Special Sponsor

Tuesday, August 14, 2007

Antispystorm = adware?

So are you get into trouble with antispystorm that prompt the users to purchase a registered version of the software so that you can remove the reported threats? I will show you how to remove the antispystorm.

HOW TO REMOVE

  1. Temporary disable system restore for XP and ME
  2. Update your antivirus definition
  3. Reboot and go to SafeMode on your computer
  4. Run full system scan and disinfect/delete infected files
  5. Run registry editor (start-> run-> regedit)


Navigate to and delete the following registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
\"AntispyStorm" = "C:\Program Files\AntispyStorm\AntispyStorm.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\AntispyStorm\"uninstallstring" = ""
C:\Program Files\AntispyStorm\uninstall.exe" -u"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Uninstall\AntispyStorm\"DisplayIcon" = "C:\Program Files\AntispyStorm\uninstall.exe,0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\AntispyStorm\"displayname" = "AntispyStorm 1.01.0027"

HKEY_LOCAL_MACHINE\SOFTWARE\AntispyStorm\
"work directory" = "C:\Program Files\AntispyStorm\"

HKEY_LOCAL_MACHINE\SOFTWARE\AntiSpyware\"InstalledApplication"
= "AntiSpyStorm"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{0723CAE4-C2AB-4995-B749-6BC9BE984564}\
"Default" = ""

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\
{EA201C93-F34A-47A5-B65D-AA7C95068E92}\InprocServer32\
"Default" = "C:\Program Files\AntispyStorm\clsReg.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\
{C8EBBFFA-881D-4F15-9D29-7435462E4294}\3.0\0\win32\
"Default" = "C:\Program Files\AntispyStorm\clsReg.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\
{D8478214-61AD-4C83-9D76-2BE980A51452}\1.0\0\win32\
"Default" = "C:\Program Files\AntispyStorm\as_ie_monitor.dll"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mdReg.clsReg\Clsid
\"Default" = "{EA201C93-F34A-47A5-B65D-AA7C95068E92}"

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\mdReg.clsReg\"Default" = "mdReg.clsReg"

Navigate to and delete the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
CLSID\{0723CAE4-C2AB-4995-B749-6BC9BE984564}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\
{4619EC5B-EF8F-44E9-9A74-6E7B5F1C4188}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\
{EFBD98B0-0C01-4325-85F8-5E791AB33570}

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\
as_ie_monitor.ie_monitor



6. Exit registry editor and restart the computer.


No comments: