Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 18, 2008, 05:43:59 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
212218
Posts
24528
Topics
57708
Members
Latest Member:
zebadee
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Internet Security - CIS
Virus/Malware Removal Assistance
FraudTool.Win32.SpyAway
« previous
next »
Pages:
[
1
]
Author
Topic: FraudTool.Win32.SpyAway (Read 2163 times)
Bracca
Comodo Member
Offline
Posts: 38
FraudTool.Win32.SpyAway
«
on:
August 29, 2008, 10:33:50 AM »
New problem. Except that this happened to my dear friend. I came to his house and wondered why he was tearing his hair out from his head. He points at the screen and there it is. F-secure says that it has found an program called
FraudTool.Win32.SpyAway
Soo umm.. What is this then? Some people on the net say that it is extremely nasty program and others say that it has nothing to do with anything. Help?
Logged
grayhair
Comodo Loves me
Offline
Posts: 184
Re: FraudTool.Win32.SpyAway
«
Reply #1 on:
August 29, 2008, 10:54:07 AM »
Maybe this will shed some light on what it is:
http://www.threatexpert.com/report.aspx?uid=df6e0947-ce3c-49c9-936f-45e13599e547
What are the particulars about the system your friend has? I.E. operating system, service patch, firewall, AV, other security software, etc.
Logged
Bracca
Comodo Member
Offline
Posts: 38
Re: FraudTool.Win32.SpyAway
«
Reply #2 on:
August 29, 2008, 11:02:09 AM »
Oookkayh... So that is a serious "health" risk to the computer? ö.ö And i will post the system specs once he returns to his home. What i understood, that is an program that is somesort of an trojan, which installs somesort of an non existing virus removal tool? Anyways. Is there any way to remove it?
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 1395
Re: FraudTool.Win32.SpyAway
«
Reply #3 on:
August 29, 2008, 11:16:27 AM »
hey guys, I did a google search on this
FraudTool.Win32.SpyAway
and came up with some results about the program, much like grayhair has shown you - offering a removal tool "spyware detector" Don't download it it's meant to be another nasty.
Logged
*Have been accepted into the Australian army, Rifleman, Full time for 4 years minimum.
Leaving on Feb 2nd.
Bracca
Comodo Member
Offline
Posts: 38
Re: FraudTool.Win32.SpyAway
«
Reply #4 on:
August 29, 2008, 11:30:15 AM »
Right'o. We will keep that on mind. But still. Anyone know how we could get rid of this problem? i mean, other way than installing the whole damn system again. It is driving my friend to insanity right about now.
Logged
grayhair
Comodo Loves me
Offline
Posts: 184
Re: FraudTool.Win32.SpyAway
«
Reply #5 on:
August 29, 2008, 11:40:19 AM »
It will be a lot easier to advise on removal attempts once more is known about this computer. When you get the info reply back. Tell your friend not to go nutso just yet, and not to make an impulse "security" purchase. Get the info posted here, and people here will try to help.
Cheers,
Logged
Bracca
Comodo Member
Offline
Posts: 38
Re: FraudTool.Win32.SpyAway
«
Reply #6 on:
August 29, 2008, 12:13:17 PM »
Thank you people. It is good to know that my and other peoples computers are well secured with guys like you willing to help us all. Thank you n.n
Logged
STCH
Newbie
Offline
Posts: 2
Re: FraudTool.Win32.SpyAway
«
Reply #7 on:
August 29, 2008, 04:20:21 PM »
Is it possible this could be a false positive? All of a sudden today I had over 10 PC's with F-secure report:
Spyware detected:
Type: riskware
Family:
Name: FraudTool.Win32.SpyAway
Object: C:\WINDOWS\system32\MSCOMCTL.OCX
I can't find any decent information about this. I ran MSCOMCTL.OCX from an "infected" PC through McAfee with the latest DATs and it came up clean. I'm stumped as to what's going on. I vaguely recall F-Secure giving me a false positive a while back. Any ideas?
Logged
grayhair
Comodo Loves me
Offline
Posts: 184
Re: FraudTool.Win32.SpyAway
«
Reply #8 on:
August 29, 2008, 04:42:11 PM »
Quote from: STCH on August 29, 2008, 04:20:21 PM
Is it possible this could be a false positive? All of a sudden today I had over 10 PC's with F-secure report:
Spyware detected:
Type: riskware
Family:
Name: FraudTool.Win32.SpyAway
Object: C:\WINDOWS\system32\MSCOMCTL.OCX
I can't find any decent information about this. I ran MSCOMCTL.OCX from an "infected" PC through McAfee with the latest DATs and it came up clean. I'm stumped as to what's going on. I vaguely recall F-Secure giving me a false positive a while back. Any ideas?
It is possible it could be an FP. You could submit the file to virustotal.com
Logged
STCH
Newbie
Offline
Posts: 2
Re: FraudTool.Win32.SpyAway
«
Reply #9 on:
August 29, 2008, 05:23:44 PM »
Submitted the file to VirusTotal.com. Found nothing. I'm assuming a false positive on this. Pity it took the patient system offline for 2 hours!
http://www.virustotal.com/analisis/1a0ff8978ceb04a5c99326b382ee4265
Logged
grayhair
Comodo Loves me
Offline
Posts: 184
Re: FraudTool.Win32.SpyAway
«
Reply #10 on:
August 29, 2008, 06:12:33 PM »
Quote from: STCH on August 29, 2008, 05:23:44 PM
Submitted the file to VirusTotal.com. Found nothing. I'm assuming a false positive on this. Pity it took the patient system offline for 2 hours!
http://www.virustotal.com/analisis/1a0ff8978ceb04a5c99326b382ee4265
Well, it seems to be good news. Wouldn't hurt to scan the computer with whatever security programs you have, or others--some suggestions here:
http://forums.comodo.com/anti_virusmalware_productsother_security_products/list_of_antivirusantimalware_products_other_utilities-t24176.0.html
Good luck, and a good weekend.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.176 seconds with 19 queries.
Powered by SMF 1.1.7
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com