Tillbaka till svenska Fidonet
English   Information   Debug  
VATICAN   0/2740
VIETNAM_VETS   0/14
VIRUS   0/378
VIRUS_INFO   0/201
VISUAL_BASIC   0/473
WHITEHOUSE   0/5187
WIN2000   0/101
WIN32   0/30
WIN95   0/4278
WIN95_OLD1   5179/70272
WINDOWS   0/1517
WWB_SYSOP   0/419
WWB_TECH   0/810
ZCC-PUBLIC   0/1
ZEC   4

 
4DOS   0/134
ABORTION   0/7
ALASKA_CHAT   0/506
ALLFIX_FILE   0/1313
ALLFIX_FILE_OLD1   0/7997
ALT_DOS   0/152
AMATEUR_RADIO   0/1039
AMIGASALE   0/14
AMIGA   0/331
AMIGA_INT   0/1
AMIGA_PROG   0/20
AMIGA_SYSOP   0/26
ANIME   0/15
ARGUS   0/924
ASCII_ART   0/340
ASIAN_LINK   0/651
ASTRONOMY   0/417
AUDIO   0/92
AUTOMOBILE_RACING   0/105
BABYLON5   0/17862
BAG   135
BATPOWER   0/361
BBBS.ENGLISH   0/382
BBSLAW   0/109
BBS_ADS   0/5290
BBS_INTERNET   0/507
BIBLE   0/3563
BINKD   0/1119
BINKLEY   0/215
BLUEWAVE   0/2173
CABLE_MODEMS   0/25
CBM   0/46
CDRECORD   0/66
CDROM   0/20
CLASSIC_COMPUTER   0/378
COMICS   0/15
CONSPRCY   0/899
COOKING   29663
COOKING_OLD1   0/24719
COOKING_OLD2   0/40862
COOKING_OLD3   0/37489
COOKING_OLD4   0/35496
COOKING_OLD5   9370
C_ECHO   0/189
C_PLUSPLUS   0/31
DIRTY_DOZEN   0/201
DOORGAMES   0/2031
DOS_INTERNET   0/196
duplikat   6000
ECHOLIST   0/18295
EC_SUPPORT   0/318
ELECTRONICS   0/359
ELEKTRONIK.GER   1534
ENET.LINGUISTIC   0/13
ENET.POLITICS   0/4
ENET.SOFT   0/11701
ENET.SYSOP   33832
ENET.TALKS   0/32
ENGLISH_TUTOR   0/2000
EVOLUTION   0/1335
FDECHO   0/217
FDN_ANNOUNCE   0/7068
FIDONEWS   23647
FIDONEWS_OLD1   0/49742
FIDONEWS_OLD2   0/35949
FIDONEWS_OLD3   0/30874
FIDONEWS_OLD4   0/37224
FIDO_SYSOP   12850
FIDO_UTIL   0/180
FILEFIND   0/209
FILEGATE   0/212
FILM   0/18
FNEWS_PUBLISH   4250
FN_SYSOP   41536
FN_SYSOP_OLD1   71952
FTP_FIDO   0/2
FTSC_PUBLIC   0/13589
FUNNY   0/4886
GENEALOGY.EUR   0/71
GET_INFO   105
GOLDED   0/408
HAM   0/16056
HOLYSMOKE   0/6791
HOT_SITES   0/1
HTMLEDIT   0/71
HUB203   466
HUB_100   264
HUB_400   39
HUMOR   0/29
IC   0/2851
INTERNET   0/424
INTERUSER   0/3
IP_CONNECT   719
JAMNNTPD   0/233
JAMTLAND   0/47
KATTY_KORNER   0/41
LAN   0/16
LINUX-USER   0/19
LINUXHELP   0/1155
LINUX   0/22020
LINUX_BBS   0/957
mail   18.68
mail_fore_ok   249
MENSA   0/341
MODERATOR   0/102
MONTE   0/992
MOSCOW_OKLAHOMA   0/1245
MUFFIN   0/783
MUSIC   0/321
N203_STAT   906
N203_SYSCHAT   313
NET203   321
NET204   69
NET_DEV   0/10
NORD.ADMIN   0/101
NORD.CHAT   0/2572
NORD.FIDONET   189
NORD.HARDWARE   0/28
NORD.KULTUR   0/114
NORD.PROG   0/32
NORD.SOFTWARE   0/88
NORD.TEKNIK   0/58
NORD   0/453
OCCULT_CHAT   0/93
OS2BBS   0/787
OS2DOSBBS   0/580
OS2HW   0/42
OS2INET   0/37
OS2LAN   0/134
OS2PROG   0/36
OS2REXX   0/113
OS2USER-L   207
OS2   0/4786
OSDEBATE   0/18996
PASCAL   0/490
PERL   0/457
PHP   0/45
POINTS   0/405
POLITICS   0/29554
POL_INC   0/14731
PSION   103
R20_ADMIN   1117
R20_AMATORRADIO   0/2
R20_BEST_OF_FIDONET   13
R20_CHAT   0/893
R20_DEPP   0/3
R20_DEV   399
R20_ECHO2   1379
R20_ECHOPRES   0/35
R20_ESTAT   0/719
R20_FIDONETPROG...
...RAM.MYPOINT
  0/2
R20_FIDONETPROGRAM   0/22
R20_FIDONET   0/248
R20_FILEFIND   0/24
R20_FILEFOUND   0/22
R20_HIFI   0/3
R20_INFO2   3018
R20_INTERNET   0/12940
R20_INTRESSE   0/60
R20_INTR_KOM   0/99
R20_KANDIDAT.CHAT   42
R20_KANDIDAT   28
R20_KOM_DEV   112
R20_KONTROLL   0/13118
R20_KORSET   0/18
R20_LOKALTRAFIK   0/24
R20_MODERATOR   0/1852
R20_NC   76
R20_NET200   245
R20_NETWORK.OTH...
...ERNETS
  0/13
R20_OPERATIVSYS...
...TEM.LINUX
  0/44
R20_PROGRAMVAROR   0/1
R20_REC2NEC   534
R20_SFOSM   0/340
R20_SF   0/108
R20_SPRAK.ENGLISH   0/1
R20_SQUISH   107
R20_TEST   2
R20_WORST_OF_FIDONET   12
RAR   0/9
RA_MULTI   106
RA_UTIL   0/162
REGCON.EUR   0/2056
REGCON   0/13
SCIENCE   0/1206
SF   0/239
SHAREWARE_SUPPORT   0/5146
SHAREWRE   0/14
SIMPSONS   0/169
STATS_OLD1   0/2539.065
STATS_OLD2   0/2530
STATS_OLD3   0/2395.095
STATS_OLD4   0/1692.25
SURVIVOR   0/495
SYSOPS_CORNER   0/3
SYSOP   0/84
TAGLINES   0/112
TEAMOS2   0/4530
TECH   0/2617
TEST.444   0/105
TRAPDOOR   0/19
TREK   0/755
TUB   0/290
UFO   0/40
UNIX   0/1316
USA_EURLINK   0/102
USR_MODEMS   0/1
Möte WIN95_OLD1, 70272 texter
 lista första sista föregående nästa
Text 6247, 243 rader
Skriven 2005-03-27 11:57:42 av mark lewis (1:3634/12)
Ärende: counterspy "review"
===========================
well, this is my first "review" type of thing so please bear with me... i've
not gone about being very scientific with it, either... i just downloaded,
installed and ran the scan on this daily-use box... this message is rather on
the "long" side... i remember seeing the line count around 240 while i was
writing it but reformatting done by my software will shorten that a bit...


