SpyEraser = legit?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Thadian, Jun 12, 2007.

  1. Thadian

    Thadian Private E-2

    Was looking some files up on the Uniblue Process Library and found their spyware program.

    Thought i would give it a try and it 'found' at least 9 possible infections that Spybot/AdAware/AVG never picked up on.

    Not quite sure what to think of it since I've never heard of it before. Anyone else use it before and vouch for it?

    EDIT: To clarify, Since the demo doesn't let you delete anything... I just wanted to know if it was worth buying.

    oh, and if anyone wanted to look into it...
    http://www.liutilities.com/products/spyeraser/
     
    Last edited: Jun 12, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is a legit product but like many, you cannot always believe everything they say and you need to be careful. You said "possible infection" that does not mean they are infected. What did it report exactly?

    svchost.exe is a great example. It could be bad and it could be valid. It all depends on where it is running from. Companies like LiUtilities can sometimes trick you into buying their software just because of the tricky wording used. Read what they say in the below link about svchost.exe.

    http://www.liutilities.com/products/wintaskspro/processlibrary/svchost/

    First they tell you is a Microsoft file.
    Then they twice tell you it is a trojan.
    Then they tell you again it is a Microsoft Windows file.
    Then they finally tell you it depends on the directory location it executes or runs from. Followed by a pitch for you to run their tool.

    Is this a blatant rogue type tool like many spyware tools? No! It is a valid tool.
    Do you need it? No!
     
    Last edited: Jun 12, 2007
  3. Thadian

    Thadian Private E-2

    heh.... Alright. Thanks for the response. Won't bother with it then. :-D
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. But you never said what it reported as "possible infection".
     
  5. Thadian

    Thadian Private E-2

    oh.... it was under the Registry keys section.

    Adware.Zango-Astrology
    (4 infections) Type: Adware Threat: High
    - hkey_local_machine\software\microsoft\windows\curr
    entversion\ext\preapproved\{8109fd3d-d891-4f80-8339-50a4913ace6f}\1\
    - same as above but with different numbers in the { }
    - ditto
    - ditto

    Adware.Zango-Solitaire
    (2 Infections) Type: Adware Threat: High
    - hkey_current_user\software\macromedia\shockwave 8\
    uicontrol\sw3dbaddriverlist1\
    - hkey_current_user\software\macromedia\shockwave 8\
    uicontrol\sw3dbaddriverlist2\

    USB Monitor
    (3 Infections) Type: Activex Trojan Adware Threat: Moderate
    - hkey_current_user\software\microsoft\windows scrip
    t\settings\\
    - hkey_current_user\software\microsoft\windows scrip
    t\\
    - hkey_current_user\software\microsoft\windows scrip
    t\settings\jitdebug\


    That's word for word what it shows me... I can then chose an action (ignore, remove, quarantine) and say "Clean System" (but of course it won't unless I buy the full version *roll eyes*)

    As much as I like to say I'm good with computers, anything registry related is beyond me and I have no clue what it means/does. :p
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you install anything from Zango? Did you see anything in Add/Remove programs related to Zango? Do you have any P2P applications installed?

    They items being reported are not big issues even if they are problems (and I'm not sure they are).

    Are you having any malware problems on your PC?
     
  7. Thadian

    Thadian Private E-2

    Never installed anything from Zango. Nothing in add/remove for Zango.

    No P2P on this computer at all.

    And not really having Malware problems... I was just looking around today and cleaning stuff out.


    I do appreciate your replies though. Always good to hear from someone that actually knows what they are talking about. :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The CLSID (the characters inbetween the {} ) does indicate Zango. But it is not a high severity issue in my book. It may be worth having you run a few scans though epecially ones that will fix things. I suggest you run the below two tools.

    AVG Anti-Spyware - The following link explains how to use AVG Antispyware: Running AVG Anti-Spyware Let it Quarantine or Deletye what it finds.

    SpyBot - Search & Destroy
    • PLEASE leave all settings at default!!!! Install, do the search for updates now and get any updates, then fix the below problem with Spybot default products. If you get an error message about "bad checksum" when trying to update, just choose a different server location. Also look for the Immunize feature in Spybot and use it. Do not use the Teatimer function. It can be a resource hog and also makes removal of certain problems more difficult. Make sure you leave the SDhelper ( IE bad download blocker) checked to install (this is the default).
    • Fixing SpyBot's Ignore Products Bug: Please run SpyBot and get into the Advanced mode by selecting Mode and then Advanced mode. Then select Settings and the in the left column select Ignore Products. In the right window pane make sure the All products tab is selected. Then in that window, right click your mouse and choose "Deselect all". Now run a scan and save a log of what it reports when finished by right clicking in the windows and saving the log.
    Attach logs from the above two scans. See: HOW TO: Attach Items To Your Post
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds