R
Robert Pendell
Here is a list of keys and program files that it is incorrectly flagging.
In effect it scares people from using this addon for MSN Messenger. Oh and
I even put in the message that it infinite loops when you either try to run
the installer or if you run the actual program file after installation.
For the installer I can understand the warning although the infinite loop
kinda needs to be corrected. Once you check the box then it finally lets it
go. Actually you have to re-run the installer but beside the point.
MsgPlus.exe though shouldn't be flagged at all with the same exact message.
I mean what is the point. It is installed already.
Bad Warning
This warning displays when attempting to run either MsgPlus-354.exe or
MsgPlus.exe
It shouldn't be shown for either. Especially MsgPlus.exe because the
application is already installed!
Warning, Messenger Plus! Software Bundler is trying
to Install!
Microsoft AntiSpyware has detected the threat Messenger Plus! trying to
install itself on your computer. The file trying to run
(C:\Downloads\MsgPlus-354.exe) has been blocked from running. If you would
like to allow Messenger Plus! continue running click the 'Allow' button
below.
Name: Messenger Plus!
Type: Software Bundler
Threat Level: Moderate
Author: Patchou
Description: Messenger Plus! is an add-on for MSN Messenger that is bundled
with third-party adware programs.
Advise: Moderate-risk items have some potential for adverse effect, but may
be part of a wanted service. Users may decide to ignore such programs after
review. Because this application gives you the option to not install the
adware that comes bundled, we recommend ignoring it.
About Software Bundler: A program that installs other potentially unwanted
software, such as adware or spyware. The license agreement of the bundling
program may require these other components in order to function.
Message Appears Multiple Times (infinite loop until ignored)
Bad Detection of spyware. Items requested for removal from Microsoft
Antispyware.
Files:
Installed to Installation Folder:
msgplus.exe
MsgPlusH.dll
MsgPlusLoader.dll
Resources\MsgPlusRes.dll
RichEdHook.dll
Installed to Windows\System32:
MsgPlusLoader.dll
Legitimately Downloaded Files:
MsgPlus-354.exe (Add-on installer) -- Flagging as Bundle may be correct for
this file
Registry Keys:
HKEY_CURRENT_USER\Software\Patchou\MsgPlus2
All Keys, Values, and Sub-Keys below this point (exact keys vary upon
installation)
Purpose: Stores preferences for this addon applicable to the currently
logged in user
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MsgPlus.Encrypted
All Keys, Values, and Sub-Keys below this point
Purpose: Class Definition for Encrypted Logs feature of this addon
HKEY_LOCAL_MACHINE\SOFTWARE\Patchou\MsgPlus2
All Keys, Values, and Sub-Keys below this point
Purpose: Stores preferences for this addon applicable to all users of the
system.
Basically I would like to see Messenger Plus! removed from the list of
software bundles in MSN Antispyware. It's program files and registry keys
once the program is installed should not be flagged at all. Anything
relating to C2 Lop though should continue to be flagged. The installer
itself (which is named MsgPlus-354.exe in this message) may continue to be
flagged as there is still potential for the spyware to be installed.
However the infinate loop condition I got should be fixed as soon as
possible.
In effect it scares people from using this addon for MSN Messenger. Oh and
I even put in the message that it infinite loops when you either try to run
the installer or if you run the actual program file after installation.
For the installer I can understand the warning although the infinite loop
kinda needs to be corrected. Once you check the box then it finally lets it
go. Actually you have to re-run the installer but beside the point.
MsgPlus.exe though shouldn't be flagged at all with the same exact message.
I mean what is the point. It is installed already.
Bad Warning
This warning displays when attempting to run either MsgPlus-354.exe or
MsgPlus.exe
It shouldn't be shown for either. Especially MsgPlus.exe because the
application is already installed!
Warning, Messenger Plus! Software Bundler is trying
to Install!
Microsoft AntiSpyware has detected the threat Messenger Plus! trying to
install itself on your computer. The file trying to run
(C:\Downloads\MsgPlus-354.exe) has been blocked from running. If you would
like to allow Messenger Plus! continue running click the 'Allow' button
below.
Name: Messenger Plus!
Type: Software Bundler
Threat Level: Moderate
Author: Patchou
Description: Messenger Plus! is an add-on for MSN Messenger that is bundled
with third-party adware programs.
Advise: Moderate-risk items have some potential for adverse effect, but may
be part of a wanted service. Users may decide to ignore such programs after
review. Because this application gives you the option to not install the
adware that comes bundled, we recommend ignoring it.
About Software Bundler: A program that installs other potentially unwanted
software, such as adware or spyware. The license agreement of the bundling
program may require these other components in order to function.
Message Appears Multiple Times (infinite loop until ignored)
Bad Detection of spyware. Items requested for removal from Microsoft
Antispyware.
Files:
Installed to Installation Folder:
msgplus.exe
MsgPlusH.dll
MsgPlusLoader.dll
Resources\MsgPlusRes.dll
RichEdHook.dll
Installed to Windows\System32:
MsgPlusLoader.dll
Legitimately Downloaded Files:
MsgPlus-354.exe (Add-on installer) -- Flagging as Bundle may be correct for
this file
Registry Keys:
HKEY_CURRENT_USER\Software\Patchou\MsgPlus2
All Keys, Values, and Sub-Keys below this point (exact keys vary upon
installation)
Purpose: Stores preferences for this addon applicable to the currently
logged in user
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MsgPlus.Encrypted
All Keys, Values, and Sub-Keys below this point
Purpose: Class Definition for Encrypted Logs feature of this addon
HKEY_LOCAL_MACHINE\SOFTWARE\Patchou\MsgPlus2
All Keys, Values, and Sub-Keys below this point
Purpose: Stores preferences for this addon applicable to all users of the
system.
Basically I would like to see Messenger Plus! removed from the list of
software bundles in MSN Antispyware. It's program files and registry keys
once the program is installed should not be flagged at all. Anything
relating to C2 Lop though should continue to be flagged. The installer
itself (which is named MsgPlus-354.exe in this message) may continue to be
flagged as there is still potential for the spyware to be installed.
However the infinate loop condition I got should be fixed as soon as
possible.