PestPatrol false alarm CWS.GoogleMS.3 xxxtoolbar.com

Discussion in 'other anti-malware software' started by FanJ, Feb 15, 2004.

Thread Status:
Not open for further replies.
  1. FanJ

    FanJ Guest

    PestPatrol gives a false positive:

    Pest: CWS.GoogleMS.3
    Pest Info: Category: Adware Background Info: Click here
    File Info: In Registry: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\zonemap\domains\xxxtoolbar.com
    Certainty: Confirmed Threatens: Confidentiality, Liability Risk: Moderate - this file can be executed! Advice: Delete or ignore
    Action: Ignored

    The reason that it is a false positive, is this:
    That registry item has dword 4.
    That registry item is placed there by IE-SPYAD from Eric Howes.
    It takes care of putting that domain in the Restricted Zone of Internet Explorer.

    The PestPatrol company has been informed very recently.

    I hope that PestPatrol will also check the dword for such things.

    See for example the following two threads at Wilders:
    http://www.wilderssecurity.com/showthread.php?t=16688
    And
    http://www.wilderssecurity.com/showthread.php?t=17490
     
  2. Goon_Boy

    Goon_Boy Registered Member

    Joined:
    Apr 22, 2002
    Posts:
    1
    As of 12 July 2004, PestPatrol is still coming up with this false positive. Dell now has a link to PP's "online scanner" via their support site, and utilization of this "feature" yields the false positive. The problem is compounded by the fact that Dell's linked version doesn't allow one to see the details of this alleged malware or actually effect repairs - one is instead routed to a "Buy this product NOW!" hustle, which will probably be a good thing (for Dell and PP, anyway), because anyone using the online scanner will be convinced they're infected with any one of a number of insidious Porn Bots, and will be tripping over themselves in their haste to..."Buy this product NOW!"

    Exceptionally low class hucksterism, Dell and PestPatrol. You should both be ashamed of yourselves.
     
  3. cezar

    cezar Guest

    Are there any of you who can tell me where i can post my Pestpatrol log so i can find out if the are false posetive. the one i have in my evalaution version of pestpatrol is: InternetAlert, 6 BonziBuddy and 2 win32 Ghost keylogger.c i got when i listen to one of the guru`s from a firewall company`s forum with bad 5.0 upgrade and download something call Bazooga Ad-aware and Spyware 1.12 remover, i don`t think what the keykooger is a false posetive but any way i want them all remove from my pc.


    Kind regards
    Cezar
     
  4. cezar

    cezar Guest

    I run an online scan on the pestpatrol website and it find no pest my pc was clean mebe it is bug in the evaluetion version of pestpatrol ?


    Kind regards
    Cezar
     
  5. nadirah

    nadirah Registered Member

    Joined:
    Oct 14, 2003
    Posts:
    3,647
    Pestpatrol is very popular for giving false positives non-stop. :rolleyes:
    Get programs like Ad-aware and Spybot-S&D, they are much better than pestpatrol. ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.