G
Guest
Hi, Beta Travelers:
I just wanted to note the following for your protection. I have been using
Norton AV for many years and I was a Windows Defender Beta user as well until
yesterday when NAV informed me that I could no longer simply update my
subscription but had to buy NAV 2006 to continue to get protection from the
still thriving malicious hacker industry out there (wankers!)
I did this and installed NAV 2006 (with the usual incredible Nortonesque
difficulties - why is it after all these years no one seems to be able to
write a decent installation program for XP??) and discovered that NAV 2006
has Anti-Spyware built in so I uninstalled Windows Defender and ran a full
scan.
Much to my surprise, and although I had been running the latest Win Defender
build with up to date definitions and scanning my system daily, NAV did find
three high risk spyware programs on my system.
So this is my last communication with this group and I wish you well and
good luck, but you may want to look around yer hard disks for the following
evil doers which Win Defender is apparently incapable of spotting.
Pass it on, fans.
)>FLAtRich
Found yesterday (7/1/06) and noted in my NAV 2006 Log:
Source: Manual Scanner
Risk category: Adware
Overall Risk Impact: Medium
Performance: Low
Privacy: Low
Removal: High
Stealth: Medium
Click for more information about this risk : Adware.Purityscan
Action taken: Removed
Description: Affected areas:
1 Files:
C:\WINNT\system32\HKDSK~1.EXE - Deleted
6 Registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4} - Deleted
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-1004\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Not detected
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-500\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Repaired
Source: Manual Scanner
Risk category: Adware
Overall Risk Impact: High
Performance: High
Privacy: Medium
Removal: High
Stealth: High
Click for more information about this risk : Adware.Quadro
Action taken: Removed
Description: Affected areas:
6 Files:
c:\WINNT\system32\DnwEJ49.exe - Deleted
c:\WINNT\system32\Gpw2p.exe - Deleted
c:\WINNT\system32\Lkzrgzf.exe - Deleted
c:\WINNT\system32\Nfw8fU8C.exe - Deleted
c:\WINNT\system32\Pelus4.exe - Deleted
c:\WINNT\system32\Tepv.exe - Deleted
12 Registry keys:
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\Enable Browser
Extensions - Repaired
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-1004\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\Enable Browser
Extensions - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Enable Browser
Extensions - Repaired
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-500\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Window
Restrictions\iexplore.exe - Not detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\iexplore.exe -
Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\New
Windows\PopupMgr - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-1004\Software\Microsoft\Internet Explorer\New Windows\PopupMgr - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\New
Windows\PopupMgr - Not detected
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\New
Windows\PopupMgr - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-500\Software\Microsoft\Internet Explorer\New Windows\PopupMgr - Not detected
1 Additional areas:
Unknown - Deleted
Source: Manual Scanner
Risk category: Dialer
Overall Risk Impact: High
Performance: High
Privacy: High
Removal: High
Stealth: High
Click for more information about this risk : Dialer.SPlanet
Action taken: Removed
Description: Affected areas:
1 Files:
C:\WINNT\Downloaded Program Files\karaoke.exe - Deleted
I just wanted to note the following for your protection. I have been using
Norton AV for many years and I was a Windows Defender Beta user as well until
yesterday when NAV informed me that I could no longer simply update my
subscription but had to buy NAV 2006 to continue to get protection from the
still thriving malicious hacker industry out there (wankers!)
I did this and installed NAV 2006 (with the usual incredible Nortonesque
difficulties - why is it after all these years no one seems to be able to
write a decent installation program for XP??) and discovered that NAV 2006
has Anti-Spyware built in so I uninstalled Windows Defender and ran a full
scan.
Much to my surprise, and although I had been running the latest Win Defender
build with up to date definitions and scanning my system daily, NAV did find
three high risk spyware programs on my system.
So this is my last communication with this group and I wish you well and
good luck, but you may want to look around yer hard disks for the following
evil doers which Win Defender is apparently incapable of spotting.
Pass it on, fans.
)>FLAtRich
Found yesterday (7/1/06) and noted in my NAV 2006 Log:
Source: Manual Scanner
Risk category: Adware
Overall Risk Impact: Medium
Performance: Low
Privacy: Low
Removal: High
Stealth: Medium
Click for more information about this risk : Adware.Purityscan
Action taken: Removed
Description: Affected areas:
1 Files:
C:\WINNT\system32\HKDSK~1.EXE - Deleted
6 Registry keys:
HKEY_LOCAL_MACHINE\SYSTEM\CURRENTCONTROLSET\ENUM\SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4} - Deleted
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-1004\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Not detected
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-500\Software\Microsoft\Internet
Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Repaired
Source: Manual Scanner
Risk category: Adware
Overall Risk Impact: High
Performance: High
Privacy: Medium
Removal: High
Stealth: High
Click for more information about this risk : Adware.Quadro
Action taken: Removed
Description: Affected areas:
6 Files:
c:\WINNT\system32\DnwEJ49.exe - Deleted
c:\WINNT\system32\Gpw2p.exe - Deleted
c:\WINNT\system32\Lkzrgzf.exe - Deleted
c:\WINNT\system32\Nfw8fU8C.exe - Deleted
c:\WINNT\system32\Pelus4.exe - Deleted
c:\WINNT\system32\Tepv.exe - Deleted
12 Registry keys:
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\Enable Browser
Extensions - Repaired
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-1004\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\Enable Browser
Extensions - Repaired
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\Enable Browser
Extensions - Repaired
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-500\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions - Repaired
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Window
Restrictions\iexplore.exe - Not detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\iexplore.exe -
Repaired
HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\New
Windows\PopupMgr - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-1004\Software\Microsoft\Internet Explorer\New Windows\PopupMgr - Repaired
HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\New
Windows\PopupMgr - Not detected
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\New
Windows\PopupMgr - Not detected
HKEY_USERS\S-1-5-21-429115175-2541319435-2214429306-500\Software\Microsoft\Internet Explorer\New Windows\PopupMgr - Not detected
1 Additional areas:
Unknown - Deleted
Source: Manual Scanner
Risk category: Dialer
Overall Risk Impact: High
Performance: High
Privacy: High
Removal: High
Stealth: High
Click for more information about this risk : Dialer.SPlanet
Action taken: Removed
Description: Affected areas:
1 Files:
C:\WINNT\Downloaded Program Files\karaoke.exe - Deleted