Description of Win32/FakeSpypro consequences of its residing on your PC

Rogue antispyware is known to be mainly released in groups of programs constituting families of clones. The clones in such groups may represent a variation of one and same rogue. A striking example of such case is Win32/FakeSpypro.
The trojan in its different modifications represents the following rogue antispyware: Antivirus Soft,   Antivirus Live, Antivirus Suite, AV Security Suite, Antivir Solution Pro, Security Suite and others.
TDSS rootkit often comes along with Win32/FakeSpypro, but its presence is case specific and mainly subject to particular rogue antispyware represented by the trojan.
The trojan is distributed from websites of the above fake security suites and from other websites disguised as a content frequently requested by users. It also connects itself to websites providing extra components for the adware promoted in specific case.  Win32/FakeSpypro does not let using major Internet search engines correctly posing misleading websites as true search results.

Win32/FakeSpypro Technical Details

  • Full name: Win32/FakeSpypro, Win32/FakeSpypro.A, Win32/FakeSpypro.B
  • Version: 2010
  • Type: Trojan horse
  • Origin: Russian federation

Signs of being infected with Win32/FakeSpypro:

Experts detect the trojan by relevant entries created in the Windows directory and the registry.  Win32/FakeSpypro generates plenty of alerts and dialog boxes and scan window named after particular rogue antispyware it promotes. That makes it easy detectable for users. If you have seen any suspicious alerts and nag screens of programs mentioned in the Technical Details above, the trojan is likely present.

Automatic Removal of Win32/FakeSpypro from your PC:

Besides the trojan and above rootkit other infections could have made their intervention into your computer thanks to vulnerabilities caused by the trojan. In order to cover any infection, remove Win32/FakeSpypro by the complex security suite available below.

Win32/FakeSpypro Removal Tool

Manual Removal of Win32/FakeSpypro:

In order to ensure safety of your PC during Win32/FakeSpypro removal, please start Windows in Safe Mode with Networking where your ultimate decision is   to remove Win32/FakeSpypro manually. Web-browsers and any programs are not recommended to run until completing the manual deletion of relevant entries.

Remove Win32/FakeSpypro files and dll’s:

%UserProfile%\Local Settings\Application Data\<random>\
%UserProfile%\Local Settings\Application Data\<random>\<random>.exe

Unregister Win32/FakeSpypro registry values:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyOverride” = “<local>”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyServer” = “http=″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run “<random>”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run “<random>”

