Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 27th, 2003, 02:20 PM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,227
Default HTASTOP is a RAT?

I've just run PestPatrol with the latest update, and it's alerted in HTASTOP - as a trojan.

This is really hard to beleive, since I downloaded it from a link here at Wilders! It says SkdRemover 1.0 (whatever that is). PestPatrols Pest Verification Token is 1255152715.

Can anyone confirm or disprove this, please?
__________________
My Novel
  #2  
Old January 27th, 2003, 02:28 PM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Charlotte, NC
Posts: 3,122
Default Re:HTASTOP is a RAT?

lol!

My money's on "Another FP from our friends at PP!" Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #3  
Old January 27th, 2003, 02:35 PM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,227
Default Re:HTASTOP is a RAT?

Thanks, Pete - for a while there I thought I was in danger of either growing up or slipping back into reality.
__________________
My Novel
  #4  
Old January 27th, 2003, 02:43 PM
snowy
 
Posts: n/a
Default Re:HTASTOP is a RAT?



Checkout

echoing what Pete said.........the below may be of some interest.....it "MAY" be an aka for what you mentioned......not sure this is allowed....mods can remove if need be: I think there is "one" removal tool specifically for this trojan:......any AT should do it


Name: SkyDance
Aliases: SKD,
Ports: 4000 (port can be changed)
Files: Skydance2.16b.zip - 267,013 bytes Skydance2_20bf.zip - 292,637 bytes Skydance2.23b.zip - 296,332 bytes Skydance2_25bf.zip - 303,060 bytes Skydance2.29b.zip - Skyserver 2.16 beta release.exe - 163,840 bytes Skyserver 2.20 beta release.exe - 172,032 bytes Skydance 2.16 beta release.exe - 409,600 bytes Skydance 2.20 beta release.exe - 430,080 bytes Hskdl.dll - 36,864 bytes Skd.exe - Skd.dll - Skdl.dll - Mail.vbs - Activex-security-off.vbs - Starturl.vbs - Regkey.vbs - Regkey.txt - bytes
Created: April 2000
Requires: N/A
Actions: Remote Access
Among the information this trojans steals is a copy of all registrysettings.
Versions: 2.0, 2.01, 2.15b, 2.16b, 2.20b, 2.291b, 2.23b, 2.25b, 2.29b,
Registers: HLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Notes: Works on Windows 95, 98, ME and NT. Password = Skydance.
Country: N/A
Program: Written in C++.

  #5  
Old January 27th, 2003, 02:49 PM
Checkout's Avatar
Checkout Checkout is offline
Security Rhinoceros
 
Join Date: Feb 2002
Posts: 1,227
Default Re:HTASTOP is a RAT?

Thanks, Snowman. I'm running a TDS3 Deep Scan right now, and I'm pretty confident that it won't find a thing. I find it easier to believe TDS than PP...
__________________
My Novel
  #6  
Old January 27th, 2003, 03:03 PM
snowy
 
Posts: n/a
Default Re:HTASTOP is a RAT?



Checkout

you are always most welcome....by the ways..last year on another machine I ran htaStop an never noticed any adverse traffic...........
  #7  
Old January 27th, 2003, 03:13 PM
sig's Avatar
sig sig is offline
Frequent Poster
 
Join Date: Feb 2002
Posts: 716
Default Re:HTASTOP is a RAT?

HTASTOP if I remember correctly is produced by the BOClean folks. No, it's not a RAT and think about it, it's not good for business for an AT company to either produce or be accused of producing a RAT. I'd trust the BOClean people over PP anyday.

It is, however, if I recall correctly, not the first time I've seen reports that PP identifies a competitor's product (or a component thereof) as suspect.
  #8  
Old January 27th, 2003, 07:22 PM
ZZZ7 ZZZ7 is offline
Regular Poster
 
Join Date: Sep 2002
Posts: 52
Default Re:HTASTOP is a RAT?

http://www.nsclean.com/htastop.html

why even use a program like PP........its pathetic!
  #9  
Old January 27th, 2003, 10:05 PM
Tassie_Devils's Avatar
Tassie_Devils Tassie_Devils is offline
Global Moderator
 
Join Date: May 2002
Location: State Queensland, Australia
Posts: 2,504
Default Re:HTASTOP is a RAT?


I have used HTAStop for over 2 years now and have run literally dozens upon dozens of scans with TDS3, Spybot [when I got it a few weeks ago] and I even had *PestPatrol* for a while and not one single peep.

FALSE ALARM CONTROLLER, I WILL BET MY HOUSE KEYS ON IT.

__________________
I'm feeling much better now since all the other people in my head and I, are working as a team!
  #10  
Old January 27th, 2003, 10:20 PM
puff-m-d's Avatar
puff-m-d puff-m-d is offline
Massive Poster
 
Join Date: Jan 2006
Location: North Carolina, USA
Posts: 3,121
Default Re:HTASTOP is a RAT?

Hello all,

I agree that HTAStop is a false positive. I have been using it for over a year with both TDS and TrojanHunter, and neither one has ever alarmed on it.

I beleive the new version of PP has a problem with false positives. Patrick has been having a problem with PP alarming on parts of his SpyBot S&D and from what I have read PP does not seem to care to fix the problem as Patrick has been trying to get them to fix it for a while now...

Just my two cents worth ....

Regards,
Kent
__________________
Best regards,
Kent
  #11  
Old January 28th, 2003, 04:20 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Re:HTASTOP is a RAT?

False positive - no need to worry .

regards,

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 01:57 PM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums