J
Jonks
Hi there,
I have 3 user accounts on my computer.
Every time someone logs in they get a warning the ActiveSearch is trying
to install.
I've checked all the places where an app could be set to run at startup,
but there is nothing there.
I've even allowed it to install (!!!), booted into safe mode and run
MSAS deep scan. When I do this, MSAS doesn't detect _anything_ even
though ActiveSearch has been allowed to install.
Here are the last logs from cleaner.log
I notice that when other spyware has been removed in the past, the
removal logs are very detailed. In this case, it appears that nothing
has been deleted by MSAS.
Thanks
22/02/2005 8:03:01
PM::------------------------------------------------------------------
22/02/2005 8:03:01 PM::Initializing Clean - (ScanID: 0)
22/02/2005 8:03:01 PM::Remove Threat (ID:14882)
22/02/2005 8:03:01 PM::Clean Threat ActiveSearch (ID:14882)
22/02/2005 8:03:01 PM::Generating threat
22/02/2005 8:03:13 PM::Clean Threat ActiveSearch (ID:14882) Complete
22/02/2005 8:03:14 PM::Remove Threat (ID:14882) Complete
22/02/2005 8:03:23 PM::Unititializing Clean
22/02/2005 8:03:23
PM::------------------------------------------------------------------
24/02/2005 9:00:11
PM::------------------------------------------------------------------
24/02/2005 9:00:11 PM::Initializing Clean - (ScanID: 0)
24/02/2005 9:00:11 PM::Remove Threat (ID:14882)
24/02/2005 9:00:11 PM::Clean Threat ActiveSearch (ID:14882)
24/02/2005 9:00:11 PM::Generating threat
24/02/2005 9:00:15 PM::Clean Threat ActiveSearch (ID:14882) Complete
24/02/2005 9:00:15 PM::Remove Threat (ID:14882) Complete
24/02/2005 9:00:24 PM::Unititializing Clean
24/02/2005 9:00:24
PM::------------------------------------------------------------------
25/02/2005 9:18:15
PM::------------------------------------------------------------------
25/02/2005 9:18:15 PM::Initializing Clean - (ScanID: 0)
25/02/2005 9:18:15 PM::Remove Threat (ID:14882)
25/02/2005 9:18:15 PM::Clean Threat ActiveSearch (ID:14882)
25/02/2005 9:18:15 PM::Generating threat
25/02/2005 9:18:20 PM::Clean Threat ActiveSearch (ID:14882) Complete
25/02/2005 9:18:20 PM::Remove Threat (ID:14882) Complete
25/02/2005 9:18:32 PM::Unititializing Clean
25/02/2005 9:18:32
PM::------------------------------------------------------------------
26/02/2005 4:13:15
PM::------------------------------------------------------------------
26/02/2005 4:13:16 PM::Initializing Clean - (ScanID: 0)
26/02/2005 4:13:16 PM::Remove Threat (ID:14882)
26/02/2005 4:13:16 PM::Clean Threat ActiveSearch (ID:14882)
26/02/2005 4:13:16 PM::Generating threat
26/02/2005 4:13:20 PM::Clean Threat ActiveSearch (ID:14882) Complete
26/02/2005 4:13:20 PM::Remove Threat (ID:14882) Complete
26/02/2005 4:13:24 PM::Unititializing Clean
26/02/2005 4:13:24
PM::------------------------------------------------------------------
27/02/2005 4:35:36
PM::------------------------------------------------------------------
27/02/2005 4:35:36 PM::Initializing Clean - (ScanID: 0)
27/02/2005 4:35:36 PM::Remove Threat (ID:14882)
27/02/2005 4:35:36 PM::Clean Threat ActiveSearch (ID:14882)
27/02/2005 4:35:36 PM::Generating threat
27/02/2005 4:35:42 PM::Clean Threat ActiveSearch (ID:14882) Complete
27/02/2005 4:35:42 PM::Remove Threat (ID:14882) Complete
27/02/2005 4:35:47 PM::Unititializing Clean
27/02/2005 4:35:47
PM::------------------------------------------------------------------
28/02/2005 9:03:50
PM::------------------------------------------------------------------
28/02/2005 9:03:50 PM::Initializing Clean - (ScanID: 0)
28/02/2005 9:03:50 PM::Remove Threat (ID:14882)
28/02/2005 9:03:50 PM::Clean Threat ActiveSearch (ID:14882)
28/02/2005 9:03:50 PM::Generating threat
28/02/2005 9:03:55 PM::Clean Threat ActiveSearch (ID:14882) Complete
28/02/2005 9:03:55 PM::Remove Threat (ID:14882) Complete
28/02/2005 9:06:58 PM::Unititializing Clean
28/02/2005 9:06:58
PM::------------------------------------------------------------------
01/03/2005 9:19:22
PM::------------------------------------------------------------------
01/03/2005 9:19:22 PM::Initializing Clean - (ScanID: 0)
01/03/2005 9:19:22 PM::Remove Threat (ID:14882)
01/03/2005 9:19:22 PM::Clean Threat ActiveSearch (ID:14882)
01/03/2005 9:19:22 PM::Generating threat
01/03/2005 9:19:25 PM::Clean Threat ActiveSearch (ID:14882) Complete
01/03/2005 9:19:25 PM::Remove Threat (ID:14882) Complete
01/03/2005 9:19:27 PM::Unititializing Clean
01/03/2005 9:19:27
PM::------------------------------------------------------------------
02/03/2005 10:21:36
PM::------------------------------------------------------------------
02/03/2005 10:21:36 PM::Initializing Clean - (ScanID: 0)
02/03/2005 10:21:36 PM::Remove Threat (ID:14882)
02/03/2005 10:21:37 PM::Clean Threat ActiveSearch (ID:14882)
02/03/2005 10:21:37 PM::Generating threat
02/03/2005 10:21:44 PM::Clean Threat ActiveSearch (ID:14882) Complete
02/03/2005 10:21:44 PM::Remove Threat (ID:14882) Complete
02/03/2005 10:21:48 PM::Unititializing Clean
02/03/2005 10:21:48
PM::------------------------------------------------------------------
03/03/2005 9:01:20
PM::------------------------------------------------------------------
03/03/2005 9:01:20 PM::Initializing Clean - (ScanID: 0)
03/03/2005 9:01:20 PM::Remove Threat (ID:14882)
03/03/2005 9:01:21 PM::Clean Threat ActiveSearch (ID:14882)
03/03/2005 9:01:21 PM::Generating threat
03/03/2005 9:01:36 PM::Clean Threat ActiveSearch (ID:14882) Complete
03/03/2005 9:01:36 PM::Remove Threat (ID:14882) Complete
03/03/2005 9:01:38 PM::Unititializing Clean
03/03/2005 9:01:38
PM::------------------------------------------------------------------
04/03/2005 8:45:58
PM::------------------------------------------------------------------
04/03/2005 8:45:58 PM::Initializing Clean - (ScanID: 0)
04/03/2005 8:45:58 PM::Remove Threat (ID:14882)
04/03/2005 8:45:58 PM::Clean Threat ActiveSearch (ID:14882)
04/03/2005 8:45:58 PM::Generating threat
04/03/2005 8:46:09
PM::------------------------------------------------------------------
04/03/2005 8:46:09 PM::Initializing Clean - (ScanID: 0)
04/03/2005 8:46:09 PM::Remove Threat (ID:14882)
04/03/2005 8:46:09 PM::Clean Threat ActiveSearch (ID:14882)
04/03/2005 8:46:09 PM::Generating threat
04/03/2005 8:46:12 PM::Clean Threat ActiveSearch (ID:14882) Complete
04/03/2005 8:46:13 PM::Remove Threat (ID:14882) Complete
04/03/2005 8:46:14 PM::Unititializing Clean
04/03/2005 8:46:14
PM::------------------------------------------------------------------
05/03/2005 7:05:01
PM::------------------------------------------------------------------
05/03/2005 7:05:01 PM::Initializing Clean - (ScanID: 0)
05/03/2005 7:05:01 PM::Remove Threat (ID:14882)
05/03/2005 7:05:01 PM::Clean Threat ActiveSearch (ID:14882)
05/03/2005 7:05:01 PM::Generating threat
05/03/2005 7:05:05 PM::Clean Threat ActiveSearch (ID:14882) Complete
05/03/2005 7:05:05 PM::Remove Threat (ID:14882) Complete
05/03/2005 7:05:10 PM::Unititializing Clean
05/03/2005 7:05:10
PM::------------------------------------------------------------------
06/03/2005 6:17:58
AM::------------------------------------------------------------------
06/03/2005 6:17:58 AM::Initializing Clean - (ScanID: 0)
06/03/2005 6:17:58 AM::Remove Threat (ID:14882)
06/03/2005 6:17:58 AM::Clean Threat ActiveSearch (ID:14882)
06/03/2005 6:17:58 AM::Generating threat
06/03/2005 6:18:02 AM::Clean Threat ActiveSearch (ID:14882) Complete
06/03/2005 6:18:02 AM::Remove Threat (ID:14882) Complete
06/03/2005 6:18:04 AM::Unititializing Clean
06/03/2005 6:18:04
AM::------------------------------------------------------------------
I have 3 user accounts on my computer.
