PDA

View Full Version : RegistryFix malware?



aquatrecentquarante
2008-01-02, 09:20
I am surprised that RegistryFix is recognized by Spybot as a malware..
please confirm that before I'll destroy it...
thanks

spybotsandra
2008-01-02, 12:56
Hello,

The reasons why Spybot - Search & Destroy detects this software are several ones:
There are anti-spyware tools like 1stAntivirus, 100PercentAntiSpyware, AdArmor, Ad-Protect, Ad-PurgeSpywarerAndAdwareRemoverPro, AdsAlert, ADS-Remover, AdwareAlert, AdwareBazooka, AdwareDeluxe, Adware-Patrol, AdWare Pro, AdwarePunisher, Adware Remover, Adware Remover2007, AdwareSheriff, AdwareSpy, AdwareStriker, AdwareX Eliminator, AgentSpyware, AlfaCleaner, AntiSpyStorm, AntispywareBot, Antispywaresoldier, AntiSpyWare2007, AntiSpyZone, AntiVerMinsPro, AntiVirGear, Antivirus Gold, AntiVirusPro, Awola.Anti-Spyware, BPSAdwareCops, BPS AdwareStriker, BPS.SpyEliminator, BPS Spyware Cops, BPS Spyware Remover, BPS SpywareStriker, BPS.SpywareZapper, BreakSpyware, CleanSpaceUltimate, Contra-Spy, Contra-Virus, CyberDefender, DiaRemover, Doctor-Adware, Doctor-Adware-Pro,DoctorSpyware, DrAntispy, DriveCleaner2006, Easy-Spyware-Killer, ErrorClean, ErrorDoctor, ErrorGuard, ErrorKiller, ErrorSafe, ETD-Security-Scanner, EyeSpyNow, ExpertAntivirus, FixerAntispy, FlashDollars.AntiVirusProtection, FlashDollars.RegistryRepair, FlashDollars.SpywareRemover, Fraud.XPAntivirus, FroggieScan, Goodbye-Spy, IEDefender, KazaapAdwareAndSpywareRemover, KillSpy, LocusSoftware.BestsellerAntivirus, LocusSoftware.PCPrivacyTool, LocusSoftware.SecurePCCleaner, MacroVirus, MagicAntiSpy, MalwareAlarm, MalwareBot, MalwareBurn, MalwareScanner, MalwareWipe, Maxion.MaxnetShield, MrAntispy, MySpyProtector, Neospace-Internet-Security, NoAdware, Nous-Tech.UCleaner, Nous-Tech.UDefender, Nous-Tech.UFixer, Nous-Tech.Ultimate-Fake-Security-Center, One-Shot-Antivirus, OnlineGuard, Pal-Spyware-Remover, PC-Health-Plan, PerformanceOptimizer, Pestbot, PestCapture, PSGuard, PurityScan, RazeSpyware, Registry Cleaner, RegistryFix, RegSweep, Repair Registry Pro, SecureMyPC, ScanSpyware, Spionfrei, SpyAgent, SpyAnalyst, SpyAnyWhere, SpyAxe, SpyBlocs, SpyBouncer, SpyCleaner, Spycontra, SpyCrush, SpyDawn, Spydeface, SpyDefence, SpyDefender, SpyDestroy-Pro, SpyFalcon, SpyGuard, SpyHeal, SpyHunter, SpyKiller, SpyLax, SpyLocked, SpyMarshall, SpyOfficer, SpyOnThis, SpyQuake, SpyRemover, SpySherrif, SpyShredder, SpySoap, SpySpotter, SpyStriker, SpyTrooper, SpyVampire, SpyViper, SpywareAnnihilatorPro, SpywareBomber, SpywareBot, SpywareCleaner, SpywareDetector, SpywareLocker, SpywareNO!, SpyWareRemover, SpyWare-Secure, SpywareSheriff.FakeAlert, SpywareSoftStop, SpywareSolver, SpywareStormer, SpywareStrike, SpywareQuake, StartGuard, SynergeticSoft.PrivacyDefender, SysProtect, SysRegistryCleaner, SystemDoctor2006, Trek Blue Error Nuker, Trojan-Guarder, TrueSword, TrustCleaner, UltimateCleaner, UltraSoft.Xlib, UtileProtection, VarioAntivirus, Vario.RogueAntiSpy, Virusblast, VirusBurst, VirusLocker, VirusProtect, VirusProtectPro, VirusRanger, VirusRescue, VirusSchlacht, WareOut, WinAntivirusPro2006, WinFixer, WinHound, WinSoftware, WinSoftware.WinAntiSpyware2006, WinSoftware.WinAntiVirusPro2006, WinSoftware.WinAntiVirus2006, WiperWizard, WorldAntispy, X-Con-Spyware-Destroyer, X-Spyware, XSRemover, YourSoft-AntiVS and YourSoft-AntiVT which have a very dubious or bad character.
They state to be an anti-spyware tool but employ questionable advertising methods: In the form of a PopUp they offer a scan of your system. They refer you to an infection of viruses and spyware on your system which is actually not true, because the listed items are not really on your pc. After downloading the software you can only scan for the threats. If the threats (pseudo-infections) are detected you have to register first and pay (up to $30) in order to remove them. Some of these dubious anti-spyware tools do also create a toolbar in IE and create recurring PopUps.

