Jump to content

Removal instructions for AdCare


Recommended Posts

  • Staff

What is AdCare?

The Malwarebytes research team has determined that AdCare is a fake anti-malware application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue. You are strongly advised to follow our removal instructions below.

How do I know if I am infected with AdCare?

This is how the main screen of the rogue application looks:

main.png

You will find these icons on your desktop and in your taskbar:

icons.png

And see this type of warning during install:

warning1.png

How did AdCare get on my computer?

Rogue programs use different methods for spreading themselves. This particular one was downloaded from their site.

How do I remove AdCare?

Our program Malwarebytes' Anti-Malware can detect and remove this rogue application.

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware

    [*]Then click Finish.

    [*]If an update is found, it will download and install the latest version.

    [*]Once the program has loaded, select Perform quick scan, then click Scan.

    [*]When the scan is complete, click OK, then Show Results to view the results.

    [*]Be sure that everything is checked, and click Remove Selected. Reboot your computer if prompted.

    [*]When completed, a log will open in Notepad. The rogue application should now be gone.

Is there anything else I need to do to get rid of AdCare?

  • No, Malwarebytes' Anti-Malware removes AdCare completely.

How would the full version of Malwarebytes' Anti-Malware help protect me?

We hope our application has helped you eradicate this malicious software. If your current security solution let this infection through, you might please consider purchasing the FULL version of Malwarebytes' Anti-Malware for additional protection.

As you can see below the full version of Malwarebytes' Anti-Malware would have protected you against the AdCare rogue. It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.

protection1.png

protection.png

Technical details for experts

Signs in a HijackThis log:

C:\Program Files\adcare\adcare.exe

O4 - HKLM\..\Run: [adcareup] C:\Program Files\adcare\adcareup.exe hideup

Alterations made by the installer:

