Downloader . Adware.Ezula (Summary)
Software Name: Adware.Ezula
Company Name: Ezula, Inc
Product Name: Adware.Ezula
Classification: Downloader
Website: http://www.ezulaadvertisingrevenuenetwork.com
Brief:
An application that connects to its controlling servers to retrieve and display pop-up advertisements. May link keywords found on web pages to other sites.
IMPORTANT!
Some of the Downloader.Adware.Ezula components
are listed below. The list is compiled as a reference. The list might
not be complete and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect removal
of certain software might make your computer unstable or even unusable.
Removal of adware component might affect the related ad-supported software.
If you suspect that you have an unwanted instance of Adware.Ezula
installed on your computer we recommend a free
audit of your system with INAC Anti Spyware.
Adware.Ezula might create following folders (and inject its files inside
the folders):
- %PROGRAMS%\TopText iLookup
- %PROGRAM_FILES%\eZula
- %PROGRAMS%\EARN
- %PROGRAM_FILES%\web offer
- %WINDOWS%\iLookup
Adware.Ezula might create following files (some of the files might be
loaded in memory while the software is running):
- %WINDOWS%\system32\stub.exe
- %WINDOWS%\system\stub.exe
- %WINDOWS%\Downloaded Program Files\ezulaboot.dll
- %WINDOWS%\eZinstall.exe
- %WINDOWS%\Downloaded Program Files\ezstub.dll
- %WINDOWS%\Downloaded Program Files\ezstub.INF
- %SYSTEM%\ezstub.exe
- %SYSTEM%\topsys.exe
- %PROFILE%\Local Settings\Temp\ez.exe
- %PROFILE%\Local Settings\Temp\woinstall.exe
- %SYSTEM%\woinstall.exe
- %WINDOWS%\woinstall.exe
- %SYSTEM%\ezPopstub.exe
- %WINDOWS%\iLookup\TTIL.exe
- %PROFILE%\Local Settings\Temp\all_files8.exe
- %PROFILE%\Local Settings\Temp\update_8.exe
Adware.Ezula is often accompanied by the following tracking cookies:
n/a
Adware.Ezula might create following registry keys (and inject subkeys
and values):
- HKEY_CLASSES_ROOT\AppID\eZulaBootExe.EXE
- HKEY_CLASSES_ROOT\AppID\eZulaMain.EXE
- HKEY_CLASSES_ROOT\AppID\{8A044397-5DA2-11D4-B185-0050DAB79376}
- HKEY_CLASSES_ROOT\AppID\{C0335198-6755-11D4-8A73-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{07F0A543-47BA-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{07F0A545-47BA-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{19DFB2CB-9B27-11D4-B192-0050DAB79376}
- HKEY_CLASSES_ROOT\CLSID\{2079884B-6EF3-11D4-8A74-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{2306ABE4-4D42-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{2BABD334-5C3F-11D4-B184-0050DAB79376}
- HKEY_CLASSES_ROOT\CLSID\{3D7247DE-5DB8-11D4-8A72-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{3D7247E8-5DB8-11D4-8A72-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{55910916-8B4E-4C1E-9253-CCE296EA71EB}
- HKEY_CLASSES_ROOT\CLSID\{58359010-BF36-11d3-99A2-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{B1DD8A69-1B96-11D4-B175-0050DAB79376}
- HKEY_CLASSES_ROOT\CLSID\{C03351A4-6755-11D4-8A73-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{C4FEE4A7-4B8B-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\CLSID\{D290D6E7-BF9D-42F0-9C1B-3BC8AE769B57}
- HKEY_CLASSES_ROOT\EZulaAgent.eZulaCtrlHost
- HKEY_CLASSES_ROOT\EZulaAgent.eZulaCtrlHost.1
- HKEY_CLASSES_ROOT\eZulaAgent.IEObject
- HKEY_CLASSES_ROOT\eZulaAgent.IEObject.1
- HKEY_CLASSES_ROOT\EZulaAgent.PlugProt
- HKEY_CLASSES_ROOT\EZulaAgent.PlugProt.1
- HKEY_CLASSES_ROOT\eZulaAgent.ToolBarBand
- HKEY_CLASSES_ROOT\eZulaAgent.ToolBarBand.1
- HKEY_CLASSES_ROOT\EZulaBoot.InstallCtrl
- HKEY_CLASSES_ROOT\EZulaBoot.InstallCtrl.1
- HKEY_CLASSES_ROOT\EZulaBootExe.InstallCtrl
- HKEY_CLASSES_ROOT\EZulaBootExe.InstallCtrl.1
- HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaCode
- HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaCode.1
- HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaHash
- HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaHash.1
- HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaSearch
- HKEY_CLASSES_ROOT\EZulaFSearchEng.eZulaSearch.1
- HKEY_CLASSES_ROOT\EZulaFSearchEng.PopupDisplay
- HKEY_CLASSES_ROOT\EZulaFSearchEng.PopupDisplay.1
- HKEY_CLASSES_ROOT\EZulaFSearchEng.ResultHelper
- HKEY_CLASSES_ROOT\EZulaFSearchEng.ResultHelper.1
- HKEY_CLASSES_ROOT\EZulaFSearchEng.SearchHelper
- HKEY_CLASSES_ROOT\EZulaFSearchEng.SearchHelper.1
- HKEY_CLASSES_ROOT\EZulaMain.eZulaSearchPipe
- HKEY_CLASSES_ROOT\EZulaMain.eZulaSearchPipe.1
- HKEY_CLASSES_ROOT\EZulaMain.TrayIConM
- HKEY_CLASSES_ROOT\EZulaMain.TrayIConM.1
