Remove AdSentinel and RealTimeLeads (Removal Guide)

Click here to visit Original posting

Remove AdSentinel and RealTimeLeads (Removal Guide)

  • Wed, 15 Feb 2017 17:42:05 EST
  • Read 0 times

AdSentinel or RealTimeLeads is an adware program that injects advertisements into web sites that you are visiting. This adware is able to inject these advertisements by configuring your computer to send all web traffic through a bundled Privoxy proxy server that has a filename of AdSentinel.exe.

While running, AdSentinel will use a renamed Privoxy proxy server to inject javascript into the header and footer of web sites that you are viewing. That injections that occur will be determined by the default.action and default.filter configuration files that are bundled with AdSentinel. This allows it to inject scripts that can display advertisements, gather statistical information, change the layout of a page, and perform redirects depending on what javascript is injected. This is a major cause of concern as people who have this program installed may not even know that this is occurring.

When display advertisements, the ads may be labeled RealTimeleads, but could also be labeled with other names depending on the script injected.

How was AdSentinel installed on my Computer?

It is important to note that the AdSentinel is bundled with and installed by free programs that did not adequately disclose that other software would be installed along with it. Therefore, it is important that you pay close attention to license agreements and installation screens when installing anything off of the Internet. If an installation screen offers you Custom or Advanced installation options, it is a good idea to select these as they will typically disclose what other 3rd party software will also be installed. Furthermore, If the license agreement or installation screens state that they are going to install a toolbar or other unwanted adware, it is advised that you immediately cancel the install and not use the free software.

In my opinion, the AdSentinel adware program is a large privacy risk due to the fact that it can inject any javascript script into web sites that you are visiting. This provides a great deal of control to not only your browsing experience, but also to your privacy. Therefore, I feel if you have AdSentinel installed you should remove it using the following guide for free.

