<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Spyware Docter - Another Rogue? in Security</title>
<link>http://www.dslreports.com/forum/r13633399</link>
<description></description>
<language>en</language>
<pubDate>Fri, 04 Dec 2009 16:10:39 EDT</pubDate>
<lastBuildDate>Fri, 04 Dec 2009 16:10:39 EDT</lastBuildDate>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13634334</link>
<description><![CDATA[<A HREF="/useremail/u/299537"><b>sashwa</b></A> : Thanks Eric for your response.  I probably used the wrong terminology when I said "false positives".  I wasn't really worried about the cookies.  I was more concerned about the items that appeared in the <br><br>HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\<br><br>because it seemed like they were mostly Symantec/Norton <br>entries.  Im using NAV 2004 that is fully updated.<br><br>Also as far as I know I have never been hijacked or infected.  I run Ad-Aware, Spybot, and MS AntiSpyware regularly and none of them have ever identified any of those keys before.<br><br>sash  :)<br><SMALL>--<br><A HREF="http://www.broadbandreports.com/forum/sanfran">Northern California Forum</A> ~ <A HREF="http://www.broadbandreports.com/forum/helix">Team Four</A> ~ <A HREF="http://www.broadbandreports.com/forum/dist">ECO Clicks</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13634334</guid>
<pubDate>Sat, 11 Jun 2005 15:11:48 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633582</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : RedhatCOC:<br><br>You wrote:<br><br><div class="bquote"><SMALL>said by  MattUK <A HREF="/useremail/u/789436"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>I think another important point is if generally "security people" haven't heard of an antispyware utility, and it doesn't let you clean the infections without paying, then they will be suspicious. Just my opinion!<br></DIV>I agree with you on this. I've been telling anti-spyware vendors for some time to ditch the trial versions in which removals are disabled. A program that reports detected malware but then demands money to remove it rubs many people the wrong way and raises suspicions.<br><br>The vendors who use these kinds of trials are worried that if they offer a full-featured trial, perhaps with a time limit of 15 days, then users will simply use the trial version to resolve their current problems without paying for the full version.<br><br>While it's likely that some users will use a full-featured/time-limited trial in that way, I think it much better to go out of your way to avoid doing anything that smacks of the "hard sell."<br><br>Anti-spyware vendors play by a special set of rules. What's legitimate and above-board in the marketing and advertising for one type of software program can prove problematic when used to sell an anti-spyware utility, because many if not most of your customers are already victims -- of spyware and adware. As such, one must take great care in dealing with these victims.<br><br>Best,<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633582</guid>
<pubDate>Sat, 11 Jun 2005 13:14:06 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633525</link>
<description><![CDATA[<A HREF="/useremail/u/789436"><b>MattUK</b></A> : Thank you for clearing that up Eric. I shall let the person know, as I trust your analysis of A/S programs. <br><br>I think another important point is if generally "security people" haven't heard of an antispyware utility, and it doesn't let you clean the infections without paying, then they will be suspicious. Just my opinion!<br><br>Kindest regards and many thanks.<br>Matt<br><SMALL>--<br>&raquo;<A HREF="http://forum.gladiator-antivirus.com" >forum.gladiator-antivirus.com</A> /// Gladiator Security Forum Admin // &raquo;<A HREF="http://www.kleendesigns.co.uk" >www.kleendesigns.co.uk</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633525</guid>
<pubDate>Sat, 11 Jun 2005 13:04:26 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633441</link>
<description><![CDATA[<A HREF="/useremail/u/378696"><b>eburger68</b></A> : Hi All:<br><br>Spyware Doctor from PC Tools is a completely legitimate anti-spyware utility. It's installed on on my box right now, and I test with it regularly.<br><br>Sashwa, the vast majority of the detections reported by Spyware Doctor in your scan appear to be legitimate detections, not false positives. <br><br>The first 10 detections are cookies. I've long advocated that anti-spyware utilities move cookie management out of the threat scanner and into a separate utility, but these aren't false positives per se -- they're simply cookies that Spyware Dcotor is offering to remove for you.<br><br>The next several detections all involve CLSIDs that appear to be legitimate detections. These Registry keys are probably just remnants left behind from previous infestations or installations. Nothing serious, but they don't appear to be false positives.<br><br>D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9 - see:<br>&raquo;<A HREF="http://sarc.com/avcenter/venc/data/adware.halflemon.html" >sarc.com/avcenter/venc/data/adwa&middot;&middot;&middot;mon.html</A><br><br>15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6 - see:<br>&raquo;<A HREF="http://sarc.com/avcenter/venc/data/pf/adware.blazefind.html" >sarc.com/avcenter/venc/data/pf/a&middot;&middot;&middot;ind.html</A><br><br>C1E58A84-95B3-4630-B8C2-D06B77B7A0FC - see:<br>&raquo;<A HREF="http://castlecops.com/tk524-Nhelper_dll.html" >castlecops.com/tk524-Nhelper_dll.html</A><br>&raquo;<A HREF="http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453074928" >www3.ca.com/securityadvisor/pest&middot;&middot;&middot;53074928</A><br><br>42F2C9BA-614F-47C0-B3E3-ECFD34EED658 - see:<br>&raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/adware.istbar.html" >securityresponse.symantec.com/av&middot;&middot;&middot;bar.html</A><br><br>The last reported detection does indeed appear to be a false positive ( SahAgent C:\Program Files\EmotiPad Plus\Cache\smile_omfg.gif). I would suggest reporting it to PC Tools.<br><br>A few comments, if I may (and these are directed at no one in particular).<br><br>1) Don't assume that because you think you have a malware-free box that any reported detections by an anti-malware utility must be false positives. Do some research yourself and look into the reported detections. Until you do that, you can't say one way or the other what the detections are.<br><br>2) The mere existence of false positives does not make an anti-malware utility "rogue," because all anti-malware utilities will have false positives at some point. You've got to evaluate those false positives by asking:<br><br>- How common are the false positives?<br>- What were the causes of false positives? A poorly designed scan engine, bad data, or researcher error? <br>- How diligent is the vendor in soliciting reports of false positives, testing for false positives, and correcting those false positives in a timely manner?<br><br>Not all false positives are created equal.<br><br>In any case, I hope the above has been of help.<br><br>Edit: looks like this may be a bit more complicated than I first assumed. All of those CLSIDs were listed in this key:<br><br>HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\<br><br>I'm still trying to find good info on just what that key is used for, but it appears to be an XP SP2 key, possibly a place where IE keeps track of the ActiveX controls that it has downloaded and/or installed. The data in this key appears to be harmless, but just what caused the keys to be created in the first place is still not clear. At the very least the ClSIDs do match known pieces of spyware/adware.<br><br>Best,<br><br>Eric L. Howes]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633441</guid>
<pubDate>Sat, 11 Jun 2005 12:51:11 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633399</link>
<description><![CDATA[<A HREF="/useremail/u/879997"><b>dadkins</b></A> : Eric L. Howes tested it his antispyware tests:<br>&raquo;<A HREF="http://spywarewarrior.com/asw-test-results-1.htm" >spywarewarrior.com/asw-test-results-1.htm</A><br><br>Didn't do too bad either.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633399</guid>
<pubDate>Sat, 11 Jun 2005 12:44:09 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633366</link>
