Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 7th, 2009, 12:08 AM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Need info on Spyware Cease

My grandmother called me today saying her computer is broken (again). Apparently she downloaded some sort of registry cleaning/fixing software that came with Spyware Cease (or vice versa). She was in the middle of scanning her computer with these programs, they had found some problems, she minimized the window and then I guess her computer locked up. She says she rebooted it about six times. I'm not sure if it's her whole computer that isn't working correctly or just AOL (she's very confusing). I know she said she couldn't get AOL to work. She also said these products were recommended by AOL (whatever that means). For all I know, she could've seen an advertisement on AOL's website.

Does anyone know anything about Spyware Cease and a registry program that might come with it? I've tried searching about this product but it looks like some people think it's legitimate and others think it's not. So I don't know what to think. It might help my grandmother's computer problem if I knew a little more about these programs.
  #2  
Old August 7th, 2009, 12:13 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Need info on Spyware Cease

It's a rogue.
http://www.malwarebytes.org/malwaren...e.SpywareCease

http://www.malwarebytes.org/malwarenet.php
  #3  
Old August 7th, 2009, 12:19 AM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Need info on Spyware Cease

Edited.
*** I see Franklin found it listed as a rogue before I posted.
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.
  #4  
Old August 7th, 2009, 12:43 AM
prairie dog's Avatar
prairie dog prairie dog is offline
Regular Poster
 
Join Date: Jun 2009
Posts: 129
Default Re: Need info on Spyware Cease

Have a look at this spybot S&D thread. I would get it off her system
__________________
Avira Antivir Personal and MBAM Pro
Firewall-online armor premium
on demand:Hitman Pro and SAS
FF3-noscript, adblock plus, keyscrambler, Betterprivacy, TrackMeNot and WOT
Sandboxie
  #5  
Old August 7th, 2009, 03:03 AM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Need info on Spyware Cease

Thanks. I'll get that off as soon as I can. I have a couple more questions though.

I noticed that this program will scan a computer for threats but won't remove them unless you pay for the full program. So since she says her computer locked up and AOL won't work, does that sound like she probably paid for it and it removed some important files? If that's the case and I can't get into windows, should I boot into safe mode and use the "last known good configuration" option? Or should I use system restore? I've removed a program like this from her computer before, but that's before the full program was installed and so it didn't do any real damage.

I guess I should mention that her computer is Win XP.
  #6  
Old August 7th, 2009, 03:09 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Need info on Spyware Cease

in safe mode with networking download a copy of malwarebytes and remove this faker
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #7  
Old August 7th, 2009, 04:25 AM
chris1341's Avatar
chris1341 chris1341 is offline
Frequent Poster
 
Join Date: Apr 2008
Location: Scotland
Posts: 624
Default Re: Need info on Spyware Cease

Quote:
Originally Posted by ohblu
Thanks. I'll get that off as soon as I can. I have a couple more questions though.

I noticed that this program will scan a computer for threats but won't remove them unless you pay for the full program. So since she says her computer locked up and AOL won't work, does that sound like she probably paid for it and it removed some important files? If that's the case and I can't get into windows, should I boot into safe mode and use the "last known good configuration" option? Or should I use system restore? I've removed a program like this from her computer before, but that's before the full program was installed and so it didn't do any real damage.

I guess I should mention that her computer is Win XP.

I looked at this before I'm not sure it contains malicious code just produces a huge amount of FP's to try and force the gullible to buy.

It maybe some of the FP's that have been removed by the programme are important files and that's causing the lock ups.

It's a good example of why every good security set up needs decent imaging software to replace infected systems with a clean backups.

If you don't have that system restore might let you roll back to a pre-install state.

If it is the Spyware Cease itself that causing the issues Jmonge is right MBAM is excellent at cleaning up after this particular rogue.

Cheers
__________________
Chris
  #8  
Old August 7th, 2009, 04:43 AM
Franklin's Avatar
Franklin Franklin is offline
Very Frequent Poster
 
Join Date: May 2005
Location: West Aussie
Posts: 2,517
Default Re: Need info on Spyware Cease

Can anyone find it listed as a download at Softpedia? If not then just having the award posted at their site qualifies it as a rogue.

