<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>startupware.com &#187; Identification</title>
	<atom:link href="http://www.startupware.com/category/identification/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.startupware.com</link>
	<description>Reversing the Model for Spyware Removal</description>
	<lastBuildDate>Tue, 20 Jul 2010 13:26:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>FTC places temporary halt on XP Antivirus and Family</title>
		<link>http://www.startupware.com/identification/ftc-places-temporary-halt-on-xp-antivirus-and-family/</link>
		<comments>http://www.startupware.com/identification/ftc-places-temporary-halt-on-xp-antivirus-and-family/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 17:24:30 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://www.startupware.com/?p=67</guid>
		<description><![CDATA[The Federal Trade Commission has gone to U.S. District Court, and shut down, at least for the moment, Innovative Marketing, Inc. and ByteHosting Internet Services, LLC, who they&#8217;ve identified as the source of such nasty-ware as WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus.
Here&#8217;s their press item:
http://www.softwarekb.com/news/2008/12/11/court-halts-bogus-computer-scans/
This group of rogue programs has made this past year [...]]]></description>
			<content:encoded><![CDATA[<p>The Federal Trade Commission has gone to U.S. District Court, and shut down, at least for the moment, Innovative Marketing, Inc. and ByteHosting Internet Services, LLC, who they&#8217;ve identified as the source of such nasty-ware as WinFixer, WinAntivirus, DriveCleaner, ErrorSafe, and XP Antivirus.</p>
<p>Here&#8217;s their press item:<br />
<a href="http://www.softwarekb.com/news/2008/12/11/court-halts-bogus-computer-scans/">http://www.softwarekb.com/news/2008/12/11/court-halts-bogus-computer-scans/</a></p>
<p>This group of rogue programs has made this past year interesting for me. I clean up these programs more than any other type of malware, and yes, I get paid. But all in all, I&#8217;d rather be upgrading hard drives and building new systems.</p>
<!-- AdSense Now! V1.92 -->
<!-- Post[count: 2] -->
<div class="adsense adsense-leadout" style="text-align:center;margin: 12px;"><br><iframe src="http://rcm.amazon.com/e/cm?t=sciencetransl-20&o=1&p=12&l=ur1&category=electronicsrot&f=ifr" width="300" height="250" scrolling="no" border="0" marginwidth="0" style="border:none;" frameborder="0"></iframe>

<br></div>]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/ftc-places-temporary-halt-on-xp-antivirus-and-family/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nero 7 Essentials</title>
		<link>http://www.startupware.com/identification/nero-7-essentials/</link>
		<comments>http://www.startupware.com/identification/nero-7-essentials/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 19:31:28 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/2008/02/22/nero-7-essentials/</guid>
		<description><![CDATA[I&#8217;ve been getting some very specific complaints about Nero 7 Essentials. &#8220;The computer slows down. It crashes. Started with the new DVD writer.&#8221; All the drives in question were bundled with the OEM version of Nero 7 Essentials. Time for another test. Test box for today is running an Athlon XP 1900+, Windows 2000 Pro [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been getting some very specific complaints about Nero 7 Essentials. &#8220;The computer slows down. It crashes. Started with the new DVD writer.&#8221; All the drives in question were bundled with the OEM version of Nero 7 Essentials. Time for another test. Test box for today is running an Athlon XP 1900+, Windows 2000 Pro with Service Pack 4, no antivirus or security software whatsoever, lots of memory and drive space, and not much on the hard drive.</p>
<p>Before the install, I ran Hijack This and added everything to the &#8216;ignore&#8217; list, and ran CCleaner, and accepted every registry issue found&#8211;it&#8217;s a clean test box, so there wasn&#8217;t much.</p>
<p>Started the install:<br />
<img src="http://www.startupware.com/art/nero7-1.jpg" alt="Nero 7 Welcome Screen" /></p>
<p>I chose all the default options:<br />
<img src="http://www.startupware.com/art/nero7-2.jpg" alt="Nero 7 typical install" /></p>
<p>At the truly arrogant file options, I made no changes&#8211;Nero wants to be your program for everything related to content. Apparently it&#8217;s more than a DVD burning program, in the opinion of the publisher.<br />
<img src="http://www.startupware.com/art/nero7-3.jpg" alt="Nero 7 file options" /></p>
<p>At the install options, I again made no changes. Note the &#8220;Nero Scout&#8221; item at bottom left, unchecked by default.<br />
<img src="http://www.startupware.com/art/nero7-4.jpg" alt="Nero 7 options" /></p>
<p>The install completed without problems. I restarted the computer, and went looking. No new system tray icon appears, and no indication that I&#8217;ve installed anything more than a DVD burner. But wait, there&#8217;s something&#8211;in the Windows menus, in the Nero group, I see Nero Scout. Ooh, options. Here&#8217;s the view&#8211;it&#8217;s ON by default, and installed without asking:<br />
<img src="http://www.startupware.com/art/nero7-5.jpg" alt="Nero 7 indexing without asking" /></p>
<p>Ran HijackThis again. There are only two new entries:<br />
O4 &#8211; HKLM\..\Run: [NeroFilterCheck]<br />
     C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe<br />
O23 &#8211; Service: NMIndexingService &#8211; Nero AG &#8211;<br />
     C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe</p>
<p>So my DVD burner software includes a full indexing scan for files, also called &#8216;desktop search&#8217;, on by default, of all types (it&#8217;s on that &#8216;Files&#8217; tab), with no system tray icon, and no obvious place to type in a search. What does this have to do with burning a DVD? <em>(Nero, if you&#8217;re reading this, send me an answer&#8211;I&#8217;ll post it.)</em></p>
<p>I won&#8217;t comment much on the functionality of the product, except for one item: DVD-video functions (Nero Vision and some other areas) work for 30 days, then display an expired message. OK, I have no problem with a vendor trying to upsell, but announce that the product is half real and half 30-day trial in advance, and give me an option to uninstall the dead software chunks&#8211;I don&#8217;t need all this clutter.</p>
<p>Uninstalled. No error messages. Restarted the PC. Ran HijackThis a third time, and both autostart entries have been removed&#8211;good so far. Under C:\Program Files, there&#8217;s a leftover folder &#8220;Nero&#8221; containing 4 files and 2 more folders. Sloppy, but not unusually so. There&#8217;s a file left in the c:\WinNT folder, &#8220;NeroDigital.ini&#8221;.</p>
<p>Ran CCleaner, and checked the registry. Remember, I cleaned it before the install. There are now 380 registry errors. These are in the categories of:</p>
<ol> &#8216;Unused File Extension&#8217; mostly for graphics still formats, </ol>
<ol>&#8216;ActiveX/COM Issue&#8217; for &#8216;AppCore.MediaSource, </ol>
<ol>&#8216;Invalid or empty file class&#8217; for CDmaker, and </ol>
<ol>several hundred &#8220;Open with Application Issue&#8217; entries, pointing to &#8220;HKCR\NeroExpress.Files7&#8230;&#8221;</ol>
<p>Overall results:<br />
Is it startupware? Absolutely. It adds two autoplay entries, one totally unrelated to the program&#8217;s function, doesn&#8217;t ask permission before adding the unrelated functions, and turns on a processor-intensive application by silent default.</p>
<p><strong>Recommendations&#8211;</strong></p>
<p>First, don&#8217;t install with the defaults. Uncheck every file format on ALL the pages in the install options, except those that you&#8217;ll really use the program for. If in doubt, uncheck it.</p>
<p>Second, check off that box: &#8220;Configure Nero Scout on first usage&#8221; and then disable it. </p>
<p>Or find the autoplay entry for Nero Scout, it&#8217;s in Control Panel, Administrative Tools, Services, NMIndexingService&#8211;choose stop, and disable. Then find and delete the file:<br />
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe</p>
<p>And finally, consider some other program. This install doesn&#8217;t inspire trust.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/nero-7-essentials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Review of 3721(dot)com</title>
		<link>http://www.startupware.com/identification/review-of-3721dotcom/</link>
		<comments>http://www.startupware.com/identification/review-of-3721dotcom/#comments</comments>
		<pubDate>Thu, 08 Sep 2005 11:18:50 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=11</guid>
		<description><![CDATA[Had a request to look at this site.  Tried it, with my usual test box of totally clean, totally unpatched Win XP Home, no service packs, no antivirus, no nothing of any kind, just running a hardware firewall in the router. 
