Adware
. Adware.MediaTickets (Summary)
Software Name: Adware.MediaTickets
Company Name: MediaTickets
Product Name: Adware.MediaTickets
Classification: Adware
Website: http://wwww.mediatickets.net
Brief:
Silently connects to its controlling servers where it downloads files. May display pop-up advertisements.
IMPORTANT!
Some of the Adware.Adware.MediaTickets components are listed below. The
list is compiled as a reference. The list might not be complete
and it doesn't represent instructions for manual removal.
We DO NOT recommend manual removal. Incorrect
removal of certain software might make your computer unstable
or even unusable.
Removal of adware component might affect the related ad-supported
software.
If you suspect that you have an unwanted instance
of Adware.MediaTickets installed on your
computer we recommend a free
audit of your system with INAC Anti Spyware.
Adware.MediaTickets might create following folders
(and inject its files inside the folders):
- %APPDATA%\cemu
- %PROGRAM_FILES%\tuap
- %PROGRAM_FILES%\ctut
Adware.MediaTickets might create following
files (some of the files might be loaded in memory while
the software is running):
- %APPDATA%\wcdh.exe
- %PROFILE%\Local Settings\Temp\ps_install-mt.exe
- %PROFILE%\Local Settings\Temp\rs.exe
- %WINDOWS%\Downloaded Program Files\MediaTicketsInstaller.INF
- %WINDOWS%\Downloaded Program Files\MediaTicketsInstaller.ocx
- %SYSTEM%\mt-uninstaller.exe
- %SYSTEM%\wapitr.exe
- %SYSTEM%\wnstssv.exe
- %APPDATA%\paro.exe
- %SYSTEM%\ebzm.dll
- %SYSTEM%\windos.exe
- %SYSTEM%\twink64.exe
- %APPDATA%\thus.exe
- %APPDATA%\dees.exe
- %system%\wcpsvit.exe
- %APPDATA%\boau.exe
- %SYSTEM%\nfawm.dll
- %SYSTEM%\wnsapisu.exe
- %PROFILE%\Local Settings\Temp\!update.exe
- %SYSTEM%\xujmdb.dll
- %SYSTEM%\oi-uninstaller.ico
- %SYSTEM%\boau.exe
- %PROGRAM_FILES%\tuap\boau.exe
- %WINDOWS%\ru.exe
- %WINDOWS%\Tasks\RUTASK.job
Adware.MediaTickets is often accompanied by the following
tracking cookies:
n/a
Adware.MediaTickets might create following registry
keys (and inject subkeys and values):
- HKEY_CLASSES_ROOT\CLSID\{7D39A396-CBB8-4739-B97C-83FAA4682E00}
- HKEY_CLASSES_ROOT\CLSID\{9EB320CE-BE1D-4304-A081-4B4665414BEF}
- HKEY_CLASSES_ROOT\Interface\{13158297-E165-4962-9379-94DC52246ABB}
- HKEY_CLASSES_ROOT\Interface\{69DF6590-4A40-45E4-AC8A-C2F1CFCDD640}
- HKEY_CLASSES_ROOT\MEDIATICKETSINSTALLER.MediaTicketsInstallerCtrl.1
- HKEY_CLASSES_ROOT\MEDIATICKETSINSTALLER.MediaTicketsInstallerCtrl.1\CLSID
- HKEY_CLASSES_ROOT\TypeLib\{D7CD3877-8986-48B7-9462-02E361391987}
- HKEY_LOCAL_MACHINE\SOFTWARE\ClickSpring
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9EB320CE-BE1D-4304-A081-4B4665414BEF}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\*/MediaTicketsInstaller.ocx*
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MediaTickets
- HKEY_USERS\*\Software\Acre
- HKEY_CLASSES_ROOT\CLSID\{39DA2444-065F-47CB-B27C-CCB1A39C06B7}
- HKEY_CLASSES_ROOT\Interface\{3E4C3E0B-6BBE-4C94-86CA-6F055A989693}
- HKEY_CLASSES_ROOT\Interface\{81EB72D7-3949-450F-B035-DE599959814F}
- HKEY_CLASSES_ROOT\TypeLib\{46605C8C-D306-4E2D-B367-9B53690CB867}
- HKEY_CLASSES_ROOT\CLSID\{65F6632D-E214-0AC4-8005-655578F67F3A}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{65F6632D-E214-0AC4-8005-655578F67F3A}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{63A73170-EB16-5E9D-DD05-655578F1723F}
- HKEY_CLASSES_ROOT\CLSID\{9AE7A573-629E-1811-BC59-3F76616956B3}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9AE7A573-629E-1811-BC59-3F76616956B3}
- HKEY_USERS\*\Software\Ccon
- HKEY_USERS\*\Software\Tcpi
- HKEY_USERS\*\Software\Daho
- HKEY_CLASSES_ROOT\CLSID\{F86F49AB-DF48-A595-4BD0-F53AE4441FE2}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F86F49AB-DF48-A595-4BD0-F53AE4441FE2}
- HKEY_CLASSES_ROOT\CLSID\{5528A9B2-4507-66D6-7377-6D0387B1CEBC}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5528A9B2-4507-66D6-7377-6D0387B1CEBC}
- HKEY_USERS\*\Software\Ceru
- HKEY_USERS\*\Software\Odla
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OIN
- HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5FC6A9C7-4A7A-65DD-2091-66833CDACABE}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
Objects\{5FC6A9C7-4A7A-65DD-2091-66833CDACABE}
- HKEY_CLASSES_ROOT\CLSID\{DE2F6B2C-8D92-FC3D-CB49-FEBADF3643E7}
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DE2F6B2C-8D92-FC3D-CB49-FEBADF3643E7}
Adware.MediaTickets might create following registry
values:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs|*\MediaTicketsInstaller.ocx
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Pdsb
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|WTSS
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Sbpa
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Ifshcn
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Nqcfrv
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run|Ltho
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Rhra
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Swpfhbrs
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Ceso
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Zvmv
- HKEY_USERS\*\Software\Microsoft\Windows\CurrentVersion\Run|Hmqqx
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\URLSearchHooks|{5FC6A9C7-4A7A-65DD-2091-66833CDACABE}
- HKEY_USERS\*\Software\Microsoft\Internet Explorer\URLSearchHooks|{DE2F6B2C-8D92-FC3D-CB49-FEBADF3643E7}
Adware.MediaTickets might create registry values with
following data:
n/a
Adware.MediaTickets might insert following entries
in the HOSTS file:
n/a
Click here to scan
your computer for Adware.MediaTickets free of charge