False positives from PestPatrol?

Discussion in 'other anti-malware software' started by ragna, Jul 25, 2004.

Thread Status:
Not open for further replies.
  1. Nick

    Nick Registered Member

    Joined:
    May 14, 2002
    Posts:
    187
    Location:
    California
    I ran the online scanner yesterday and got the same entry for VX2 that is there because IE Spyad put it in the restricted zone. I got another hit for something I forgot, but it was a killbit set by SpywareBlaster. There were a couple more results attributed to various protections that I use. So Pest Patrol remains false positive king for me.

    I will say that they don't add spyware, so I agree that someone better have proof before say that. They may suck, but they aren't malware pushers.
     
  2. Ronin

    Ronin Guest

    In my book, Pest patrol shouldn't count as a trustworthy scanner any more, given the insane levels of false positives unmatched by any other product.
    A level that has being consistently maintainined for years.

    Perhaps false positives work as goad to purchase?

    Time to remove them from http://www.spywarewarrior.com/rogue_anti-spyware.htm#trustworthy
    as a trustworthy scanner?
     
  3. dread

    dread Registered Member

    Joined:
    May 18, 2004
    Posts:
    195
    Lol thats a joke Ronin cuase of Perhaps false positives work as goad to purchase? Bs. They tell you it happens. You can sumbit you log and they will try to fix the false positives. Now I will say I am unhappy with techsupports response now these days they dont get back with as fast as they use to. But Perhaps false positives work as goad to purchase? bs read http://research.pestpatrol.com/Analyses/FalseAlarms.asp they know it happens and they tell you it will happen. Email them and tell them you want to be a beta tester and test for fasle alarms. And from what I see from these forums Spy Sweeper is just as bad about false positives and they dont have no system to reports false positives. So if you gonna sit here and say about removing pp for false positives as goad to purchase you need to include Spy Sweeper cuase its just as bad.
     
  4. FanJ

    FanJ Guest

    Hi Dread,

    Thanks for that link !
    I didn't know that that page existed at the PP-site :oops:

    (I hope it will be maintained and will give correct info ;) ).
     
  5. ragna

    ragna Registered Member

    Joined:
    Apr 15, 2004
    Posts:
    12
    Location:
    Belgium
    And they did!
    They told me that the last set of scan strings they released had quite a few false alarms. But they just released new ones that should have resolved most of the issues and that i should run PPUpdater.
    I did and i am glad that indeed these false positives are gone :) .
    Although it seems that i now have another , but not certain. Gonna take a closer look at it later when i have some time.
    Still glad that the support of Pestpatrol answered my email ---> perhaps the program has false positives but luckily it has also good support it seems ;) .
     
  6. Ronin

    Ronin Guest

    Dread, nice to see the no 1 fan of Pest Patrol is still around. Still holding strong in your faith despite the setbacks?

    Actually that was the term used by the page I referenced, it was not my phrase. I advance it has a possibility only because the number and frequently of FPs are so high.

    Funny, this link isn't more widely known. I supposed the No1 Pest Patrol fan like yourself would know about it. But the rest of us wouldn't. So it might indeed still accomplish it purpose of scaring newbies.

    Sigh, I have being testing Pest Patrol on and off for months, and never once did it give me zero-false positive. Not once. Typically, it says I have about 5-10 pieces of adware and keyloggers and the type detected keeps changing. I guess there must be a really busy hacker on my computer :p
    Yes, Spy sweeper is almost but not quite as bad. But we are talking abt Pest Patrol here.

    It's a very weak defence if your only defence is to point out that another product is just as bad lol.

    BTW I know even Spybot ,ad-aware is not immune to false positives. Typically I get about 1 every time and that is with beta signatures! That is loads better than Pest Patrol.
     
  7. ragna

    ragna Registered Member

    Joined:
    Apr 15, 2004
    Posts:
    12
    Location:
    Belgium
    Ok, this seems be to a neverending story ;) . I updated the program, ran another scan, and some of the former entries are gone now. But... here are some other entries no other anti-spyware program can find:

    - NetSpy KeyLogger: C:\Windows\uninst.exe :eek: (this seems weird cause it is from InstallShieldCorporation)

    - MC 30 Day: C:\Program Files\RealAlternative\RealMedia Browser (i am quite certain this is a fp, cause a friend of mine told me that this has been known as a fp)

    - System Soap Pro (at several places)

    - Save Now: C:\Windows\Lastgood\System32\msvcirt.dll (but this is from Microsoft Corporation!! :eek: )

    - BonziBuddy: C:\Windows\Lastgood\speech\... (several .dll there) (all MS Corporation too)

    I send the log again to Pestpatrol, but submit the files here because they might be helpful for others.
     
