PDA

View Full Version : spywareblastersetup34.exe is identified as EBlaster,commercial keylogger by X-Cleaner


bclabc
September 17th, 2005, 03:50 PM
spywareblastersetup34.exe is identified as EBlaster, a commercial keylogger by X-Cleaner Deluxe. This is new. See the Log from X-Cleaner below.

I let X-Cleaner delete the spywareblaster setup file and downloaded it once each from geek.com and download.com. X-Cleaner thought the newly downloaded spywareblaster setup file contained EBlaster as well each time.

I thought that SpywareBlaster support should contact X-Cleaner and see what is going on here. http://www.xblock.com

Thank you.

X-Cleaner Log:

20050915 224435 - INFO: Params : DEBUGLOG
20050915 224435 - INFO: Program: C:\Program Files\X-Cleaner\XCleaner_full.exe
20050915 224435 - Logging activated via reg setting
20050915 224435 - Starting: X-Cleaner Deluxe build 38576
20050915 224436 - Dataload:Begin
20050915 224436 - Dataload:Loading sigs from C:\Program Files\X-Cleaner\xc_sigs.dat
20050915 224436 - Dataloader: begin
20050915 224438 - Dataloader: end
20050915 224438 - Dataload:QuickScan:Items:1094
20050915 224439 - Dataload:DeepScan:Items:17932
20050915 224439 - Dataload:DeepScan:Version: 2005-9-14 14:52:18
20050915 224439 - Dataload:End
20050915 224439 - Loaded sigs externally
20050915 224439 - Internet Update test Begin
20050915 224439 - Internet Update test end
20050915 224443 - DeepScanEngine: FileDetect by Scan: 21982
20050915 224443 - DeepScanEngine: FileDetect: M:\downloads\spywareblastersetup34.exe
20050915 224444 - Detect V2:EBlaster
20050915 224444 - Detection Result:Detected EBlaster:
Files (1) :
M:\downloads\spywareblastersetup34.exe


20050915 224608 - FILEN:Del: File: M:\downloads\spywareblastersetup34.exe

Beefcarver
September 17th, 2005, 04:02 PM
you might have gotten a nasty in the download from those websites. Why dont you try to download the spywareblaster from where they made it at www.javacool.com and be safe. Try that and see if xcleaner finds it again.

There are no keyloggers in the spywarblaster program, somone on this forum advised to always download programs from the source of which it was made.
very solid advice I think.

bclabc
September 17th, 2005, 04:57 PM
Thank you for your suggestion.
I went to the official Javacool website which is
http://www.javacoolsoftware.com/spywareblaster.html. I followed the download links on their download page:

http://www.javacoolsoftware.com/sbdownload.html

I used Download.com and MajorGeeks
( I said Geek.com wrongly in the original post.)

From the SpywareBlaster download page:

SpywareBlaster 3.4 Download

Choose the nearest download site...
SpywareBlaster is freeware. Please consider donating to further our cause!

Please choose one of the following download locations:

> Download SpywareBlaster 3.4 from Download.com *Primary Download Location*
> Download SpywareBlaster 3.4 from MajorGeeks (USA and other locations)
> Download SpywareBlaster 3.4 from TechSpot
> Download SpywareBlaster 3.4 from Softpedia
> Download SpywareBlaster 3.4 from Net-Integration
> Download SpywareBlaster 3.4 from ct7support.com
> Download SpywareBlaster 3.4 through the Coral Distribution Network

Beefcarver
September 17th, 2005, 05:39 PM
sorry about that. Did you try to download from majorgeeks then enable all protections and try to update again? And retry the xclaner to see if it finds it again? It may be a false positive on xcleaner.

javacool
September 18th, 2005, 02:23 AM
-{ Quote: "spywareblastersetup34.exe is identified as EBlaster, a commercial keylogger by X-Cleaner Deluxe. This is new. See the Log from X-Cleaner below.

I let X-Cleaner delete the spywareblaster setup file and downloaded it once each from geek.com and download.com. X-Cleaner thought the newly downloaded spywareblaster setup file contained EBlaster as well each time.

I thought that SpywareBlaster support should contact X-Cleaner and see what is going on here. http://www.xblock.com

Thank you.
" }-

Hi and thank you for the heads-up. :)

Unfortunately, the problem will probably get fixed faster if you (the customer) contact X-Cleaner about the problem.

But it does indeed look like a false-positive.

Best regards,

-Javacool

bclabc
September 20th, 2005, 10:16 PM
I did report this issue to X-Cleaner and it has been fixed. X-Cleaner released new signagtures Monday that have removed spywareblastersetup.exe as a threat.