UndergroundLair Adware pop-up ads

R

RF

Anti-spyware successfully detects but does not seem able
to remove the pop-up trjoan from UndergroundLair.
Specifically, the scan results show infection in the
registry:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVerion
\Explorer\pup

I have used regedit to delete this registry entry directly
and it immediately reappears.

Antispyware has detected this trojan in each of the last
10 scans, I have seletced "Remove" each time, and have
even rebooted a few times, and the trojan remains.

Is anyone looking into this?
 
A

Andre Da Costa

Ad-Aware - www.lavasoftusa.com - Use this, it guranteed to remove it.

Its actually a browser helper object (BHO), here is how to remove those:
1. Click "Tools" - "Advanced Tools" - "System Explorers".

2. In the left pane, underneath "Internet Explorer", click "IE BHOs".

You will see a list of installed Browser Helper Objects. As noted in the
key, BHOs preceded by a star should be safe, those next to an exclamation
point are unknown, and those next to a red "X" are those Microsoft
AntiSpyware deem hazardous.

Click a BHO for more detailed information if available, such as the BHO
name, description, and publisher name. Also, in the right pane, you can
choose to temporarily or permanently block the BHO. If the BHO is hazardous,
you may want to consider permanently removing it. However, for unknown BHOs,
you may want to consider only temporarily removing the object and examining
the effects later from within Internet Explorer.

Also restart in safe mode and a do a full system scan. On the Scan Page
choose scan options > Full system scan.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top