The about.htm page asked me to install the Chinese Language Pack. Answered OK, [...]]]></description>
			<content:encoded><![CDATA[<p>Had a request to look at this site.  Tried it, with my usual test box of totally clean, totally unpatched Win XP Home, no service packs, no antivirus, no nothing of any kind, just running a hardware firewall in the router. </p>
<p>The about.htm page asked me to install the Chinese Language Pack. Answered OK, it wanted the CD. I don&#8217;t get out of my chair that easily&#8230; clicked cancel. (Remember, I test like novices surf&#8230;) It took me back to the English about.htm page. </p>
<p>Found the how-to-use page, and let it install the Chinese keywords utility. The Install and Run warning, was properly signed by VeriSign, but the message was mostly bad font blocks. (No Chinese font loaded, as above.) Next, had a pop-up box all in Chinese, with one button. Clicked that, it went away. Nothing else happened. Restarted IE, nothing. </p>
<p>Restarted Win XP Home, and IE. There are 5 new icons in the tool bar, all Yahoo-related. Some Chinese characters appear in the right-end of the address bar. </p>
<p>All this was added to the autoplays, as reported by HijackThis: </p>
<p>Running processes:<br />
C:\WINDOWS\system32\rundll32.exe<br />
C:\WINDOWS\System32\wpabaln.exe </p>
<p>R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://seek.3721.com/srchasst.htm<br />
R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://seek.3721.com/srchcust.htm<br />
O2 &#8211; BHO: IE &#8211; {D157330A-9EF3-49F8-9A67-4141AC41ADD4} &#8211; C:\WINDOWS\DOWNLO~1\CnsHook.dll<br />
O4 &#8211; HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\DOWNLO~1\CnsMin.dll,Rundll32<br />
O4 &#8211; HKLM\..\Run: [helper.dll] C:\WINDOWS\system32\rundll32.exe C:\PROGRA~1\3721\helper.dll,Rundll32<br />
O8 &#8211; Extra context menu item: Quick Search (Yisou.com) &#8211; res://C:\WINDOWS\DOWNLO~1\CnsMinEx.dll/1003<br />
O9 &#8211; Extra button: Short Message &#8211; {00000000-0000-0001-0001-596BAEDD1289} &#8211; http://sms.3721.com/ie/index.htm (file missing)<br />
O9 &#8211; Extra button: Yahoo 1G mail &#8211; {507F9113-CD77-4866-BA92-0E86DA3D0B97} &#8211; http://cn.mail.yahoo.com/promo/rd1 (file missing)<br />
O9 &#8211; Extra button: E bazar &#8211; {59BC54A2-56B3-44a0-93E5-432D58746E26} &#8211; http://cn.rd.yahoo.com/auct/promo/3721/200508/ielogo-wcfashion/*<br />
http://cn.promo.auctions.yahoo.com/200507/fashion/index.html?refcode=3721200508ielogo-wcfashion (file missing)<br />
O9 &#8211; Extra button: 3721 Assistant &#8211; {5D73EE86-05F1-49ed-B850-E423120EC338} &#8211;<br />
http://assistant.3721.com/index.htm?fb=Cns (file missing)<br />
O9 &#8211; Extra button: Instant Messenger &#8211; {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -<br />
http://cn.rd.yahoo.com/home/messenger/bjk/clientbtn/?http://cn.messenger.yahoo.com/ (file missing)<br />
O9 &#8211; Extra button: (no name) &#8211; {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} &#8211;<br />
http://assistant.3721.com/security1.htm?fb=Cns (file missing)<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Repair Browser &#8211; {ECF2E268-F28C-48d2-9AB7-8F69C11CCB71} &#8211;<br />
http://assistant.3721(DOT)com/security1.htm?fb=Cns (file missing)<br />
O9 &#8211; Extra button: (no name) &#8211; {FD00D911-7529-4084-9946-A29F1BDF4FE5} &#8211;<br />
http://assistant.3721.com/clean1.htm?fb=Cns (file missing)<br />
O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Clean Internet access record &#8211; {FD00D911-7529-4084-9946-A29F1BDF4FE5} &#8211;<br />
http://assistant.3721(DOT)com/clean1.htm?fb=Cns (file missing)<br />
O11 &#8211; Options group: [!CNS] Chinese keywords </p>
<p>UNINSTALL&#8211;There was an entry in the add/remove list for Chinese keywords. Ran it. The uninstall was perfect. That&#8217;s rare&#8211;it put the autoplays back exactly as they were. </p>
<p>Overall, the install is sloppy&#8211;note the (file missing) on some of the items above. The uninstall was good. Clearly not a drive-by download. I saw no extra popups at the site, before or after installing the plug-in, or after removing it. </p>
<p>While the site is on the SpybotSD list of sites that it adds to the restricted sites list in IE, my test, as of Sept 8, 2005, didn&#8217;t show anything more suspicious than an overly-invasive toolbar with a sloppy install. </p>
<p>I&#8217;d like anyone who can read Chinese to repeat the test&#8211;I could easily have missed installing a optional portion of the toolbar.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/review-of-3721dotcom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Crawler(dot)com toolbar</title>
		<link>http://www.startupware.com/identification/crawlerdotcom-toolbar/</link>
		<comments>http://www.startupware.com/identification/crawlerdotcom-toolbar/#comments</comments>
		<pubDate>Thu, 25 Aug 2005 06:46:59 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=12</guid>
		<description><![CDATA[Downloaded and tested the Crawler.com search toolbar, which allows users to search multiple search engines at once. 
Test run Aug 25th, 2005, clean Win XP Home, no patches, not activated, no drivers except automatically-installed items from the Windows installation. Items listed as detected by HijackThis. 