- HKEY_CLASSES_ROOT\Interface\{07F0A542-47BA-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{07F0A544-47BA-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{1823BC4B-A253-4767-9CFC-9ACA62A6B136}
- HKEY_CLASSES_ROOT\Interface\{19DFB2CA-9B27-11D4-B192-0050DAB79376}
- HKEY_CLASSES_ROOT\Interface\{27BC6871-4D5A-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{3D7247DD-5DB8-11D4-8A72-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{3D7247F1-5DB8-11D4-8A72-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{4FD8645F-9B3E-46C1-9727-9837842A84AB}
- HKEY_CLASSES_ROOT\Interface\{58359012-BF36-11D3-99A2-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{7EDC96E1-5DD3-11D4-B185-0050DAB79376}
- HKEY_CLASSES_ROOT\Interface\{8A0443A2-5DA2-11D4-B185-0050DAB79376}
- HKEY_CLASSES_ROOT\Interface\{8EBB1743-9A2F-11D4-8A7E-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{C03351A3-6755-11D4-8A73-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{C4FEE4A6-4B8B-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\Interface\{EF0372DC-F552-11D3-8528-0050DAB79376}
- HKEY_CLASSES_ROOT\Interface\{EF0372DE-F552-11D3-8528-0050DAB79376}
- HKEY_CLASSES_ROOT\TypeLib\{07F0A536-47BA-11D4-8A6D-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\TypeLib\{083FA8F4-84F4-11D4-8A77-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\TypeLib\{3D7247D1-5DB8-11D4-8A72-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\TypeLib\{58359011-BF36-11D3-99A2-0050DA2EE1BE}
- HKEY_CLASSES_ROOT\TypeLib\{8A044396-5DA2-11D4-B185-0050DAB79376}
- HKEY_CLASSES_ROOT\TypeLib\{C0335197-6755-11D4-8A73-0050DA2EE1BE}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3D7247DE-5DB8-11D4-8A72-0050DA2EE1BE}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/ezstub.dll*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eZula
- HKEY_USERS\*\Software\eZula
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\EARN
- HKEY_CLASSES_ROOT\AppID\AtlBrowser.EXE
- HKEY_CLASSES_ROOT\AppID\{0818D423-6247-11D1-ABEE-00D049C10000}
- HKEY_CLASSES_ROOT\AtlBrCon.AtlBrCon
- HKEY_CLASSES_ROOT\AtlBrCon.AtlBrCon.1
- HKEY_CLASSES_ROOT\CLSID\{25630B47-53C6-4E66-A945-9D7B6B2171FF}
- HKEY_CLASSES_ROOT\CLSID\{370F6354-41C4-4FA6-A2DF-1BA57EE0FBB9}
- HKEY_CLASSES_ROOT\CLSID\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}
- HKEY_CLASSES_ROOT\CLSID\{6DF5E318-6994-4A41-85BD-45CCADA616F8}
- HKEY_CLASSES_ROOT\CLSID\{788C6F6F-C2EA-4A63-9C38-CE7D8F43BCE4}
- HKEY_CLASSES_ROOT\CLSID\{78BCF937-45B0-40A7-9391-DCC03420DB35}
- HKEY_CLASSES_ROOT\CLSID\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
- HKEY_CLASSES_ROOT\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}
- HKEY_CLASSES_ROOT\CLSID\{E7A05400-4CFA-4DF3-A643-E40F86E8E3D7}
- HKEY_CLASSES_ROOT\CLSID\{F75521B8-76F1-4A4D-84B1-9E642E9C51D0}
- HKEY_CLASSES_ROOT\EZulaMain.eZulaPopSearchPipe
- HKEY_CLASSES_ROOT\EZulaMain.eZulaPopSearchPipe.1
- HKEY_CLASSES_ROOT\Interface\{241667A3-EC83-4885-84DD-C2DAAFC1C5EA}
- HKEY_CLASSES_ROOT\Interface\{25630B50-53C6-4E66-A945-9D7B6B2171FF}
- HKEY_CLASSES_ROOT\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
- HKEY_CLASSES_ROOT\Interface\{370F6353-41C4-4FA6-A2DF-1BA57EE0FBB9}
- HKEY_CLASSES_ROOT\Interface\{788C6F6E-C2EA-4A63-9C38-CE7D8F43BCE4}
- HKEY_CLASSES_ROOT\Interface\{78BCF936-45B0-40A7-9391-DCC03420DB35}
- HKEY_CLASSES_ROOT\Interface\{955CBF48-4313-4B1F-872B-254B7822CCF2}
- HKEY_CLASSES_ROOT\Interface\{9CFA26C2-81DA-4C9D-A501-F144A4A000FA}
- HKEY_CLASSES_ROOT\Interface\{EFA52460-8822-4191-BA38-FACDD2007910}
- HKEY_CLASSES_ROOT\TypeLib\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9}
- HKEY_CLASSES_ROOT\TypeLib\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
- HKEY_CLASSES_ROOT\TypeLib\{9CFA26C1-81DA-4C9D-A501-F144A4A000FA}
- HKEY_CLASSES_ROOT\TypeLib\{BAF13496-8F72-47A1-9CEE-09238EFC75F0}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{A166C1B0-5CDB-447A-894A-4B9FD7149D51}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CFA26C0-81DA-4C9D-A501-F144A4A000FA}
- HKEY_USERS\*\Software\Web Offer
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Web Offer
Adware.Ezula might create following registry values:
- HKEY_CLASSES_ROOT\AppID\eZulaBootExe.EXE|AppID
- HKEY_CLASSES_ROOT\AppID\eZulaMain.EXE|AppID
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\ezstub.dll
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|eZmmod
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|eZulaMain
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|eZWO
Adware.Ezula might create registry values with following data:
n/a
Adware.Ezula might insert following entries in the HOSTS file:
n/a
Click
here to scan your computer for Adware.Ezula free of charge
|