Author Topic: WARNING!!! SPYWARE TERMINATOR!!!  (Read 49138 times)

0 Members and 1 Guest are viewing this topic.

gdiloren

  • Guest
WARNING!!! SPYWARE TERMINATOR!!!
« on: July 26, 2007, 04:40:44 PM »
Spyware terminator messed up a lot of computers this week. They inserted a big big false positive (???) in the winlogon.exe file as Trojan Phoney.WXP  in the registry. Don't take any action, you won't be able to logon on start-up. I had to format and reinstall everything from a fresh copy of Windows. I'm mad about them! For more info, go on the spyware terminator web forumhttp://http://forum.spywareterminator.com/Default.aspx?g=posts&t=2446
 :'(

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #1 on: July 26, 2007, 04:42:34 PM »
Got this result by doing a complete all files scan. Again, at the detection, do nothing and read their forum. I  quit ST, for my part, they lost a guy!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #2 on: July 26, 2007, 04:55:37 PM »
Whilst this FP could well be serious as it was for you, but to leave over one FP would mean you have no other program to choose, I don't know of any security application that hasn't had an FP. I have had at least one FP on every piece of security software I have installed.

All detections should be investigated (google, etc.), nothing deleted only quarantined, but check when files that have been on your system for some time (explorer, created, modified dates, etc.) are suddenly detected.

Yes, it is hard to remain calm and investigate when the brown stuff hits the fan.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #3 on: July 26, 2007, 05:04:19 PM »
If you go to the ST forum link, you'll see that either deleting (as I did) or quarantinying it (as I should have done) will seriously mess-up your PC. This is an important flaw. It's unacceptable!

drhayden1

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #4 on: July 26, 2007, 05:05:57 PM »
glad i took off spyware terminator after it installed in my add/remove products a whopping 425MB instead of the 25MB their tech support told was right and there was a bug in my os and it wasn't their fault....
glad i didn't put it back on my laptop computer after i did a complete os and drivers restore couple of weeks ago ;)
crappy software-crappy tech support=crap off my computer 8)
i mentioned it here also...starts at reply 13  http://forum.avast.com/index.php?topic=29516.0 on both pages
« Last Edit: July 26, 2007, 05:19:20 PM by drhayden1 »

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #5 on: July 26, 2007, 05:08:03 PM »
I think the same!! CRAP! >:(

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #6 on: July 26, 2007, 05:45:41 PM »
I'm astonished!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #7 on: July 26, 2007, 06:34:39 PM »
If you go to the ST forum link, you'll see that either deleting (as I did) or quarantinying it (as I should have done) will seriously mess-up your PC. This is an important flaw. It's unacceptable!

Had you quarantined it, if running windows should have stopped deletion or quarantine, generally you will be OK until you next boot.

I'm trying to highlight the importance of investigation before action and certainly before you next boot, not just for you but for those reading this in the future. The same investigation should be carried out for every detection.

FPs are a fact of life and not something to jump ship for, others issues as mentioned poor support, etc. yes.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #8 on: July 26, 2007, 06:58:02 PM »
BELIEVE ME...there was nothing to investigate. This appeared like a critical infection with 3 stars and it seems that even to quarantine winlogon.exe and its  infected registry key would have been the same as deleting it. As a lesson, I'm going to stick to well-known softwares like Avast, Ad-Aware 2007, Spybot Search and Destroy, Windows Defender and Cyberhawk frow well known companies. This way, I'm sure not to ever format again my drive!!

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #9 on: July 26, 2007, 07:03:34 PM »
http://http://forum.antivir.de/thread.php?threadid=24654&sid=c6eed8ae62a42cc26075eb776e20a5b5
All over the world, all over the forums, they messed-up things!

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #10 on: July 26, 2007, 07:05:11 PM »
By the way, I don't think the user should pay " " for " that ".

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #11 on: July 26, 2007, 07:09:31 PM »
Sorry there is always something to investigate, never take 'anything' at face value, do so and you risk a repeat performance of what has just happened, but with a different application since you are/have removed ST.

It doesn't matter how many starts it has got always investigate.

All of the programs you have mentioned have suffered FP detections that have causes issues, just ask Dan about AdAware 2007.

I would suggest you investigate dick imaging software that can take an exact image of your hard disk. I use Drive Image 7.1 (the last one before symantec bought the company) there is also Acronis True Image and others. I run mine once a week and if I have a crash or serious problem that will take more than 30 minutes to resolve I will restore the last image, this usually takes me about 15 minutes. You also need to ensure you regularly back up data you don't want to loose, documents, emails, email address book, bookmarks, etc. do this daily.

With a good back-up and recovery strategy you can recover from virtually anything in a short time without too much stress.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

gdiloren

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #12 on: July 26, 2007, 07:18:54 PM »
Thanks but at the moment of scanning, Google lead to nothing on the Phoney Trojan except for the ST web page definition which is poor info. You're right about imaging my drive. I want to put this in case some Avast user needs help:The problem turned out to be that the
Winlogon userinit entry was set to "wsupdater.exe," and not
"userinit.exe,". I fixed the problem by 1) booting to a Repair Console
(IBM provides this on their laptops), 2) changing directory to
C:\WINDOWS\System32, and 3) copying userinit.exe to wsaupdater.exe
(there was no wsaupdater.exe present). I then 4) rebooted into Safe mode
and successfully logged-on as Adminstrator (for the first time in
several days!) Next step was to 5) edit the registry and change
userinit in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon from "wsaupdater.exe," to "userinit.exe,"; 6)
final reboot and back to normal! --Rick Lewis--


drhayden1

  • Guest
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #13 on: July 26, 2007, 07:47:24 PM »
Quote
just ask Dan about AdAware 2007
and a-squared free also on false positives....
i have had my share of false positive problems and it getting to be old news but something we have to deal with some of the crappy software we have out there for us to have horror's with ??? :o ::)
http://forum.antivir.de/thread.php?threadid=24654&sid=c6eed8ae62a42cc26075eb776e20a5b5p
and i sent that link above to the st tech support just to see what type of response i will get or not ;)
« Last Edit: July 26, 2007, 07:56:55 PM by drhayden1 »

Offline MikeBCda

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2247
Re: WARNING!!! SPYWARE TERMINATOR!!!
« Reply #14 on: July 26, 2007, 07:57:42 PM »
Slightly off-topic, but closely related...

Could someone please post an addy for one or more good multi-engine online scanners, which is another defense against FPs? I know Jotti's one of them, and there are a few others I've seen recommended, but I'm too lazy to phrase a search properly.

One game which I've had for at least a couple of years suddenly last weekend had a-squared "find" a supposed backdoor in its uninstaller.  I suspect that's just one more of a-squared's notorious FPs, but it wouldn't hurt to double-check.

(Edit) I just checked that file via Jotti, and interestingly, a-squared didn't report anything there.  Maybe they cleaned up that particular FP since last weekend.
« Last Edit: July 26, 2007, 08:05:34 PM by MikeBCda »
Intel Atom D2700, 2 gig RAM, Win 7 x64 SP1 & IE-11, Firefox 51.0
(default). 320 gig HD, 15Mb DSL, Win firewall, Avast 12.3.2280 free, SpywareBlaster, MBAM Prem., Crypto-Prevent