Spy Sweeper with AntiVirus

The most award-winning anti-spyware software

Spy Sweeper with Antivirus

Get serious about removing spyware with Spy Sweeper - the award-winning anti-spyware software trusted by millions of home computer users.

Add to Cart Button

$29.95

Spyware & Virus Directory

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 


W32.ASpam.Trojan.B

Risk Level 1: Very Low

Discovered: April 4, 2000
Type: Trojan Horse

SUMMARY


This Trojan is disguised as an antispam tool from Microsoft. Upon executing the Trojan, the user is presented with a dialog box.

Protection

  • Virus Definitions (Intelligent Updater) April 6, 2000

Threat Assessment

Wild

  • Wild Level: Medium
  • Number of Infections: 0 - 49
  • Number of Sites: 3 - 9
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Medium
  • Payload: Compromises security settings: Unauthorized users may have access to files on your computer

Distribution

  • Distribution Level: Low
  • Name of Attachment: ASPAM.EXE
  • Size of Attachment: 173,568 bytes
  • Target of Infection: Windows registry

TECHNICAL DETAILS


This Trojan drops a file named Drvman32.dll in the WindowsSystem folder of the infected machine. It also modifies several registry keys to ensure that the Trojan will be executed at the next restart of Windows.
The Trojan has been distributed in a spoofed email message that appears as though it was sent from microsoft.com. A copy of the message follows:

From: aspam@microsoft.com
To: Microsoft; Users
Sent: Tuesday, March 21, 2000 5:16 PM
Subject: Microsoft Anti-Spam Policy

Microsoft Anti-Spamming Policy
To All Microsoft Users:

Microsoft Corporation does not endorse "spamming"!
We do not want people to receive unsolicited email.  
In the strictest sense of the definition, you can
not contact anyone via email unless that person has
specifically told you that you can contact them or
invited contact (i.e. classified ad).  This applies
to businesses, non-profit organizations, and
individuals.

We do support open communications and we feel that
99.9% percent of the Microsoft Users community
wants to hear about our new products, critical
updates, and be informed about resources that are
available on-line.

The best way to let this many people know about
the important matters, pertinent information, and
resources is via email.  Most people do not
appreciate receiving junk mail (normally without a
valid reply address and a questionable "offer"
of some kind).  However, there are some people
that are offended about receiving legitimate email
telling them about similar interest matters.

Participate in the Microsoft Anti Spam Policy and
remember YOU CAN STOP IT!!!! Here we want to say:
This is not an UCemail, because you are getting
something for free!!!

Now we are proud to announce that our best
developers have a solution to the most troublesome
Internet problem nowadays: SPAM email!!!. Let this
be the last unexpected mail message you receive.
The software included in this mail will navigate
you through the things you need to do in order to
restrain SPAM emails.

To all true Microsoft Users.... Thank you for your
time and understanding.

Sincerely,
    Adam Ross
    Director of Microsoft Anti Spam Campaign
    Microsoft Corporation 2000

Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

REMOVAL


To remove this Trojan, perform the following steps:
  1. Using Windows Explorer delete the file C:WindowsSystemDrvman32.dll
  2. Using regedit delete the following registry keys or values:

    HKEY_LOCAL_MACHINESoftwareClassesCLSID{499DB658-1909-420B-931A-4A8CAEFD232F}
    (delete entire key)

    HKEY_LOCAL_MACHINESoftwareClassesDRVMAN32.IEClass
    (delete entire key)

    HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects {499DB658-1909-420B-931A-4A8CAEFD232F}
    (delete this value only)



Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:

Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.

Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.

Additional Highlights

As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:

Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps

Easy Management: Quickly and simply configure program, sweep and upgrade options

Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper

Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off

Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."



"This program's dominance is apparent as soon as you install it."