Adware

Adware.WhenUSave.Ancient removal guide

Malware Removal

The Adware.WhenUSave.Ancient is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.WhenUSave.Ancient virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality

How to determine Adware.WhenUSave.Ancient?


File Info:

name: 56CD17CB22D132FD10B1.mlw
path: /opt/CAPEv2/storage/binaries/fb093e39b794e509722ad662b664aa8955820d65477abc9eaa53ab554354ebd6
crc32: 085EE998
md5: 56cd17cb22d132fd10b1e55a857ae14c
sha1: 69cfe61a897130d105de079a38c4350198ef6217
sha256: fb093e39b794e509722ad662b664aa8955820d65477abc9eaa53ab554354ebd6
sha512: 0a11fb2ea8c32c5070f95dca542f36f24b2da215b60ef63697ff456b8711daad4da6652d426cf3d6cf72bc22d367ec0c0d31809bc1dfab579b14503b5881b7ba
ssdeep: 3072://nKKS7NM6+lhaFbtICLtUlZ/2pBgYZuxiarkseIi://nKKS7NRWCZHLtw/p/kXI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167D3386B77E3CCA1D5B6007045A69FFED6B5EE35092049C783B03E1FBD74282952B24A
sha3_384: e2b955e80f67672bca6157e8241301e5d26d035621b27cb54dfc324be38c99bb38f4b31eb939744fa251e6d17e58de74
ep_bytes: 558bec83ec445657ff15786141008bf0
timestamp: 2006-12-11 16:14:59

Version Info:

CompanyName: MeMedia
FileDescription: MeMedia Setup
FileVersion: 6, 3, 0, 0
InternalName: MeMediaSetup.exe
LegalCopyright: (c) 2006 MeMedia. All rights reserved.
OriginalFilename: MeMediaSetup.exe
ProductName: MeMedia Setup
ProductVersion: 6, 3, 0, 0
Translation: 0x0409 0x04b0

Adware.WhenUSave.Ancient also known as:

LionicRiskware.Win32.WhenU.1!c
DrWebAdware.SaveNow.190
MicroWorld-eScanAdware.WhenU.BTE
FireEyeAdware.WhenU.BTE
McAfeeMeMedia.d
CylanceUnsafe
AlibabaAdWare:Win32/WhenU.2cfc5d7c
VirITSpyware.WhenU.R
SymantecAdware.WhenUSearchBar
ESET-NOD32a variant of Win32/Adware.WhenU.AA
TrendMicro-HouseCallDialer_Win32Dial
Kasperskynot-a-virus:WebToolbar.Win32.WhenU.k
BitDefenderAdware.WhenU.BTE
NANO-AntivirusTrojan.Win32.MLW.ejmft
AvastFileRepMalware [PUP]
RisingTrojan.Mploit/Android!8.11B3A (CLOUD)
ComodoMalware@#23xxc3p9ss5zj
VIPRETrojan.Win32.Generic!BT
TrendMicroDialer_Win32Dial
McAfee-GW-EditionMeMedia.d
EmsisoftAdware.WhenU.BTE (B)
JiangminWebToolbar.WhenU.bo
eGambitGeneric.Malware
AviraADSPY/AdSpy.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1854D1
KingsoftWin32.Troj.WhenU.k.(kcloud)
MicrosoftTrojan:Win32/Occamy.AB
ZoneAlarmnot-a-virus:WebToolbar.Win32.WhenU.k
GDataAdware.WhenU.BTE
CynetMalicious (score: 100)
ALYacAdware.WhenU.BTE
MAXmalware (ai score=95)
MalwarebytesAdware.WhenUSave.Ancient
APEXMalicious
TencentWin32.Trojan.Whenu.Sxov
YandexTrojan.GenAsa!qdESWAsbkVE
MaxSecureTrojan.Malware.1089906.susgen
FortinetRiskware/WhenU
WebrootW32.Malware.Gen
AVGFileRepMalware [PUP]
Cybereasonmalicious.b22d13

How to remove Adware.WhenUSave.Ancient?

Adware.WhenUSave.Ancient removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment