Monday, May 17, 2010

How to remove Antispysolution.com and Antispysolution.net browser hijackers

If your browser constantly is redirected to Antispysolution.com or Antispysolution.net website, which have a Internet Explorer cannot display the webpage header, it means that your computer is infected with malicious program called Antispyware Soft. This program – fake antivirus application, which also known as rogue antispyware. The website stats:



Internet Explorer cannot display the webpage.:
Internet Explorer Warning - visiting this web site may harm your computer!

Most likely causes:
* The website contains exploits that can launch a malicious code on your computer
* Suspicious network activity detected
* There might be an active spyware running on your computer

What you can try:
Purchase for secure Internet surfing (Recommended).
Check your computer for viruses and malware.
More information

Screen shoot of the malicios website below:


Antispysolution.com and Antispysolution.net - browser hijackers

Obviously, you can not trust neither these Antispysolution.com and Antispysolution.net websites nor its affiliate Antispyware Soft. These two created with one purpose, using deception and threats to force you to open your wallet and pull out the money. Do not need! Remember the important rule, if your PC was infected with Antispyware Soft, you need to ignore all that it shows you and temporarily stop using the computer. Use the Antispyware Soft removal guide or the instructions below, which will remove redirect to Antispysolution.com or Antispysolution.net malicious site and any other infections you may have on your computer for free.

How to remove Antispysolution.com and Antispysolution.net browser hijackers


1. Download HijackThis from here, but before saving, in the Save dialog, rename HijackThis.exe to iexplore.exe and save it to your desktop.
2. Run HijackThis.
3. In the main menu click to "Do a system scan only" button.
4. Look for these lines and place a checkmark against each of the following, if still present

R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O4 – HKLM\..\Run: [{RANDOM}] %UserProfile%\Local Settings\Application Data\{RANDOM}\{RANDOM}tssd.exe
O4 – HKCU\..\Run: [{RANDOM}] %UserProfile%\Local Settings\Application Data\{RANDOM}\{RANDOM}tssd.exe
5. Make sure your Internet Explorer (& or any other browser) is closed when you click Fix Checked!
7. Download Malwarebytes Anti-malware.
8. Double click mbam-setup.exe to install the application.
9. When installation is complete, make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
10. If an update is found, it will download and install the latest version.
11. Once the program has loaded, select "Perform Quick Scan", then click Scan.
12. When the scan is done, click OK, then Show Results to view the results.
13. Make sure that everything is checked, and click Remove Selected.
14. Once disinfection is finished, a log will open in Notepad and you may be prompted to Restart.

Note: if you can`t download these suggested programs above, you need uncheck "Use a proxy server" option by doing: Run Internet Explorer, open Tools menu, select Internet Options. Open Connections Tab and click to Lan Settings button. Uncheck “Use a proxy server” box. Click OK. Click Apply. Click OK.

If the instructions does not help you, then ask for help in the Spyware removal forum

1 comment:

  1. Prog-
    Oddly coincidental I get this virus within hours of your posting this article... ;)
    Thanks, though. Worked perfectly to fix something extremely frustrating.
    Before performing the above, I restarted in Safe Mode with Networking, ran regedit, and searched through and deleted all entries with "tssd" (sometimes entire blocks). Then disabled the proxy server and followed you step by step. (didn't test it without doing the registry editing, so presumably the Malwarebytes would have picked them up, but it never hurts to be sure!)
    Again, thanks.

    ReplyDelete