SpywareGuide powered by Actiance Security Labs
Search SpywareGuide Database & Site
Home Access the Guide
List of Products List of Companies List of Categories
Tools
X-RayPC
Terms and Definitions
 
Full Name:
FraudTool-AntiSpySpider Websearch   Read More
Type: Trojan
SG Index: 4 [Explain]
Removal tools: List of products that detect/remove/protect against FraudTool-AntiSpySpider:
  • IM, P2P control, malware prevention and web filtering in single appliance: Unified Security Gateway
  • Category Description: Trojans are malicious applications that pose themselves as legitimate software in order to trick users to install them. Once on the victim's machine, it may run any number of malicious process to steal vital information or inflict damage to other software.
    Comment: FraudTool-AntiSpySpider is used to disable the Windows Task Manager and Registry editor. Can display an infection message in the system tray. This tool is used with AntiSpySpider to trick the user into purchasing the application. Downloads and displays advertisements.
    Screenshots:
    FraudTool-AntiSpySpider Fake malware warning.
    FraudTool-AntiSpySpider Fake spyware warning message.
       
    Manual removal:
    Disable System Restore.
    Clean with X-Cleaner.
    Do not restart the computer when X-Cleaner prompts.

    Steps to re-enable the Task Manager and registry editor:

    Go to Start->Run-> type mmc and hit enter.
    The Console window will open.

    Click on File and choose ->Add/Remove snap-in-
    Then click on Add and you get a list of snap-in.
    Select "Group Policy Object Editor" and click Add then click finish, close and last click OK

    Under Console Root, expand the Local Computer Policy
    Then expand the User Configuration container.
    Click on Administrative Templates then click on System.
    In the right pane find "Prevent access to registry editing tools" double click on it and dot Disabled. Click OK

    Locate the Ctrl+Alt+Del Options folder. Click on it.
    In the right pane, find "Remove Task Manager" double click on it and DOT disabled. Click OK

    Close the Console window and reboot.

    After reboot, remove the following files:
    c:\WINDOWS\homepage.html
    c:\WINDOWS\index.html
    c:\WINDOWS\promo1.html
    c:\WINDOWS\promo2.html
    c:\WINDOWS\promo3.html
    c:\WINDOWS\promo4.html
    c:\WINDOWS\promo5.html
    c:\WINDOWS\promo6.html
    c:\WINDOWS\promogif1.gif
    c:\WINDOWS\promogif2.gif
    c:\WINDOWS\promogif3.gif
    c:\WINDOWS\system32\adult.txt
    c:\WINDOWS\system32\finance.txt
    c:\WINDOWS\system32\lt.res
    c:\WINDOWS\system32\other.txt
    c:\WINDOWS\system32\pharma.txt
    c:\WINDOWS\system32\sft.res
    c:\WINDOWS\system32\sn.txt
    Properties:
  •  Alters Key Windows Components
  •  Autostarts/Stays Resident
  •  Connects to the internet
  •  Fake You are infected alerts
  •  Shows Advertisements
  • Related Products
    Product Category Comment
  •  AntiSpySpider
  • Miscellaneous Security

    Click here to leave feedback for this product

    Recent Modifications
    2012-1-30  HostSeeker Toolbar
    2012-1-13  2000Cracks
    2012-1-13  7AdPower Dialer
    2012-1-13  Absolu-trans
    2012-1-13  AccessPlugin
    2012-1-13  AcidBattery
    2012-1-13  Acidoor
    2012-1-13  Active-X Dialer
    2012-1-13  Adcheat
    2012-1-13  Adh1_sexarea
     
    Company  | Site and Spyware FAQ
    © Copyright 2003-2011, Actiance, Inc. All rights reserved.   Privacy Policy