Name:  Soft.JPG
Views: 421
Size:  18.1 KB
  #9  
Old August 7th, 2009, 06:21 AM
gery gery is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 1,646
Default Re: Need info on Spyware Cease

WOT reports the site as poor reputation but Norton 360 says it is clean wonder why this is ok with Norton
__________________
Windows Vista Home Premium
AVG IS SAS Pro
The Lord is my Shepherd i shall not want Psalm 23;1
  #10  
Old August 7th, 2009, 06:35 AM
Retadpuss's Avatar
Retadpuss Retadpuss is offline
Suspended Member
 
Join Date: Apr 2009
Posts: 226
Default Re: Need info on Spyware Cease

it is a rogue.
  #11  
Old August 7th, 2009, 06:36 AM
gery gery is offline
Very Frequent Poster
 
Join Date: Mar 2008
Posts: 1,646
Thumbs down Re: Need info on Spyware Cease

is there something wrong with Norton then?
AVG also does not mark it as bad
__________________
Windows Vista Home Premium
AVG IS SAS Pro
The Lord is my Shepherd i shall not want Psalm 23;1

Last edited by gery : August 7th, 2009 at 06:51 AM.
  #12  
Old August 7th, 2009, 06:54 AM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,301
Default Re: Need info on Spyware Cease

Quote:
Originally Posted by gery
is there something wrong with Norton then?
I think it's more to do with a classification issue. Norton analysts probably determined there's no malicious code in the file. I note there doesn't appear to be a category for fraudulent/rogue software at Norton Safe Web.

Last edited by TonyW : August 7th, 2009 at 07:14 AM.
  #13  
Old August 7th, 2009, 08:26 AM
andyman35 andyman35 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 2,270
Default Re: Need info on Spyware Cease

Quote:
Originally Posted by Franklin
Can anyone find it listed as a download at Softpedia? If not then just having the award posted at their site qualifies it as a rogue.

Attachment 211089
No mention of it on Softpedia they obviously just nicked the 100% award logo.

In other respects this would appear to belong to the class of rogue that actually has some real functionality mixed in with the dodgy FPs,which probably keeps it hovering within the grey area.

Last edited by andyman35 : August 7th, 2009 at 08:31 AM.
  #14  
Old August 7th, 2009, 08:45 AM
Keyboard_Commando's Avatar
Keyboard_Commando Keyboard_Commando is offline
Frequent Poster
 
Join Date: Mar 2009
Posts: 682
Default Re: Need info on Spyware Cease

http://www.spywareremoversolution.com/ Seems to be a promotional site to a bunch of crapware, including Spyware Cease.

Has no warning from WOT even though it is giving positive reviews to a bunch of rogue applications. http://www.spywareremoversolution.co...easereview.php

WOT users report them.
  #15  
Old August 7th, 2009, 09:28 AM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Need info on Spyware Cease

k9 blocked this page
http://127.0.0.1:2372/blockpage?id=288
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #16  
Old August 7th, 2009, 11:03 AM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,301
Default Re: Need info on Spyware Cease

Quote:
Originally Posted by jmonge
That'll be your own block page for the domain which we can't see; K9 does have it listed under the Spyware/Malware Sources category, which is why it's blocked for you.
  #17  
Old August 7th, 2009, 11:14 AM
simisg's Avatar
simisg simisg is offline
Frequent Poster
 
Join Date: Nov 2008
Posts: 390
Default Re: Need info on Spyware Cease

i have microsoft security essentials in my pc and not detect this rogue and others.....from this site http://www.spywareremoversolution.com/ why microsoft alow these rogues ?? its all about money ? malwarebytes detects all as rogues......and wot says red sites.....
  #18  
Old August 7th, 2009, 12:07 PM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,301
Default Re: Need info on Spyware Cease

Quote:
Originally Posted by simisg
why microsoft alow these rogues ?? its all about money ? malwarebytes detects all as rogues......and wot says red sites.....
Some AVs are better than others at detecting rogues as rogues. Many of these files are clean; if you submit for analysis, some virus analysts will tell you the files don't contain malicious code, and they often don't. They need more analysis and the applications looked into in more detail as to what they're trying to do. Trouble is there's so many out there now and they look authentic with one goal in mind: to try and extract your hard earned cash to fix what they claim are viruses or system errors. This is why they're rogues.
  #19  
Old August 7th, 2009, 09:55 PM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Need info on Spyware Cease

I got it fixed using System Restore.

