Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 17 March 2013

Remove Chitka pop up ads, removal instructions

Posted on 13:11 by Unknown
Chitka pop up ads are truly annoying, lots of people have this issue, but the worse part is that these frequent intrusive pop-ups are caused by malicious software. What is Chitka? Honestly, I'm not quite sure what it is. I mean I couldn't find anything, any clue about it. Google search suggested Chitika which is a perfectly legitimate online advertising network and obviously has nothing do to with this malware. It sounds almost the same, though. Actually, I think that those who run the malware campaign did this on purpose. They probably try to mislead users.

The primary reason behind the creation and use of this malware is that it enables one to generate profit by forcing hits to specific websites and advertisements. At the same time, it might be used as marketing and commercial strategy for publicity purposes. One way or another, infected users who are getting a bunch of Chitka pop ups and redirects are not happy at all. What is more, they can't remove the culprit of this infection. That’s why I wrote a step-by-step guide on how to remove Chitka pop up virus and other pop-ups from your computer. Please follow the removal instructions below.

Many people are clueless on how they become victims of this malware. They just keep getting popups on their web browsers, sometimes bottom right corner but very often both. Here’s a good example:



Chitka pop up ad appears in the lower right corner of the browser window. And at the same time, in the lower left corner there's another fake pop-up claiming that your Flash Player is outdated. It says: Please install Flash Player HD to continue. Obviously, it's a scam. I've said this many times before – download and install Flash layer from the official website only.

Here’s another example of Chitka pop up:



This time only one pop-up but highly targeted one, because the malware gathered enough information about victim's interests and displayed the most relevant advertisement. Sometimes, it takes only a few minutes and keywords to select relevant enough ads and sometimes scammers simply display ads according to your location.

This last one shows the Facebook style pop up. That’s why some users say they got infected with Chitka/Facebook pop up ads.



Furthermore, this malware redirects users to malicious websites or web pages full of ads when they click links on the page they are browsing. Usually, Chitka pop ups cannot be closed. It simply doesn't have the small "X" to close it.

Chitka ads and redirect issue is not necessary the same for all users. From what I've seen, these popups and redirects are caused by malicious browser helper object and modified Windows Hosts file. I got the malware for testing purposes from an adult site. However, I'm pretty sure it's promoted via infected websites and may even come bundled with freeware. The malware installed a web browser extension called Flash Player Update 11.0 and modified Windows Hosts will so that certain websites were redirected through servers controlled by scammers. It is worth mentioning that the malicious web browser extension was locked which makes the removal a little bit challenging, at least for less computer savvy users. Besides, the extension name itself may stop some people from removing it. It looks like a legitimate extension and most users know that web browser use Flash Player plugins to display interactive content and Flash documents.

But I also found another sample of this malware and it actually came packed with ZeroAccess rootkit. So far, I’ve seen to possible culprits of Chitka pop-ups – a rootkit and a malicious web browser extensions + Hosts file modification. Maybe there are even more combinations but I couldn’t find them at the time I was researching this malware.

Last but not least, this malware affects all major web browsers: Google Chrome, Mozilla Firefox and Internet Explorer. I’m not sure if it works on Macs and Safari. Cross platform malware became very popular, so I wouldn’t be very surprised. To get rid of this malware completely you should use the tools recommend below.

Do you have any additional information or questions on the Chitka pop up virus? Post your comment or question below. Good luck and be safe online!


Chitka pop up ads removal instructions:

1. Download recommended anti-malware software (direct download) and run a full system scan to remove this virus from your computer.





2. Reset Windows HOSTS file.

Go to: C:\WINDOWS\system32\drivers\etc.
Double-click "hosts" file to open it. Choose to open with Notepad or any other text editor.



The Windows hosts file should look the same as in the image below (Windows XP). There should be only one line:

127.0.0.1 localhost (Windows XP)

127.0.0.1 localhost ::1 (Windows Vista/7/8).

If there are more lines, then remove them and save changes. Read more about Windows Hosts file here: http://support.microsoft.com/kb/972034



Alternate method: to reset the Hosts file back to the default automatically, download and run Microsoft Fix it tool and follow the steps in the Fix it wizard.

3. Remove malicious extensions from your web browser.

Google Chrome:
1. Click on Chrome menu button. Go to Tools → Extensions.
2. Click on the trashcan icon and remove the extensions that might be causing Chitka pop ups. Basically, remove all extensions that you didn't install. It's perfectly OK to remove all extensions since by default Google Chrome comes without any extensions.

Mozilla Firefox:
1. Go to Tools → Add-ons.
2. Select Extensions. Remove all extensions that you didn't install. Please note, by default Firefox comes without any extensions.

Internet Explorer:
1. Go to Tools → Manage Add-ons. If you have the latest version, simply click on the Settings button.
2. Select Toolbars and Extensions. Remove all add-ons that you didn't install or you believe may cause those annoying pop-ups to show up.

4. Download CCleaner and tidy up your computer, remove temp files, etc.

5. If the problem persists, please read this web document and follow the steps carefully: http://deletemalware.blogspot.com/2010/02/remove-google-redirect-virus.html

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Adware | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • How to remove 'TidyNetwork' adware virus from your computer
    As internet users most of us have seen those irritating little pop-up windows that are advertising something that we normally have little or...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ▼  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ▼  March (17)
      • False Positive: Ikarus and Comodo detecting TDSSKi...
      • Remove Price Peep (Uninstall Guide)
      • Remove Solid Savings (Uninstall Guide)
      • Identity Theft Protection – How to Stop Your Life ...
      • Remove PC Fix Speed and 24x7 Help (Uninstall Guide)
      • This website has been blocked for you! removal ins...
      • Remove Why do I see this page? virus - Attention R...
      • AVASoft Professional Antivirus Firewall Alert remo...
      • Remove Ukash virus
      • Remove Department of Justice virus
      • How to Remove AVASoft Professional Antivirus – AV...
      • Remove System message - Error Seek popup and relat...
      • Remove Chitka pop up ads, removal instructions
      • Remove Win 7 Security Cleaner Pro, removal instruc...
      • How to Remove 22find
      • How to Remove Disk Antivirus Professional (Uninsta...
      • Know the Enemy – Identifying & Removing the FBI Virus
    • ►  February (7)
    • ►  January (7)
  • ►  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ►  July (11)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile