Note that many websites have their own advertising, unrelated to adware.
This adware is primarily installed in the system32 folder of the infected machine. The most prominent sign of this infection is the creation of the file nssys32.exe, which uses the autostarter value "nsdriver". Other files related to this programs infection are randomly generated files placed in the system32 folder. These files also are linked to autostarts that are randomly generated from nssys32.exe.