<description><![CDATA[<A HREF="/useremail/u/377471"><b>TheJoker</b></A> : If you check the Rogue/Suspect list at &raquo;<A HREF="http://www.spywarewarrior.com/rogue_anti-spyware.htm" >www.spywarewarrior.com/rogue_ant&middot;&middot;&middot;ware.htm</A>, you will find that PC Tools Spyware Doctor is <B>not</B> on the Rouge list.<br><SMALL>--<br>TheJoker</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633366</guid>
<pubDate>Sat, 11 Jun 2005 12:40:46 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633248</link>
<description><![CDATA[<A HREF="/useremail/u/299537"><b>sashwa</b></A> : One of my staff bought this program for his home computer.  He likes it.<br><br>I tried the scan and wasn't impresssed and it seemed to me to have false positives. It said I had 19 infections.  :o  Which I highly doubt.<br><br>From my last scan:<br><br>Scans (basic information only): <br> <br>Scan Results:<br>scan start: 6/11/2005 9:08:34 AM <br>scan stop: 6/11/2005 9:15:56 AM <br>scanned items: 70604 <br>found items: 19 <br>found and ignored: 0 <br>tools used: General Scanner, Process Scanner, Hosts scanner, LSP Scanner, Registry Scanner, Cookie Scanner, Browser Defaults, Favorites and ZoneMap Scanner, Browser Scanner, Disk Scanner <br> <br> <br>    <br> Infection Name Location Risk <br> Tracking Cookie(s) me@go[1].txt Medium <br> Tracking Cookie(s) me@forbes[2].txt Medium <br> Tracking Cookie(s) me@rating[1].txt Medium <br> Tracking Cookie(s) me@tripod[1].txt Medium <br> Tracking Cookie(s) me@www.all-yours[1].txt Medium <br> Tracking Cookie(s) me@wellsfargo[2].txt Medium <br> Tracking Cookie(s) me@pogo[1].txt Medium <br> Tracking Cookie(s) me@login[2].txt Medium <br> Tracking Cookie(s) me@www.netlingo[2].txt Medium <br> Tracking Cookie(s) me@home[1].txt Medium <br> HalfLemon HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9} Elevated <br> HalfLemon HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D94AAA2A-C415-42E3-82B6-49FAB4EBFFE9}\iexplore Elevated <br> MediaPass HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} High <br> MediaPass HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}\iexplore High <br> NavHelper HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} Info <br> NavHelper HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC}\iexplore Info <br> YourSiteBar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658} High <br> YourSiteBar HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{42F2C9BA-614F-47C0-B3E3-ECFD34EED658}\iexplore High <br> SahAgent C:\Program Files\EmotiPad Plus\Cache\smile_omfg.gif Elevated <br>    <br> <br>Other Sections:<br> <br><SMALL>--<br><A HREF="http://www.broadbandreports.com/forum/sanfran">Northern California Forum</A> ~ <A HREF="http://www.broadbandreports.com/forum/helix">Team Four</A> ~ <A HREF="http://www.broadbandreports.com/forum/dist">ECO Clicks</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633248</guid>
<pubDate>Sat, 11 Jun 2005 12:20:33 EDT</pubDate>
</item>

<item>
<title>Re: Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633241</link>
<description><![CDATA[<A HREF="/useremail/u/874633"><b>anthrorules</b></A> : yes, it's rogue...piece of *&^%]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633241</guid>
<pubDate>Sat, 11 Jun 2005 12:19:03 EDT</pubDate>
</item>

<item>
<title>Spyware Docter - Another Rogue?</title>
<link>http://www.dslreports.com/forum/remark,13633093</link>
<description><![CDATA[<A HREF="/useremail/u/789436"><b>MattUK</b></A> : A friend of mine on another forum downloaded <A HREF="https://www.pctools.com/spyware-doctor/?ref=ov_uk">Spyware Docter</A> following a link from Virus Bulletin. He was angry when, after the scan finished, it had found 3 pieces of "spyware" on his machine, but wanted money to take them off. <br><br>Although, in all fairness, their website states: <br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Please note the trial version is limited to scan only.<HR></BLOCKQUOTE><br><br>The friend is suspicious that these are false positives. Should this program be considered for Eric's list?<br><br>Thoughts?<br><SMALL>--<br>&raquo;<A HREF="http://forum.gladiator-antivirus.com" >forum.gladiator-antivirus.com</A> /// Gladiator Security Forum Admin // &raquo;<A HREF="http://www.kleendesigns.co.uk" >www.kleendesigns.co.uk</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13633093</guid>
<pubDate>Sat, 11 Jun 2005 11:54:43 EDT</pubDate>
</item>

</channel>
</rss>
