Dec 30

SpyEraser Adware Removal Instructions

The Emsi Software malware research team has discoverd a new outbreak of the SpyEraser adware. a-squared Anti-Malware detects this malware as Adware.Win32.SpyEraser.

SpyEraser is a rogue scanner program. This fake scanner application tries to trick you by displaying false positive/misleading scan results report, which says that your computer is infected with viruses or trojan, but you will not be able to delete them before you buy this fraud application.

SpyEraser sites:

  • hxxp://www. spyeraser-security.com
  • hxxp://www. spyeraser-trial.com

Create new files and directories:

  • %ProgramFiles%\SpyEraser\data.dll
  • %ProgramFiles%\SpyEraser\SpyEraser.exe
  • %ProgramFiles%\SpyEraser\Uninstall.exe
  • %AllUsersProfile%\Desktop\SpyEraser.lnk
  • %AllUsersProfile%\Start Menu\Programs\SpyEraser\SpyEraser\Launch SpyEraser.exe.lnk
  • %AllUsersProfile%\Start Menu\Programs\SpyEraser\SpyEraser\SpyEraser Uninstall.exe.lnk
  • %UserProfile%\Local Settings\Application Data\Downloaded Installations\{E5FF35CB-AAE1-4CD6-BFDE-D0BCE9CCBA4C}\SpyEraser.msi
  • %SystemRoot%\Installer\{6A2724E2-5E36-4F2E-9B3D-4A716774B3F9}\SpyEraser.exe1_5D3FA81F1A6D4924AD5250A57005F147.exe

Create new registry entries:

  • HKEY_LOCAL_MACHINE\software\Classes\Installer\Features\2E4272A663E5E2F4B9D3A41776473B9F
  • HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F
  • HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F\SourceList
  • HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F\SourceList\Media
  • HKEY_LOCAL_MACHINE\software\Classes\Installer\Products\2E4272A663E5E2F4B9D3A41776473B9F\SourceList\Net
  • HKEY_LOCAL_MACHINE\software\Classes\Installer\UpgradeCodes\21B289D0EDBF1BD48A4C39C60AF74DE9
  • HKEY_LOCAL_MACHINE\software\microsoft\SpyEraser
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\21B289D0EDBF1BD48A4C39C60AF74DE9
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA061871792C67E4997020ED0AF0253E
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBAB827A17F9D9B40B5A18854589281C
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\Features
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\InstallProperties
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\Patches
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2E4272A663E5E2F4B9D3A41776473B9F\Usage
  • HKEY_LOCAL_MACHINE\software\microsoft\Windows\CurrentVersion\Uninstall\{6A2724E2-5E36-4F2E-9B3D-4A716774B3F9}

Screenshots:

How to remove the infection of SpyEraser (Adware.Win32.SpyEraser)?

To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.

Tags: ,

One Response to “SpyEraser Adware Removal Instructions”

  1. HENRY Says:


    CheapTabletsOnline.com. Canadian Health&Care.Best quality drugs.No prescription online pharmacy.Special Internet Prices. High quality drugs. Buy pills online

    Buy:Viagra Super Force.Cialis Super Active+.Cialis Professional.Cialis Soft Tabs.Tramadol.Cialis.Soma.Viagra Super Active+.Super Active ED Pack.Levitra.VPXL.Viagra.Zithromax.Propecia.Viagra Professional.Viagra Soft Tabs.Maxaman….