Installing the Crawler toolbar added these items to the system [...]]]></description>
			<content:encoded><![CDATA[<p>Downloaded and tested the Crawler.com search toolbar, which allows users to search multiple search engines at once. </p>
<p>Test run Aug 25th, 2005, clean Win XP Home, no patches, not activated, no drivers except automatically-installed items from the Windows installation. Items listed as detected by HijackThis. </p>
<p>Installing the Crawler toolbar added these items to the system settings:<br />
Running processes:<br />
C:\Program Files\Crawler\CToolbar.exe </p>
<p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://portal.crawler.com/search/ie.aspx?tb_id=60002<br />
R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.crawler.com/?tbid=60002<br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://portal.crawler.com/search/ie.aspx?tb_id=60002<br />
R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Crawler\ctbr.dll/sa<br />
R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://portal.crawler.com/search/ie.aspx?tb_id=60002<br />
R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Crawler\ctbr.dll/sa<br />
R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =<br />
R3 &#8211; URLSearchHook: (no name) &#8211; {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} &#8211; C:\PROGRA~1\Crawler\ctbr.dll<br />
O2 &#8211; BHO: (no name) &#8211; {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} &#8211; C:\PROGRA~1\Crawler\ctbr.dll<br />
O3 &#8211; Toolbar: &#038;Crawler Toolbar &#8211; {4B3803EA-5230-4DC3-A7FC-33638F3D3542} &#8211; C:\PROGRA~1\Crawler\ctbr.dll<br />
O8 &#8211; Extra context menu item: Crawler Search &#8211; tbr:iemenu<br />
O18 &#8211; Protocol: tbr &#8211; {4D25FB7A-8902-4291-960E-9ADA051CFBBF} &#8211; C:\PROGRA~1\Crawler\ctbr.dll </p>
<p>When Internet Explorer is NOT running, CToolbar continues to run, and it autoplays with the system. </p>
<p>Uninstall results&#8211;this item not removed&#8211;it&#8217;s the IE home page:<br />
R0 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.crawler.com/?tbid=60002 </p>
<p>Overall: The main executable runs when it shouldn&#8217;t, for no stated purpose. Uninstall doesn&#8217;t restore home page but does restore all other settings. Search results from toolbar show pay-for-display ads first, clearly labeled, before showing true search results which may or may not be on the first page of results. </p>
<p>Summary: I wouldn&#8217;t automatically delete this one if the user finds it helpful&#8211;doesn&#8217;t appear to do anything disruptive. The publisher should fix the way it runs ctoolbar, so that it starts with IE, and doesn&#8217;t run all the time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/crawlerdotcom-toolbar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yahoo Messenger 6.0.0.1922</title>
		<link>http://www.startupware.com/identification/yahoo-messenger-6001922/</link>
		<comments>http://www.startupware.com/identification/yahoo-messenger-6001922/#comments</comments>
		<pubDate>Thu, 21 Jul 2005 13:53:06 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=10</guid>
		<description><![CDATA[Product Review&#8211;Yahoo Messenger 
Test run July 20, 2005, default settings on clean install of Windows XP Home, OEM edition. Unpatched, no service packs, antivirus, or blocking software. Hardware firewall was the only security in place. 
Version tested: Listed in &#8216;About&#8217; box as &#8220;Yahoo! Messenger 6.0.0.1922 and MyYahoo Module 6.0.0.600, (C)1997-2004.&#8221; 
Summary: Not evil, and not [...]]]></description>
			<content:encoded><![CDATA[<p>Product Review&#8211;Yahoo Messenger </p>
<p>Test run July 20, 2005, default settings on clean install of Windows XP Home, OEM edition. Unpatched, no service packs, antivirus, or blocking software. Hardware firewall was the only security in place. </p>
<p>Version tested: Listed in &#8216;About&#8217; box as &#8220;Yahoo! Messenger 6.0.0.1922 and MyYahoo Module 6.0.0.600, (C)1997-2004.&#8221; </p>
<p>Summary: Not evil, and not adware. Not harmless, either&#8211;it&#8217;s a massive set of changes to the system. Uninstallation is massively incomplete. Utility and value are dubious. </p>
<p>Recommendation, Business systems: Unwarrantied product with invasive settings. Prohibit all installations. Should be removed without option as part of all standard maintenance on corporate PCs. </p>
<p>Recommendation, Personal systems: Advise removal&#8211;there are too many autoplays and performance hits. Yahoo mail customers are vastly better off getting their emails from the &#8216;MyYahoo&#8217; service, which requires no software installation. Could be left behind on non-networked systems with only one educated user, if adequate system speed is available to counter the slowdown caused by the software. </p>
<p>LICENSE<br />
======= </p>
<p>The license agreement was the usual bizare set of disclaimers, not as bad as most, not as fair as it could be. There was one term that was interesting&#8211;note the absolute lack of notice when they decide to convert the service into anything else. There are no limits, and no notice, and no recourse. </p>
<p>&#8220;13. MODIFICATIONS TO SERVICE<br />
Yahoo! reserves the right at any time and from time to time to modify or discontinue, temporarily or permanently, the Service (or any part thereof), with or without notice. You agree that Yahoo! shall not be liable to you or to any third party for any modifcation, suspension or discontinuance of the Service.&#8221; </p>
<p>INSTALLATION<br />
============ </p>
<p>The installation ran smoothly. It&#8217;s the type that does the download during the install (5.37 Mb), but does calculate and display the time needed. For the test, I chose the defaults for everything. The &#8216;Anti-Spy&#8217; button on the toolbar, on first press, offers to download and install, and has its own license agreement. There is a default checkbox on the Anti-Spy product that changes Yahoo! to the default search engine. </p>
