Comet Systems

J

Jeff Allen

I thought I had managed to remove Comet Systems using
Ad-Aware but MS Antispyware keeps giving me the following
pop-up warning message when I boot up my PC:

"Microsoft AntiSpyware has detected the threat Comet
Systems trying to install a Internet Explorer Web rowser on
your computer"...

and so before doing anything else I do a full MS
AntiSpyware system scan. But this tells me the PC is clean.
Subsequently when I select "remove" on the pop-up window it
says that the threat has been successfully removed.
However, from looking at the log file it appears that MS
Antispyware doesn't actually do anything when trying to
remove the threat.

02/05/2005 18:03:49::Initializing Clean - (ScanID: 0)
02/05/2005 18:03:49::Clean Threat Comet Systems (ID:14852)
02/05/2005 18:03:49::Generating threat
02/05/2005 18:03:56::Clean Threat Comet Systems (ID:14852)
Complete
02/05/2005 18:04:01::Unititializing Clean

(i.e. I would have expected references to registry keys
being removed, files being deleted, etc in the above log
file extract).

Up to now I've tried a full system scan (in safe mode)
which doesn't pick up upon anything and also reinstalling
MS Antispyware but each time on boot up I get the same
pop-up warning message about Comet Systems. Both Ad-Aware
and Sbybot tell me that the PC is clean.

Any ideas ??
 
A

Andre Da Costa

See links:
http://securityresponse.symantec.com/avcenter/venc/data/spyware.cometcursor.html

Comet Cursor:
Comet Cursor
http://www.doxdesk.com/parasite/CometCursor.html
http://securityresponse.symantec.com/avcenter/venc/data/spyware.cometcursor.html
CS - Couterspy reports Comet Cursor to be active in MSAS
quarantine folder.

Empty Quarantine folder and check again.
--
~Robear Dyer (PA Bear)
MS MVP-Windows (IE/OE) & Security


That's interesting--have you looked to see what's actually in the quarantine
folder? It's a subfolder of the Microsoft Antispyware installation
folder--which is typically c:\program files\microsoft antispyware.
 
J

Jeff Allen

OK, I have now managed to remove the Comet Systems threat
by using Spy Sweeper instead of MS AntiSpyware. Spy Sweeper
detected several entries in the Registry related to Coment
Systems that other products such MS AntiSpyware, Ad-Aware
and Sbybot failed to detect.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top