More dubious anti-spyware tools you will find here:
http://spywarewarrior.com/rogue_anti-spyware.htm

Best regards
Sandra
Team Spybot

aquatrecentquarante
2008-01-03, 09:18
thanks for your quick and complete reply;
I know now what I have to do;
"cordialement"

Mike...
2008-01-10, 22:04
Sandra, from where did you copy and paste that list?

I own a copy of RegistryFix and all of a sudden Spybot finds 19 entries for it and in my opinion mislabels it as malware.

It's a registry scanner, it has nothing to do with anti-spyware. It's basically a more advanced version of Crap Cleaner's registry cleaner for example. Nothing weird. Does its job, no side effects. No problems with the credit card.

Methinks, false positive, puely looking at this program.

Also, that links says nothing about RegistryFix.

:scratch:

tashi
2008-01-10, 23:25
Hi Mike... I made an inquiry for further details. :)

spybotsandra
2008-01-11, 10:14
Hello,

RegistryFix is no false positive.
It is a rogue software.
RegistryFix belongs to Marketflip Technologies like the rogue antispyware software NoAdware or Spyware Solver. Its domain is registered through domains by proxy. Neither license nor website state proper contact information or any information about the company. False positives and warning messages serve to make the user buy the software. This software is identical to ErrorClean which is also from Marketflip Technologies.

Best regards
Sandra
Team Spybot

Mike...
2008-01-11, 13:53
Yes, I can also read the explanation Spybot gives me, but surely one's own instinct, common sense and first hand experience with the program are more important than a piece of text on my screen.

And again, where did you copy and paste the above text from?

Even if it belongs to some shady company, which may or may not have other programs that are a bit on the dubious side, is that reason enough to label this specific program as malware?

Malware, malicious software. So, what are the malicious things that this program does to my computer? Can you explain that? Because there's nothing weird going on on my PC.

Don't think I'm advertising this program, but first the Spybot alerts and then this thread and particularly your response strike me as odd. Copy and paste, then a link with no information about this particular program. Having a user remove software that may very well be harmless. Then some more text copied from somewhere.

What ever happened to the old brain? ;)

Not sure if you have a testing environment, but why not install a copy and see for yourself what it does or does not do.

MisterW
2008-01-11, 23:36
Mike,
of course we have a testing enviroment and of course we tested this tool to make sure about what we are talking. When we installed RegistryFix in this clean enviroment it showed us about 100 "heavy" threads. Most of them were important registry keys and not some crap that should be deleted.
When we tried to see which company is behind this software we recognized that they hide behind domainsbyproxy. So it is not possible to get in contact with them for the normal user.
Because it shows a lot of harmless registry keys as a thread and if you would delte those some programs would not work any more, we decided to detect it as Malware.

Both posts from Sandra where totally correct and from our database. The first one lists a lot of rogue progams that are working with similar ways to cheat users (showing false positives as high risk problems making the user buy the full version). The last post shows the official description that is included in Spybot too.

And if you do not want to remove RegistryFix you can exclude it from detection by right click on it.
regards,
Markus

registryfix
2008-01-12, 00:10
Hello,

My name is Michael and I work for Registryfix. What MisterW has posted is entirely without merit. When we contacted spybot via email about their detection of our software, we were never informed of our software detecting anything that could harm a PC.

Our software has been marketed and sold for the last several years and has been used by millions of consumers. Using it will in no way damage your PC or programs used on your PC.

"When we tried to see which company is behind this software we recognized that they hide behind domainsbyproxy. So it is not possible to get in contact with them for the normal user."

We have a live email address as well as live chat offered via our website 363 days a year, if a customer needs to contact us, they get assistance immediately. I will also add that spybot never attempted to contact us.

On that note, if any customer here has had their software removed by spybot and requires assistance, you can reach our staff at any one of our contact pages.

-Michael

MisterW
2008-01-12, 00:36
Michael,
So if your customers can reach your company 363 days a year I do not see the reason why you have to cover your real adress by using an service like domainsbyproxy where no user can see any details about your company.

Where did you sent those mails? I don't think that we got any mail from your company but will check that when I am back at the office on Monday. In fact we have a lot of screenshots showing that your software detected harmless entries.

If you have any question do not hesitate to contact me via mail 365 days a year: reviews(at)spybot.info (at=@)

regards,
Markus