Home Malware Programs Trojans 2Antispyware

2Antispyware

Posted: January 9, 2007

2Antispyware or 2-Antispyware is a fake anti-spyware program that is often downloaded and installed without user knowledge or consent by a Trojan or through browser security holes. 2Antispyware launches on Windows startup and may generate large numbers of popup adverts. Antispyware will also display notifications of imaginary security risks in its attempts to get the user to purchase the full version. 2Antispyware program can be extremely difficult to remove manually, and will continue to try to recreate itself. 2Antispyware parasite is affiliated with the website 2-antispyware.com.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 2-AntiSpyware.lnk
    2 2-AntiSpywareInstaller[1].exe
    3 AntiSpyware.exe
    4 AntiSpyware.lnk
    5 ExplorerMenu.dll
    6 ExplorerMenu202.dll
    7 IEPlugin.dll
    8 IEPlugin153.dll

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}2-AntispywareFolder\shellex\ContextMenuHandlers\Scanwith 2-AntiSpywareMicrosoft\InternetExplorer\Extensions\47E775F6-22CC-48a1-8746-E1A22CDDA7B5SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\575C5E89-0591-49FE-BCF2-5559182CB6B5
  • The following CLSID's were detected:
    HKEY..\..\{CLSID Path}575C5E89-0591-49FE-BCF2-5559182CB6B52F3D01F3-2A8E-4814-AA0F-8315172D22BF

One Comment

  • Polzsaii says:

    Me too, I'm lucky I got my computer fixed by soomnee in my family that managed to remove this thing. I don't have the money for a new computer and I'm lucky I backed up data too. And small? I bet everyone who makes these are over weight and live in a basement.

Loading...