AdRotator is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified : 08/08/2010.

0_Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– A toolbar is an additional internet browser bar.
– An Adware is a program that adds other programs without the knowledge of the user.
– Vendor : PUP.Optional

0_Main_Actions

– It installs a plugin of the browser Google Chrome (G2),
– It installs a program of extension for browser Mozilla Firefox (M2),
– It installs a plugin of the browser Mozilla Firefox (P2),
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a process launched at startup of the system (RP),
– It settled in the Base of registers to be launched each time with the system (O4),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),
– It changes the Internet research provider (O69),

0_Zhpdiag

O2 – BHO: ezLife browser enhancer bfknqvyu – {3A059345-FCE3-4813-8F9E-124AFC5E3E67} . (…) — C:\WINDOWS\system32\bfknqvyu.dll
O2 – BHO: gooochi browser enhancer – {A6DCFE0F-B499-9CC8-285D-40426F1C8194} . (…) — C:\WINDOWS\system32\zmlpokpghukwzsza.dll
O2 – BHO: extrafind

[64Bits] – {Random CLSID} . (…) — C:\Windows\SysWow64\.dll
O2 – BHO: sleekseek [64Bits] – {8a62d38c-951d-c2e7-b222-8f0e2eab72a0} . (…) — C:\Windows\SysWow64\95c2d4c6.dll
O4 – HKLM\..\Run: [ezLife] Clé orpheline
O4 – HKLM\..\Run: [ustsipmsciajc] . (…) — C:\WINDOWS\system32\zmlpokpghukwzsza.dll
O42 – Logiciel: RON Too1 Gooochi – (…) [HKLM] — qsaxgyuyasytg
O42 – Logiciel: SmartAds browser enhancer – (…) [HKLM] — Smart-Ads-Solutions
O42 – Logiciel: ezLife browser enhancer – (…) [HKLM] — ezLife
O42 – Logiciel: NavigationProgram – (…) [HKLM] — NavigationProgram
O42 – Logiciel: Snappyads Games Collection – (…) [HKLM] — SnappyadsGames[HKCU\Software\ezLife] O43 – CFD:Common File Directory —-D- C:\Program Files\Smart-Ads-Solutions
O43 – CFD:Common File Directory —-D- C:\Program Files\ezLife
O69 – SBI: SearchScopes [HKCU] {DECA3892-BA8F-44b8-A993-A466AD694AE4} – (Yoog Search) – http://www15.yoog.com
O69 – SBI: SearchScopes [HKCU] {FC9813D7-7D0E-4F06-9ACE-40AD88E97929} – (Yoog Search) – http://www15.yoog.com[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3A059345-FCE3-4813-8F9E-124AFC5E3E67}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A6DCFE0F-B499-9CC8-285D-40426F1C8194}] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\qsaxgyuyasytg] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Smart-Ads-Solutions] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ezLife] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\NavigationProgram] [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SnappyadsGames] [HKCU\Software\Microsoft\Internet Explorer\searchscopes\{56256a51-b582-467e-b8d4-7786eda79ae0}] [HKLM\Software\Microsoft\Internet Explorer\searchscopes\{56256a51-b582-467e-b8d4-7786eda79ae0}]

0_Alias

Adware.AdRotator [Malwarebytes] Adware:Win32/AdRotator
Adware/AdRotator.A

Remove_Software

– Remove software in Windows Configuration Panel,
0_ZHPcleaner
Remove with ZHPcleaner
ZHPCleaner_EN2
0_Zhpdiag
Diagnose with ZHPDiag
ZHPDiag_2-300x220

2016-12-30T07:34:15+00:00 Categories: Adware, Hijacker, Polluteware, PUP|Tags: , , , , |Comments Off on Adware.AdRotator