1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. System Infected: Adware.DNSUnlocker Activity

System Infected: Adware.DNSUnlocker Activity

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

Adware.DNSUnlocker is an adware program that displays advertisements in web browsers without user consent.

Additional Information

Adware.DNSUnlocker is an adware program that displays advertisements in web browsers without user consent.

Affected

  • Windows

Response

If you are receiving a high amount of Trojan.Zlob.Q Activity Warnings, the
following instructions may help to correct the problem.

Open a blank .txt file and and paste the following instructions into it:

bitsadmin /reset
reg delete
HKEY_CURRENT_USER\Console\%SystemRoot%_System32_WindowsPowerShell_v1.0_powershell.e
xe /f
reg delete HKEY_CURRENT_USER\Console\%SystemRoot%_System32_svchost.exe /f
reg delete HKEY_CURRENT_USER\Console\taskeng.exe /f

Save the file and change the extension to .bat.

Run the file with administrator permissions.

Disclaimer: This batch script is provided as-is with no warranty. If you have jobs
set up in your environment, please note that this batch file may delete clean
files.
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube