MS AS deleted HP DeskJet driver as High Risk MalWare

G

Gennadii

Hello!

I share here my experience with MS AS and comparison it
with SpyBot S&D and Ad-Aware SE Personal.

1. MS AS has detected "EZCyberSearch (AdWare)" - 5 records
in the "uninstall"-section of Registry.

2. HP DeskJet driver E:\WINNT\system32\spool\drivers\w32x86
\3\hpztsb01.exe had been WRONGLY recognized as HIGH THREAT
LEVEL HIGHJACK "EUniverse Updater (Browser Hijacker)"
(????!!!!). I kept the copy in ZIP archive before MS AS
deleeted it from the original place.

It detectet nothing but these two events above in more
than 18000 files and 8700 registry entries.

In parallel, SpyBot S&D detected:
1. "CoolWWWSearch.CameUP" registry record and some cookies.

Ad-Aware SE Personal on the same media has detected:
1. 8 records in the Registry of "CoolWebSearch"
2. "Alexa" Registry record
3. Many Malware files that I kept as examples after
cleaning dirty user's computers in a separate directories
on my Hard Disk (part of them in compressed ZIP or CAB
archives). Among
them: "WindUpdates", "AltNetBDE", "180Solutions", "Search
Relevancy" and many kinds of cookies.

KazaaBeGone program located 21 registry records not
related to the mentionned above issues.

Bazooka didn't detect nothing and HiJackThis Log file
didn't change its content in spite of all found above
issues had been fixed.
 
R

Ron Chamberlin

I am tempted to make a reply which someone without a sense of humor might
misinterpret. Fans of HP printer drivers will know what I mean.>
Yuppers.

Ron
 
G

Gennadii

That's what I've got in the Command Prompt:
FCIV -md5 -sha1 "e:\program files\Microsoft
Antispyware\gcThreatAuditScanData.gcd"
28c23c6fa2d17c071523b8dcb56fa699
6d18cee025d6d145f4ca749e8649dc14ae28d140 e:\program
files\microsoft antispyware\gcthreatauditsta.gcd

It corresponds to the latest definitions #5699

To avoid mistake I put again the deleted file into its
plase and made scan again. It had been detected again.
 
B

Bill Sanderson

Thanks - I just wanted to tie down the versions of the entities involved so
that this can be replicated easily. I guess I needed to ask you what
specific printer and version of driver as well.

That filename looks familiar, but perhaps from long familiarity with HP
drivers--I'm not sure I've got the specific file in place on any of the
machines I admin.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top