MAS/CS Fright

G

Guest

i've got CounterSpy and Giant - er.. MS AntiSpy running
back to back - disapointed in the performance guys - have
the full set working everything active. Have used GIANT
professional and to great satisfaction.

Sweeping with
MSA it turns up:
(2 locations)
Grokster
"Type: Adware Bundler
Threat Level: Moderate
Author: Grokster, LTD

Description: Grokster (free version)
installs adware and spyware including
GAIN, CyDoor, My Search,
WebRebates, and Relivant Knowledge.

Advice: This software is not necessarily
adware. However, it does install other
adware programs as well as perform
potential hazardous actions on your
computer. In either case this software is
not to be trusted.

About Adware Bundler: A Bundler is a
software program that installs adware
on your computer either with your
permission or without. Most of the
software classified as a bundler requires
that the adware program(s) be installed
in order for the actual software to
complete installation or run. In addition
in most cases if the adware is removed
the software will seize to function as
well."

CounterSpy comes up with:
aprox. 50 locations
"Amitis1.3
Type: RAT
Level: Severe
Author: Stacked_shit

Description: Amitis is a trojan and
written in delphi, and it is more powerful
than its previous versions.

Advice: This is a very high risk threat
and should be removed immediately as to
prevent harm to your computer or your
privacy.

About RAT: A Remote Administration
Tool (RAT) is a Trojan type of software
that when run, provides an attacker with
the capability of remotely controlling a
user's computer (victim) over the Internet.
The attacker usually has full access to
functions on the victim's computer. The
victim's computer usually listens on the
Internet for the attacker's commands."

BizDefender 2
aprox 50 locations
"Type: Commercial Key Logger
Level: Elevated
Author: htp://www.bizdefender.com

Description: You can now completely
take control over the remote computers
and also you can benefit of the most
comprehensive reports ever.

Advice: This is a high risk threat and
should be removed or quarantined as to
prevent harm to your computer or your
privacy.

About Commercial Key Logger: A
commercial key logger is a program that
is installed by a user of a computer to
explicitly monitor the activity of other
users. These types of program can be
installed using stealth tactics to hide
themselves from other users. In addition
these programs can be purchased from
commercial organizations for this use."

AB System Spy
aprox. 40 location
"Type: Commercial Key Logger
Level: Elevated
Author: Aby Software

Description: It takes screenshots,
Stealth Tactics, Logs keystrokes, Sends
mail, Stays Resident, Connects to the
internet

Advice: This is a high risk threat and
should be removed or quarantined as to
prevent harm to your computer or your
privacy.

About Commercial Key Logger: A
commercial key logger is a program that
is installed by a user of a computer to
explicitly monitor the activity of other
users. These types of program can be
installed using stealth tactics to hide
themselves from other users. In addition
these programs can be purchased from
commercial organizations for this use."

Child Control
aprox. 20 locations
"Type: Surveillance
Level: High
Author: Salfeld Computer

Description: It is a survelliance tool ,
which keeps monitoring every activity on
your computer.

Advice: This is a very high risk threat
and should be removed immediately as to
prevent harm to your computer or your
privacy.

About Surveillance:" (description ends..)

Spyex
numerous locations
"Type: Key Logger
Level: High
Author: SharewareLab.com

Description: SpyEX allows monitor any
kind of activity performed by you in your
computer .

Advice: This is a very high risk threat
and should be removed immediately as to
prevent harm to your computer or your

privacy.

About Key Logger: A key logger program
runs in the background, recording all the
keystrokes made by a user. Once
keystrokes are logged, they are hidden in
the machine for later retrieval, or shipped
secretly raw to the attacker via email or
over the Internet."

Webmailspy
aprox. 20 locations
"Type: Surveillance
Level: Elevated
Author: Exploreanywhere

Description: It is a spyware, it keeps
eye on every incoming and outgoing
mails.

Advice: This is a high risk threat and
should be removed or quarantined as to
prevent harm to your computer or your
privacy."

and a cookie.

NOTE THE FR@GGIN'SEVERITY OF THESE LAPSES!
This release is dangerous for people used to GIANT.
Get it together or GET OUT!
 
S

Steve Dodson [MSFT]

What tool is reporting these ? If is is Windows AntiSpyware, are we not
removing them correctly? What is the behavior?

Also, the fact that it is finding these items in many many locations (50+)
indicates the detection may be related to cookies. I would be interested in
knowing what the program was detecting as each of these.

If they are in fact cookies, this would be expected because we turned off
cookie detection for the beta.

