FullContext Removal: Remove FullContext Forever
Let our support team solve your problem with FullContext and repair FullContext right now!
Leave the detailed description of your FullContext problem in the form below. Our support team will contact you in several minutes and give a step-by-step instruction on how to fix FullContext problem. Please be specific. Do your best describing the problem. This will help us recommend right and complete FullContext problem removal solution.
Describe your problem here and we'll contact you in several minutes:
Warning:
1) We hate spam as much as you do. We will not share your email with any third party or publish it anywhere. Your email is used only to contact you and give you FullContext removal solution.
2) All fields of this form are obligatory.
Threat's profile
|
Name of the threat: FullContext |
| Command or file name: adsponsor.exe |
| Threat type: Spyware\trojan |
| Affected OS: Win32 (Windows 9x, Windows XP, Windows Vista) |
FullContext intrusion method
FullContext copies its file(s) to your hard disk. Its typical file name is adsponsor.exe. Then it creates new startup key with name FullContext and value adsponsor.exe. You can also find it in your processes list with name adsponsor.exe or FullContext.
If you have further questions about FullContext, please fill in the form above and we'll contact you shortly.
» Download program to remove FullContext (FullContext Removal Tool)
Recommended Solution
If you are not sure what to delete, use our award winning program - FullContext Removal Tool.
FullContext Removal Tool will find and fully remove FullContext and all problems associated with FullContext virus.
Fast, easy, and handy, FullContext Removal Tool protects your computer against FullContext that does harm to your computer and breaks your privacy. FullContext Removal Tool scans your hard disks and registry and destroys any manifestation of FullContext. Standard anti-virus software can do nothing against malicious programs like FullContext. Remove FullContext straight away!
» Download FullContext Removal Tool now for free
How to fix FullContext
This problem can be solved manually by deleting all registry keys and files connected with FullContext, removing it from starup list and unregistering all corresponding DLLs. Additionally missing DLL's should be restored from distribution in case they are corrupted by FullContext.
To get rid of FullContext, you should:
1. Kill the following processes and delete the appropriate files:
• adsponsor[1].exe
• assistantlibrary.dll
• batty2.dll
• batty2.exe
• batty2[1].exe
• batty2[2].exe
• battyrun2.dll
• cmfibula.exe
• cmfibula[1].exe
• cmintex.exe
• cmmanupd[1].exe
• contexapp.exe
• datahtml.sdf
• datajava.sdf
• equpd.exe
• fddmmmkd.dll
• fjjekjpp.dll
• igdjhgeh.dll
• jonapdno.dll
• lanecaff.dll
• padrecover1.exe
• padrecover1[1].exe
• padsysassistant.exe
• padsyslibrary.sys
• padsyslibrary2.sys
• padupd3.exe
• padupd5.exe
• padupd6.exe
• padupd7[1].exe
• pscastor.exe
• psupdate.exe
• tpuninstall.exe
• tspd.dll
• tspd.exe
• tspd[1].exe
• upd.exe
Warning: you should delete only those files which checksums are listed as malicious. There may be valid files with the same names in your system. We recommend you to use FullContext Removal Tool for safe problem solution.
2. Delete the following malicious folders:
• C:\Program Files\padsysassistant\
• C:\Program Files\pscastor\
• C:\Program Files\pslister\
• C:\Program Files\cmfibula\
• C:\Program Files\cmintex\
• C:\Program Files\batty2\
• C:\Documents and Settings\User\Desktop\exe\exe\
• C:\Program Files\adsponsor\
3. Delete the following malicious registry entries and\or values:
• Key: CLSID\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\InprocServer32 Value: ThreadingModel
• Key: AdBand.BandBHO.1
• Key: AdBand.BandBHO.1\CLSID
• Key: AdBand.BandBHO
• Key: AdBand.BandBHO\CLSID
• Key: AdBand.BandBHO\CurVer
• Key: AdBand.BandImpl.1
• Key: AdBand.BandImpl.1\CLSID
• Key: AdBand.BandImpl
• Key: Software\Microsoft\Windows\CurrentVersion\Run\EQArticle
• Key: Software\Microsoft\Windows\CurrentVersion\Run\EQBranch
• Key: Software\Microsoft\Windows\CurrentVersion\Run\AXVenore
• Key: Software\Microsoft\Windows\CurrentVersion\Run\AXFibula
• Key: Software\Microsoft\Windows\CurrentVersion\Run\CMFibula
• Key: Software\Microsoft\Windows\CurrentVersion\Run\PSLister
• Key: Software\Microsoft\Windows\CurrentVersion\Run\PSCloner
• Key: Software\Microsoft\Windows\CurrentVersion\Run\PSDream
• Key: Software\Microsoft\Windows\CurrentVersion\Run\Batty
• Key: CLSID\{994D478A-45D0-4DB4-AE27-738B1E346F99}
• Key: CLSID\{994D478A-45D0-4DB4-AE27-738B1E346F99}\InprocServer32 Value: ThreadingModel
• Key: CLSID\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA} Value: AppID
• Key: CLSID\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}\ProgID
• Key: CLSID\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}\VersionIndependentProgID
• Key: CLSID\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}\InprocServer32 Value: ThreadingModel