<p>Misleading: One program install results in three entries under Add/Remove programs, for Yahoo! extras, Yahoo! Messenger, and Yahoo! Toolbar. The &#8216;Yahoo! Anti-Spy&#8217; product has its own Add/Remove entry, matching the install. </p>
<p>Added to running files:<br />
C:\Program Files\Messenger\msmsgs.exe<br />
C:\Program Files\Yahoo!\Messenger\ypager.exe </p>
<p>System settings changes, according to HijackThis:<br />
R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = </p>
<p>http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*</p>
<p>http://www.yahoo.com/search/ie.html</p>
<p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = </p>
<p>http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*</p>
<p>http://www.yahoo.com</p>
<p>R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = </p>
<p>http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*</p>
<p>http://www.yahoo.com</p>
<p>R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = </p>
<p>http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*</p>
<p>http://www.yahoo.com/ext/search/search.html</p>
<p>R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = </p>
<p>http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*</p>
<p>http://www.yahoo.com</p>
<p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = </p>
<p>http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com</p>
<p>O2 &#8211; BHO: Yahoo! Companion BHO &#8211; {02478D38-C3F9-4efb-9B51-7695ECA05670} &#8211;<br />
C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll </p>
<p>O3 &#8211; Toolbar: &#038;Yahoo! Companion &#8211; {EF99BD32-C1FB-11D2-892F-0090271D4F88} &#8211;<br />
C:\PROGRA~1\YAHOO!\COMPAN~1\INSTALLS\cpn\ycomp5_5_7_0.dll </p>
<p>O4 &#8211; HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet </p>
<p>O8 &#8211; Extra context menu item: &#038;Yahoo! Search &#8211; file:///C:\Program Files\Yahoo!\Common/ycsrch.htm </p>
<p>O8 &#8211; Extra context menu item: Yahoo! &#038;Dictionary &#8211; file:///C:\Program Files\Yahoo!\Common/ycdict.htm </p>
<p>O8 &#8211; Extra context menu item: Yahoo! &#038;Maps &#8211; file:///C:\Program Files\Yahoo!\Common/ycmap.htm </p>
<p>O9 &#8211; Extra button: Messenger &#8211; {4528BBE0-4E08-11D5-AD55-00010333D0AD} &#8211; C:\Program<br />
Files\Yahoo!\Messenger\yhexbmes0521.dll </p>
<p>O9 &#8211; Extra &#8216;Tools&#8217; menuitem: Yahoo! Messenger &#8211; {4528BBE0-4E08-11D5-AD55-00010333D0AD} &#8211;<br />
C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll </p>
<p>UNINSTALL<br />
========= </p>
<p>All FOUR uninstall programs completed without failures or warnings. </p>
<p>These three settings were left behind: </p>
<p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*</p>
<p>http://www.yahoo.com/ext/search/search.html</p>
<p>R1 &#8211; HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*</p>
<p>http://www.yahoo.com/ext/search/search.html</p>
<p>R1 &#8211; HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*</p>
<p>http://www.yahoo.com</p>
<p>Yahoo shortcuts were left behind, in Favorites and in Links.<br />
In the read-only folder &#8220;C:\Program Files\Yahoo!&#8221; 221 files and 20 folders were left behind, total 12.4 Mb. </p>
<p>In the read-only folder &#8220;C:\Program Files\Internet Explorer\SIGNUP\Yahoo&#8221; 8 files were left behind, total 168 Kb. </p>
<p>REINSTALL TEST<br />
==============<br />
On a second installation after removal, the Yahoo Messenger install program advised me that it was already installed&#8211;was I sure that I wanted to install it anyway? My interpretation&#8211;even Yahoo&#8217;s software detects that their uninstall is incomplete. </p>
<p>POST-MORTEM<br />
=========== </p>
<p>Interesting follow-up, post-test: Yahoo sent an email message to confirm that I had activated the toolbar, and mention their use of email bugs (which they call &#8216;web beacons&#8217;) to confirm that I had read it. The email did NOT include any removal instructions for either the email message or the toolbar itself. </p>
<p>From their privacy information, linked in the email: &#8220;Web pages may contain an electronic file called a web beacon, that allows a web site to count users who have visited that page or to access certain cookies.&#8221; </p>
<p>The email claims that the toolbar provides these benefits, among others (not tested):<br />
&#8220;Protect your PC with powerful anti-spy technology&#8230;&#8221;<br />
&#8220;&#8230;Eliminate annoying pop-up ads with Pop-Up Blocker.&#8221; </p>
<p>From the email itself: &#8220;You may have noticed a powerful tool from Yahoo! that resides on your browser. It&#8217;s called the Yahoo! Toolbar and it was voted CNET Editors&#8217; Choice in November 2004.<br />
So what&#8217;s that mean for you?<br />
It means you have more control over your web browsing experience. And since the Yahoo! Toolbar is customizable, you get quick and easy access to all the things that interest you the most&#8230;&#8221;<br />
&#8220;&#8230;This is a service email related to your use of the Yahoo! Toolbar. Please do not respond to this email. To learn more about Yahoo!&#8217;s use of personal information, including the use of web beacons in HTML-based email, please read our Privacy Policy. Yahoo! is located at 701 First Avenue, Sunnyvale, CA 94089.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/yahoo-messenger-6001922/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Product Revew&#8211;Hotbar</title>
		<link>http://www.startupware.com/identification/product-revew-hotbar/</link>
		<comments>http://www.startupware.com/identification/product-revew-hotbar/#comments</comments>
		<pubDate>Thu, 21 Jul 2005 09:38:11 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=13</guid>
		<description><![CDATA[Test run July 21, 2005, default settings on clean install of Windows XP Home, OEM edition. Unpatched, no service packs, antivirus, or blocking software. Hardware firewall was the only security in place. 
