PDA

View Full Version : SpywareDetector on Malware list



gpolkga
2006-07-06, 05:46
A recent Spybot update lists Spyware Detector as malware. What evidence is there of this? Spywarewarrior has removed it from their list.

spybotsandra
2006-07-06, 10:25
Hello,

The reasons why Spybot - Search & Destroy detects this software as malware are several ones:
There are anti-spyware tools like SpywareDetector which have a very dubious or bad character. They state to be an anti-spyware tool but employ questionable advertising methods: In the form of a PopUp they offer a scan of your system. They refer you to an infection of viruses and spyware on your system which is actually not true, because the listed items are not really on your pc. After downloading the software you can only scan for the threats. If the threats (pseudo-infections) are detected you have to register first and pay (up to $30) in order to remove them. Some of these dubious anti-spyware tools do also create a toolbar in IE and create recurring PopUps.

Screenshots are availible at: http://board.protecus.de/showtopic.php?threadid=15694

More dubious anti-spyware tools you will find here:
http://spywarewarrior.com/rogue_anti-spyware.htm

Best regards
Sandra
Team Spybot

Susan528
2006-07-16, 14:04
Thanks, I looked at that post. Unfortunately I studied Spanish and not German but I noticed dates to left was 2005 so I went with the most current date which is in Spyware Warrior's rogue list.

Thanks for the information.

Yodama
2006-07-17, 09:54
the reason why SpywareDetector is listed as Malware is that it can get installed without userconsent along with a Smithfraud-C infection.
So basically SpywareDectector will find an infection on your computer, an infection that came along with it. Then they charge you to remove the infection they are responsible for.

concerning Spywarewarrior:
They do a lot of testing to keep their rogue/suspect list up to date.
Unfortunately these rogues keep popping up in masses and of course changing quickly.
This makes it very hard for anyone to always keep an updated list of those.
Just imagine how long it would take to retest each item in the Spywarewarrior list regularly.

I am not saying the list is unreliable, in fact I am glad it exists, but we cannot make our detections of rogues based on Spywarewarriors list alone.

Since we tested a SpywareDetector sample that came along with Smithfraud, it is clearly Malware and will be treated as such.

rachna
2007-02-23, 16:14
Spyware Detector is an outstanding anti-spyware product, having maximum number of spyware database definitions and capability to remove all new as well as old spyware threats. It also has active monitoring to prevent users from incoming threats. It has a large customer base and provides email, chat and remote connection based technical support free of charge to all subscribed users. It offers incremental updates so that users get the patch as soon as possible. It updates it definitions about 2-3 times a day on the average. It is continuously upgrading product for new techniques of detecting and killing the infections including heuristics.

Most of the anti-spyware products end up with few false positive even though this issue gets the maximum attention in spyware labs. So if any user finds any false positive they are encouraged to remove it. It is never intentional to show users any spyware entry, which is not present on their PC. Our technical support is working very hard to make sure that spyware detector remove 1005 infections without wrongly identifying any legitimate entries.

Max Secure Software had written to SpyBot since they were detecting Spyware Detector as spyware and after further investigation, they have removed this false positive of spybot and do not detect spyware detector any more as spyware.

Devan
2007-02-25, 17:52
Spyware Detector is an outstanding anti-spyware product, having maximum number of spyware database definitions and capability to remove all new as well as old spyware threats. It also has active monitoring to prevent users from incoming threats. It has a large customer base and provides email, chat and remote connection based technical support free of charge to all subscribed users. It offers incremental updates so that users get the patch as soon as possible. It updates it definitions about 2-3 times a day on the average. It is continuously upgrading product for new techniques of detecting and killing the infections including heuristics.

Most of the anti-spyware products end up with few false positive even though this issue gets the maximum attention in spyware labs. So if any user finds any false positive they are encouraged to remove it. It is never intentional to show users any spyware entry, which is not present on their PC. Our technical support is working very hard to make sure that spyware detector remove 1005 infections without wrongly identifying any legitimate entries.

Max Secure Software had written to SpyBot since they were detecting Spyware Detector as spyware and after further investigation, they have removed this false positive of spybot and do not detect spyware detector any more as spyware.
Can we have an administrator look into this?

/edit.

Since we tested a SpywareDetector sample that came along with Smithfraud, it is clearly Malware and will be treated as such.

