|
Microsoft Windows Antispyware (Beta) by
Microsoft
Date Reviewed: 1/10/2005
| Microsoft
Antispyware is the latest entry into the crowded spyware
removal field of software. Microsoft purchased and rebranded Giant
Company's Antispyware product as their own and from the initial beta
release it appears to be worth a good look with automatic update
features, a SpyNet community of beginners and experts to find and
classify spyware for removal, along with monitoring protection to stop
browser hijacks and other issues. Be warned however, this program only
works with Windows 2000, XP or later Windows operating system. |
|
With
all the hype surrounding this new entry in removal programs how did it
do with my test computer infected with the following spyware:
After
installing, automatically updating, and scanning the system with a full
scan, Microsoft
Antispyware identified 30 spyware threats, including 9 memory
processes, 2012 spyware files, and 3087 infected registry entries. As
shown below each threat has a description of the threat, severity
rating, and the choice between four actions: Ignore, Remove,
Quarantine, or Always Ignore. I chose to Remove all 30 spyware threats
and allowed the program to go to work. After several minutes of screens
flashing by showing processes being terminated, files and folders being
deleted, and registry entries being removed, the program asked to
reboot.


Upon
rebooting, Microsoft's spyware monitoring displayed a warning that Wintools trojan
was trying to load, it then proceeded to remove WinTools again and once
again reboot. This time it displayed a warning that Huntbar (the
websearch.com spyware) was trying to load, I chose to remove it and
again rebooted the computer. Opening Microsoft's Antispyware now shows
the system is completely free of spyware, so I ran the scan one more
time to be sure and it came up with 4 of the same threats it claimed to
have removed previously: 2 instances of Exact Advertising (Bargain Buddy
and a downloader), WinTools,
and the Websearch.com
toolbar. I chose to remove all 4 once more. Another reboot
and additional scan shows 1 threat (part of the Exact Advertising
downloader) still remains and 2 more subsequent scans do not remove it
either.
As
shown by the Hijackthis
log after running Microsoft
Antispyware, several programs still remain including the
persistent TBPS.exe file from websearch.com.
I removed the following items via Hijackthis,
manually deleted the files the Microsoft Antispyware was showing as the
Exact.TrojanDownloader that simply wouldn't go away and rebooted a
final time.
R0
- HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZWYYYYYYYYUS
Out
of curiousity, I ran Ad-Aware SE and Spybot Search and Destroy after MS
Antispyware said it was completely spyware free. Ad-Aware still found
145 instances of registry entries, cookies, and files remaining that
needed to be quarantined, while Spybot found 109 problems remaining.
Conclusions
Microsoft's
Antispyware utility is a solid start for the giant software
company, however it didnt completely remove several threats and left
Hotbar completely intact. As expected, Weatherbug was also left on the
machine. However, its failure to remove some programs put it currently
a notch below Lavasoft's
Ad-Aware SE Personal in my opinion.
Spyware
found by Microsoft Antispyware (Beta) on test machine
TV Media
Display (Adware)
WinTools (Trojan)
Exact.Bullseyenetwork (Adware)
Exact.ISEXEng (Trojan)
Network Essentials (Browser Hijacker)
Search Enhancement (Browser Hijacker)
MyWebSearch Toolbar (Browser Hijacker)
Top Rebates (Browser Plugin)
180search Assistant (Adware)
Possible Browser Hijack (Browser Hijacker)
Exact.Cashback (Adware)
Exact.Navisearch (Adware)
Zango Search Assistant (Adware)
Superlogy.com (Browser Plugin)
Exact.Downloader (Trojan Downloader)
Exact.Bargain Buddy (Adware)
Cydoor (Adware)
DownloadWare (Adware)
Huntbar (Browser Hijacker)
Websearch Toolbar (Browser Plugin)
Claria.Date Manager (Adware)
FunWebProducts (Adware)
Hotbar.Shopping Reports (Adware)
Claria (Adware)
Claria.Dashbar (Toolbar)
Exact Search Bar (Browser Plugin)
GAIN (Adware)
Claria.Precision Time (Adware)
MyWay Search Bar (Browser Plugin)
Popular Screensavers (Adware Bundler)
Hijackthis
Log Before Running Microsoft Antispyware (Beta)
R1 -
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.websearch.com/ie.aspx?tb_id=50024
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=50024
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.websearch.com/ie.aspx?tb_id=50024
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName
=
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972}
- C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: MyWebSearch Search Assistant BHO -
{00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program
Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} -
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: ShprRprts - {2A8A997F-BB9F-48F6-AA2B-2762D50F9289} -
C:\Program Files\ShopperReports\Bin\1.0.0.1\SmrtShpr.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} -
C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} -
C:\PROGRA~1\Toolbar\toolbar.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344}
- C:\WINDOWS\System32\nvms.dll
O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program
Files\Hotbar\bin\4.5.3.0\HbHostIE.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14}
- C:\WINDOWS\System32\mscb.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA}
- C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: My &Web Search -
{07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program
Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: &Search Toolbar -
{339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} -
C:\Program Files\Hotbar\bin\4.5.3.0\HbHostIE.dll
O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common
Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [WebRebates0] "C:\Program
Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [sau] c:\program files\180search assistant\sau.exe
O4 - HKLM\..\Run: [cjmj] C:\WINDOWS\cjmj.exe
O4 - HKLM\..\Run: [CashBack] C:\Program Files\CashBack\bin\cashback.exe
O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye
Network\bin\bargains.exe
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program
Files\Hotbar\bin\4.5.3.0\WeatherOnTray.exe
O4 - HKLM\..\Run: [Hotbar] C:\Program
Files\Hotbar\bin\4.5.3.0\HbInst.exe /Upgrade
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O4 - HKCU\..\Run: [MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program
Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: Date Manager.lnk = C:\Program Files\Date
Manager\DateManager.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common
Files\GMT\GMT.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program
Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Program
Files\PrecisionTime\PrecisionTime.exe
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZWYYYYYYYYUS
O8 - Extra context menu item: Web Rebates - file://C:\Program
Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}
- C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/MyWebSearchInitialSetup1.0.0.8-2.cab
O16 - DPF: {87067F04-DE4C-4688-BC3C-4FCF39D609E7} -
http://download.websearch.com/Dnl/T_50024/QDow_AS2.cab
O16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller
Class) - http://www.180searchassistant.com/180saax.cab
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} -
C:\PROGRA~1\Toolbar\toolbar.dll
Hijackthis
Log After Running Microsoft Antispyware (Beta)
R0 -
HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} - C:\Program
Files\Hotbar\bin\4.5.3.0\HbHostIE.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -
C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Hotbar - {B195B3B3-8A05-11D3-97A4-0004ACA6948E} -
C:\Program Files\Hotbar\bin\4.5.3.0\HbHostIE.dll
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program
Files\Hotbar\bin\4.5.3.0\WeatherOnTray.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft
AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKLM\..\Run: [Hotbar] C:\Program
Files\Hotbar\bin\4.5.3.0\HbInst.exe /Upgrade
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program
Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
/background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.EXE 1
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZWYYYYYYYYUS
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}
- C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
Read other Spyware Removal Program
Reviews
[an error occurred while processing this directive]
|
Tools for Removing Spyware, Adware, and Malware
PC HELL
Other Pages
Spyware/Adware Removal Help
MSBlast.exe Worm Removal
Welchia (Dllhost.exe and SVCHost.exe) Worm Removal
Uninstall McAfee Instructions
Uninstall Norton Instructions
Uninstall Avast Instructions
Uninstall AVG Instructions
Uninstall Antivir Instructions
Uninstall Panda Instructions
How to Manually Run the Microsoft Malicious Software Removal Tool
Bloodhound.Exploit.6 Virus Removal
MyDoom Virus Removal
MiMail.C Virus Removal
Swen Worm Virus Removal
SoBig.F Worm Removal
Dumaru Virus Removal
BugBear.B Worm Removal
SoBig.E Worm Removal
Pop Up Ad Removal Info
KAK Worm Removal
MiMail.A Worm Removal
W95.MTX Virus Removal
Snow White Virus Removal
BadTrans Trojan Removal
Wininit Virus (Bymer Trojan)
Happy99 Worm Removal
VBS Netlog Worm Removal
Pretty Park Worm Removal
Sasser Worm Virus Removal
Backdoor SDBot.H Trojan Removal
VBS.Loveletter Help
Computer Security Information
Back Orifice Information
PC HELL Main Page
iPadastic - News, Tutorials, Help, Tips, and Hints for the iPad
Download Hoyle Games including Casino 3D, Card, Board, and Solitaire games.
|