Version tested: Listed in folder names as 4.6.1.0/
&#8216;Click here&#8217; on main Hotbar page gave no option, but started the &#8220;Take control of email&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>Test run July 21, 2005, default settings on clean install of Windows XP Home, OEM edition. Unpatched, no service packs, antivirus, or blocking software. Hardware firewall was the only security in place. </p>
<p>Version tested: Listed in folder names as 4.6.1.0/<br />
&#8216;Click here&#8217; on main Hotbar page gave no option, but started the &#8220;Take control of email&#8221; installation, despite listing several other products. </p>
<p>Redirects searches to resultsmaster.com/SmartOffers </p>
<p>Summary: A kinder, gentler product than the last time I looked at Hotbar, circa 2003. Still doesn&#8217;t do anything useful, but no longer appears to take over the system. </p>
<p>Recommendation, Business systems: Remove. Serves no business purpose. </p>
<p>Recommendation, Personal systems: Remove. Redirects web searches. </p>
<p>LICENSE<br />
======= </p>
<p>First license I&#8217;ve seen that regulates emotional content&#8211;&#8217;desire&#8217; is apparently now a legal term: </p>
<p>&#8220;(b) You shall receive, and desire to so receive, various products/services, marketing ads, and campaigns of third parties through the appearance of links, menus, pop-ups, and other methods on and/or in connection with the Service and the Software (all of the foregoing &#8220;Third Party Promotions&#8221;).&#8221; </p>
<p>INSTALLATION<br />
============ </p>
<p>End of first installation caused spontaneous reboot, followed by standard Windows file check of drives. Corrupted file c:\windows\system32\config\software.log. On a second reboot, no Hotbar product appeared to have been installed, although one new entry showed up in HijackThis: </p>
<p>Added to running files:<br />
C:\Program Files\Hotbar\Bin\4.6.1.0\WeatherOnTray.exe<br />
C:\Program Files\Hotbar\Bin\4.6.1.0\HbOEAddOn.exe<br />
C:\Program Files\Hotbar\Bin\4.6.1.0\HbSrv.exe </p>
<p>System settings changes, according to HijackThis: </p>
<p>R0 &#8211; HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Services/resultsmaster/ResultsMasterHomeLeftPane.htm </p>
<p>O2 &#8211; BHO: ShprRprts &#8211; {2A8A997F-BB9F-48F6-AA2B-2762D50F9289} &#8211; C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll </p>
<p>O2 &#8211; BHO: Hotbar &#8211; {B195B3B3-8A05-11D3-97A4-0004ACA6948E} &#8211; C:\Program Files\Hotbar\Bin\4.6.1.0\HbHostIE.dll </p>
<p>O3 &#8211; Toolbar: Hotbar &#8211; {B195B3B3-8A05-11D3-97A4-0004ACA6948E} &#8211; C:\Program Files\Hotbar\Bin\4.6.1.0\HbHostIE.dll </p>
<p>O4 &#8211; HKLM\..\Run: [WeatherOnTray] C:\Program Files\Hotbar\Bin\4.6.1.0\WeatherOnTray.exe </p>
<p>O4 &#8211; HKLM\..\Run: [Hotbar] C:\Program Files\Hotbar\Bin\4.6.1.0\HbOEAddOn.exe </p>
<p>O4 &#8211; HKLM\..\Run: [wzalvupo] C:\WINDOWS\System32\bkteqtfq.exe </p>
<p>O9 &#8211; Extra button: ShopperReports &#8211; Compare travel rates &#8211; {946B3E9E-E21A-49c8-9F63-900533FAFE14} &#8211; C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll </p>
<p>O9 &#8211; Extra button: ShopperReports &#8211; Compare product prices &#8211; {E77EDA01-3C56-4a96-8D08-02B42891C169} &#8211; C:\Program Files\ShopperReports\Bin\1.0.4.0\ShprRprt.dll </p>
<p>O16 &#8211; DPF: {69FD62B1-0216-4C31-8D55-840ED86B7C8F} (HbInstObj) &#8211; http://installs.hotbar.com/installs/hotbar/programs/hotbar.cab </p>
<p>UNINSTALL<br />
========= </p>
<p>Misleading: Separate uninstalls for Hotbar Outlook Tools, Hotbar Web Tools, and Shopper Reports by Hotbar, resulting from one install program of Outlook Tools. Each of these ended the install process with a visit to a web page asking for feedback on the uninstallation. Reboot was required after the last of the uninstalls. </p>
<p>Left behind two empty readonly folders in c:\Program Files, for Hotbar and ShopperReports. </p>
<p>These settings were left behind:<br />
O16 &#8211; DPF: {69FD62B1-0216-4C31-8D55-840ED86B7C8F} (HbInstObj) &#8211; http://installs.hotbar.com/installs/hotbar/programs/hotbar.cab </p>
<p>No shortcuts were left behind.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/product-revew-hotbar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SmileyCentral review</title>
		<link>http://www.startupware.com/identification/smileycentral-review/</link>
		<comments>http://www.startupware.com/identification/smileycentral-review/#comments</comments>
		<pubDate>Thu, 21 Jul 2005 08:35:05 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=14</guid>
		<description><![CDATA[Product Review&#8211;SmileyCentral (Ask Jeeves, Inc.) 
Test run July 21, 2005, default settings on clean install of Windows XP Home, OEM edition. Unpatched, no service packs, antivirus, or blocking software. Hardware firewall was the only security in place. 
Version tested: No version number, but copyright date in the license is June 1, 2005. Also known as [...]]]></description>
			<content:encoded><![CDATA[<p>Product Review&#8211;SmileyCentral (Ask Jeeves, Inc.) </p>
<p>Test run July 21, 2005, default settings on clean install of Windows XP Home, OEM edition. Unpatched, no service packs, antivirus, or blocking software. Hardware firewall was the only security in place. </p>
<p>Version tested: No version number, but copyright date in the license is June 1, 2005. Also known as FunWebProducts. </p>
<p>Summary: Claims not to be adware or spyware, and I saw no indications to indicate that this is anything more than some cute buttons and icons, plus lots of settings changes relating to search functions. The apparent revenue model for the free product is that it directs your searches to AskJeeves.com, where they make money on sponsored ads. </p>
<p>Recommendation, Business systems: Remove&#8211;serves no business purpose, has no warranty, and may add to network traffic. </p>
<p>Recommendation, Personal systems: Mostly harmless. </p>
<p>LICENSE<br />
=======<br />
Under section 2, License conditions&#8211;the program phones home for updates: </p>
<p>&#8220;We may require the updating of the Software on your computer when we release a new version of the Software, or when we make new features available. This update may occur automatically or through other means and may occur all at once or over multiple sessions.&#8221; </p>
<p>INSTALLATION<br />
============ </p>
<p>Added to running files:<br />
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE </p>
<p>System settings changes, according to HijackThis: </p>
<p>R3 &#8211; URLSearchHook: (no name) &#8211; {00A6FAF6-072E-44cf-8957-5838F569A31D} &#8211; C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL </p>
<p>O2 &#8211; BHO: MyWebSearch Search Assistant BHO &#8211; {00A6FAF1-072E-44cf-8957-5838F569A31D} &#8211; C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL </p>
<p>O2 &#8211; BHO: mwsBar BHO &#8211; {07B18EA1-A523-4961-B6BB-170DE4475CCA} &#8211; C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL </p>
<p>O4 &#8211; HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe </p>
<p>O4 &#8211; HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe </p>
<p>O4 &#8211; Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE </p>
<p>O4 &#8211; Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE </p>
<p>O8 &#8211; Extra context menu item: &#038;Search &#8211; http://bar.mywebsearch.com/menusearch.html?p=ZNxdm824YYUS </p>
<p>O16 &#8211; DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} &#8211; http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/SmileyCentralFWBInitialSetup1.0.0.8-2.cab </p>
<p>UNINSTALL<br />
========= </p>
<p>Listed in Add/Remove programs as &#8220;My Web Search (SmileyCentral). Uninstall requires reboot. </p>
<p>These settings were left behind: </p>
<p>O16 &#8211; DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} &#8211; http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/SmileyCentralFWBInitialSetup1.0.0.8-2.cab </p>
<p>Left behind read-only folder C:\Program Files\FunWebProducts, containing 2 files, 3 folders. The custom icon selected as a cursor was also left behind. </p>
<p>No shortcuts were left behind. </p>
<p>REINSTALL TEST<br />
============== </p>
<p>No problems. Worked same as the first install. The second uninstall failed at reboot, with a &#8216;RUNDLL&#8217; error box: &#8220;Error loading C:\PROGRA~1\UNINST~1.DLL. The specified module could not be found.&#8221; Message did not appear on subsequent reboot. </p>
<p>POST-MORTEM<br />
=========== </p>
<p>Surprise, surprise. There are so many ads for this product that I just expected the worst. But it&#8217;s clearly not that. Definitely a lightweight, and some home users may enjoy it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/smileycentral-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You have been Updated</title>