the box:
this box is a celeron 300a with 256 meg of ram running win98se on a 30gig
harddrive... there is no modem... only a network card and a sound card... the
motherboard is an intel 440bx-2... definitely nothing fancy and pretty far
behind the curve of today's machines... this system was set up and installed
Dec 21, 2000... it has seen a lot of use over these last 4 years...


downloading:
getting counterspy wasn't so hard... i just had to give them a name and an
email address... of course i created and used a new sneakemail address... "just
in case" ya know ;)  once this was done, i was carried over to the page where i
could download the 13Meg installer... the version of counterspy their
downloaded pushed to me was v1.0.29 which i tacked on to the filename since
they were sending a "plain" filename, counterspy.exe... i stored it on my
machine as counterspy-1.0.29-EVAL.exe since i was not getting the full
registered version or a license key...


installation:
once the installer was received, i ran it after saving my registry and checking
the registry's current startup locations and several other key sections... the
installer created three new registry keys in
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

"sunasDTServ" = "C:\Program Files\Sunbelt Software\CounterSpy
Client\sunasDTServ.exe" ["Sunbelt Software Inc."]

"Default" = (no data)

"sunasServ" = "C:\Program Files\Sunbelt Software\CounterSpy
Client\sunasServ.exe" ["Sunbelt Software Inc."]


and one new registry key in
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\

"Default" = (no data)


i suspect that those "Default" blank ones are coding errors... they were not
there before running the counterspy installer... after the reboot, the
sunasDTServ key had been converted to all caps... the other two keys stayed the
same and the key in the RunOnce section had been removed...


initial update:
when the system reloaded, there was a counterspy icon in the system tray and
another one on the desktop... i clicked the one on the desktop to open the
program so i could run my first scan...

upon opening, there was a box that popped up in the lower right corner of the
screen that said that it was updating the spyware definitions... at this point,
the software firewall started popping up alerts as the counterspy updater
attempted to access the internet... it was allowed access to 127.0.0.1:8080
which is my filtering proxy and then it also wanted access a UDP ports... the
UDP port appears to be used to send back ACKs as each block of downloaded
material comes in... for those old timers, yeah, kinda like xmodem ACKs each
block ;)

i left the system to run its download for a bit... due to my slow connection,
it took a while... during this time, i tried to do a few other things but the
counterspy updater had a tight grip on the system... it hadn't even redrawn its
own window after i had ok'd the firewall's popups...

i am unable to determine exactly what the updater downloaded... i should have
taken a snapshot of the install directory before allowing the update to take
place... there are several files in the install directory that contain
timestamps consistant with the updater's execution... one of those files is
3Meg in size...


initial scan:
after the updater finished, the program appeared to simply close. i double
clicked on the desktop icon again and was greeted with the counterspy splash
box and then their "first time execution wizard" which set the defaults and
wanted to try updating a second time... i had to clear another UDP port thru
the firewall for this... after that, i simply kept clicking NEXT until the
wizard was completed... then i ended up at a screen where i could execute the
initial system scan... i selected to run a full deep scan on the entire system
and added a checkmark to the box to scan the entire drive... then i started the
process and watched as counterspy went to work...

after some 4000 files, counterspy said that it had found something it calls
NetAware and says that it is surveillance related... i ran into problems at
this point because i tried to use the mouse and click on this item to see what
it was and to see if counterspy would allow me to look at details while it was
running... when i clicked on this item, i saw a box popup and then disappear...
it took me a few times to realize that i had to click and hold so as to keep
the box up... unfortunately, there wasn't as much detail in the box as i'd have
liked to see... specifically the filename of the suspected infestation...


trouble:
after i had read what was in this box, i doubleclicked on the name and watched
as the program crashed and windows popped up its standard "application fault"
box... shrugging our shoulders, i cleared that box off the screen and restarted
counterspy... this time i left it to do its thing and went to watch a few shows
on television...


the results:
after some 3 hours 40 minutes, counterspy completed the initial full system
scan... it said that it had found three spyware products...


recommended action: quarantine
spyware name: NetAware (Surveillance)
threat level: [ELEVATED]

recommended action: ignore
spyware name: Weatherbug (Low Risk Adware)
threat level: [LOW]

recommended action: quarantine
spyware name: Find Protected (Potentially Dangerous)
threat level: [ELEVATED]


the first result is pointing to a shortcut that i had created on my desktop to
access one of our network shares for ease of use... the filename is
c:\windows\desktop\shortcut to files.lnk

here is what counterspy says about this result...

==========
  NetAware
  Type: Surveillance
  Level: Elevated
  Author: Infiltration Systems

  Description: NetAware is a monitoring tool that logs
  and records all shared file activity on your computer
  or network.

  Advice: This is a high risk threat and should be
  removed or quarantined as to prevent harm to your
  computer or your privacy.

  About Surveillance: [blank]
==========

there is nothing dangerous about this link and counterspy
completely missed the other three shortcuts to additional
network resources on the desktop that were created at the same
time and in the same manner... false positive - strike 1...



the second result, weatherbug, i expected... weatherbug installs minibug...
minibug retrieves the advertisement skins for the weatherbug application
interface...

here is what counterspy says about this result...

==========
  Weatherbug
  Type: Low Risk Adware
  Level: Low
  Author: WeatherBug

  Description: Minibug is an adware that displays ads
  on to your computer.

  Advice: This is a low risk adware application and
  will not cause direct harm to your computer,
  removing it is not required. However, it is strongly
  recommended that you review this application's End User
  License Agreement (EULA) as well as review the
  application's privacy policies.

  About Low Risk Adware: Low risk adware is an adware
  application that is designed to potential show
  advertisements via popups. However, this type of adware
  program is installed with the user's knowledge and
  conforms to the programs EULA which is usually presented
  to the user prior to download and during installation.   A low risk adware
program will not transmit personal or   identifiable information.
==========

we'd already neutered minibug by simply blocking its access to
the internet from the firewall...



the last result appears to be another case similar to the first result. this
time, it is looking at the unrar.dll file that comes with antivir from
free-av.com... antivir uses this dll to look inside archives for virus infected
files...

here is what counterspy says about this result...

==========
  Find Protected
  Type: Potentially dangerous utilities/tools
  Level: Elevated
  Author: AKS-Labs.

  Description: Find Protected is a softare designed to
  search for password protected files on local disks and
  across a network. With Find Protected you can located
  MS Office password protected files and popular password
  protected archives, such as WinZip and WinRar. Also,
  you can find some encryption systems, such as PGP Disk.

  Advice: This is a low risk application and will not
  cause direct harm to your computer, removing it is not
  required. However, it is strongly recommended that you
  review this application's End User License Agreement
  (EULA) as well as review the application's privacy
  policies.

  About Potentially dangerous utilities/tools: [blank]
==========

ok? you can do this with most any archiver and some scripting... no big deal...
false positive - strike 2

at this point, i simply closed counterspy as i didn't want to do anything with
what it had found...

counterspy's interface looks nice and decently thought out... i've not gone
tripping around in it other than just to do the scan of this system to see what
it was finding...

overall, counterspy appears to be a good package... is it worth the
registration fee? i can't really say... that's one of those subjective
things... i've not had any problems with the freeware antispyware tools that
i've used for several years... i find them to be quite adaquate for the job and
i've not gotten any false positives from them... just because something costs
money or is commercial doesn't make it better (or worse) than something that is
free or costs less...

)\/(ark

 * Origin: (1:3634/12)