Welcome, Guest. Please login or register.
November 18, 2008, 05:41:04 PM

Login with username, password and session length

212214 Posts
24527 Topics
57707 Members

Latest Member: Pirate1111

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  FraudTool.Win32.SpyAway
« previous next »
Pages: [1] Go Down Print
Author Topic: FraudTool.Win32.SpyAway  (Read 2155 times)
Bracca
Comodo Member
**
Offline Offline

Posts: 38


« on: August 29, 2008, 10:33:50 AM »

New problem. Except that this happened to my dear friend. I came to his house and wondered why he was tearing his hair out from his head. He points at the screen and there it is. F-secure says that it has found an program called FraudTool.Win32.SpyAway Soo umm.. What is this then? Some people on the net say that it is extremely nasty program and others say that it has nothing to do with anything. Help?
Logged
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #1 on: August 29, 2008, 10:54:07 AM »

   Maybe this will shed some light on what it is:


http://www.threatexpert.com/report.aspx?uid=df6e0947-ce3c-49c9-936f-45e13599e547

  What are the particulars about the system your friend has?  I.E. operating system, service patch, firewall, AV, other security software, etc.
Logged
Bracca
Comodo Member
**
Offline Offline

Posts: 38


« Reply #2 on: August 29, 2008, 11:02:09 AM »

Oookkayh... So that is a serious "health" risk to the computer? ö.ö And i will post the system specs once he returns to his home. What i understood, that is an program that is somesort of an trojan, which installs somesort of an non existing virus removal tool? Anyways. Is there any way to remove it?
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 1395



WWW
« Reply #3 on: August 29, 2008, 11:16:27 AM »

hey guys, I did a google search on this FraudTool.Win32.SpyAway and came up with some results about the program, much like grayhair has shown you - offering a removal tool "spyware detector" Don't download it it's meant to be another nasty.
Logged

*Have been accepted into the Australian army, Rifleman, Full time for 4 years minimum.
Leaving on Feb 2nd.
Bracca
Comodo Member
**
Offline Offline

Posts: 38


« Reply #4 on: August 29, 2008, 11:30:15 AM »

Right'o. We will keep that on mind. But still. Anyone know how we could get rid of this problem? i mean, other way than installing the whole damn system again.  It is driving my friend to insanity right about now.  Undecided
Logged
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #5 on: August 29, 2008, 11:40:19 AM »

   It will be a lot easier to advise on removal attempts once more is known about this computer.  When you get the info reply back.  Tell your friend not to go nutso just yet, and not to make an impulse "security" purchase.  Get the info posted here, and people here will try to help.

   Cheers,

 Cheers
Logged
Bracca
Comodo Member
**
Offline Offline

Posts: 38


« Reply #6 on: August 29, 2008, 12:13:17 PM »

Thank you people. It is good to know that my and other peoples computers are well secured with guys like you willing to help us all. Thank you n.n  Love Comodo
Logged
STCH
Newbie
*
Offline Offline

Posts: 2


« Reply #7 on: August 29, 2008, 04:20:21 PM »

Is it possible this could be a false positive? All of a sudden today I had over 10 PC's with F-secure report:

Spyware detected:
Type: riskware
Family:
Name: FraudTool.Win32.SpyAway
Object: C:\WINDOWS\system32\MSCOMCTL.OCX

I can't find any decent information about this. I ran MSCOMCTL.OCX from an "infected" PC through McAfee with the latest DATs and it came up clean. I'm stumped as to what's going on. I vaguely recall F-Secure giving me a false positive a while back. Any ideas?
Logged
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #8 on: August 29, 2008, 04:42:11 PM »

Is it possible this could be a false positive? All of a sudden today I had over 10 PC's with F-secure report:

Spyware detected:
Type: riskware
Family:
Name: FraudTool.Win32.SpyAway
Object: C:\WINDOWS\system32\MSCOMCTL.OCX

I can't find any decent information about this. I ran MSCOMCTL.OCX from an "infected" PC through McAfee with the latest DATs and it came up clean. I'm stumped as to what's going on. I vaguely recall F-Secure giving me a false positive a while back. Any ideas?


   It is possible it could be an FP.  You could submit the file to virustotal.com
   
Logged
STCH
Newbie
*
Offline Offline

Posts: 2


« Reply #9 on: August 29, 2008, 05:23:44 PM »

Submitted the file to VirusTotal.com. Found nothing. I'm assuming a false positive on this. Pity it took the patient system offline for 2 hours!  Angry

http://www.virustotal.com/analisis/1a0ff8978ceb04a5c99326b382ee4265
Logged
grayhair
Comodo Loves me
****
Offline Offline

Posts: 184


« Reply #10 on: August 29, 2008, 06:12:33 PM »

Submitted the file to VirusTotal.com. Found nothing. I'm assuming a false positive on this. Pity it took the patient system offline for 2 hours!  Angry

http://www.virustotal.com/analisis/1a0ff8978ceb04a5c99326b382ee4265


   Well, it seems to be good news.  Wouldn't hurt to scan the computer with whatever security programs you have, or others--some suggestions here:

http://forums.comodo.com/anti_virusmalware_productsother_security_products/list_of_antivirusantimalware_products_other_utilities-t24176.0.html


  Good luck, and a good weekend.    Comodo Rocks   Cheers
   
Logged
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.172 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com