Home Malware Programs Adware Adware:Win32/HitLink


Posted: November 21, 2012

Threat Metric

Threat Level: 2/10
Infected PCs: 39
First Seen: November 21, 2012
OS(es) Affected: Windows

Adware:Win32/HitLink is an adware program that displays out of context advertisements. Adware:Win32/HitLink hijacks the targeted web browser and redirects PC users to suspicious advertisement websites. Once executed, Adware:Win32/HitLink drops potentially malicious files on the infected computer system. Adware:Win32/HitLink also modifies the Windows Registry. Adware:Win32/HitLink modifies the certain registry entry so that it can run automatically every time Windows is started. Adware:Win32/HitLink also makes modifications to the Windows Registry to create an option in the Programs and Features control panel menu that will uninstall the application. Adware:Win32/HitLink checks if the PC user visits any websites that include the certain strings in their URLs. Any text the computer user puts into the search box of the website is transferred to a server, via the certain URL. The server will then guide the hijacked web browser to display pop-up advertisements. Adware:Win32/HitLink strives to check for and install updated versions of itself by connecting to the certain server.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:

%ProgramFiles%\hitlink\uninstall_hitlink.exe File name: %ProgramFiles%\hitlink\uninstall_hitlink.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ProgramFiles%\hitlink\hitlink.exe File name: %ProgramFiles%\hitlink\hitlink.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\uninstall_hitlink.exe "DisplayName" = "Windows hitlink ad-System [hitlink]"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run "hitlink.exe" = "%ProgramFiles%\hitlink\hitlink.exe"HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\uninstall_hitlink.exe "UninstallString" = "%ProgramFiles%\hitlink\uninstall_hitlink.exe delete"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\uninstall_hitlink.exeHKEY_CURRENT_USER\Software\hitlink