• Key: CLSID\{6CA1C00B-90FC-4F3E-911F-95306ABA43AA}\TypeLib
• Key: CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA} Value: AppID
• Key: CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}\ProgID
• Key: CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}\VersionIndependentProgID
• Key: CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}\InprocServer32 Value: ThreadingModel
• Key: CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}\TypeLib
• Key: CLSID\{2BC9C452-BB57-4896-A9A2-64611E06C5AA}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
• Key: TypeLib\{D5599FAE-28AA-4C2B-A29C-6C0CD5B245AA}\1.0
• Key: TypeLib\{D5599FAE-28AA-4C2B-A29C-6C0CD5B245AA}\1.0\0\win32
• Key: TypeLib\{D5599FAE-28AA-4C2B-A29C-6C0CD5B245AA}\1.0\HELPDIR
• Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}
• Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\iexplore Value: Count
• Key: SOFTWARE\Classes\CLSID\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\InprocServer32
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{04CDB16C-AB38-43CD-A86A-6FEB90290939}
• Key: SOFTWARE\Classes\CLSID\{04CDB16C-AB38-43CD-A86A-6FEB90290939}
• Key: TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}\1.0\FLAGS
• Key: TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}\1.0\0\win32
• Key: TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}\1.0\HELPDIR
• Key: Software\Microsoft\Windows\CurrentVersion\Run\SDVita
• Key: Software\Microsoft\Windows\CurrentVersion\Run\SDExana
• Key: TypeLib\{1B8B502E-455B-4022-BE27-736D9F808A18}\1.0
• Key: Software\Microsoft\Windows\CurrentVersion\Run\PECarlin
• Key: Software\Microsoft\Windows\CurrentVersion\Run\PSHope
• Key: Software\Microsoft\Windows\CurrentVersion\Run\PSCastor
• Key: CLSID\{04CDB16C-AB38-43CD-A86A-6FEB90290939}
• Key: Software\CMFibula Value: Registered
• Key: Software\CMIntex Value: Registered
• Key: Software\PadsysAssistant Value: Country
• Key: Software\PSCastor Value: Country
• Key: Software\PSDream Value: Country
• Key: Software\PSLister Value: Country
• Key: Software\PSCloner Value: aid
• Key: Software\Batty2 Value: JAVAFilterVersion
• Key: Software\PadsysAssistant Value: Registered
• Key: Software\PadsysAssistant Value: aid
• Key: Software\PadsysAssistant Value: Version
• Key: Software\PadsysAssistant Value: ConfigCache
• Key: Software\PadsysAssistant Value: ConfigExpire
• Key: Software\PadsysAssistant Value: TPA
• Key: System\CurrentControlSet\Services\searchassistant Value: Type
• Key: System\CurrentControlSet\Services\searchassistant Value: Start
• Key: System\CurrentControlSet\Services\searchassistant Value: ErrorControl
• Key: System\CurrentControlSet\Services\searchassistant Value: ImagePath
• Key: System\CurrentControlSet\Services\searchassistant Value: DisplayName
• Key: System\CurrentControlSet\Services\searchassistant\Security Value: Security
• Key: System\CurrentControlSet\Services\searchassistant Value: DeleteFlag
• Key: System\CurrentControlSet\Services\searchassistant Value: Start
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT Value: NextInstance
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000\Control Value: *NewlyCreated*
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000 Value: Service
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000 Value: Legacy
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000 Value: ConfigFlags
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000 Value: Class
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000 Value: ClassGUID
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_SEARCHASSISTANT\0000 Value: DeviceDesc
• Key: SYSTEM\CURRENTCONTROLSET\SERVICES\searchassistant\Enum
• Key: SYSTEM\CURRENTCONTROLSET\SERVICES\searchassistant\Enum Value: Count
• Key: SYSTEM\CURRENTCONTROLSET\SERVICES\searchassistant\Enum Value: NextInstance
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\Root\LEGACY_SEARCHASSISTANT\0000\Control Value: ActiveService
• Key: Software\CMIntex Value: ConfigCache
• Key: Software\CMIntex Value: ConfigDate
• Key: Software\CMIntex Value: URLSearchHookVersion
• Key: Software\CMIntex Value: TPA
• Key: Software\PSCastor Value: aid
• Key: Software\PSCastor Value: Version
• Key: Software\PSCastor Value: TPA
• Key: Software\Microsoft\Windows NT\CurrentVersion\Windows Value: AppInit_DLLs
• Key: AppID\AdBand.DLL Value: AppID
• Key: Software\CMFibula Value: ConfigCache
• Key: Software\CMFibula Value: ConfigDate
• Key: Software\CMFibula Value: URLSearchHookVersion
• Key: Software\\AdSponsor Value: Installed
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdSponsor Value: DisplayName
• Key: Software\Microsoft\Windows\CurrentVersion\Uninstall\AdSponsor Value: UninstallString
• Key: Software\Microsoft\Windows NT\CurrentVersion\Windows Value: AppInit_DLLs
• Key: Software\Batty2 Value: Registered
• Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\iexplore Value: Type
• Key: Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\iexplore Value: Time
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks Value: {04CDB16C-AB38-43CD-A86A-6FEB90290939}
