Reply
Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

NAB can not quarantine a Risk.

You can see at this Picture , its a Fake Antispyware Program "adwarebot2008 from adwarebot.com" and Norton Antibot can not quarantine this Program , NAB says to me this Fake-Antispyware its a valid allowed or System Process ?! i do not allowed this.

 

[url=http://www.abload.de/image.php?img=adwarebot20083lt.jpg][img]http://www.abload.de/thumb/adwarebot20083lt.jpg[/img][/url]

http://www.abload.de/image.php?img=adwarebot20083lt.jpg

 

You can also test this at example on a Virtual PC.

Symantec Employee
athena
Posts: 100
Registered: ‎04-07-2008

Re: NAB can not quarantine a Risk.

Hi Voyager10,

 

I am looking into this, please give me another couple of days and will come back to you.

 

Thanks!

Symantec Employee
athena
Posts: 100
Registered: ‎04-07-2008

Re: NAB can not quarantine a Risk.

Hi again,

 

Our team researched the specific app and found that it is not malicious.

When we tested it on a clean Windows XP sp2 image (in English), it did not report any false details, except for realvnc keys. We did not find enough evidence that this is a misleading app.

 

Please let me know if you have any additional info on why this application is not clean.

Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: NAB can not quarantine a Risk.

[ Edited ]

@athena

 

thanks , but here on this Picture you can see its a misleading Application  !  it shows 321 infected Files and will only clean this after you buy this Application.  http://www.abload.de/image.php?img=adwarebot20083lt.jpg

 

Norton Antibot do not quarantine this ?! sorry but this is not ok . :smileymad:

 


Please let me know if you have any additional info on why this application is not clean.


 

not Problem, here you can see it.  (i rename this setupxv.exe from adwarebot.com to adwarebot.exe on 03.May.2008)

 

Datei adwarebot.exe empfangen 2008.05.07 21:18:03 (CET)

Ergebnis: 10/31 (32.26%)

 

AntiVir 7.8.0.11 2008.05.07 DR/FraudTool.SpywareStop.B.10
AVG 7.5.0.516 2008.05.07 Potentially harmful program Fake_AntiSpyware.RN
BitDefender 7.2 2008.05.07 Adware.SpyClean.A
DrWeb 4.44.0.09170 2008.05.07 Adware.Sguide.4
eSafe 7.0.15.0 2008.05.07 suspicious Trojan/Worm
Fortinet 3.14.0.0 2008.05.07 Misc/SpywareStop
Ikarus T3.1.1.26.0 2008.05.07 Downloader.FraudTool.SpywareStop.B.10
Kaspersky 7.0.0.125 2008.05.07 not-a-virus:FraudTool.Win32.SpywareStop.b
Norman 5.80.02 2008.05.07 W32/SpySheriff.DI
Webwasher-Gateway 6.6.2 2008.05.07 Trojan.Dropper.FraudTool.SpywareStop.B.10

 

Today show this Webside a New Version Setupxv.exe (against Antivirus Recognition) but its the same Fake Antispyware.

 

Datei setupxv.exe empfangen 2008.05.07 21:42:59 (CET)

Ergebnis: 6/31 (19.36%)

AVG 7.5.0.516 2008.05.07 Potentially harmful program Fake_AntiSpyware.RV
DrWeb 4.44.0.09170 2008.05.07 Adware.Sguide.4
eSafe 7.0.15.0 2008.05.07 suspicious Trojan/Worm
Fortinet 3.14.0.0 2008.05.07 Misc/SpywareStop
Kaspersky 7.0.0.125 2008.05.07 not-a-virus:FraudTool.Win32.SpywareStop.b
Norman 5.80.02 2008.05.07 W32/SpySheriff.DI

 

 

 

 

Message Edited by Voyager10 on 05-07-2008 12:49 PM
Message Edited by Voyager10 on 05-07-2008 12:55 PM
Stu Rootkit Eradicator
Rootkit Eradicator
Stu
Posts: 5,210
Registered: ‎04-08-2008

Re: NAB can not quarantine a Risk.

Do you have a sample zipped?
"All that we are is the result of what we have thought"
Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: NAB can not quarantine a Risk.

[ Edited ]

I have both Samples , from 3.May and Today.

Norton Antivirus do not recognize this and Norton Antibot can not quarantine this... very good !?

 

ps. and no its not zipped.

Message Edited by Voyager10 on 05-07-2008 12:54 PM
Stu Rootkit Eradicator
Rootkit Eradicator
Stu
Posts: 5,210
Registered: ‎04-08-2008

Re: NAB can not quarantine a Risk.

Please zip them and PM me
"All that we are is the result of what we have thought"
Keylogger Crusher
Voyager10
Posts: 434
Registered: ‎05-03-2008

Re: NAB can not quarantine a Risk.

why ?

 

Download this "download.adwarebot.com/setupxv.exe" and go on a Virtual PC with XP and Norton Antibot . Then start this setupxv.exe ! You can see the same http://www.abload.de/image.php?img=adwarebot20083lt.jpg if you will remove this with Norton Antibot.

Stu Rootkit Eradicator
Rootkit Eradicator
Stu
Posts: 5,210
Registered: ‎04-08-2008

Re: NAB can not quarantine a Risk.

Maybe I'm nuts.

Where is the download link?

"All that we are is the result of what we have thought"
Tony_Weiss
Posts: 7,366
Topics: 502
Kudos: 1,528
Solutions: 280
Registered: ‎04-07-2008

Re: NAB can not quarantine a Risk.

To clarify, it seems that the program is a trial version, which analyzes your system and informs you that you need to register in order to clean based on the analysis. Is this correct? This is similar to most programs that offer a trial version. They allow you to test out the functionality, but restrict any abuse of their software. Please let me know if I am misunderstanding the situation.
Tony Weiss
Norton Forums Global Community Manager
Symantec Corporation