  File System
===============
In the existing folder C:
Adds the file adcareprovision.txt"="20:21 18/08/10 0 bytes
In the existing folder C:\Documents and Settings\{username}\Desktop
Adds the file ??????.lnk"="20:22 18/08/10 686 bytes
Adds the folder C:\Documents and Settings\{username}\Start Menu\Programs\adcare
Adds the file ??????.lnk"="20:22 18/08/10 698 bytes
Adds the file adcare ????.lnk"="20:22 18/08/10 709 bytes
Adds the folder C:\Program Files\adcare
Adds the file uninstall.exe"="13:53 18/06/10 1113088 bytes
Adds the file ntfile.ini"="20:22 18/08/10 0 bytes
Adds the file filecheck.ini"="18:29 05/06/07 502 bytes
Adds the file config.ini"="11:08 05/06/09 839 bytes
Adds the file adcareup.exe"="11:06 02/07/10 1040384 bytes
Adds the file adcare.exe"="11:01 02/07/10 3023872 bytes
Adds the folder C:\Program Files\adcare\value
Adds the file wurl.da"="10:51 22/03/07 127834 bytes
Adds the file wcode8.da"="14:16 02/07/10 873832 bytes
Adds the file wcode7.da"="18:12 05/01/10 1249227 bytes
Adds the file wcode6.da"="13:05 16/01/09 1901051 bytes
Adds the file wcode5.da"="13:13 10/03/08 404801 bytes
Adds the file wcode4.da"="14:26 06/04/10 323 bytes
Adds the file wcode3.da"="14:26 06/04/10 323 bytes
Adds the file wcode2.da"="14:26 06/04/10 323 bytes
Adds the file wcode1.da"="14:26 06/04/10 323 bytes
Adds the file wcode.da"="14:26 06/04/10 323 bytes
Adds the file wac.da"="14:46 14/09/06 8812 bytes
Adds the file skey.da"="09:42 10/10/07 0 bytes
Adds the file pattern.da"="17:28 10/07/09 239098 bytes
Adds the file chdir.da"="12:13 17/04/07 788 bytes
Adds the file b_ac.da2"="14:08 03/02/07 16877 bytes
Adds the folder C:\Program Files\adcare\report
Adds the file 2010-08.ale"="20:29 18/08/10 240 bytes
Adds the file +?+f.txt"="01:55 05/01/07 218 bytes
Adds the folder C:\Program Files\adcare\img
Adds the file ws.gif"="13:30 08/06/10 16876 bytes
Adds the file win.gif"="15:52 14/08/07 56556 bytes
Adds the file view_button.gif"="10:06 14/08/07 712 bytes
Adds the file tmp2.gif"="11:39 28/05/10 197 bytes
Adds the file tmp.gif"="15:12 15/06/10 3894 bytes
Adds the file title7.gif"="15:44 13/08/07 13067 bytes
Adds the file title6.gif"="15:44 13/08/07 7578 bytes
Adds the file title6-1.gif"="15:44 13/08/07 7500 bytes
Adds the file title5.gif"="15:43 13/08/07 8124 bytes
Adds the file title4.gif"="15:42 13/08/07 12962 bytes
Adds the file title4-1_.gif"="15:43 13/07/07 6038 bytes
Adds the file title4-1.gif"="11:52 28/05/10 30018 bytes
Adds the file title3.gif"="15:42 13/08/07 13514 bytes
Adds the file title2.gif"="15:41 13/08/07 13227 bytes
Adds the file title1.gif"="15:42 13/08/07 11027 bytes
Adds the file Thumbs.db"="10:50 18/06/10 357888 bytes
Adds the file sysdown.gif"="11:40 28/05/10 14889 bytes
Adds the file pass_change.gif"="11:39 28/05/10 10274 bytes
Adds the file pass.gif"="15:28 15/06/10 11558 bytes
Adds the file messageyes_or_no.gif"="10:32 18/06/10 10323 bytes
Adds the file messageok.gif"="10:29 18/06/10 10195 bytes
Adds the file main2.jpg"="10:59 16/06/10 199843 bytes
Adds the file main1.jpg"="10:58 16/06/10 185354 bytes
Adds the file main.jpg"="10:53 16/06/10 57999 bytes
Adds the file loading.gif"="15:11 15/06/10 10756 bytes
Adds the file left_btn_on_06.gif"="17:49 29/07/09 4084 bytes
Adds the file left_btn_on_05.gif"="17:48 29/07/09 4407 bytes
Adds the file left_btn_on_04.gif"="17:49 29/07/09 4375 bytes
Adds the file left_btn_on_03.gif"="17:49 29/07/09 4285 bytes
Adds the file left_btn_on_02.gif"="17:49 29/07/09 4098 bytes
Adds the file left_btn_on_01.gif"="17:48 29/07/09 4300 bytes
Adds the file left_btn_click_06.gif"="10:46 10/06/10 3190 bytes
Adds the file left_btn_click_05.gif"="10:46 10/06/10 3613 bytes
Adds the file left_btn_click_04.gif"="10:46 10/06/10 3669 bytes
Adds the file left_btn_click_03.gif"="10:46 10/06/10 3671 bytes
Adds the file left_btn_click_02.gif"="10:45 10/06/10 3580 bytes
Adds the file left_btn_click_01.gif"="10:45 10/06/10 3981 bytes
Adds the file left_btn_06.gif"="10:47 10/06/10 2347 bytes
Adds the file left_btn_05.gif"="10:47 10/06/10 2690 bytes
Adds the file left_btn_04.gif"="10:47 10/06/10 2702 bytes
Adds the file left_btn_03.gif"="10:47 10/06/10 2777 bytes
Adds the file left_btn_02.gif"="10:47 10/06/10 2664 bytes
Adds the file left_btn_01.gif"="10:47 10/06/10 3084 bytes
Adds the file install02.gif"="17:12 28/07/07 3101 bytes
Adds the file install01.gif"="15:26 15/06/10 16431 bytes
Adds the file icn_dell.ico"="11:34 16/06/10 17542 bytes
Adds the file end_popup04.gif"="15:30 15/06/10 10624 bytes
Adds the file end_popup03.gif"="15:37 15/06/10 11877 bytes
Adds the file end_popup02.gif"="15:29 15/06/10 14537 bytes
Adds the file end_popup01.gif"="15:23 15/06/10 14326 bytes
Adds the file download.gif"="15:39 15/06/10 4276 bytes
Adds the file dotline_loading.gif"="19:37 28/07/07 768 bytes
Adds the file del.gif"="15:36 15/06/10 14537 bytes
Adds the file ber.gif"="11:50 28/05/10 17729 bytes
Adds the file alram.gif"="10:45 17/06/10 26476 bytes
Adds the file 9_over.jpg"="11:30 26/05/10 4014 bytes
Adds the file 9.jpg"="11:59 25/05/10 1974 bytes
Adds the file 8_over.jpg"="11:29 26/05/10 4695 bytes
Adds the file 8.jpg"="11:58 25/05/10 2348 bytes
Adds the file 7_over.jpg"="11:28 26/05/10 4264 bytes
Adds the file 7.jpg"="11:58 25/05/10 2118 bytes
Adds the file 6_over.jpg"="11:38 26/05/10 2658 bytes
Adds the file 6.jpg"="11:58 25/05/10 1357 bytes
Adds the file 5_over.jpg"="11:37 26/05/10 2743 bytes
Adds the file 5.jpg"="11:57 25/05/10 1389 bytes
Adds the file 4_over.jpg"="11:36 26/05/10 2526 bytes
Adds the file 4.jpg"="11:57 25/05/10 1281 bytes
Adds the file 3_over.jpg"="11:26 26/05/10 2574 bytes
Adds the file 3.jpg"="11:57 25/05/10 1300 bytes
Adds the file 2_over.jpg"="11:25 26/05/10 2680 bytes
Adds the file 256_2.ico"="11:26 16/06/10 17542 bytes
Adds the file 256_1.ico"="11:26 16/06/10 17542 bytes
Adds the file 2.jpg"="11:57 25/05/10 1360 bytes
Adds the file 1_over.jpg"="11:23 26/05/10 4458 bytes
Adds the file 16_over.jpg"="11:35 26/05/10 3668 bytes
Adds the file 16.jpg"="11:35 26/05/10 1844 bytes
Adds the file 15_over.jpg"="11:35 26/05/10 3671 bytes
Adds the file 15.jpg"="11:34 26/05/10 1841 bytes
Adds the file 14_over.jpg"="11:33 26/05/10 3918 bytes
Adds the file 14.jpg"="11:33 26/05/10 1964 bytes
Adds the file 13_over.jpg"="11:32 26/05/10 4038 bytes
Adds the file 13.jpg"="11:32 26/05/10 2027 bytes
Adds the file 10_over.jpg"="11:31 26/05/10 4633 bytes
Adds the file 10.jpg"="11:59 25/05/10 2279 bytes
Adds the file 1.jpg"="11:57 25/05/10 2250 bytes
Adds the file +++n.gif"="15:35 15/06/10 13584 bytes