		<link>http://www.startupware.com/identification/you-have-been-updated/</link>
		<comments>http://www.startupware.com/identification/you-have-been-updated/#comments</comments>
		<pubDate>Sun, 10 Jul 2005 15:17:02 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=22</guid>
		<description><![CDATA[Yup, that&#8217;s what&#8217;s on screen this morning.  I&#8217;ve been Updated, and there is this always-on-top message asking me to click on &#8220;Update&#8221;. Somehow or another, Viewpoint Media Player slipped past a fully-patched Win 2000 Pro setup with blocking in place on the autoplay settings. The product claims to send non-personally-identifiable information back to a [...]]]></description>
			<content:encoded><![CDATA[<p>Yup, that&#8217;s what&#8217;s on screen this morning.  I&#8217;ve been Updated, and there is this always-on-top message asking me to click on &#8220;Update&#8221;. Somehow or another, Viewpoint Media Player slipped past a fully-patched Win 2000 Pro setup with blocking in place on the autoplay settings. The product claims to send non-personally-identifiable information back to a server in order to run a toolbar, and online research claims that it hijacks search results. There&#8217;s no toolbar here, so I&#8217;ll guess I saw the very first message. AdAware and SpybotSD don&#8217;t identify it as a threat.</p>
<p>It doesn&#8217;t play fair. I can highlight the license agreement, but it won&#8217;t let me copy it. Same on a &#8216;Who is viewpoint?&#8217; entry.  Well, I did capture the main window as a jpg. As adware goes (if that&#8217;s all it is), it&#8217;s pretty tame. I had no trouble removing it by killing the process viewmgr.exe, running the Viewpoint uninstall, and cleaning out two related files from the temporary files folder. I&#8217;m curious how it got past my blocks.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/identification/you-have-been-updated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Virgin Windows Report&#8211;Win XP Home, SP2 OEM</title>
		<link>http://www.startupware.com/working-models/virgin-windows-report-win-xp-home-sp2-oem/</link>
		<comments>http://www.startupware.com/working-models/virgin-windows-report-win-xp-home-sp2-oem/#comments</comments>
		<pubDate>Sun, 10 Jul 2005 14:43:11 +0000</pubDate>
		<dc:creator>FileTiger</dc:creator>
				<category><![CDATA[Definitions]]></category>
		<category><![CDATA[Identification]]></category>

		<guid isPermaLink="false">http://startupware.com/?p=9</guid>
		<description><![CDATA[Just finished building a new box for a client. Took the opportunity to grab the task list. The list below is what Windows Task Manager reported as running processes immediately after installation, after hardware detection, but before any drivers were installed. No patches, no antivirus, no software installs of any kind, no exposure to the [...]]]></description>
			<content:encoded><![CDATA[<p>Just finished building a new box for a client. Took the opportunity to grab the task list. The list below is what Windows Task Manager reported as running processes immediately after installation, after hardware detection, but before any drivers were installed. No patches, no antivirus, no software installs of any kind, no exposure to the internet, or even to a CDROM other than Windows itself. </p>
<p>OS version: Windows XP, Service Pack 2, OEM edition<br />
Motherboard: MSI M8M Neo-V, with AMD Sempron 2800+ processor.<br />
Any hardware support below, if any, was autodetected during install&#8211;no software or driver installs had been run when this process list was captured: </p>
<p>alg.exe<br />
csr.exe<br />
Explorer.EXE<br />
lsass.EXE<br />
msiexec.exe<br />
services.exe<br />
smss.exe<br />
svchost.exe (5 instances running)<br />
System<br />
System Idle Process<br />
taskmgr.exe<br />
winlogon.exe<br />
wmiprvse.exe<br />
wpabaln.exe<br />
wuaudit.exe </p>
<p>As I (or others), build more systems, we&#8217;ll post more of these &#8220;Virgin Windows Task Lists&#8221;. </p>
<p>I didn&#8217;t have a chance to grab a HijackThis log of the box in this condition, but that I will next time, and get a more complete picture of just what is part of the default configuration.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.startupware.com/working-models/virgin-windows-report-win-xp-home-sp2-oem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
