Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 12th, 2004, 03:12 PM
bch
 
Posts: n/a
Default SpySweeper False Positive

Downloaded the Google Toolbar a few days ago. A scan with SpySweeper is flagging the Google Toolbar falsely as BrowserVillage Sidebar. An example of one of the CLSIDs it wants to delete is AA58ED58-01DD-4D91-8333-CF10577473F7. Checked this on Tony Klein's BHO list and it is associated with the Google Toolbar and not BrowserVillage Sidebar.

Also scanned with AdawareSE, Spybot, PestPatrol, SpySubtractPro, and AOL Spyware Protection. The programme BHO Demon is correctly showing the Google Toolbar and not BrowserVillage Sidebar.

Have emailed Webroot's UK office and have just advised them on their Support page.

This is for information in case anyone else is troubled with this false positive.
  #2  
Old September 13th, 2004, 03:03 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

SpySweeper also found Marketscore on my machine. I went to Start/Search/All Files and Folders and typed in Marketscore. It found an Internet Explorer shortcut to Marketscore which had not been on my machine prior to updating the definitions from SpySweeper. I deleted this and SpySweeper stopped flagging it.

Ironically, I have been running SpySweepers's IE Favourites Shield and know for a fact that I did not add Marketscore to my IE Favourites list. I am the only user of this machine. It was definitely not on my machine prior to updating the definitions from SpySweeper.

(I have posted this on the other thread concerning SpySweeper.)
  #3  
Old September 13th, 2004, 03:02 PM
azumi21's Avatar
azumi21 azumi21 is offline
Regular Poster
 
Join Date: Aug 2004
Posts: 129
Default Re: SpySweeper False Positive

Quote:
Originally Posted by bch
Downloaded the Google Toolbar a few days ago. A scan with SpySweeper is flagging the Google Toolbar falsely as BrowserVillage Sidebar. An example of one of the CLSIDs it wants to delete is AA58ED58-01DD-4D91-8333-CF10577473F7. Checked this on Tony Klein's BHO list and it is associated with the Google Toolbar and not BrowserVillage Sidebar.

Also scanned with AdawareSE, Spybot, PestPatrol, SpySubtractPro, and AOL Spyware Protection. The programme BHO Demon is correctly showing the Google Toolbar and not BrowserVillage Sidebar.

Have emailed Webroot's UK office and have just advised them on their Support page.

This is for information in case anyone else is troubled with this false positive.

i wouldn't trust a google toolbar installed on my browser (no matter what is is identified as). i would delete it.
  #4  
Old September 13th, 2004, 03:21 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,946
Default Re: SpySweeper False Positive

Quote:
Originally Posted by azumi21
i wouldn't trust a google toolbar installed on my browser (no matter what is is identified as). i would delete it.

There's nothing wrong with the Google toolbar; in fact it's one application I couldn't do without...

A glaring False Positive indeed, and I reckon SpySweeper will hasten to correct it...
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #5  
Old September 13th, 2004, 03:35 PM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

Thank you for your responses and I have to agree with Tony Klein about the Google Toolbar. (Your BHO Demon is an excellent programme and I'm pleased I've had the opportunity to tell you that.) I haven't heard anything from SpySweeper. On checking, they haven't opened the ticket left on their support forum. I'm sure the matter will be resolved but am still curious as to how the Marketsco IE Shortcut got onto my machine.
  #6  
Old September 14th, 2004, 06:25 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

Just updated the latest definitions from SpySweeper and the programme is no longer flagging BrowserVillage Sidebar so the matter has been resolved. Its still flagging Marketscore but no doubt this will be resolved in due course.
  #7  
Old September 14th, 2004, 07:28 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

Apologies, Tony Klein. I have just realised that you are not the author of the BHODemon programme but rather the BHO List.
  #8  
Old September 15th, 2004, 05:17 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

Received an email from SpySweeper instructing me to upgrade from version 3 to version 3.2.0 (Build 146) Spyware Definitions 383. (Another 12 months updates thrown in). Having done another scan it now doesn't flag Marketscore but it flags the Google Toolbar again but, this time, as WebSearch Toolbar. Scanned with PestPatrol and SpySubtractPro which found nothing plus I simply do not have WebSearch Toolbar on this machine or the associated files that come with it.

I've emailed SpySweeper again with this information so they can look into it.
  #9  
Old September 15th, 2004, 05:25 AM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: SpySweeper False Positive

I wonder why the definitions is 383.
Mine says as in the screenshot.

Gerard
Attached Images
 
__________________
25 forum posting etiquette tips
  #10  
Old September 15th, 2004, 06:42 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

gerardwil.

Definitely says 383 in respect of version 3.2.0.
  #11  
Old September 15th, 2004, 06:50 AM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: SpySweeper False Positive

Quote:
Originally Posted by bch
gerardwil.

Definitely says 383 in respect of version 3.2.0.

OK, lets say it different: I wonder why mine says 504 if that makes any difference.
__________________
25 forum posting etiquette tips
  #12  
Old September 15th, 2004, 07:01 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

gerardwil.

Tried to post a screenshot but I must have to be a fully fledged member before I have that facility. Have checked the webroot site and it is showing version 3.2.0 as the latest version. You might try the Options section in SpySweeper and clicking on "Update Programme" to see if you can get the latest version.
  #13  
Old September 15th, 2004, 07:09 AM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: SpySweeper False Positive

Ofcourse I did that and it says I have the latest version.
Also I asked webroot and they give me very fast a ticket, but that is still open for about 5 days
Cheers,

Gerard
__________________
25 forum posting etiquette tips
  #14  
Old September 17th, 2004, 07:49 AM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Default Re: SpySweeper False Positive

Today my ticket is gone without giving me any answer

Am still having 3.1.0.134 and used spywaredefinitions : 504

Trying to update it keeps saying: you have most recent definitions.



Gerard
__________________
25 forum posting etiquette tips
  #15  
Old September 17th, 2004, 08:05 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

gerardwil.

Seems they roll out updated versions of the programme to new customers first. If you go to http://support.webroot.com/ics/suppo...asp?deptID=776 you can request the updated version.

Hope this is of help but just ignore it if you have already done this.
  #16  
Old September 17th, 2004, 08:50 AM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,257
Default Re: SpySweeper False Positive

Hi Gerard

Here's a direct Link to the Webroot updatepage, unfortunately Webroot is not quick to ad the newest builds ( mine is 3.2.0 build 142 definitions 395) to the update server, so we have to check the forums and help each other out.

Regards
__________________
Errare humanum est
  #17  
Old September 17th, 2004, 08:55 AM
bch
 
Posts: n/a
Default Re: SpySweeper False Positive

Downloaded the latest definitions (numbered 395) and SpySweeper is no longer flagging the Google Toolbar as some other toolbar.
  #18  
Old September 19th, 2004, 02:08 AM
gerardwil gerardwil is online now
Massive Poster
 
Join Date: Jan 2004
Posts: 4,507
Thumbs up Re: SpySweeper False Positive

Hi,

Just to let you know that Webroot e-mailed me the solution. They send me a link to download another copy of Spy Sweeper. Installed it and now says: version 3.2 (build 146) spyware definitions 397.
New expire date september 19 2005.
So I am happy now again

Gerard
__________________
25 forum posting etiquette tips
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:13 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums