What is “Win32/Adware.MediaTickets.F”?

Malware Removal

The Win32/Adware.MediaTickets.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Win32/Adware.MediaTickets.F virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Attempts to identify installed AV products by registry key
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

nf.clickspring.net
cu.clickspring.net

How to determine Win32/Adware.MediaTickets.F?


File Info:

crc32: CB7B889C
md5: 143c2ec80f64fd077056daa1f3ab14a0
name: 143C2EC80F64FD077056DAA1F3AB14A0.mlw
sha1: c3bb9bf7c145611bd40ea17da79a82b27de2730c
sha256: 15a82e470eeb59705db21d6a930619a8fe44de919f056953ea436cfe77ffe423
sha512: c4798e33d13677abd8550d56f9d1e1a0b5efbc1732d01fead3f842b9bf8f22d7d55c524f80177d195444a2c059f7dfac7b2f6f3a89322e6a24713292e2157c50
ssdeep: 3072:dEXepXylYC9Ly3+aHLazX3vFUBssJUxaPJUrS:dZcO3wzX3vFUBsSocB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Adware.MediaTickets.F also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.PurityScan.a!c
Elasticmalicious (high confidence)
DrWebTrojan.PurityAd.501
CynetMalicious (score: 100)
ALYacGen:Variant.Adware.Barys.571
CylanceUnsafe
ZillyaAdware.MediaTickets.Win32.91
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Starter.ali2000005
Cybereasonmalicious.80f64f
CyrenW32/PurityScan.C.gen!Eldorado
SymantecAdware.Purityscan
ESET-NOD32a variant of Win32/Adware.MediaTickets.F
APEXMalicious
AvastWin32:PurityScan-U [Trj]
ClamAVWin.Trojan.PurityScan-4
KasperskyTrojan-Downloader.Win32.PurityScan.ch
BitDefenderGen:Variant.Adware.Barys.571
NANO-AntivirusTrojan.Win32.PurityScan.ebzzgh
MicroWorld-eScanGen:Variant.Adware.Barys.571
TencentWin32.Trojan-downloader.Purityscan.Dvqa
Ad-AwareGen:Variant.Adware.Barys.571
SophosClickSpring (PUA)
ComodoApplicUnwnt@#25eupus3m8qg1
BitDefenderThetaGen:NN.ZexaF.34170.imW@aed@E@m
VIPREPurityScan
TrendMicroMal_PuriDL
McAfee-GW-EditionAdware-ClickSpring.l
FireEyeGeneric.mg.143c2ec80f64fd07
EmsisoftGen:Variant.Adware.Barys.571 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.PurityScan.ma
AviraHEUR/AGEN.1106571
Antiy-AVLTrojan/Generic.ASMalwS.1848E4B
MicrosoftTrojan:Win32/Wacatac.A!ml
ZoneAlarmTrojan-Downloader.Win32.PurityScan.ch
GDataGen:Variant.Adware.Barys.571
AhnLab-V3Trojan/Win32.Agent.C57883
Acronissuspicious
McAfeeAdware-ClickSpring.l
MAXmalware (ai score=100)
VBA32Win32.Trojan.Dropper.Heur
MalwarebytesMalware.AI.2814426267
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_PuriDL
IkarusTrojan-Downloader.Win32.PurityScan
FortinetW32/Generic.AC.6202!tr
AVGWin32:PurityScan-U [Trj]
Paloaltogeneric.ml

How to remove Win32/Adware.MediaTickets.F?

Win32/Adware.MediaTickets.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment