Threat Database Adware Adware.TimeSink.AA

Adware.TimeSink.AA

By CagedTech in Adware

Threat Scorecard

Popularity Rank: 22,606
Threat Level: 20 % (Normal)
Infected Computers: 15
First Seen: April 25, 2022
Last Seen: June 28, 2026
OS(es) Affected: Windows

The detection of Adware.TimeSink.AA on your system indicates the presence of a potentially unwanted program that may be causing disruptions to your online experience. This type of adware is designed to generate revenue for its creators by displaying unwanted advertisements, collecting user data, and potentially redirecting users to malicious websites. It is essential to understand the nature of this threat and take immediate action to remove it from your system.

What Is Adware.TimeSink.AA?

Adware.TimeSink.AA is a type of adware program that is designed to display unwanted advertisements on infected systems. The name "Adware.TimeSink.AA" suggests that it may be a variant of adware that is designed to generate revenue by displaying advertisements that are tailored to the user's interests. However, the exact nature and behavior of this adware program are not well understood, and it is crucial to exercise caution when dealing with any type of malware.

How Adware.TimeSink.AA Operates

Adware programs like Adware.TimeSink.AA typically operate by installing themselves on a system without the user's knowledge or consent. Once installed, they may begin to display unwanted advertisements, collect user data, and potentially redirect users to malicious websites. These programs may also modify system settings, such as changing the default search engine or homepage, to further facilitate their malicious activities. In some cases, adware programs may also install additional malware or potentially unwanted programs on the system.

Symptoms of Infection

The symptoms of an Adware.TimeSink.AA infection may vary, but common indicators include an increase in unwanted advertisements, slow system performance, and unexpected changes to system settings. Users may also notice that their browser homepage or search engine has been changed without their consent. In some cases, the adware program may also cause the system to become unstable or crash frequently.

  • Unwanted advertisements or pop-ups
  • Slow system performance
  • Unexpected changes to system settings
  • Browser homepage or search engine changes
  • System instability or crashes

How to Remove Adware.TimeSink.AA

  1. Boot your system in Safe Mode with Networking to prevent the adware program from loading
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove any malware
  3. Uninstall any suspicious programs or applications that may be related to the adware infection
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons
  5. Reboot your system and perform another full scan to ensure that the adware program has been completely removed

Conclusion

Removing Adware.TimeSink.AA from your system requires a combination of technical expertise and caution. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your system is free from this potentially unwanted program. It is essential to remain vigilant and take steps to prevent future infections, such as keeping your operating system and software up to date, using strong antivirus software, and avoiding suspicious downloads or links.

Analysis Report

General information

Family Name: Adware.TimeSink.AA
Signature status: No Signature

Known Samples

MD5: ab60eb2319aa04dc95d6fb6cf9619ffd
SHA1: f737be83859fa2aa9bc22393d1b7a16341ef070e
SHA256: 4A375711B24A5A497B523625C94F2D5E8441B7DAA1DABC10E3639E608AB8B625
File Size: 1.05 MB, 1045328 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Conducent Technologies, Inc.
File Description TSInstall
File Version 4, 0, 0, 1
Internal Name TSInstall
Legal Copyright Copyright © 1999
Original Filename TSInstall.exe
Product Name Conducent Technologies, Inc. TSInstall
Product Version 4, 0, 0, 1

File Traits

  • dll
  • x86

Block Information

Total Blocks: 190
Potentially Malicious Blocks: 53
Whitelisted Blocks: 137
Unknown Blocks: 0

Visual Map

x 0 x x x x 0 x 0 x 0 x x x x x x x x 0 x x 0 x x x x 0 x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • TimeSink.A

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\program files (x86)\timesink\adgateway\tsadbot.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\ivoxicqinstall.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\tsad.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\tsadbot.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\vcpdll.dll Generic Write,Read Attributes
c:\windows\tsad.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\vcpdll.dll Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\timesink, inc.\adgateway\channels\ivoxicq::channelid 眈湩楳整ഀ瀍ܞ᨝ᄝḒഇČ᨝ᄝ㼬᜙਱尒 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::timesink ad client "C:\Program Files (x86)\TimeSink\AdGateway\TSAdBot.exe" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enablefiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableautofiletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::enableconsoletracing RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filetracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::consoletracingmask ￿ RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::maxfilesize  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\tracing\rasapi32::filedirectory %windir%\tracing RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Network Winsock2
  • WSAStartup
Network Icmp
  • IcmpCreateFile
  • IcmpSendEcho

Shell Command Execution

C:\Users\Tuznzthq\AppData\Local\Temp\TSAdBot.exe (NULL)
C:\Program Files (x86)\TimeSink\AdGateway\TSAdBot.exe (NULL)

Related Posts

Trending

Most Viewed

Loading...