  8. Devinco

    Devinco Registered Member

    Joined:
    Jul 2, 2004
    Posts:
    2,524
    Hi Ragna,

    It may be a false positive, but if it is really a BonziBuddy component, then it would be good to get rid of.
    That's what I don't like about PP, you can't trust it and always have to double check everything.
     
  9. ragna

    ragna Registered Member

    Joined:
    Apr 15, 2004
    Posts:
    12
    Location:
    Belgium
    Now you 've got me scared :( !
    How do i know if these are false or real alarms!?
    Anxious waiting on an answer on my email to Pestpatrol, or is there someone here who could help... ;)
     
  10. tImEwArP

    tImEwArP Guest

    Well, i am also getting that Netspy keylogger in C:\WINDOWS\uninst.exe. I've seen others list it as well, so i'm pretty sure it's a FP. But i'm not getting any of the others you listed Ragna.

    I am getting VX2 (4 entries found in registry) though, along with Netspy keylogger. It may depend on whether you have programs like IE-Spyad, SpywareBlaster, a host file, ect... I pretty sure VX2 is caused by IE-Spyad.
     
  11. Bonzifriend

    Bonzifriend Guest

    Hmm this is Bonzi Buddy we are talking about right not some stealthy keylogger?

    One would think that if one was really infected by it, one would know with all the popups and ads?

    So maybe to be charitable Pest patrol is picking up on some harmless left over residue?
     
  12. icio

    icio Guest

    OS: Windows XP
    Product Edition: Evaluation
    PestPatrol version: 07/06/2004 4.4.3.24
    PPServer.dll version: 26/01/2003
    PPMemCheck version: 02/04/2004
    PestPatrolCL version: 07/06/2004 4.4.3.19
    PPUpdater version: 03/05/2004 4.4.3.36
    PPfile.dat version: 11/08/2004
    PPInfo.dat version: 11/08/2004
    Spyware.dat version: 11/08/2004

