Adware

Win32/Adware.WhenU.SaveNow potentially unwanted information

Malware Removal

The Win32/Adware.WhenU.SaveNow potentially unwanted is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.WhenU.SaveNow potentially unwanted virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs

How to determine Win32/Adware.WhenU.SaveNow potentially unwanted?


File Info:

crc32: 7528861F
md5: 59affbf0ac277c078b1b67e02c51fd7a
name: trfrogmansetup.exe
sha1: 4b126a8450ffbca600b75d999460f5fece7e9f65
sha256: d35efb1630e61bb649b467936213e0dcef8b0895ee5273408517de1dd9055b22
sha512: a142561b05ce8f2a1ced8b71311d0d7cbd392f0ca3ac85ad037185533c68bc9cafc0c5e4750900b78fc5902d7bbf08e39e23450a44960503543b4ceb04c4b2f1
ssdeep: 49152:pba+3BlJO4jz5z0x0HX+Co2ugA9CimlXTrE3HCAWa59:pba+3Bi4jzA0HXRKCi33bWa59
type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

InternalName:
FileVersion:
CompanyName: FunGamesGalaxy.com
Comments: This installation was built with Inno Setup: http://www.innosetup.com
ProductName:
ProductVersion:
FileDescription: Treasure Frogman Setup
OriginalFilename:
Translation: 0x0409 0x04e4

Win32/Adware.WhenU.SaveNow potentially unwanted also known as:

BkavW32.HfsAdware.CB6F
DrWebAdware.SaveNow.320
FireEyeGen:Adware.Heur.gq1@RSwwO6ii
Qihoo-360Win32/Virus.WebToolbar.b01
VIPREWhenU
SangforMalware
BitDefenderGen:Adware.Heur.gq1@RSwwO6ii
Cybereasonmalicious.0ac277
TrendMicroADW_WENHU
CyrenW32/SaveNow.WEFM-5734
Paloaltogeneric.ml
GDataGen:Adware.Heur.gq1@RSwwO6ii
Kasperskynot-a-virus:WebToolbar.Win32.WhenU.a
NANO-AntivirusRiskware.Win32.WhenU.dwtfrb
ViRobotAdware.WhenU.1979621
RisingTrojan.Win32.Generic.14B706C7 (C64:YzY0OhrRsMfcvXJp)
SophosWhenU (PUA)
ComodoApplicUnsaf.Win32.Adware.WhenU.SaveNow@48y6
F-SecureAdware:W32/WhenU
EmsisoftGen:Adware.Heur.gq1@RSwwO6ii (B)
F-ProtW32/SaveNow.D
AviraADSPY/AdSpy.Gen
ArcabitAdware.Heur.ED1421B
ZoneAlarmnot-a-virus:WebToolbar.Win32.WhenU.a
MicrosoftTrojan:Win32/Detplock
VBA32Adware.SaveNow
MAXmalware (ai score=96)
CylanceUnsafe
PandaAdware/SaveNow
ESET-NOD32Win32/Adware.WhenU.SaveNow potentially unwanted
TrendMicro-HouseCallADWARE_SAVENOW
eGambitUnsafe.AI_Score_97%
FortinetRiskware/WhenU
AVGWin32:SaveNow-I [PUP]
AvastWin32:SaveNow-I [PUP]

How to remove Win32/Adware.WhenU.SaveNow potentially unwanted?

Win32/Adware.WhenU.SaveNow potentially unwanted removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment