Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Need a little advice... (part 2)

[Fixed] Hijackthis! Logs - [Resolved] Need a little advice... (part 2) posted in the Security & Safety forums; Hi again guys. . . . I'm back with some more problems,, but more serious this time... Cant understand why none of the other apps that i used over the ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-23-2006
notech's Avatar
Bronze Member
My PC
 
Join Date: Oct 2006
Location: Ireland
Posts: 39
PC Experience: Some Experience
notech - See this Members User comments on their Profile page
Send a message via MSN to notech
Default [Resolved] Need a little advice... (part 2)

Hi again guys. . . .

I'm back with some more problems,, but more serious this time...

Cant understand why none of the other apps that i used over the last while didn't pick these files up,, maybe someone can enlighten me. . . .


I was under the impression that everything should have been ok after the [fixed] HijackThis! Log that i posted the other day was "clear"
After some advice from a friend i installed CounterSpy to have look at my system. After coming up clean with all of the other apps that i've used, i was somewhat surprised when it found the following > > > >

GunnSpy v0.52 Backdoor

RePass Password Cracker/Stealer

I-Spy (the_seed) Password Cracker/Stealer

Pretty serious problems i would think. . . .
Ive got them in quarantine at the moment and need some advice on the safest way to remove them completely...
Ive enclosed the log from CounterSpy and a fresh HJT log also...
The FunWeb i can deal with,, i just left it there for the moment, as that's not my main priority right now. However all advice and help will be greatly appreciated...

CounterSpy log > > > >


Spyware Scan Details
Start Date: 21/11/2006 22:31:14
End Date: 21/11/2006 22:59:36
Total Time: 28 mins 22 secs

Detected spyware

FunWebProducts Potentially Unwanted Program more information...
Details: Fun Web Products bundles adware software in its products.
Status: Ignored

Infected files detected
C:\WINDOWS\system32\f3PSSavr.scr

Infected registry entries detected
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings \Yahoo\BuddyIcons\notech_1\notech_1 YourIcon none
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings \Yahoo\Friends\notecha1 MessageCount 6
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings \Yahoo SessionCount 1
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings \Yahoo SessionTimestamp 7795669
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings UID 2A9A78BD-775A-4E1E-BE6F-563816307349
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings BinParam234
HKEY_CURRENT_USER\SOFTWARE\FunWebProducts\Settings BinParam129


MyWebSearch Toolbar Potentially Unwanted Program more information...
Details: MyWebSearch Toolbar is a customizable Internet Explorer search toolbar with various other tools.
Status: Ignored

Infected registry entries detected
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\ProgID MyWebSearch.HTMLPanel.1
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}\VersionIndependentProgID MyWebSearch.HTMLPanel
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} MyWebSearch HTML
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} My &Web Search
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\ProgID MyWebSearchToolBar.ToolbarPlugin.1
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}\VersionIndependentProgID MyWebSearchToolBar.ToolbarPlugin
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} MyWebSearch Toolbar Plugin
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\MiscStatus\1 132497
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\ProgID FunWebProducts.DataControl.1
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A}\VersionIndependentProgID FunWebProducts.DataControl
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} DataCtrl Class
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\ProgID MyWebSearch.PseudoTransparentPlugin.1
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}\VersionIndependentProgID MyWebSearch.PseudoTransparentPlugin
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} MyWebSearch Pseudo Transparent Plugin
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus\1 131473
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}\MiscStatus 0
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} MyWebSearch Popup Menu Plugin
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} HttpControl Class
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}\ProxyStubClsid32 {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} _IDataCtrlEvents
HKEY_CLASSES_ROOT\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
HKEY_CLASSES_ROOT\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{1F52A5FA-A705-4415-B975-88503B291728}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{1F52A5FA-A705-4415-B975-88503B291728} IDataCtrl
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} IMyWebSearchHTMLPanel
HKEY_CLASSES_ROOT\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
HKEY_CLASSES_ROOT\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{3E720453-B472-4954-B7AA-33069EB53906}\ProxyStubClsid32 {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{3E720453-B472-4954-B7AA-33069EB53906} _IMyWebSearchHTMLPanelEvents
HKEY_CLASSES_ROOT\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9} IMyWebSearchPseudoTransparent
HKEY_CLASSES_ROOT\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9} IMyWebSearchPopupMenu
HKEY_CLASSES_ROOT\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9} IMyWebSearchSkinWindow
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} IHttpControl
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}\ProxyStubClsid32 {00020420-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F} IHttpControlEvents
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel\CLSID {3E720452-B472-4954-B7AA-33069EB53906}
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel\CurVer MyWebSearch.HTMLPanel.1
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel MyWebSearch HTML Panel
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin\CLSID {7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin\CurVer MyWebSearch.PseudoTransparentPlugin.1
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin MyWebSearch Pseudo Transparent Plugin
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin.1
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin.1\CLSID {7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlu gin.1 MyWebSearch Pseudo Transparent Plugin
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin \CLSID {53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin \CurVer MyWebSearchToolBar.ToolbarPlugin.1
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin MyWebSearch Toolbar Plugin
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin .1
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin .1\CLSID {53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin .1 MyWebSearch Toolbar Plugin
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1\CLSID {3E720452-B472-4954-B7AA-33069EB53906}
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 MyWebSearch HTML Panel


