Malware

AdWare.Win32.TimeSink removal instruction

Malware Removal

The AdWare.Win32.TimeSink is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.TimeSink virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by installation directory
  • Generates some ICMP traffic

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine AdWare.Win32.TimeSink?


File Info:

crc32: 89CA2DA8
md5: 55c970cbde81e16f0e6456e5e47d408c
name: llftpr1.exe
sha1: 0c38276d2c20d3da305ec5129beb645f4522dfa8
sha256: a0f185af01c1fbd28e5542017c1cc25663bc282c62573194137dba94ec7e4e76
sha512: ceceadb154c458641b7447bbb2afe6972bbdfcf26722d132a3b3726a848803d783a5a53fa3ef2269eaa92d8ecc9a726b2caa61cc7cfa5ddd8c234faf6d93cf8f
ssdeep: 49152:Ae2VFtfsMfflQSffN0VMcVk0AYVAwt3J93oskOxKyEmfjdAbKmh4TDnlFlq3D:ytHffWyfNAV/ACt3JCsxxK1+jdLmhSbC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1999
InternalName: TSInstall
FileVersion: 4, 0, 0, 1
CompanyName: Conducent Technologies, Inc.
ProductName: Conducent Technologies, Inc. TSInstall
ProductVersion: 4, 0, 0, 1
FileDescription: TSInstall
OriginalFilename: TSInstall.exe
Translation: 0x0409 0x04b0

AdWare.Win32.TimeSink also known as:

MicroWorld-eScanGen:Adware.Heur.Mw3@Rydo5jfi
CMCAdWare.Win32!O
CAT-QuickHealSpyware.Conducent
McAfeeAdware-TSADB
CylanceUnsafe
VIPREConducent/Timesink
K7GWAdware ( 004a418a1 )
K7AntiVirusAdware ( 004a418a1 )
TheHackerAdware/TimeSink
Invinceaheuristic
NANO-AntivirusRiskware.Win32.TimeSink.ridbu
F-ProtW32/TSAdbot.A
SymantecAdware.TSAdBot
ClamAVWin.Adware.Timesink-1
GDataGen:Adware.Heur.Mw3@Rydo5jfi
Kasperskynot-a-virus:AdWare.Win32.TimeSink
BitDefenderGen:Adware.Heur.Mw3@Rydo5jfi
RisingSpyware.Conducent!8.254B (RDM+:cmRtazpJdkXo1xUoDSXg66cS0NAk)
Ad-AwareGen:Adware.Heur.Mw3@Rydo5jfi
SophosAdGateway Timesink Installer (PUA)
ComodoApplication.Win32.Adware.TimeSink@39av
F-SecureGen:Adware.Heur.Mw3@Rydo5jfi
DrWebAdware.TimeSink
ZillyaAdware.TimeSink.Win32.43
McAfee-GW-EditionAdware-TSADB
EmsisoftGen:Adware.Heur.Mw3@Rydo5jfi (B)
CyrenW32/TSAdbot.CVHK-1288
JiangminAdWare/TimeSink.a
WebrootSpyware:Win32/Conducent
MAXmalware (ai score=68)
Antiy-AVLGrayWare[AdWare]/Win32.TimeSink
KingsoftWin32.Adware.TimeSink.98.(kcloud)
MicrosoftSpyware:Win32/Conducent
Endgamemalicious (high confidence)
ZoneAlarmnot-a-virus:AdWare.Win32.TimeSink
AVwareConducent/Timesink
VBA32Adware.TimeSink
MalwarebytesAdware.TSAdBot
PandaSpyware/Conducent-Timesink
ArcabitAdware.Heur.E443C9
ESET-NOD32Win32/Adware.TimeSink
TencentWin32.Adware.Timesink.Sxev
YandexAdware.TimeSink!siI5CG3j3cw
FortinetAdware/TimeSink
AVGWin32:Timesink-B [PUP]
Cybereasonmalicious.bde81e
AvastWin32:Timesink-B [PUP]

How to remove AdWare.Win32.TimeSink?

AdWare.Win32.TimeSink removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment