Adrozek virus is not a new player in the malware arena. It appeared several years ago, and remembered as a trojan, that was used to distribute adware and browser hijackers. After the significant decrease in activity at the beginning of 2020, it came back at the edge of 2021, spreading the annoying malware. In this article, you will see the guide for Adrozek removal, ways of its injection, and possible danger that can be carried by this unwanted program.
What is Adrozek?
| Name | Adrozek trojan |
| Detection names | Win32:Adware(AdwareX-gen [Adw], Trojan.GenericKDZ.70522, Variant of Win32/Kryptik.HAYM, Trojan.PWS.Stealer.29366, Trojan:Win32/Adrozek!BV, Adware.DownloadAssistant, HEUR:Trojan-Downloader.Win32.Razy.gen, ML.Attribute.HighConfidence1 |
| Effect | Misleading search query results, browser performance declining, dubious pop-up ads appearance |
| Variations | Adrozek!BV, Adrozek.I, Adrozek.A |
Adrozek is a trojan virus with unusual specialization. While the majority of other trojans are used to inject spyware, keyloggers, stealers, worms2 or even ransomware, this one acts as the adware or browser hijacker3. Such a feature has quite a logical explanation: adware and hijackers became much harder to inject because of increased levels of cyber hygiene knowledge among the users, along with the omnipresent anti-malware software.
For different reasons, trojan is much easier to hide and/or correct to avoid the antivirus software detection. Of course, the security tools will get the definition database updates, that will allow them to detect Adrozek. But while it functions without the antivirus reaction, its developers are earning the money and can create another version, that will be unseen by anti-malware programs, again.
Adrozek attack scheme
Such a cycle will repeat until the users will not stop using the main sources of the lion’s share of malware – cracked programs and dubious utilities. Cracks are created by hackers, who set the program code to skip the license checking procedure. They want to be paid for their work, but their illegal actions force them to earn money in the same illegal way. Crack makers can add the unwanted apps or even viruses to earn money. And according to the statistics4, Adrozek distribution through this scheme became enormously active.
Statistics of Adrozek distribution
Is Adrozek dangerous?
As it was mentioned, trojan virus penetrates your computer together with the installation of the cracked program or untrustworthy apps. Hence, your PC is in danger at least because such applications can harm your system as the result of low quality. Adrozek harm has other nature – it changes the settings in your browsers (Chrome, Mozilla, Edge and Yandex browser are under attack), then makes significant changes in your PC registry. Finally, this malware changes the browser search results – they become full of advertising pages with dubious content, so you are not able to search the things you really need.
In contrast to “classic” search/browser hijackers, Adrozek does not add any separated program, like the rest of such viruses do. It adds a single extension, that differs depending on the browser it hits. Besides adding the extension, it also changes several settings in DLLs that are responsible for the security and showing the list of installed plugins.
Browser Extension paths examples :
| Browser name | Extension pathway |
| Microsoft Edge | %localappdata%\Microsoft\Edge\User Data\Default\Extensions\fcppdfelojakeahklfgkjegnpbgndoch |
| Google Chrome | %localappdata%\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm (might vary) |
| Mozilla Firefox | %appdata%\Roaming\Mozilla\Firefox\Profiles\ |
| Yandex Browser | %localappdata%\Yandex\YandexBrowser\User Data\Default\Extensions\fcppdfelojakeahklfgkjegnpbgndoch |
In addition to all changes in browser settings it disables the browser automatically updates, that can easily wipe out the changes implemented by Adrozek: all damaged DLLs5 will be restored to originals, as well as other settings.
The registry changes that were mentioned above are the last step before taking the control on your search query results. In the HKLM/Software/Wow6432Node/
Registry changes implemented by Adrozek
Being fully activated, Adrozek masks under the name of AudioLava.exe, QuickAudio.exe, or converter.exe processes. One of these processes can easily be spotted in the Task Manager, however, suspending them will not stop the malware: it will launch its process back.
As you can see, Adrozek affects a large amount of different settings not only in your browser files, but also in the registry. Such alterations can create a significant influence on the PC performance – the excessive registry keys may slow down your system performance, because Windows checks all of them after every launch.