Antispy Spider removal

Felecha

Golden Member
Sep 24, 2000
1,434
0
0
Anyone seen anything about Antispy Spider? My neighbor calls me for tech support. She opened an email that she shouldna, and it loaded in this monstrous thing that keeps popping up ads and giving her dire warnings, the usual malware stuff. But it also disabled Task Manager and Regedit. Pretty nifty tricks.

I've seen a few sites but I dont know whether to trust THEM in all cases.

I see there is a reg hack I could do that would set
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System - DisableRegedit=0
which looks like it would re-enable regedit.

I know enough to follow instructions, I am comfortable in the Registry, I just dont have a lot of seat of the pants experience, so a reliable steer would really help
 

Felecha

Golden Member
Sep 24, 2000
1,434
0
0
so it looks like this HJT thingie will point to the bad files and registry issues, and I hope that would jive with what I have found on websites about AntispySpider as to files and reg. I can then go to safe mode and clean up.

That sounds like a safe approach, and I know how to do it all, just never had any virus or malware on my own systems which i keep fairly well protected.

Thanks

F
 

Felecha

Golden Member
Sep 24, 2000
1,434
0
0
I read something else on another topic that made me wonder - what about a System Restore? She has XP. I have never done a System Restore, never needed to. It seems that if we go back to before she opened the email, if that really does turn back the dial in time, then hey, it's fixed. Is System Restore easy and reliable? I'm sure there's nothing since the attack that she would mind losing

 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: Felecha
I read something else on another topic that made me wonder - what about a System Restore? She has XP. I have never done a System Restore, never needed to. It seems that if we go back to before she opened the email, if that really does turn back the dial in time, then hey, it's fixed. Is System Restore easy and reliable? I'm sure there's nothing since the attack that she would mind losing

You could give it a try. It won't take super-long, but it also may not solve the problem either.

Personally, I'd just back up her stuff, verify that I've got everything necessary to reinstall Windows from scratch, then nuke the Windows installation to smithereens with DBAN, reinstall Windows and secure it properly this time, which would also involve showing the owner how to use her Admin account when she needs to, and her non-Admin account when she doesn't.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
It's a rogue program, and it does affect the Task Manager and regedit.

PM me her HJT log and I'll be happy to take you through the steps. I'm surprised that she hasn't experienced one of the symptoms which is that her IE will randomly open pages to Russian sites.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |