Adware.LinkSwift

Adware.LinkSwift Description

Adware.LinkSwift is an adware application that is known for displaying several coupon and online shopping deals. The Adware.LinkSwift ads will display at random sometimes offering outrageous deals. When clicked on, many of the Adware.LinkSwift ads will redirect users to unwanted sites or ones attempting to make other offers on shopping sites. Some of the Adware.LinkSwift ad links are viewed as being sponsored by other well-known sites like Google, Facebook and amazon. Removal of Adware.LinkSwift is an essential step to putting a stop to annoying ads and popups that may be displayed on a system infected with adware.

Infected with Adware.LinkSwift? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect Adware.LinkSwift

Security Doesn't Let You Download SpyHunter or Access the Internet?


Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics


Our MalwareTracker shows malware activity across the world. Explore real-time data of Adware.LinkSwift outbreaks and other threats from global to local level.

File System Details

Adware.LinkSwift creates the following file(s):
# File Name Size MD5 Detection Count
1 system32\drivers\{25d71abf-7776-46f5-a269-9951331f9030}w64.sys 61,112 d7bf1deb9a8f9d07a5bdbf36dbb1ed86 879
2 system32\drivers\{25d71abf-7776-46f5-a269-9951331f9030}Gw64.sys 61,112 2bb86a0ab448fb8baa4986bd5d03bbc4 203
3 %PROGRAMFILES(x86)%\LinkSwift\updater.exe 50,464 0b9c8589c0bcdd8ac33e177ef4f44a96 122
4 http_static.linkswift.co_0.localstorage-journal 80
5 %LocalAppData%\Google\Chrome\User Data\Default\Local Extension Settings\odpccdgkmiicgocepijnaeihjnjnomca 76
6 %PROGRAMFILES(x86)%\LinkSwift 74
7 %PROGRAMFILES%\LinkSwift 73
8 %LOCALAPPDATA%\Google\Chrome\User Data\Default\odpccdgkmiicgocepijnaeihjnjnomca 72
9 %UserProfile%\Local Settings\Application Data\Google\Chrome\User Data\Default\odpccdgkmiicgocepijnaeihjnjnomca 71
10 %WINDIR%\System32\drivers\{25d71abf-7776-46f5-a269-9951331f9030}t.sys 55,224 a8e2fe9a28a55db99f21a7fbe6a072a0 64
11 %PROGRAMFILES%\LinkSwift\bin\utilLinkSwift.exe 65,312 10df38f1a1fe6b0865d2885ac09024fe 4,157
12 %WINDIR%\System32\drivers\{25d71abf-7776-46f5-a269-9951331f9030}Gw.sys 52,920 96100423c810c537ff3658ec42420999 32
13 %PROGRAMFILES%\LinkSwift\LinkSwift.Common.dll 14,112 2fe4fff249d0bb8b53c93c5025fdbe86 22
14 chrome-extension_odpccdgkmiicgocepijnaeihjnjnomca_0.localstorage 7
15 %PROGRAMFILES%\LinkSwift\updateLinkSwift.exe 206,624 dc4d31a8bab280a535376b7c44c81cd0 2,404

Registry Details

Adware.LinkSwift creates the following registry entry or registry entries:
HKEY..\..\..\..{RegistryKeys}
Software\LinkSwift
SOFTWARE\Wow6432Node\Google\Chrome\Extensions\odpccdgkmiicgocepijnaeihjnjnomca
SYSTEM\ControlSet001\services\eventlog\Application\Update LinkSwift
SYSTEM\ControlSet001\services\Update LinkSwift
SYSTEM\CurrentControlSet\services\Update LinkSwift
SYSTEM\CurrentControlSet\services\eventlog\Application\Update LinkSwift
SOFTWARE\Microsoft\Tracing\updateLinkSwift_RASAPI32
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateLinkSwift_RASAPI32
SOFTWARE\Microsoft\Tracing\updateLinkSwift_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Tracing\updateLinkSwift_RASMANCS
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\LinkSwift
SOFTWARE\Wow6432Node\LinkSwift
Software\Microsoft\Internet Explorer\Approved Extensions, value: {323420B6-65E5-4657-8106-A27392D4D4AA}
Software\Microsoft\Internet Explorer\DOMStorage\linkswift.co
SYSTEM\ControlSet001\services\eventlog\Application\Util LinkSwift
SYSTEM\ControlSet001\services\Util LinkSwift
SYSTEM\ControlSet002\services\eventlog\Application\Util LinkSwift
SYSTEM\ControlSet002\services\Util LinkSwift
SYSTEM\CurrentControlSet\services\Util LinkSwift
SYSTEM\CurrentControlSet\services\eventlog\Application\Util LinkSwift
HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}
LinkSwift
The following CLSID's were found:
HKEY..\..\{CLSID Path}
{323420b6-65e5-4657-8106-a27392d4d4aa}
{339CA35C-F74A-44C3-BD78-9CE3E8C9C560}
{49FB101A-0A00-4E85-A807-8785C2D32604}
{62E29692-5062-40FE-9989-1A9E9B8F76A5}
{D638CED8-793B-4629-A3FB-C0FB0C2B0EE8}

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 14 + 9 ?