GunnSpy v0.52 Backdoor more information...
Details: GunnSpy is a Backdoor Trojan that steals the user information and mail it to a pre-defined e-mail address.
Status: Quarantined

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 1
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Folder0 C:\Documents and Settings\Deco\Desktop
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 4096


RePass Password Cracker/Stealer more information...
Details: Repass is a hidden trojan which run's on the vicitm's machine without his/her consent.
Status: Quarantined

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 1
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Folder0 C:\Documents and Settings\Deco\Desktop
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 4096


I-Spy (the_seed) Password Cracker/Stealer more information...
Details: I-Spy is a kind of spyware that capture passwords of Dialup, cached, mail, network and mozilla in a text file and upload that file automatically to the pre-defined web address.
Status: Quarantined

Infected registry entries detected
HKEY_CURRENT_USER\Software\NirSoft\MessenPass
HKEY_CURRENT_USER\Software\NirSoft\MessenPass ShowGridLines 1
HKEY_CURRENT_USER\Software\NirSoft\MessenPass SaveFilterIndex 0
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Folder0 C:\Documents and Settings\Deco\Desktop
HKEY_CURRENT_USER\Software\NirSoft\MessenPass WinPos
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Columns
HKEY_CURRENT_USER\Software\NirSoft\MessenPass Sort 4096



Again,, thanks in advance for any help received. . . .
Attached Files
File Type: log hijackthis.log (8.5 KB, 1 views)


  #2  
Old 11-23-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,734
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Hi notech.

MessenPass is a password recovery tool that reveals the passwords of several instant messenger applications. I cannot confirm this yet, but it should be a legitimate application. MessenPass can only be used to recover the passwords for the current logged-on user on your local computer. It cannot be used for grabbing the passwords of other users.

CounterSpy detected this application as GunnSpy v0.52 Backdoor,RePass Password Cracker/Stealer andI-Spy (the_seed) Password Cracker/Stealer.


Hold on which I contact Sunbelt and see what they have to say about this. It may be a false positive for all we know. Meanwhile, let's deal with MyWebSearch.

1) Click on Start, Settings, Control Panel
2) Double click on Add/Remove Programs
3) Find "My Web Search" in the list of installed programs and click on Change/Remove to uninstall it. You may also want to uninstall any of the following items associated with FunWebProducts.
  • My Web Search (Smiley Central or FWP product as applicable)
  • My Way Speedbar (Smiley Central or other FWP as applicable)
  • My Way Speedbar (AOL and Yahoo Messengers) (beta users only)
  • My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
  • Search Assistant - My Way
6) Next, open My Computer, Drive C, and double-click on the Program Files folder
7) Right-click and delete the folders for:
  • FunWebProducts
  • MyWebSearch


  #3  
Old 11-23-2006
notech's Avatar
Bronze Member
My PC
 
Join Date: Oct 2006
Location: Ireland
Posts: 39
PC Experience: Some Experience
notech - See this Members User comments on their Profile page
Send a message via MSN to notech
Default

Cheers mate,, thanks for your input...

Lets hope it's a false positive then...

I've sorted the MyWebSearch problem,, or rather CounterSpy sorted it for me because there was nothing in add/remove programs or any folders containing MyWebSearch in program files. But CounterSpy found a heap of registry strings and removed them...
It seems like a good program but it's one hell of a resource hog!!

My "other half" had smiley central installed sometime ago and i removed it so i reckon that's where MWS came from in the first place...

So i'll await your next reply to see what feedback you got from SunBelt regarding those other files,, before doing anything with them...


  #4  
Old 11-24-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,734
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Sure thing, it could be mere hours or numerous weeks before they respond though.


  #5  
Old 11-24-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,734
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Speak of the devil! I have just gotten a reply from Eric L. Howes from Sunbelt Software:
CounterSpy does target MessenPass because it can be used for malicious
purposes. Also, many malicious application re-use components of
MessenPass -- that's why other applications can come up in the
detections.

That said, we will try to consolidate all the MessenPass traces under
the MessenPass threat, which you can then tell CounterSpy to "Always
Ignore." This consolidation won't occur until the next definitions
release for CounterSpy.
It is up to you whether you want to uninstall it. You can do it via Add/Remove Programs.


  #6  
Old 11-24-2006
notech's Avatar
Bronze Member
My PC
 
Join Date: Oct 2006
Location: Ireland
Posts: 39
PC Experience: Some Experience
notech - See this Members User comments on their Profile page
Send a message via MSN to notech
Default

Ok,, cheers for your time and help mate. . . .

I think i'll hold on to it for now and just keep them 3 files in quarintene
till i make up my mind on weather to keep or get rid of it...

Tanx again...


  #7  
Old 11-25-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,734
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

You're always welcome.

For malware prevention tips, look no further than here:
http://www.pchelpforum.com/hijackthi...afterwork.html


Good luck, and see you around the forum.



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 04:08 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top