Every time someone logs in they get a warning the ActiveSearch is trying
to install.
I've checked all the places where an app could be set to run at startup,
but there is nothing there.
I've even allowed it to install (!!!), booted into safe mode and run
MSAS deep scan. When I do this, MSAS doesn't detect _anything_ even
though ActiveSearch has been allowed to install.
Here are the last logs from cleaner.log
I notice that when other spyware has been removed in the past, the
removal logs are very detailed. In this case, it appears that nothing
has been deleted by MSAS.
Thanks
22/02/2005 8:03:01
PM::------------------------------------------------------------------
22/02/2005 8:03:01 PM::Initializing Clean - (ScanID: 0)
22/02/2005 8:03:01 PM::Remove Threat (ID:14882)
22/02/2005 8:03:01 PM::Clean Threat ActiveSearch (ID:14882)
22/02/2005 8:03:01 PM::Generating threat
22/02/2005 8:03:13 PM::Clean Threat ActiveSearch (ID:14882) Complete
22/02/2005 8:03:14 PM::Remove Threat (ID:14882) Complete
22/02/2005 8:03:23 PM::Unititializing Clean
22/02/2005 8:03:23
PM::------------------------------------------------------------------
24/02/2005 9:00:11
PM::------------------------------------------------------------------
24/02/2005 9:00:11 PM::Initializing Clean - (ScanID: 0)
24/02/2005 9:00:11 PM::Remove Threat (ID:14882)
24/02/2005 9:00:11 PM::Clean Threat ActiveSearch (ID:14882)
24/02/2005 9:00:11 PM::Generating threat
24/02/2005 9:00:15 PM::Clean Threat ActiveSearch (ID:14882) Complete
24/02/2005 9:00:15 PM::Remove Threat (ID:14882) Complete
24/02/2005 9:00:24 PM::Unititializing Clean
24/02/2005 9:00:24
PM::------------------------------------------------------------------
25/02/2005 9:18:15
PM::------------------------------------------------------------------
25/02/2005 9:18:15 PM::Initializing Clean - (ScanID: 0)
25/02/2005 9:18:15 PM::Remove Threat (ID:14882)
25/02/2005 9:18:15 PM::Clean Threat ActiveSearch (ID:14882)
25/02/2005 9:18:15 PM::Generating threat
25/02/2005 9:18:20 PM::Clean Threat ActiveSearch (ID:14882) Complete
25/02/2005 9:18:20 PM::Remove Threat (ID:14882) Complete
25/02/2005 9:18:32 PM::Unititializing Clean
25/02/2005 9:18:32
PM::------------------------------------------------------------------
26/02/2005 4:13:15
PM::------------------------------------------------------------------
26/02/2005 4:13:16 PM::Initializing Clean - (ScanID: 0)
26/02/2005 4:13:16 PM::Remove Threat (ID:14882)
26/02/2005 4:13:16 PM::Clean Threat ActiveSearch (ID:14882)
26/02/2005 4:13:16 PM::Generating threat
26/02/2005 4:13:20 PM::Clean Threat ActiveSearch (ID:14882) Complete
26/02/2005 4:13:20 PM::Remove Threat (ID:14882) Complete
26/02/2005 4:13:24 PM::Unititializing Clean
26/02/2005 4:13:24
PM::------------------------------------------------------------------
27/02/2005 4:35:36
PM::------------------------------------------------------------------
27/02/2005 4:35:36 PM::Initializing Clean - (ScanID: 0)
27/02/2005 4:35:36 PM::Remove Threat (ID:14882)
27/02/2005 4:35:36 PM::Clean Threat ActiveSearch (ID:14882)
27/02/2005 4:35:36 PM::Generating threat
27/02/2005 4:35:42 PM::Clean Threat ActiveSearch (ID:14882) Complete
27/02/2005 4:35:42 PM::Remove Threat (ID:14882) Complete
27/02/2005 4:35:47 PM::Unititializing Clean
27/02/2005 4:35:47
PM::------------------------------------------------------------------
28/02/2005 9:03:50
PM::------------------------------------------------------------------
28/02/2005 9:03:50 PM::Initializing Clean - (ScanID: 0)
28/02/2005 9:03:50 PM::Remove Threat (ID:14882)
28/02/2005 9:03:50 PM::Clean Threat ActiveSearch (ID:14882)
28/02/2005 9:03:50 PM::Generating threat
28/02/2005 9:03:55 PM::Clean Threat ActiveSearch (ID:14882) Complete
28/02/2005 9:03:55 PM::Remove Threat (ID:14882) Complete
28/02/2005 9:06:58 PM::Unititializing Clean
28/02/2005 9:06:58
PM::------------------------------------------------------------------
01/03/2005 9:19:22
PM::------------------------------------------------------------------
01/03/2005 9:19:22 PM::Initializing Clean - (ScanID: 0)
01/03/2005 9:19:22 PM::Remove Threat (ID:14882)
01/03/2005 9:19:22 PM::Clean Threat ActiveSearch (ID:14882)
01/03/2005 9:19:22 PM::Generating threat
01/03/2005 9:19:25 PM::Clean Threat ActiveSearch (ID:14882) Complete
01/03/2005 9:19:25 PM::Remove Threat (ID:14882) Complete
01/03/2005 9:19:27 PM::Unititializing Clean
01/03/2005 9:19:27
PM::------------------------------------------------------------------
02/03/2005 10:21:36
PM::------------------------------------------------------------------
02/03/2005 10:21:36 PM::Initializing Clean - (ScanID: 0)
02/03/2005 10:21:36 PM::Remove Threat (ID:14882)
02/03/2005 10:21:37 PM::Clean Threat ActiveSearch (ID:14882)
02/03/2005 10:21:37 PM::Generating threat
02/03/2005 10:21:44 PM::Clean Threat ActiveSearch (ID:14882) Complete
02/03/2005 10:21:44 PM::Remove Threat (ID:14882) Complete
02/03/2005 10:21:48 PM::Unititializing Clean
02/03/2005 10:21:48
PM::------------------------------------------------------------------
03/03/2005 9:01:20
PM::------------------------------------------------------------------
03/03/2005 9:01:20 PM::Initializing Clean - (ScanID: 0)
03/03/2005 9:01:20 PM::Remove Threat (ID:14882)
03/03/2005 9:01:21 PM::Clean Threat ActiveSearch (ID:14882)
03/03/2005 9:01:21 PM::Generating threat
03/03/2005 9:01:36 PM::Clean Threat ActiveSearch (ID:14882) Complete
03/03/2005 9:01:36 PM::Remove Threat (ID:14882) Complete
03/03/2005 9:01:38 PM::Unititializing Clean
03/03/2005 9:01:38
PM::------------------------------------------------------------------
04/03/2005 8:45:58
PM::------------------------------------------------------------------
04/03/2005 8:45:58 PM::Initializing Clean - (ScanID: 0)
04/03/2005 8:45:58 PM::Remove Threat (ID:14882)
04/03/2005 8:45:58 PM::Clean Threat ActiveSearch (ID:14882)
04/03/2005 8:45:58 PM::Generating threat
04/03/2005 8:46:09
PM::------------------------------------------------------------------
04/03/2005 8:46:09 PM::Initializing Clean - (ScanID: 0)
04/03/2005 8:46:09 PM::Remove Threat (ID:14882)
04/03/2005 8:46:09 PM::Clean Threat ActiveSearch (ID:14882)
04/03/2005 8:46:09 PM::Generating threat
04/03/2005 8:46:12 PM::Clean Threat ActiveSearch (ID:14882) Complete
04/03/2005 8:46:13 PM::Remove Threat (ID:14882) Complete
04/03/2005 8:46:14 PM::Unititializing Clean
04/03/2005 8:46:14
PM::------------------------------------------------------------------
05/03/2005 7:05:01
PM::------------------------------------------------------------------
05/03/2005 7:05:01 PM::Initializing Clean - (ScanID: 0)
05/03/2005 7:05:01 PM::Remove Threat (ID:14882)
05/03/2005 7:05:01 PM::Clean Threat ActiveSearch (ID:14882)
05/03/2005 7:05:01 PM::Generating threat
05/03/2005 7:05:05 PM::Clean Threat ActiveSearch (ID:14882) Complete
05/03/2005 7:05:05 PM::Remove Threat (ID:14882) Complete
05/03/2005 7:05:10 PM::Unititializing Clean
05/03/2005 7:05:10
PM::------------------------------------------------------------------
06/03/2005 6:17:58
AM::------------------------------------------------------------------
06/03/2005 6:17:58 AM::Initializing Clean - (ScanID: 0)
06/03/2005 6:17:58 AM::Remove Threat (ID:14882)
06/03/2005 6:17:58 AM::Clean Threat ActiveSearch (ID:14882)
06/03/2005 6:17:58 AM::Generating threat
06/03/2005 6:18:02 AM::Clean Threat ActiveSearch (ID:14882) Complete
06/03/2005 6:18:02 AM::Remove Threat (ID:14882) Complete
06/03/2005 6:18:04 AM::Unititializing Clean
06/03/2005 6:18:04
AM::------------------------------------------------------------------