She says she bought a program called Registry Easy for $10 that came with Spyware Cease. She says she never scanned the computer with Spyware Cease, only with Registry Easy. It was during the scan with Registry Easy that the computer locked up. When I started it in normal mode, it was super slow then froze. Hijack This showed that Spyware Cease was a running process and installed in the Program Files folder. Other than that, there was no other indications of malware.

Is Registry Easy considered rogue software too? If so, is there anyway to get her $10 back?
  #20  
Old August 7th, 2009, 10:04 PM
Toby75's Avatar
Toby75 Toby75 is offline
Frequent Poster
 
Join Date: Mar 2006
Posts: 461
Default Re: Need info on Spyware Cease

Guess it's real easy to get a McAfee secure seal these days. Just give 'em $1800/yr and you can get the seal even if your product is a rogue. Isn't that just friggin wonderful.
Attached Thumbnails
Click image for larger version

Name:	Untitled.jpg
Views:	6
Size:	97.6 KB
ID:	211120  

  #21  
Old August 7th, 2009, 11:52 PM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Need info on Spyware Cease

ohblu,
I don't know if Registry Easy is a rogue but apparently they are looking for developers! Seriously.
I see the website has a "McAfee Secure" logo at the top right corner just like in Toby's screenshot.


http://www.registryeasy.com/about-us.php

Evidently A-Squared detected them as malware and d-listed them earlier this year.

http://forum.emsisoft.com/Default.aspx?g=posts&t=4303


In June IObit Security 360 classified it as a rogue.

http://forums.iobit.com/showthread.php?t=2976

So there are two conflicting opinions on whether Registry Easy is malware/a rogue or not.
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.

Last edited by the Tester : August 8th, 2009 at 12:11 AM.
  #22  
Old August 8th, 2009, 12:17 AM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Need info on Spyware Cease

She says she got it from a website called clkbank.com and paid $10. What are the thoughts on that? I'm trying to get information on this website. Registry Easy's website charges $34.95 so I want to make sure she didn't give out her credit card number to crooks.
  #23  
Old August 8th, 2009, 12:24 AM
JRViejo's Avatar
JRViejo JRViejo is offline
Global Moderator
 
Join Date: Jul 2008
Posts: 10,413
Default Re: Need info on Spyware Cease

ohblu, here's some info on that site: http://whois.domaintools.com/clkbank.com.
  #24  
Old August 8th, 2009, 12:38 AM
the Tester's Avatar
the Tester the Tester is offline
Very Frequent Poster
 
Join Date: Jul 2002
Location: The Gateway to the Blue Hills,WI.
Posts: 2,855
Default Re: Need info on Spyware Cease

Do you know when she bought the license for the program?
According to clickbank's policy she may be able to get a refund if it's within 60 days of purchase. Clickbank is evidently just a retail website.
Cheesesoft is the developer of both SpywareCease and Registry Easy.That's the connection for the two programs.


http://www.clickbank.com/return_policy.html
__________________
Windows 7 64 bit,Win Patrol Plus,Operamail, Bitdefender Plus AV 2013,gmx mail.

Last edited by the Tester : August 8th, 2009 at 12:44 AM.
  #25  
Old August 8th, 2009, 12:59 AM
ohblu ohblu is offline
Regular Poster
 
Join Date: Jul 2008
Location: Colorado
Posts: 78
Default Re: Need info on Spyware Cease

Ok. Thanks. She bought it sometime this week. But how can a refund be issued? I mean, usually when you purchase software, the sale is final. Also, what reason should she give them for wanting to get a refund? The software messed up her computer?
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:04 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums