|
PROFESSIONAL NEWSGROUPS WINDEV, WEBDEV and WINDEV Mobile |
| | | | | |
[wd 8] Spyware and Ad-aware |
Started by Gerard van Woudenberg, Jun., 29 2004 6:13 PM - 3 replies |
| |
| | | |
|
| |
Posted on June, 29 2004 - 6:13 PM |
There is a lot spyware and ad aware going arround. But now i have found something very strange. One of our customers have Spybot - Search & Destroy running (also in resident mode). When he installed one of our programs (Made with WD 8 installer) he got at the end (the installer was allready closed) a message from Spybot. Process ID 2516 Filename DEL246.tmp found in (document and settings, locals settings Temp Identified as: FunWebProducts. My first step was to install on a clean computer the program Spybot SD Run it and destroy any ad aware or spy programs. Then restarted the computer and run the proccess again. It did not found any FunwebProducts whatsoever. Then i installed the same program on this computer with the same result. The only differance is that the number in the DEL file changes. The customer is angry with us as they accuse us from distributing spyware. Is there anybode in the community who can explain this. I also tried to run other setups from non WD programs on the same computer, no warnings. I tried to recompile and make a new installation on a clean computer. The result remains the same, you get a warning from spybot SD. I take this very seriously and hope you will do the same. Please try this out and give your outcome to this forum. With kind regards Gerard van Woudenberg
Our homebase |
| |
| |
| | | |
|
| | |
| |
Posted on June, 29 2004 - 6:30 PM |
Gerard, If you install ad-aware before spybot then you will get also a warning that parts of ad-aware will be recognised as spyware. The same is true when you install radmin (simular to PC-Anywhere ) and you do a virusscan with Norton, parts of radmin are not clean. The point is that those software tools are really good but at some points they make a small mistake. Maybe I am wrong, but I don't think so. Vriendelijke groeten Freddy Baert Member of the Dutch windev user-group
There is a lot spyware and ad aware going arround. But now i have found something very strange. One of our customers have Spybot - Search & Destroy running (also in resident mode). When he installed one of our programs (Made with WD 8 installer) he got at the end (the installer was allready closed) a message from Spybot. Process ID 2516 Filename DEL246.tmp found in (document and settings, locals settings Temp Identified as: FunWebProducts. My first step was to install on a clean computer the program Spybot SD Run it and destroy any ad aware or spy programs. Then restarted the computer and run the proccess again. It did not found any FunwebProducts whatsoever. Then i installed the same program on this computer with the same result. The only differance is that the number in the DEL file changes. The customer is angry with us as they accuse us from distributing spyware. Is there anybode in the community who can explain this. I also tried to run other setups from non WD programs on the same computer, no warnings. I tried to recompile and make a new installation on a clean computer. The result remains the same, you get a warning from spybot SD. I take this very seriously and hope you will do the same. Please try this out and give your outcome to this forum. With kind regards Gerard van Woudenberg |
| |
| |
| | | |
|
| | |
| |
Posted on June, 29 2004 - 8:54 PM |
Hi friends, the problem is with pattern files. Every anti-virus/ant-spyware program is based on a pattern file. The pattern file contains unique pieces of the malware and compares them to the files on your harddisk in order to be able to identify any infected files or to find the bad ones. If you install a second virus-scanner on you computer, both scanners will detect the pattern file of the other scannner as 'malware'. Of course, the wide-spead programs like Norton, PC-cillin, f-prot etc know of each other and ignore the pattern files of the competition. However, you'd get a false 'alarm' whenever your anti-virus software is not so well-known. Afaik, Ad-aware knows of spybot, but not the other way around .. Best regards, Guenter
Gerard, If you install ad-aware before spybot then you will get also a warning that parts of ad-aware will be recognised as spyware. The same is true when you install radmin (simular to PC-Anywhere ) and you do a virusscan with Norton, parts of radmin are not clean. The point is that those software tools are really good but at some points they make a small mistake. Maybe I am wrong, but I don't think so. Vriendelijke groeten Freddy Baert Member of the Dutch windev user-group There is a lot spyware and ad aware going arround. But now i have found something very strange. One of our customers have Spybot - Search & Destroy running (also in resident mode). When he installed one of our programs (Made with WD 8 installer) he got at the end (the installer was allready closed) a message from Spybot. Process ID 2516 Filename DEL246.tmp found in (document and settings, locals settings Temp Identified as: FunWebProducts. My first step was to install on a clean computer the program Spybot SD Run it and destroy any ad aware or spy programs. Then restarted the computer and run the proccess again. It did not found any FunwebProducts whatsoever. Then i installed the same program on this computer with the same result. The only differance is that the number in the DEL file changes. The customer is angry with us as they accuse us from distributing spyware. Is there anybode in the community who can explain this. I also tried to run other setups from non WD programs on the same computer, no warnings. I tried to recompile and make a new installation on a clean computer. The result remains the same, you get a warning from spybot SD. I take this very seriously and hope you will do the same. Please try this out and give your outcome to this forum. With kind regards Gerard van Woudenberg |
| |
| |
| | | |
|
| | |
| |
Posted on June, 30 2004 - 1:09 PM |
Gerard van Woudenberg, as end-user (test-user)of the program i am now testing the by you developed piece of software. Normally any third party software will be validated on "ugly" proggies before it will be installed on the appropriate machine. What i have done now is first install your developed application on the appropriate machine, after that installed Spybot search & destroy and scanned the machine via Spybot on "ugly" programs. It did not find any FunWebProducts. This means that the spybot program made a false positive recognition, because otherwise it would also give a scan-warning AFTER the program was installed. Spybot has never given me false positive recognitions before so i will inform the programmer of Spybot Search & Destroy. Then he can make an effort looking into the matter.
There is a lot spyware and ad aware going arround. But now i have found something very strange. One of our customers have Spybot - Search & Destroy running (also in resident mode). When he installed one of our programs (Made with WD 8 installer) he got at the end (the installer was allready closed) a message from Spybot. Process ID 2516 Filename DEL246.tmp found in (document and settings, locals settings Temp Identified as: FunWebProducts. My first step was to install on a clean computer the program Spybot SD Run it and destroy any ad aware or spy programs. Then restarted the computer and run the proccess again. It did not found any FunwebProducts whatsoever. Then i installed the same program on this computer with the same result. The only differance is that the number in the DEL file changes. The customer is angry with us as they accuse us from distributing spyware. Is there anybode in the community who can explain this. I also tried to run other setups from non WD programs on the same computer, no warnings. I tried to recompile and make a new installation on a clean computer. The result remains the same, you get a warning from spybot SD. I take this very seriously and hope you will do the same. Please try this out and give your outcome to this forum. With kind regards Gerard van Woudenberg |
| |
| |
| | | |
|
| | | | |
| | |
| | |
| |
|
|
|