StripPlayer Description:
A downloader for a premium-rate phone dialer
providing access to the porn site strip-player.com.
The 'StripSetup' ActiveX control can be used on
any web page, by any author, to download and run
any executable file. There are no security checks
whatsoever.
Installation can happen totally automatically
on versions of Internet Explorer older than IE6
Service Pack 1, as a security hole is exploited
to add the manufacturers, 'Electronic Group', to
the list of publishers you trust, allowing them
to install any software they like.
Electronic Group are known to install at least
two other types of dialer software this way,
IEAccess
and
DialerOffline. The dialler itself may also
be installed by a simpler EXE file for non-IE
browsers, but this is not detected by the script
at this site and does not present the same risk.
Also known as: strip-player
StripPlayer Automatic Removal:
Using Spyware Doctor
to detect and remove StripPlayer AUTOMATICALLY!
Sponsored Links:
StripPlayer Manual Removal:
Open the registry (Start->Run->regedit) and
delete the following keys:
HKEY_CLASSES_ROOT\ActiveStripSetup.EGStripDownload
HKEY_CLASSES_ROOT\ActiveStripSetup.EGStripDownload.1
HKEY_CLASSES_ROOT\CLSID\{E3F7205F-2AE0-4BF0-816B-2D24A5F20EC7}
HKEY_CLASSES_ROOT\TypeLib\{357AA41A-B7A8-4632-A27D-5B980B25CF43}
HKEY_CLASSES_ROOT\Interface\{BC23F736-C5BE-47FB-B459-1757933E5DF3}
Then open the System folder (in the Windows
folder, 'System32' under Windows XP/2000/NT, or
'System' under Windows Me/98/95), and delete the
ActiveStripSetup.dll file.
To remove the dialler itself, delete the
folder 'C:\Program Files\strip-player' and any
links to it on the desktop and/or Start menu.
Finally, if you fell victim to the exploit
used to load StripPlayer automatically, you will
need to remove Electronic Group from your trusted
publishers, or they will still be able to install
their software in the future. Check the registry
key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust
Providers\Software Publishing\Trust Database\0
for an entry with the value 'Electronic Group'.
Delete it if it exists, if so, patching/updating
IE is probably a very good idea.
You can also go to HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates
and delete Electronic Group's key. It should
begin '08F573...'.
More
Removal Instructions for Adware/Spyware Programs -
'S'
|
(If you can not see the issued comment, please enable your browser to support javascript and refresh this page.)