Array
View Associated AdSentinel Files

C:\Program Files\U_[random_word]\ C:\Program Files\U_[random_word]\delayLaunch.exe C:\Program Files\U_[random_word]\enter.txt C:\Program Files\U_[random_word]\funinstall.bat C:\Program Files\U_[random_word]\getsystemid.bat C:\Program Files\U_[random_word]\HiddenLaunchSync.exe C:\Program Files\U_[random_word]\hwids.txt C:\Program Files\U_[random_word]\ifslsp.dll C:\Program Files\U_[random_word]\install-lsp.bat C:\Program Files\U_[random_word]\install-service-64.bat C:\Program Files\U_[random_word]\install-service.bat C:\Program Files\U_[random_word]\instlsp.exe C:\Program Files\U_[random_word]\killrem.bat C:\Program Files\U_[random_word]\killservice.bat C:\Program Files\U_[random_word]\otp.exe C:\Program Files\U_[random_word]\regname.txt C:\Program Files\U_[random_word]\restart-proxy.bat C:\Program Files\U_[random_word]\software_version.txt C:\Program Files\U_[random_word]\start.exe C:\Program Files\U_[random_word]\uninstall-lsp.bat C:\Program Files\U_[random_word]\uninstall-service-64.bat C:\Program Files\U_[random_word]\uninstall-service.bat C:\Program Files\U_[random_word]\U_[random_word].exe C:\Program Files\[random_word]\ C:\Program Files\[random_word]\HiddenLaunchAsync.exe C:\Program Files\[random_word]\HiddenLaunchSync.exe C:\Program Files\[random_word]\LSP\ C:\Program Files\[random_word]\LSP\Vista\ C:\Program Files\[random_word]\LSP\Vista\enter.txt C:\Program Files\[random_word]\LSP\Vista\ifslsp.dll C:\Program Files\[random_word]\LSP\Vista\install-lsp-64.bat C:\Program Files\[random_word]\LSP\Vista\install-lsp.bat C:\Program Files\[random_word]\LSP\Vista\instlsp.exe C:\Program Files\[random_word]\LSP\Vista\uninstall-lsp-64.bat C:\Program Files\[random_word]\LSP\Vista\uninstall-lsp.bat C:\Program Files\[random_word]\LSP\Win7\ C:\Program Files\[random_word]\LSP\Win7\enter.txt C:\Program Files\[random_word]\LSP\Win7\ifslsp.dll C:\Program Files\[random_word]\LSP\Win7\install-lsp-64.bat C:\Program Files\[random_word]\LSP\Win7\install-lsp.bat C:\Program Files\[random_word]\LSP\Win7\instlsp.exe C:\Program Files\[random_word]\LSP\Win7\uninstall-lsp-64.bat C:\Program Files\[random_word]\LSP\Win7\uninstall-lsp.bat C:\Program Files\[random_word]\LSP\Win8\ C:\Program Files\[random_word]\LSP\Win8\enter.txt C:\Program Files\[random_word]\LSP\Win8\ifslsp.dll C:\Program Files\[random_word]\LSP\Win8\install-lsp-64.bat C:\Program Files\[random_word]\LSP\Win8\install-lsp.bat C:\Program Files\[random_word]\LSP\Win8\instlsp.exe C:\Program Files\[random_word]\LSP\Win8\uninstall-lsp-64.bat C:\Program Files\[random_word]\LSP\Win8\uninstall-lsp.bat C:\Program Files\[random_word]\LSP\WinXP\ C:\Program Files\[random_word]\LSP\WinXP\enter.txt C:\Program Files\[random_word]\LSP\WinXP\ifslsp.dll C:\Program Files\[random_word]\LSP\WinXP\install-lsp-64.bat C:\Program Files\[random_word]\LSP\WinXP\install-lsp.bat C:\Program Files\[random_word]\LSP\WinXP\instlsp.exe C:\Program Files\[random_word]\LSP\WinXP\uninstall-lsp-64.bat C:\Program Files\[random_word]\LSP\WinXP\uninstall-lsp.bat C:\Program Files\[random_word]\PROXY\ C:\Program Files\[random_word]\PROXY\adsentinel.exe C:\Program Files\[random_word]\PROXY\adsentinel.log C:\Program Files\[random_word]\PROXY\boot.js C:\Program Files\[random_word]\PROXY\config.txt C:\Program Files\[random_word]\PROXY\cyggcc_s-1.dll C:\Program Files\[random_word]\PROXY\cygwin1.dll C:\Program Files\[random_word]\PROXY\cygz.dll C:\Program Files\[random_word]\PROXY\default.action C:\Program Files\[random_word]\PROXY\default.filter C:\Program Files\[random_word]\PROXY\install-proxy-64.bat C:\Program Files\[random_word]\PROXY\install-proxy.bat C:\Program Files\[random_word]\PROXY\license.txt C:\Program Files\[random_word]\PROXY\match-all.action C:\Program Files\[random_word]\PROXY\mgwz.dll C:\Program Files\[random_word]\PROXY\restart.bat C:\Program Files\[random_word]\PROXY\rules.txt C:\Program Files\[random_word]\PROXY\script_version.txt C:\Program Files\[random_word]\PROXY\templates\ C:\Program Files\[random_word]\PROXY\templates\blocked C:\Program Files\[random_word]\PROXY\templates\cgi-style.css C:\Program Files\[random_word]\PROXY\templates\connect-failed C:\Program Files\[random_word]\PROXY\templates\connection-timeout C:\Program Files\[random_word]\PROXY\templates\default C:\Program Files\[random_word]\PROXY\templates\forwarding-failed C:\Program Files\[random_word]\PROXY\templates\no-server-data C:\Program Files\[random_word]\PROXY\templates\no-such-domain C:\Program Files\[random_word]\PROXY\templates\show-request C:\Program Files\[random_word]\PROXY\TopScript1.js C:\Program Files\[random_word]\PROXY\trust.txt C:\Program Files\[random_word]\PROXY\uninstall-proxy-64.bat C:\Program Files\[random_word]\PROXY\uninstall-proxy.bat C:\Program Files\[random_word]\PROXY\user.action C:\Program Files\[random_word]\PROXY\user.filter C:\Program Files\[random_word]\SERVICE\ C:\Program Files\[random_word]\SERVICE\getsystemid.bat C:\Program Files\[random_word]\SERVICE\hwids.txt C:\Program Files\[random_word]\SERVICE\install-service-64.bat C:\Program Files\[random_word]\SERVICE\install-service.bat C:\Program Files\[random_word]\SERVICE\ProxySetter.exe C:\Program Files\[random_word]\SERVICE\regname.txt C:\Program Files\[random_word]\SERVICE\release.txt C:\Program Files\[random_word]\SERVICE\restart.bat C:\Program Files\[random_word]\SERVICE\restart_has_run.txt C:\Program Files\[random_word]\SERVICE\setProxyTask.bat C:\Program Files\[random_word]\SERVICE\S[random_word].exe C:\Program Files\[random_word]\SERVICE\uninstall-service-64.bat C:\Program Files\[random_word]\SERVICE\uninstall-service.bat C:\Program Files\[random_word]\SERVICE\unsetProxyTask.bat C:\Program Files\[random_word]\SERVICE\version.txt C:\Program Files\[random_word]\Uninstall.exe C:\ProgramData\1111_ver.txt C:\ProgramData\GYL.txt C:\ProgramData\OTP C:\ProgramData\OTP\restart.bat C:\ProgramData\burl.txt C:\ProgramData\proxySuccess.txt C:\ProgramData\proxy_impersonations.txt C:\ProgramData\proxy_run.txt C:\ProgramData\proxy_sessions.txt C:\ProgramData\proxy_sessions_processed.txt C:\ProgramData\proxy_user_name.txt C:\ProgramData\regname_b.txt C:\ProxySetter.txt C:\compare1.txt C:\compare2.txt C:\compare3.txt C:\fjson.txt C:\flver3.txt C:\otpu.txt C:\otpu2.txt C:\pjson.txt C:\version.txt

View Associated AdSentinel Registry Information

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer 127.0.0.1:8118 HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\[random_word] HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies\ 1127.0.0.1:8118 HKLM\SYSTEM\CurrentControlSet\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000021\ProtocolName adsentinel HKLM\SYSTEM\CurrentControlSet\services\[random_word] HKLM\SYSTEM\CurrentControlSet\services\U_[random_word]