    Pests found:
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\clsid\{71a2702f-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\clsid\{71a27032-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\clsid\{71a27034-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd2-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd4-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd5-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd6-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd7-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fd9-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fdb-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fdd-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fde-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe0-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe1-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe2-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe4-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe5-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe7-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{065e6fe8-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{62fcac31-2581-11d2-baf1-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a2702e-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a27031-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a27033-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a27036-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\typelib\{065e6fd1-1bf9-11d2-bae8-00104b9e0792},na,na,19/08/2004,00-00-00-00-00-00,ITA
    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\typelib\{71a2702d-c7d8-11d2-bef8-525400dfb47a},na,na,19/08/2004,00-00-00-00-00-00,ITA
    CGI-Bin Spyware Cookie,C:\Documents and Settings\Windows XP\Cookies\windows xp@cgi-bin[1].txt,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifctrl.anigif,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifppg.anigifppg,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifppg.anigifppg.1,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifppg.anigifppg\curver,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifppg2.anigifppg2,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifppg2.anigifppg2.1,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\anigifppg2.anigifppg2\curver,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\clsid\{61ab12e1-a5ff-11d1-b2e9-444553540000},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\clsid\{6dc82d15-92f2-11d1-a255-00a0c932c7df},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\clsid\{82351441-9094-11d1-a24b-00a0c932c7df},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\interface\{5252ac41-94bb-11d1-b2e7-444553540000},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\interface\{82351440-9094-11d1-a24b-00a0c932c7df},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Download Accelerator Plus,HKEY_LOCAL_MACHINE\software\classes\typelib\{82351433-9094-11d1-a24b-00a0c932c7df},na,na,19/08/2004,00-00-00-00-00-00,ITA
    GnucDNA,C:\WINDOWS\system32\gnucdna.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Grokster,HKEY_CLASSES_ROOT\appid\altnet signing module.exe|appid,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Grokster,HKEY_CLASSES_ROOT\appid\{8b0fef15-54dc-49f5-8377-8172de975f75},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Grokster,HKEY_CLASSES_ROOT\clsid\{e813099d-5529-47f4-9b37-4afafcb00a43},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Grokster,HKEY_CLASSES_ROOT\interface\{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Grokster,HKEY_CLASSES_ROOT\interface\{e813099d-5529-47f4-9b37-4afafcb00a43},na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_CURRENT_USER\software\kazaa,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\classes\appid\{8b0fef15-54dc-49f5-8377-8172de975f75},na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\in|b0seconds,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\in|b1,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\lastestimate|b,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\lastestimate|time,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\out|b0,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\out|b0seconds,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\bandwidth\out|b1,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\cloudload|sharedir,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\connectioninfo,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\connectioninfo|kazaanet,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\localcontent|databasedir,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa\localcontent|downloaddir,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa|listenport,na,na,19/08/2004,00-00-00-00-00-00,ITA
    KaZaA,HKEY_LOCAL_MACHINE\software\kazaa|tmp,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Lop.com,C:\WINDOWS\system32\fmgkiw.dll,-308992934,8ce0248ad6c4d80cb3f280f2b24db764,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus,HKEY_LOCAL_MACHINE\software\classes\morpheus|url protocol,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\beegd10.ocx,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\clsncx22.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\clsnol22.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\clsnpb22.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\clsnrn22.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\decln.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\declw.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\mfimage.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\npmirage.dll,na,na,19/08/2004,00-00-00-00-00-00,ITA
    Morpheus 1.9,C:\WINDOWS\system32\s4setp.exe,na,na,19/08/2004,00-00-00-00-00-00,ITA
    NetSpy KeyLogger,C:\WINDOWS\uninst.exe,-1994962759,72827d5d38d38a46231cb38e1f3fc5e3,19/08/2004,00-00-00-00-00-00,ITA
    Online-Dialer,HKEY_CLASSES_ROOT\clsid\{02c20140-76f8-4763-83d5-b660107b7a90},na,na,19/08/2004,00-00-00-00-00-00,ITA
    TOPicks,HKEY_LOCAL_MACHINE\software\classes\appid\altnet signing module.exe|appid,na,na,19/08/2004,00-00-00-00-00-00,ITA
    TOPicks,HKEY_LOCAL_MACHINE\software\classes\clsid\{e813099d-5529-47f4-9b37-4afafcb00a43},na,na,19/08/2004,00-00-00-00-00-00,ITA
    TOPicks,HKEY_LOCAL_MACHINE\software\classes\interface\{ad5bc1f0-72d8-44b3-8e3d-8e8fecce43fb},na,na,19/08/2004,00-00-00-00-00-00,ITA
    TOPicks,HKEY_LOCAL_MACHINE\software\classes\interface\{e813099d-5529-47f4-9b37-4afafcb00a43},na,na,19/08/2004,00-00-00-00-00-00,ITA
    Unknown BHO,C:\WINDOWS\downlo~1\wmv9vcm.inf,na,na,19/08/2004,00-00-00-00-00-00,ITA
    WebDialer,HKEY_CLASSES_ROOT\interface\{abc7630f-71ce-4a96-9aa6-0469457b9ba3},na,na,19/08/2004,00-00-00-00-00-00,ITA
    WebDialer,HKEY_CLASSES_ROOT\typelib\{8512b008-b0aa-451f-a744-a289fd8ffde6},na,na,19/08/2004,00-00-00-00-00-00,ITA
    WurldMedia,HKEY_LOCAL_MACHINE\software\morp,na,na,19/08/2004,00-00-00-00-00-00,ITA
    WurldMedia.Mo,C:\WINDOWS\system32\moconfig.exe,na,na,19/08/2004,00-00-00-00-00-00,ITA
    XoloX,HKEY_CLASSES_ROOT\clsid\{f02c0ae1-d796-42c9-81e1-084d88f79b8e},na,na,19/08/2004,00-00-00-00-00-00,ITA
    XoloX,HKEY_CLASSES_ROOT\typelib\{2850bdc7-2330-4e31-9fa0-88268846539a},na,na,19/08/2004,00-00-00-00-00-00,ITA
     
  13. icio

    icio Guest

    Are they FP?
     
  14. Infinity

    Infinity Registered Member

    Joined:
    May 31, 2004
    Posts:
    2,651
    better to scan your system with spybot AND adaware in safe mode, this should give you a fair idea on any malware on your machine...

    beginning boot process press F8 and choose safe mode, then let adaware se and spybot (updated) run.
     
