The new MS Antispyware/aka Giant Antispyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by NewsFlash, Jan 8, 2005.

  1. NewsFlash

    NewsFlash Corporal

    I just installed the new microsoft antispyware (downloaded from here) and ran my first scan. Two things showed up, WEBHANCE(spyware), and SEARCHSQUIRE(adware) which I removed after setting a restore point. After rebooting, only my wallpaper comes on the screen, none of my programs or desktop items are loading anymore!!! HELP!! I restarted in safe mode and then did a system restore and things are OK but what the hey happened?? How can I get those infections (if they are real) out without affecting my system? They are obviously important to the system operation. The 'help' section said to uninstall other antispyware programs before installing MSAntispyware--which I did not do-- I also have Spybot, Ad-Aware SE, Spyware blaster, Bazooka scanner, Norton AV &firewall. Incidentally, neither Spybot nor AdAware found those infections that MSAntispy did. So I guess my question now is did I totally mess up my computer with this thing or what? CAN ANYONE HELP PLEASE?!?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Did you update the program right after installing? as there was 2 updates in as many days.

    Was the Webhance listing a file called sporder.dll in the C:\windows\system32 folder? if so its a posible false positive as that dll is needed for internet access as well as a few other ok programs, some AVs install that dll IIRC.

    as for the other one, we would need to know the name of the file/s it found.


    as its a beta still, it is worth checking on some of the files it finds just incase they are needed.
     
  3. NewsFlash

    NewsFlash Corporal

    Halo thanks! I just updated it now on your advice. The WEBHANCER thing is indeed system32\sporder.dll, and also \sporder(3).dll -do I just leave it alone then?

    SEARCHSQUIRE shows this:

    HKEY\Current\User\Software\Microsoft\Windows\Cur....I can't see the rest

    and another HKEY just the same as above but I can't see the rest--how do you see the rest of it?
     
  4. MikeH

    MikeH Specialist

    Hey, folks- MS Antispyware found "SearchSquire" on my PC, too- the registry keys found were in "internet settings/zone maps/ domains"- no other files found- it's listed as adware from a "NewMedia Properties LLC" (listed on symantec's web site as "low"; from Jan. '04 I think)
     
  5. NewsFlash

    NewsFlash Corporal

    I quarantined my 'searchsquire' and everything is OK.

    But

    How do you read the rest of the location descriptions:
    HKEY_Curren_User_Software_Microsoft_Windows_Cur.....how do I get the rest of it?
     
  6. MikeH

    MikeH Specialist

    right-click on the string (HKCU etc.) and hold
     
  7. NewsFlash

    NewsFlash Corporal

    I right clicked but no further string info happened...just a box around it.
     
  8. Adrynalyne

    Adrynalyne Guest

    Be careful, some of the mods have found the program to be giving false postives on searchsquire.
     
  9. MikeH

    MikeH Specialist

    Thanks for that info, Adrynalyne. NewsFlash, I think that once you got the box around it, then you "click and hold" again (man, now I can't quite remember- I'm mentally irregular, though, got to excuse me ;)
     
  10. NewsFlash

    NewsFlash Corporal

    MikeH, I did 'click and hold' and it's not showing the string.
     
  11. MikeH

    MikeH Specialist

    I deleted the stuff, and now I really can't remember how I did read the whole key- sorry :rolleyes: I know it's there somewhere (I read the whole string before doing anything to it; maybe you can't read it when it's quarantined??)- there's another thread on this in "Lounge" ( http://forums.majorgeeks.com/showthread.php?t=51534 ), maybe ask there?
     
  12. NewsFlash

    NewsFlash Corporal

    MikeH, OK thanks and thanks to everyone else for their input. Cheers!
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! It is declaring the below two SearchSquire Adware
    items to be problems when they are not:

    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchsquire.com
    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchsquire.com * 4

    ZoneMap is where Spybot and other programs insert info to block bad sites.

    If it were:

    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\searchsquire.com * 2

    instead of the ending "* 4". It would be something to complain about. * 2 would be the Trusted Zone whereas * 4 is the Restricted Zone.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds