Full
Name: |
SpywareNo! |
Type: |
Miscellaneous Security |
Also Known As: |
Spyware No!
|
Created By: |
SS Development |
Danger Level: |
5 |
Category Description: |
These are usually anti-spyware or security software applications that use various forms of deception and/or unethical means or show a history of negligent false positives to goad the end user to make a purchase.
In some cases these applications maybe downloaded with some form of unwanted software at which point the rogue application is offered to the customer as a way to remove the unwanted software. |
Official Description: |
Rogue Anti-adware application
Changes windows policy settings.
Displays a warning from the system tray that your computer is infected with spyware. Will not let you remove the spyware unless you buy the full version.
Changes the desktop wallpaper with a warning message."Your System Is Infected"
|
Comment: |
Found bundled with 7 other adware products including a dialer from another website. The infection comes in the guise of winlogin.exe from this site: vxiframe.biz/adverts/progs/winlogon.exe. If you Google the file name it will yield a perfectly legitimate file from Windows. However, the contents of the file refer to this location C:\Program Files\SpywareNo\SpywareNo.exe. |
|
|
Information URL: |
http://www.spywareno.com |
Manual Removal: |
After removing with X-cleaner or Regblock, you will have to edit some registry settings.
1.Click on the start button
2.Click on run
3.Type in regedit and click ok
4.When regedit opens, browse to each one of the following keys and in the right pane change the data to 0.Right click on the "Name" choose "modify" and change the Value Data to 0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoAddingComponents"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallpaper"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoComponents"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoDeletingComponents"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoEditingComponents"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoHTMLWallPaper"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "ClassicShell"
5.After changing the policy settings, browse to the Windows directory and delete the file "desktop.html"
6. Rebott computer |