  15. luv2bsecure

    luv2bsecure Infrequent Poster

    Joined:
    Feb 9, 2002
    Posts:
    713
    Last edited: Aug 19, 2004
  16. icio

    icio Guest

    I never installed those softwares.

    In order, in a formatted pc:
    - windows xp
    - office
    - msn messenger
    - windows update
    - zone alarm
    - my-etrust
    - spybot search and destroy
    - pestpatrol
    - adware

    Then I've scanned my pc.
     
  17. ronny

    ronny Registered Member

    Joined:
    Feb 18, 2004
    Posts:
    231
    Location:
    Belgium
    Hello icio, i also found the following "BonziBuddy" 's on one comp but not on others.I asked Pestpatrol for more info but their reponse was vague.So i am trying to send them another e-mail.

    No other scanner found this! o_O
    Now i really really want to learn what this 8 entries are.Does ANYONE here know this?
    I would be very grateful ! :-* :D


    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\clsid\{71a2702f-c7d8-11d2-bef8-525400dfb47a}

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\clsid\{71a27032-c7d8-11d2-bef8-525400dfb47a}

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\clsid\{71a27034-c7d8-11d2-bef8-525400dfb47a]

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a2702e-c7d8-11d2-bef8-525400dfb47a}

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a27031-c7d8-11d2-bef8-525400dfb47a}

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a27033-c7d8-11d2-bef8-525400dfb47a}

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\interface\{71a27036-c7d8-11d2-bef8-525400dfb47a}

    BonziBuddy,HKEY_LOCAL_MACHINE\software\classes\typelib\{71a2702d-c7d8-11d2-bef8-525400dfb47a}
     
  18. Jack Black

    Jack Black Guest

    I have Pest Patrol and i am not finding BonziBuddy in any of my scans. It may depend which programs you have installed on your computer.
     
  19. bigc73542

    bigc73542 Retired Moderator

    Joined:
    Sep 21, 2003
    Posts:
    23,934
    Location:
    SW. Oklahoma
  20. ronny

    ronny Registered Member

    Joined:
    Feb 18, 2004
    Posts:
    231
    Location:
    Belgium
    Thank you Jack Black.
    Thanks Bigc73542, but i already found that site ;) .The strange thing is that i have NEVER installed that BonziBuddy program on any of my pc's. More, when i try to install it (to be able to remove it) , i can't because my protection doesn't allow me that :D .
    So because of that & because no other spywarescanner detects this 8 CLSID i am curious what they are .I checked on the site of pestpatrol but there they say they are CLSID's connected to BonziBuddy.
    Is there no way that i can see which program is connected to these CLSID?
     
    Last edited: Sep 9, 2004
  21. Jack Black

    Jack Black Guest

    I still think your finding a False Positive, because i've heard so many people complain of detecting BonziBuddy who have Pest Patrol. But i still don't know what installed program is causing the false positive. Let's see i have Spybots protection enabled, so it's not that. I also have IESpyad, so you could rule that one out. SpywareBlaster is another i have, so it's not that either. Do you have any other programs that protect you against spyware/adware?
     
  22. ronny

    ronny Registered Member

    Joined:
    Feb 18, 2004
    Posts:
    231
    Location:
    Belgium
    First & most important: thank you for the time you spend trying to help ;)
    Well i have also the spyware blocklist installed:
    http://www.spywareguide.com/blockfile.php
    but when i open it with notepad, i don't find those CLSID's there although there is one different CLSID for bonzybuddy.
     
    Last edited: Sep 9, 2004
  23. Jack Black

    Jack Black Guest

    Ok, did you just install the minimal version? Because i am going to download it and install. I will then do a Pest Patrol scan to see if it detects Bonzi Buddy.
     
  24. ronny

    ronny Registered Member

    Joined:
    Feb 18, 2004
    Posts:
    231
    Location:
    Belgium
    Jack, i installed the "experts package".
     
  25. Jack Black

    Jack Black Guest

    Just to let you know before you replied i downloaded and merged the minimal files with my reg. I ran two Pest Patrol scans (restart between each) and did not find Bonzi Buddy. I will try the expert download too. One other thing is your Pest Patrol fully up to date? My last PP update was on 8-30-04.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.