AdGoblin\AdsInContext Detection and Removal
AdGobllin\AdsInContext downloads itself onto Microsoft Internet Explorer so as to bypass any firewalls or unsophisticated anti-spyware programs. It starts every time you start up Explorer, eating up RAM, processor speed, and other system resources.
Upon starting, AdGoblin\AdsInContext runs an executable file that connects to adsincontext.com. This does three amazing things at once: it slows down your Internet connection, consumes yet more system resources, and violates user privacy.
The program records whatever information it is able to gather and communicates this to its home server. The server uses this information to deliver pop-up advertisements to your computer.
AdGoblin\AdsInContext is often downloaded with free programs (in the past, it has come bundled with Grokster). It serves no purpose other than to display advertisements.
The files below are the system files for AdGoblin, should you wish to remove the program yourself by deleting them. Please use caution with the registry keys, as deleting the wrong ones may cause your computer to stop functioning properly.
A free scan with SpyZooka can be used to detect any other harmful or privacy-violating software present on a computer.
Relative File Contents:
_ps_inst.exe
duxdiag.exe
iic3ba.exe
dandgerous creatures.dll
%windir%\eventlowg.dll
%windir%\daxtime.dll
Registry Key:
{E9306072-417E-43E3-81D5-369490BEEF7C}
HKEY_LOCAL_MACHINE clsid {029e02f0-a0e5-4b19-b958-7bf2db29fb13}
HKEY_CLASSES_ROOT ypelib {d212259d-4648-4903-9fbd-02e88785d33c}
HKEY_CLASSES_ROOT ypelib {a3a3043d-749e-433f-a26e-6227d5e9bfcd}
HKEY_CLASSES_ROOT ypelib {98349900-adc7-11d7-8515-0040050362d3}
HKEY_CLASSES_ROOT clsid {fad0b5cb-1ec4-4f37-8ecb-520faf3b9afa}
HKEY_CLASSES_ROOT clsid {f53d14a9-c1e7-409d-8521-99032d94b1ba}
HKEY_CLASSES_ROOT clsid {d3512525-e159-421f-a154-a60a738f7f6d}
HKEY_CLASSES_ROOT clsid {a94b52a0-0863-11d8-99de-444553540000}
HKEY_CLASSES_ROOT clsid {a3a3043d-749e-433f-a26e-6227d5e9bfcd}
HKEY_CLASSES_ROOT clsid {98349900-adc7-11d7-8515-0040050362d3}
HKEY_CLASSES_ROOT clsid {37b9ff8c-01d9-4fdc-a6a2-08183915c71d}
HKEY_CLASSES_ROOT clsid {029e02f0-a0e5-4b19-b958-7bf2db29fb13}
4A157FCB-C37D-4C19-958A-5DFA5880DB57
unplathping.exe
HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversion
HKEY_LOCAL_MACHINE software classes clsid {fad0b5cb-1ec4-4f37-8ecb-520faf3b9afa}
HKEY_LOCAL_MACHINE software classes clsid {d3512525-e159-421f-a154-a60a738f7f6d}
HKEY_LOCAL_MACHINE software classes clsid{a94b52a0-0863-11d8-99de-444553540000}
HKEY_LOCAL_MACHINE software classes clsid {37b9ff8c-01d9-4fdc-a6a2-08183915c71d}
HKEY_LOCAL_MACHINE software classes clsid {3182c8ab-5a3e-4644-80da-647417799b11}