• Key: Software\CMFibula Value: ConfigDate
• Key: Software\CMIntex Value: ShortcutTime
• Key: Software\Batty2 Value: ConfigCache
• Key: Software\Batty2 Value: ConfigDate
• Key: Software\PSLister Value: Registered
• Key: Software\PSLister Value: aid
• Key: Software\PSLister Value: ConfigCache
• Key: Software\PSLister Value: ConfigExpire
• Key: System\CurrentControlSet\Services\dxminiport Value: Type
• Key: System\CurrentControlSet\Services\dxminiport Value: Start
• Key: System\CurrentControlSet\Services\dxminiport Value: ErrorControl
• Key: System\CurrentControlSet\Services\dxminiport Value: ImagePath
• Key: System\CurrentControlSet\Services\dxminiport Value: DisplayName
• Key: System\CurrentControlSet\Services\dxminiport\Security Value: Security
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT Value: NextInstance
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000\Control Value: *NewlyCreated*
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000 Value: Service
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000 Value: Legacy
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000 Value: ConfigFlags
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000 Value: Class
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000 Value: ClassGUID
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\ROOT\LEGACY_DXMINIPORT\0000 Value: DeviceDesc
• Key: SYSTEM\CURRENTCONTROLSET\SERVICES\dxminiport\Enum
• Key: SYSTEM\CURRENTCONTROLSET\SERVICES\dxminiport\Enum Value: Count
• Key: SYSTEM\CURRENTCONTROLSET\SERVICES\dxminiport\Enum Value: NextInstance
• Key: SYSTEM\CURRENTCONTROLSET\ENUM\Root\LEGACY_DXMINIPORT\0000\Control Value: ActiveService
• Key: System\CurrentControlSet\Services\dxminiport Value: DeleteFlag
• Key: System\CurrentControlSet\Services\dxminiport Value: Start
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\iexplore Value: Count
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\iexplore Value: Time
• Key: Software\PadsysAssistant Value: Country
• Key: Software\PadsysAssistant Value: ActivityTimestamp
• Key: Software\PadsysAssistant Value: TpaTimestamp
• Key: Software\PSCastor Value: ConfigCache
• Key: Software\PSCastor Value: ConfigExpire
• Key: Software\PSCastor Value: Registered
• Key: Software\PSDream Value: Registered
• Key: Software\PSDream Value: aid
• Key: Software\PSDream Value: Version
• Key: Software\PSDream Value: ConfigCache
• Key: Software\PSDream Value: ConfigExpire
• Key: Software\PadsysAssistant Value: ConfigExpire
• Key: Software\PadsysAssistant Value: PopupTimestamp
• Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04CDB16C-AB38-43CD-A86A-6FEB90290939}\iexplore Value: Count
• Key: Software\PSCastor Value: aid
• Key: Software\CMIntex Value: ConfigDate
• Key: Software\PSCastor Value: ConfigCache
• Key: Software\PSCastor Value: ConfigExpire
• Key: Software\CMIntex Value: ShortcutTime
• Key: Software\Microsoft\Windows NT\CurrentVersion\Windows Value: AppInit_DLLs
• Key: Software\PSCloner Value: Country
• Key: Software\Batty2 Value: HTMLFilterVersion
• Key: Software\PSCloner Value: Registered
Warning: If value is listed for some registry entries, you should only clear these values and leave keys with such values untouched. We recommend you to use FullContext Removal Tool for safe problem solution.
Here are the descriptions of problems connected with FullContext and adsponsor.exe we received earlier:
FullContext won\'t go away. :(
Problem Summary: FullContext won\'t go away. :(
Several nights ago, my computer freaked out and started popping up lots of little \"Your computer may be infected with a virus\" warnings. I have AVG Antivirus (the free version), but that is doing nothing. There is also something stopping me from being able to update it (it says it can\'t connect to the server, although I\'m not sure that\'s connected to FullContext or not).
In addition to that, I found I was not able to log on to many of my regular websites. I could enter my username/password info, and click \"send\", but it would take several minutes of loading and end up at a \"page cannot be displayed\". Is this connected to FullContext?
Also, when I search on search engines such as google, clicking result links takes me to completely unrelated ad sites. It\'s really very annoying.
On my computer\'s reccomendation, I ended up downloading and purchasing AntiSpyware Protector. That helped a lot, wiping out the majority of the viruses EXCEPT for that sticky little FullContext.
So now I\'m kind of stuck. AntiSpyware Protector gives me a little popup that says \"could not remove registry value CLSID\", and I can\'t find it to try to remove it manually.
Since I\'m stuck, I did a search and ended up here, hoping very much that you can help. I\'m looking forward to your reply. :)
Our support has contacted the author of this message, Hilary Beutler, and helped to solve his problem.
Next threat: Funcade »
Learn more about FullContext and adsponsor.exe »
« Back to catalog
Solution: 2216
|