Tuesday, April 7, 2009

How to remove Antispylist.com hijacker


Malware Description:

Antispylist.com is home to the notorious fake spyware remover called MS Antispyware 2009 which seems to be getting pretty active these days. Just like most hijackers, Antispylist.com is mostly redirected to. This malicious activity may be caused by Trojan infection which results in altering the browser settings and thus redirecting the victims’ web-surfing to Antispylist.com. You may also find yourself on Antispylist.com site as a result of pushing a link on some strange warning that appears out of nowhere and states you have security problems. Regardless of the way you hit Antispylist.com domain, you will feel brainwashed after visiting it. It’s because Antispylist.com tries to sell the commercial version of its sponsoring malware MS Antispyware 2009 which is pathetic imitation of an anti-spyware program. The adware components presented on Antispylist.com are aiming to persuade you into installing MS Antispyware 2009 (freeware first). After installing this malicious trialware, MS Antispyware 2009 will flood your system with its fake pop-ups and misleading scanners that claim your PC if full of infections that need to be urgently removed. It’s important to realize that everything you see on Antispylist.com is misleading and tries to spoof you into buying a rogue anti-spyware. Since Antispylist.com website is rated malicious and potentially contagious, remove Antispylist.com hijacker ASAP to prevent the unwanted redirections to this fraudulent domain pushing MS Antispyware 2009 rogue.


Malware Type: Browser Hijackers

Malware Author: CrucialSoft Ltd

Threat Level: Critical

Advice: Immediately remove and scan for additional malware

How to remove Antispylist.com hijacker manually:

Manual removal of Antispylist.com hijacker and attendant malware is feasible if you have sufficient expertise in dealing with program files, system processes, .dll files and registry entries.

The associated files to be deleted are listed below:

%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\BASE
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\DELETED
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20081214155256795.log
%Documents and Settings%\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\SAVED
%UserProfile%\Start Menu\Programs\MS AntiSpyware 2009
%UserProfile%\Start Menu\Programs\MS AntiSpyware 2009\MS AntiSpyware 2009.lnk

The related registry entries to be removed are as follows:

HKEY_CURRENT_USER\Software\CrucialSoft Ltd
HKEY_CURRENT_USER\Software\CrucialSoft Ltd\MS AntiSpyware 2009
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\uninstall\MS AntiSpyware 2009 5.7
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “MS AntiSpyware 2009″

No comments:

Post a Comment