Threat Database Adware Adware.TimeSink.D

Adware.TimeSink.D

By CagedTech in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 1
First Seen: September 10, 2024
Last Seen: November 5, 2025
OS(es) Affected: Windows

The detection of Adware.TimeSink.D on your system indicates that your computer has been infected with a type of adware, which is a software designed to display unwanted advertisements on your device. Adware can be annoying and potentially harmful, as it can collect your personal data and compromise your online security. In this report, we will provide you with information about Adware.TimeSink.D, its operation, symptoms of infection, and steps to remove it from your system.

What Is Adware.TimeSink.D?

Adware.TimeSink.D is a type of adware that is designed to display unwanted advertisements on your device. The name "Adware.TimeSink.D" suggests that it is a variant of adware that can consume system resources and potentially slow down your computer. Adware can be installed on your system through various means, such as downloading free software or visiting malicious websites.

How Adware.TimeSink.D Operates

Adware.TimeSink.D operates by displaying unwanted advertisements on your device, which can be in the form of pop-ups, banners, or sponsored content. It can also collect your personal data, such as browsing history and search queries, to deliver targeted advertisements. Additionally, adware can slow down your system by consuming system resources, such as CPU and memory. In some cases, adware can also install additional malware or potentially unwanted programs (PUPs) on your system.

Symptoms of Infection

The symptoms of Adware.TimeSink.D infection can vary, but common signs include unwanted advertisements appearing on your device, slow system performance, and suspicious programs installed on your system. You may also notice that your browser homepage or search engine has been changed without your consent. Additionally, you may experience frequent pop-ups or redirects to suspicious websites.

  • Unwanted advertisements appearing on your device
  • Slow system performance
  • Suspicious programs installed on your system
  • Browser homepage or search engine changed without consent
  • Frequent pop-ups or redirects to suspicious websites

How to Remove Adware.TimeSink.D

  1. Boot your system in Safe Mode with Networking to prevent the adware from loading
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove the adware
  3. Uninstall any suspicious programs that were installed without your consent
  4. Reset your browser settings, including Chrome, Firefox, and Edge, to their default values
  5. Reboot your system and run another scan to ensure that the adware has been completely removed

Conclusion

Removing Adware.TimeSink.D from your system requires careful attention to detail and a thorough cleaning process. By following the steps outlined in this report, you can remove the adware and prevent future infections. It is essential to be cautious when downloading software and visiting websites, as adware can be installed through various means. Additionally, keeping your operating system and software up to date can help prevent vulnerabilities that adware can exploit. By taking proactive measures, you can protect your system and personal data from the risks associated with adware.

Analysis Report

General information

Family Name: Adware.TimeSink.D
Signature status: No Signature

Known Samples

MD5: cb278de70e173dc86ca0ef9fd27dfac7
SHA1: 1f6c8b281d4d6aabdb0146be7b20f76f6e58069e
SHA256: C5E2F37AF3D986C810ED0DB16A7940FBA8E62D9E949813265AA607B1FD18A07A
File Size: 994.77 KB, 994769 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • big overlay
  • No Version Info
  • x86

Block Information

Total Blocks: 311
Potentially Malicious Blocks: 41
Whitelisted Blocks: 270
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x x x x x x x x x x x 0 0 x x x x 0 0 1 1 x x x x x x x 1 x x x 0 x x x x x x x x x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Agent.JIA
  • Antavmu.A
  • TimeSink.A
  • TimeSink.D

Files Modified

File Attributes
c:\users\user\downloads\tmp1.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\tmp2.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\tmp3.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\tmp4.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\tmp5.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\tmp6.$$$ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\primavera_2001.scr Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\control panel\desktop::scrnsave.exe C:\WINDOWS\PRIMAV~1.SCR RegNtPreCreateKey
HKCU\local settings\muicache\17\52c64b7e::@mmres.dll,-800 Windows Default RegNtPreCreateKey
HKCU\local settings\muicache\17\52c64b7e::@c:\windows\system32\mmres.dll,-800 Windows Default RegNtPreCreateKey
HKCU\local settings\muicache\17\52c64b7e::@themeui.dll,-850 High Contrast #1 RegNtPreCreateKey
HKCU\local settings\muicache\17\52c64b7e::@themeui.dll,-851 High Contrast #2 RegNtPreCreateKey
HKCU\local settings\muicache\17\52c64b7e::@themeui.dll,-852 High Contrast Black RegNtPreCreateKey
HKCU\local settings\muicache\17\52c64b7e::@themeui.dll,-853 High Contrast White RegNtPreCreateKey
HKCU\software\solonewage.it\primavera_2001\screen saver::id105  RegNtPreCreateKey
HKCU\software\solonewage.it\primavera_2001\screen saver::id114 ( RegNtPreCreateKey
HKCU\software\solonewage.it\primavera_2001\effects::id100  RegNtPreCreateKey
Show More
HKCU\software\solonewage.it\primavera_2001\effects::id105  RegNtPreCreateKey
HKCU\software\solonewage.it\primavera_2001\advanced image::id101  RegNtPreCreateKey
HKCU\software\solonewage.it\primavera_2001\advanced image::id107  RegNtPreCreateKey
HKCU\software\solonewage.it\primavera_2001\advanced image::id110  RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Keyboard Access
  • GetKeyState

Shell Command Execution

rundll32.exe shell32.dll,Control_RunDLL desk.cpl,@0,1

Related Posts

Trending

Most Viewed

Loading...