I occasionally receive the following Web Shield Pop Ups: http://stats.mydatastatssrv.com/stats.gif?action . The web blocker pops up on the occasion when I start running my laptop or, in some rare instances, when chrome opens up. The pop up will repeat itself about 8 to 10 times in succession, with the pop up indicating how many times. The good news is whatever this is, Avast says it has been blocked. I cannot seem to find any relevant data on this. Avast shows my system as always clean, and no followup info.
Have run Avast Clean and Boot Scan, Comodo Cleaning Essentials, ADW Cleaner and Malware bytes. There was a couple of Adware Pup's, but everything has checked out fine now. Yet , Web Shield still occasionally pops up with this same URL warning.
What is stats.mydatastatssrv.com?
Stats.mydatastatssrv.com is a nasty compute virus which belongs to the browser hijacker family. Here are the malicious behaviors of stats.mydatastatssrv.com once it invades into the target PC:
Stats.mydatastatssrv.com redirect virus will change the browse settings in the infected PC such as altering the homepage, modifying the default search engines and adding some commercial icons.
Stats.mydatastatssrv.com browse hijacker will change the system settings. For instances, put its active files to the startup menu to make itself get started automatically, delete some important files without users’ permission to block functions of some useful programs.
Here are two effective methods to get rid of this nasty browser hijacker, choose one of you like to regain a clean PC now.
Manually remove stats.mydatastatssrv.com:
1.End all the running processes of this computer virus Open task manager by pressing Alt+Ctrl+Del keys at the same time. Another way is to click on the Start button and choose Run option, then type taskmgr into and press OK.
Stop all the malicious running processes.
2. Remove malicious add-on and extensions from your web browsers.
Internet Explorer:
(1). Click Start, type: Manage browser add-ons
(2). Hit Enter on your keyboard
(3). Click Manage add-on and disable all the suspicious add-on.
Firefox:
(1). Click the Firefox menu and click Add-on
(2). Click Extensions, select the related browser add-on and click Disable.
Google Chrome:
(1). Click the Customize and Control menu button →Tools→ click Extensions
3. Disable any suspicious startup items that are made by this computer virus.
Windows Vista or Windows7: click start menu→type msconfig in the search bar → open System Configuration →Disable all possible startup items generated.
4. Clean cookies
Internet Explorer: Tools → Internet Options →the General tab, Delete the Cookies button can be directly seen in IE6, IE7 is to click the Delete Browsing History button then tick Cookies and click Delete.
Firefox: Tools → Options → Privacy → Remove Individual Cookies → Delete corresponding cookies in the cookies showing box.
Opera: Tools → Preferences → Advanced → Cookies →Delete corresponding cookies in Management Cookies.
5. Show all hidden files and clean all the malicious files about this computer virus (1).Click the Start button and choose Control Panel, clicking Appearance and Personalization, to find Folder Options then double-click on it. (2).In the pop-up dialog box, click the View tab and uncheck Hide protected operating system files (Recommended).
(3). Clean all the malicious files about this infection as below.
%AllUsersProfile%\{random.exe\ %AllUsersProfile%\Application Data\ %AllUsersProfile%\random.exe %AppData%\Roaming\Microsoft\Windows\Templates\random.exe %Temp%\random.exe %AllUsersProfile%\Application Data\random6. Delete malicious registry entries related to this virus. Open Registry Editor by pressing Window+R keys together.(another way is clicking on the Start button and choosing Run option, then typing into Regedit and pressing Enter. )
Delete all the vicious registries as below:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\random.exe" HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\random HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Regedit32 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “CertificateRevocation” = 0 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System “DisableTaskMgr” = 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\random
If the manual guide is kinda difficult for you, please feel free to download automatic removal tool SpyHunter to drive the self-invited guest away.
Method two: Automatically remove stats.mydatastatssrv.com with Spyhunter antivirus software:
Step 1: click the icon below to download automatic removal tool SpyHunter
Step 2: follow the instructions to install SpyHunter
Step 3: run SpyHunter to automatically detect and uninstall OffersWizard
Summary: Due to the changeable characters of stats.mydatastatssrv.com, you cannot be too careful to distinguish the harmful files and registries from the system files and registries. If you have spend too much time in manual removing stats.mydatastatssrv.com and still not make any progress, you can download and install Spyhunter antivirus software here to remove stats.mydatastatssrv.com automatically for you.
No comments:
Post a Comment