D83AB92ED
VBA32BScope.Adware.SaveNow
MalwarebytesAdware.WhenU
TrendMicro-HouseCallADWARE_WHENU
YandexTrojan.GenAsa!gN8WRgxbJ8k
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/SaveNow
AVGWin32:PUP-gen [PUP]
Cybereasonmalicious.b92edb
PandaGeneric Malware

How to remove Adware.WhenU?

Adware.WhenU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment