P
Pat F
I've been running Spybot for over a year and have become
an expert at using it.
I downloaded and installed MS Anti-Spyware Beta this last
week. Kudos to MS - this software detected 152 items of
spyware undetected by Spybot between 2 Citrix Servers
running W2K, SP4, fully patched. It also re-detected one
item of spyware Spybot does detect, but that I've had
continued issues with: We've had a repeated problem with
Ceres pop-up windows. The spyware is from
abetterinternet.com, and pops up continued ad windows
titled Ceres. If you remove it, it reinstalls immediately.
I had learned to control it with Spybot in Advanced mode
by going to Tools\BHOs, and "toggling" it. This allows
the file to remain in place but disables it.
MS Anti-Spyware also detected it and removed it, but like
Spybot, it does not go deeply enough to get the
reinstaller. As soon as it's removed, it attempts to
reinstall (red pop-up from MS Anti-Spyware advising me
that Transponder.ABetterInternet.Ceres is attempting to
install). I "Remove" it again, but it immediately
attempts to reinstall, and in fact it succeeds in
reinstalling even though I've instructed Remove. I find
Ceres.dll in C\WINNT immediately after a removal, and as
soon as one of my users runs IE, it's executable,
Buddy.exe, will be recreated. The only way I can control
it is to leave ceres.dll in C:\WINNT and "toggle" it in
Spybot Tools\BHOs. This effectively blocks it, so for the
time being, I'll be leaving Spybot in place. I've
attempted to Quarantine it in MS Anti-Spyware rather than
Remove it after a scan, but my users will still get the
Ceres pop-up windows unless I use Spybot to toggle
ceres.dll. MS needs to do some further work on this to
clean out the installer entries in the registry (I've done
a lot of research on this, and that's where they are, but
abetterinternet keeps changing the names of the registry
entries, so it's a moving target).
There are also 2 other items of spyware that exhibit the
same behavior exactly, but were never detected by Spybot.
They are Transponder.Farmmext and W32.Transponder. Same
exact behavior as Transponder.AbetterInternet.Ceres. As
soon as they're removed, they attempt to reinstall. I
haven't yet had time to do the same amount of research on
these as on ceres because I didn't know I had them until
in installed MS Anti-Spyware.
Great program Microsoft, but you've still got some work to
do, at least on these 3 pests.
an expert at using it.
I downloaded and installed MS Anti-Spyware Beta this last
week. Kudos to MS - this software detected 152 items of
spyware undetected by Spybot between 2 Citrix Servers
running W2K, SP4, fully patched. It also re-detected one
item of spyware Spybot does detect, but that I've had
continued issues with: We've had a repeated problem with
Ceres pop-up windows. The spyware is from
abetterinternet.com, and pops up continued ad windows
titled Ceres. If you remove it, it reinstalls immediately.
I had learned to control it with Spybot in Advanced mode
by going to Tools\BHOs, and "toggling" it. This allows
the file to remain in place but disables it.
MS Anti-Spyware also detected it and removed it, but like
Spybot, it does not go deeply enough to get the
reinstaller. As soon as it's removed, it attempts to
reinstall (red pop-up from MS Anti-Spyware advising me
that Transponder.ABetterInternet.Ceres is attempting to
install). I "Remove" it again, but it immediately
attempts to reinstall, and in fact it succeeds in
reinstalling even though I've instructed Remove. I find
Ceres.dll in C\WINNT immediately after a removal, and as
soon as one of my users runs IE, it's executable,
Buddy.exe, will be recreated. The only way I can control
it is to leave ceres.dll in C:\WINNT and "toggle" it in
Spybot Tools\BHOs. This effectively blocks it, so for the
time being, I'll be leaving Spybot in place. I've
attempted to Quarantine it in MS Anti-Spyware rather than
Remove it after a scan, but my users will still get the
Ceres pop-up windows unless I use Spybot to toggle
ceres.dll. MS needs to do some further work on this to
clean out the installer entries in the registry (I've done
a lot of research on this, and that's where they are, but
abetterinternet keeps changing the names of the registry
entries, so it's a moving target).
There are also 2 other items of spyware that exhibit the
same behavior exactly, but were never detected by Spybot.
They are Transponder.Farmmext and W32.Transponder. Same
exact behavior as Transponder.AbetterInternet.Ceres. As
soon as they're removed, they attempt to reinstall. I
haven't yet had time to do the same amount of research on
these as on ceres because I didn't know I had them until
in installed MS Anti-Spyware.
Great program Microsoft, but you've still got some work to
do, at least on these 3 pests.