-steve


Steve Dodson [MSFT]
MCSE, CISSP
PSS Security

--

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this
message are best directed to the newsgroup/thread from which they
originated.
--------------------
 
G

Guest

AS REPORTED BY COUNTERSPY 1.0.25

(NONE of these detected by MAS)

Spyware Scan Details
Start Date: 2-1-2005 13:36:39
End Date: 22-1-2005 13:41:06
Total Time: 4 mins 27 secs

Detected spyware

Amitis1.3 RAT more information...

Details: Amitis is a trojan and written in delphi, and
it is more powerful than its previous versions.
Status: Ignored
Severe spyware - Severe threats typically are remotely
exploitable vulnerabilities, which can lead to system
compromise. Successful exploitation does not normally
require any interaction and
exploits are in the wild. There exists a high
possibility of potential system damage or security flaw.
Attacker has complete control over your computer or
install new software on you machine.

Infected folders detected
c:\documents and
settings\XXXXXXXXXXXXXXXXXX\application data\hel
c:\documents and
settings\XXXXXXXXXXXXXXXXXX\local settings\application
data\he

Infected registry keys/values detected

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\FileExts\.HLP

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\FileExts\.HLP\OpenWithList


tafbar Toolbar Browser Plug -in more
information..
Details: tafbar Toolbar collects search and browsing
habits of the user and send these habits to its remote
servers.
Status: Deleted
Elevated spyware - Elevated threats are usually threats
that fall into the range of adware in which data about a
user's habits are tracked and sent back to a server for
analysis without your consent
or knowledge.


AB System Spy Commercial Key Logger more
information...

Details: It takes screenshots, Stealth Tactics, Logs
keystrokes, Sends mail, Stays Resident, Connects to the
internet
Status: Deleted
Elevated spyware - Elevated threats are usually threats
that fall into the range of adware in which data about a
user's habits are tracked and sent back to a server for
analysis without your consent
or knowledge.

Infected registry keys/values detected

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49


HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell WinPos1024x768(1).bottom 738

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Rev 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell WFlags 0

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell ShowCmd 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell FFlags 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell HotKey 0

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Buttons -1


HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Links 0

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Address -1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Vid {65F125E5 -7BE1-4810 -BA9D -
D271C8432CE3}

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell FolderType Documents

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Mode 6

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell ScrollPos1024x768(1).x 0

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell ScrollPos1024x768(1).y 0

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell SortDir 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell Col -1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell ColInfo

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell MinPos1024x768(1).x -1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell MinPos1024x768(1).y -1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell MaxPos1024x768(1).x -1

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell MaxPos1024x768(1).y -1


HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell WinPos1024x768(1).left 154

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell WinPos1024x768(1).top 230

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\B
ags\49\Shell WinPos1024x768(1).right 913


BizDefender 2 Commercial Key Logger more
information...
Details: You can now completely take control over the
remote computers and also you can benefit of the most
comprehensive reports eve .

Status: Deleted
Elevated spyware - Elevated threats are usually threats
that fall into the range of adware in which data about a
user's habits are tracked and sent back to a server for
analysis without your consent
or knowledge.

Infected registry keys/values detected

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew ~reserved~

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew Language 1043
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Service NPF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Legacy 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 ConfigFlags 0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Class LegacyDriver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 ClassGUID
{8ECC055D -047F -11D1 -A537 0000F8753ED1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 DeviceDesc NetGroup Packet
Filter Driver

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Capabilities 0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Driver {8ECC055D -
047F -11D1 A537 -0000F8753ED1}\0045
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum 0 Root\LEGACY_NPF\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum Count 1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum NextInstance 1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersio
n\Explorer\Discardable\PostSetup\ShellNew



Webmailspy Surveillance more information...
Status: Deleted
Elevated spyware - Elevated threats are usually threats
that fall into the range of adware in which data about a
user's habits are tracked and sent back to a server for
analysis without your consent
or knowledge.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF NextInstance 1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Class LegacyDriver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 ClassGUID
{8ECC055D -047F -11D1 -A537 0000F8753ED1}
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 ConfigFlags 0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Legacy 1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Enum\Root\LEGACY_NPF\0000 Service NPF
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum 0 Root\LEGACY_NPF\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum Count 1
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001
\Services\NPF\Enum NextInstance 1


Detected Spyware Cookies
Com.com
RealMedia.com
Stat.Onestat
Tripod
CGI-Bin
 
B

Bill Sanderson

I'd weep more if I read somewhere in that list an actual executable or bit
of code related to these threats as spotted by the other program. Did I
miss one--I did read through the list, but pretty fast!
Additionally, this beta doesn't scan cookies, so every other product will
find cookies that Microsoft Antispyware does not.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top