|
How to remove
adtrgt.com popup |
|
Description of adtrgt.com popup |
|
This malware redirect your Internet Explorer browser to the website adtrgt.com. Usually it displays a popup with advertisement, in the popup window address bar, it displays "http://url.adtrgt.com/cpv.jps?...", If you click the link in the popup window, it will download some other malware. |
|
|
|
Objects of adtrgt.com popup |
|
This malware create several registry keys, registry values, and dll files.
- Add a value in registry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\random_name The value name is random, and the value looks like this : Rulldll32.exe "%SystemRoot%\system32\random_name.dll", s OR Rundll32.exe "%SystemRoot%\system32\random_name.dll", a
- Add a value in registry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SSODL The value is : {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} or something like that.
- Add a value in registry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} The value is : STS
- Add a key in registry
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\random_clsid, the random_clsid looks like "{xxxxxxxx-xxxx-xxxx-xxxxxxxxxxxx}"
- Add several dlls with random name into %SystemRoot%\system32 folder
|
|
|
|
How to remove adtrgt.com popup |
|
Run TheStubware scanner, after the scan is completed, all the adtrgt.com objects should be checked, just click "Fix selected" button, then you may need to restart Windows to complete the removal.
|
|
|
|
What if I finished the above steps but still have the malware ? |
|
Your computer may get infected by a new variant. The new variant may use different method to hide itself, but don't worry, you can run the scanner first, after the scan is done, click "View Log" button, then send your log file to me for anylasis. You can submit your log file to technical support forum or send it in email to : support@TheStubware.com. After your log file is received, you will be sent a customizing removal to remove this malware.
|
|
|
|
3 Comments |
|
|
|
Leave your comment :
|
|
|