Rachna has infiltrated the Spy-bot forums.

tashi
2007-02-25, 19:52
Can we have an administrator look into this?

/edit.


Rachna has infiltrated the Spy-bot forums.


Since we tested a SpywareDetector sample that came along with Smithfraud, it is clearly Malware and will be treated as such.


The quote from Yodama is from 2006-07-17, I will ask a Team member to comment.

Bear in mind that if an application is removed from the Rogue list or as a detection, it is not a recommendation for the product in question.

Yodama
2007-02-26, 08:45
I can confirm, that Spybot does not detect Spyware Detector anymore. Thus it is currently not regarded as malware anymore. Note that it was never detected as spyware.
That has been changed some while ago.

@Rachna

pleas stop your advertising

eveningrain
2008-07-23, 05:50
Since this is my first post, I hope I am posting in the proper place. I just purchased 2 copies of Max Secure Spyware Detector and upon running Spybot, this came up as spyware - and my definitions were up-to-date. I tried it again and again and the results were always the same. I was very angry because I did some research (or at least thought it was enough) because Spybot could not remove a program called 007 on my pc and Spyware Detector promises they could remove it. Well, after finding out that Spyware Detector could be even more of a threat, I uninstalled the programs and the next day after purchase contacted the company which provides a guarantee "Max Secure Offers "No Questions Asked" 30 day Money Back Guarantee." I wrote to them and told them their program is showing up as a spyware or malware and that I wanted a refund on my purchase and that I had removed the programs from my pc.

They wrote back, stating their program is 100% safe and that Spybot is wrong - for me to update Spybot - when it was already up-to-date, and that I should use the program a while longer. There is no way I am reinstalling their program on my pc. I have lost all confidence and faith in this program and now of course, I am having problems getting a return on my purchase - they are not honoring their "no questions asked" guarantee.

Being on a fixed income, I cannot afford to throw money away like this, and since I made the purchase through Pay Pal, I am now attempting to get them to do something - so far, no luck, it takes time I guess. In the meantime, the company insists I continue to try out their program, to send them logs, etc., which I won't do - why should I provide them with more info on my set-up - I am afraid about trusting this company at all, especially now, when they won't even honor their own software guarantee.

I have used Spybot for years and it's the best program I have ever used. Today, I know it's nearly necessary to have more than one Spyware program with all the junk that is out there. I have nothing to hide, but it worries me very much that someone can see everything I have and do on my pc - even to the point of taking screen shots.

Please - does anyone have any advice for me? Is this program legit or what? Being disabled and homebound, my pc is my lifeline to the outside world, but now I'm even afraid to use it - that I might pick up something else without realizing it.

Thank you for your help.

Evening Rain

drragostea
2008-07-23, 18:58
It seems to me that 'SpywareDetector' is not SpywareWarrior's Rouge Anti-Spyware List anymore. However, we cannot be sure as it was last updated in May, 2007.
List of Rogue/Suspect Anti-Spyware Products (http://www.spywarewarrior.com/rogue_anti-spyware.htm#notes)

I did some research on the site with McAfee's SiteAdvisor:
http://www.siteadvisor.com/sites/spywaredetector.com?ref=safesearch&client_ver=FF_26.6_6271&locale=en-US&premium=false&aff_id=0
--
In my personal perspective, it sounds like this 'SpywareDetector' is using marketing/advertising pressure to make users purchase their product. In a sense, sometimes it promotes a sense of panic.

"Warning! Your computer is infected with Spyware. Click here to remove it".
"Your computer is infected with a malicious trojan! Purchase the #1 Spyware removal tools to remove it".

No offense, but I have distaste towards 'rogue' products who claim and somewhat boast about 'worldwide product', 'trusted', 'five stars'. One trick I use to distinguish whether the 'awards' the products receives are fake or not is the 'company' or site they receive it from. Take like the 'Editors's Award of 2008 from C!Net' for example. I've used a exclaimation mark because there's a spacing (l) between C and Net. That would be a 'genuine' award.
If a product just says 'five stars' and 'recommended by experts' with a logo and no 'distinguishable' text from the site or place it received it from, it's most likely a fake. I won't say it's always like that, might in a majority of the cases it is.
--
As for the '007' entry it is spyware. Was Spybot-SD successful in removing it? How about booting in 'Safe Mode' and removing it? If the problem still persists and it's becoming an annoyance you can request help in the Malware Forums.

To top this off: Read Tony Klein's So how did I get infected in the first place? (http://forums.spybot.info/showthread.php?t=279)

Safe surfing and welcome to the forums.

wyrmrider
2008-07-23, 20:20
I'll see if spywarrarrior can take another look at it however if they re using FP's and scare tactics as a goad to purchase it would be listable

Ban the Spammers
or not spam
but any affiliation is not disclosed

perhaps it is spybot that should reconsider

md usa spybot fan
2008-07-23, 20:55
gpolkga:

There is a detection named "SpywareDetector" in the Malware.sbi file. I don't know exactly what the "SpywareDetector" detection(s) are checking for or if the detections are intended to actually detect the "Max Secure Spyware Detector" product that you posted about.

I would like to suggest that you repost in the False Positives (http://forums.spybot.info/forumdisplay.php?f=16) forum so that it is more likely that your query will receive the attention of a "Team Spybot" member. Please follow the posting instructions for that forum:
How to report False Positives
http://forums.spybot.info/showthread.php?t=19117

dvmorrison
2008-09-15, 23:04
I cannot understand why Spybot continues to detect Max Software's Spyware Detector as malware (I only became aware of this today subsequent to uploading latest version of Spybot - I had previously been using an earlier version which nicely complimented the Spyware Detector, and Adaware products. Fortunately, I caught it in the list and was able to omit it from entries to be deleted, thereby avoiding the hassle of communicating with the Max folks to reinstall and re-registeri my Detector product. I've subsequently modified settings in Spybot Mode options to ignore the product from further scans.
The Detector product is highly regarded in the industry, it's data base is maintained vigorously with frequent updates to new threats, and has gained an increasingly large installation base of paid, loyal users over the last few years. Instead of persisting in what appears to be a pissing contest between your two excellent products, I believe it would be in the best interest of user security for the products to play well together once again.
Klaatu Barada Nikto

wyrmrider
2008-09-16, 02:14
again we find affiliates
those who profit somehow from a rogue product pimping and spaming this forum

any google search will find many horror stories

here's a reasonably unbiased review friom March of this year
http://www.2-spyware.com/review-max-secure-spyware-detector.html

Max Secure Spyware Detector review
Max Secure Spyware Detector uses false positives. The application was tested on clean uninfected computer. Both full and quick system scans were performed. The program found 4 critical objects related to 3 worms. Analysis showed that registry entry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Zone Labs Client associated with Chod mass-mailing worm actually is related with fully legitimate ZoneAlarm Pro firewall. Directories C:\Program Files\mIRC, C:\Program Files\eMule and C:\Program Files\eMule\Incoming belong to mIRC chat client and harmless file sharing program eMule. These applications have nothing in common with Serflog worm. See a screenshot below.

Full system scan approximately takes one minute. The program doesn't thoroughly check the content of each file.

Free version allows to remove parasites only once. After later scans it will refuse to eliminate malware and will ask to register and purchase the full product.

There is a strange mistake in Max Secure Spyware Detector interface. Instead of "Spyware" developers decided to use the word "Worms". Does this mean that Max Secure Spyware Detector finds only worms?

The official domain is spywaredetector.net.

We DO NOT recommend purchasing or using this program.

wyrmrider
2008-09-16, 02:47
False positives as an inducement is grounds for listing
bundling with adware/ malware/ spyware by affiliates is grounds for listing

here is the laugh of the day
recommending spy Hunter for removing
http://www.411-spyware.com/remove-spywaredetector

and

will the real Spyware Detector please stand up
http://www.411-spyware.com/remove/rogue-anti-spyware

https://www.ripoffreport.com/reports/0/244/RipOff0244136.htm

tashi
2008-09-16, 03:35
Hello dvmorriso,

Please note md usa spybot fan's suggestion to another member.



I would like to suggest that you repost in the False Positives (http://forums.spybot.info/forumdisplay.php?f=16) forum so that it is more likely that your query will receive the attention of a "Team Spybot" member. Please follow the posting instructions for that forum:

How to report False Positives
http://forums.spybot.info/showthread.php?t=19117




again we find affiliates
those who profit somehow from a rogue product pimping and spaming this forum
You do not know that wyrmrider, at this time a member is merely asking questions.

If users wish to query a detection please post in the false positive forum.

If the topic is left unanswered Team will see it more readily.

Best regards.