Registry
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\adcare]
"SlowInfoCache"="PJ@."
"Changed"="PJ@."
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"adcareup"="'C:\Program Files\adcare\adcareup.exe hideup'"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adcare]
"UninstallString"="'C:\Program Files\adcare\uninstall.exe'"
"DisplayName"="'adcare ????'"
"DisplayIcon"="'C:\Program Files\adcare\uninstall.exe'"
[HKEY_CURRENT_USER\Software\adcare]
"timer_alram"="'60000'"
"timer_maine"="'60000'"
"ver"="'1.0'"
"pid"="'homepage'"
[HKEY_CURRENT_USER\Software\noadcare]
"true"="'true'"

Malwarebytes' Anti-Malware log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4446

Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512

8/18/2010 8:37:39 PM
mbam-log-2010-08-18 (20-37-39).txt

Scan type: Quick scan
Objects scanned: 117800
Time elapsed: 3 minute(s), 31 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 1
Folders Infected: 5
Files Infected: 111

Memory Processes Infected:
C:\Program Files\adcare\adcare.exe (Rogue.AdCare) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adcare (Rogue.AdCare) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\adcare (Rogue.AdCare) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\adcareup (Rogue.Adcare) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\adcare (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\report (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Documents and Settings\{username}\Start Menu\Programs\adcare (Rogue.AdCare) -> Quarantined and deleted successfully.

Files Infected:
C:\Program Files\adcare\adcare.exe (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\adcareup.exe (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\config.ini (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\filecheck.ini (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\ntfile.ini (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\uninstall.exe (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\+++n.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\1.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\10.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\10_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\13.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\13_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\14.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\14_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\15.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\15_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\16.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\16_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\1_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\2.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\256_1.ico (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\256_2.ico (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\2_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\3.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\3_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\4.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\4_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\5.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\5_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\6.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\6_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\7.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\7_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\8.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\8_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\9.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\9_over.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\alram.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\ber.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\del.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\dotline_loading.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\download.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\end_popup01.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\end_popup02.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\end_popup03.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\end_popup04.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\icn_dell.ico (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\install01.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\install02.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_01.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_02.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_03.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_04.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_05.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_06.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_click_01.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_click_02.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_click_03.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_click_04.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_click_05.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_click_06.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_on_01.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_on_02.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_on_03.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_on_04.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_on_05.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\left_btn_on_06.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\loading.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\main.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\main1.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\main2.jpg (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\messageok.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\messageyes_or_no.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\pass.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\pass_change.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\sysdown.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\Thumbs.db (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title1.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title2.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title3.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title4-1.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title4-1_.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title4.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title5.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title6-1.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title6.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\title7.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\tmp.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\tmp2.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\view_button.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\win.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\img\ws.gif (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\report\+?+f.txt (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\report\2010-08.ale (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\b_ac.da2 (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\chdir.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\pattern.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\skey.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wac.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode1.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode2.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode3.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode4.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode5.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode6.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode7.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wcode8.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Program Files\adcare\value\wurl.da (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Documents and Settings\{username}\Start Menu\Programs\adcare\adcare ????.lnk (Rogue.AdCare) -> Quarantined and deleted successfully.
C:\Documents and Settings\{username}\Start Menu\Programs\adcare\??????.lnk (Rogue.AdCare) -> Quarantined and deleted successfully.

As mentioned before the full version of Malwarebytes' Anti-Malware could have protected your computer against this threat.

We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention

Save yourself the hassle and get protected.

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.