<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 Forums - Tech Off - IE8 picked up spyware (too quickly)</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Forums/rss"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 Forums - Tech Off - IE8 picked up spyware (too quickly)</title>
		<link>http://channel9.msdn.com/Forums</link>
	</image>
	<description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
	<link>http://channel9.msdn.com/Forums</link>
	<language>en</language>
	<pubDate>Sat, 25 May 2013 07:58:14 GMT</pubDate>
	<lastBuildDate>Sat, 25 May 2013 07:58:14 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<c9:totalResults>5</c9:totalResults>
	<c9:pageCount>-5</c9:pageCount>
	<c9:pageSize>-1</c9:pageSize>
	<item>
		<title>Tech Off - IE8 picked up spyware (too quickly)</title>
		<description><![CDATA[<p>I installed IE8 on a Windows XP SP3 computer (new and clean install, fully patched system, running Windows Defender, NOD32 antivirus and&nbsp;windows malicious software removal tool). I used it for about 2 days (with a limited account) and then I ran a SpywareDoctor*
 scan.
<div>It found a spyware called Spyware.BaiDu!</div>
<div>No warez, porn, file-sharing site was visited and I haven't installed any toolbars or adds-ons.<br /></div>
<div>
<div><br /></div>
<div>Any ideas how to avoid such infections?</div>
<div><br /></div>
<div>It'd be interesting to see a test in which somebody visits specifically dangerous sites with IE8 and see how many malware is picked up.</div>
<div>( I won't do it for you... <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif' alt='Smiley' /></div>
<div><br /></div>
<div>I copy here the log file of SpywareDoctor.</div>
<div>Notice that it seems that the spyware modified registry. Again: it was used under a limited account. :-/</div>
<div><br /></div>
<div>( *SpywareDoctor is a software which is included in Google Pack - a collection of essential softwares distributed by Google. )<br /></div>
<div>
<div>
<div><br /></div>
<div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:390</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span><br /></div>
<div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}, BlockType</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:390</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}, CompatibilityFlags</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:390</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}, DllName</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:390</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}, MasterCLSID</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:390</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}, Version</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:390</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Key</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:421</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}, BlockType</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:421</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}, CompatibilityFlags</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:421</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}, DllName</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:421</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Value</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}, Version</span></div>
<div><span class="Apple-style-span"><br /></span></div>
<div><span class="Apple-style-span">2009.03.22. 21:34:30:421</span><span class="Apple-tab-span"><span class="Apple-style-span">
</span></span></div>
<div><span class="Apple-style-span">Infection was detected on this computer</span></div>
<div><span class="Apple-style-span">Threat Name - Spyware.BaiDu</span></div>
<div><span class="Apple-style-span">Type - Registry Key</span></div>
<div><span class="Apple-style-span">Risk Level - Medium</span></div>
<div><span class="Apple-style-span">Infection - HKEY_LOCAL_MACHINE\\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}</span></div>
</div>
</div>
</div>
</div>
</div></p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/462138#462138</link>
		<pubDate>Mon, 23 Mar 2009 21:07:51 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/462138#462138</guid>
		<dc:creator>akopacsi</dc:creator>
		<slash:comments>5</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/akopacsi/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Tech Off - IE8 picked up spyware (too quickly)</title>
		<description><![CDATA[<p>From the little Google searching I just did (I don't use Spyware Doctor myself), I'm inclined to think that this may be a false positive.&nbsp; The program that PCTools calls Spyware.BaiDu is a BHO, and therefore should be registered in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
 Helper Objects, not in \Extension Compatibility\...&nbsp; I think Spyware Doctor may be picking up on Internet Explorer's BHO blacklist or list of compatibility shims.<br /></p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/3c9f94e7006f4aeba9ac9deb0004aa5c#3c9f94e7006f4aeba9ac9deb0004aa5c</link>
		<pubDate>Mon, 23 Mar 2009 22:37:43 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/3c9f94e7006f4aeba9ac9deb0004aa5c#3c9f94e7006f4aeba9ac9deb0004aa5c</guid>
		<dc:creator>JonathonW</dc:creator>
		<slash:comments>5</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/CannotResolveSymbol/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Tech Off - IE8 picked up spyware (too quickly)</title>
		<description><![CDATA[<p>Hmm, a spyware detector included in Google Pack claims that a Baidu BHO is spyware.</p>
<p>Baidu is a popular search engine in China, more popular than Google China.</p>
<p>There seems to be a conflict of interest here...</p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/1347a897cebe419084c09deb0004aa83#1347a897cebe419084c09deb0004aa83</link>
		<pubDate>Wed, 25 Mar 2009 06:03:02 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/1347a897cebe419084c09deb0004aa83#1347a897cebe419084c09deb0004aa83</guid>
		<dc:creator>Joe Chung</dc:creator>
		<slash:comments>5</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/joechung/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Tech Off - IE8 picked up spyware (too quickly)</title>
		<description><![CDATA[<p><blockquote><div class="quoteUser">joechung said:</div><div class="quoteText">
<p>Hmm, a spyware detector included in Google Pack claims that a Baidu BHO is spyware.</p>
<p>Baidu is a popular search engine in China, more popular than Google China.</p>
<p>There seems to be a conflict of interest here...</p>
</div></blockquote>What's even more surprising is that it appears that the said spyware detector does a blind scan ignoring the usage of registry keys. Even if that &quot;Extension Compatibility&quot; key&nbsp;is not documented it should be pretty obvious what it does. Besides, if the
 computer was really infected then shouldn't the dll file be somewhere around?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/7640b8b824c64486a1d39deb0004aaab#7640b8b824c64486a1d39deb0004aaab</link>
		<pubDate>Wed, 25 Mar 2009 08:48:10 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/7640b8b824c64486a1d39deb0004aaab#7640b8b824c64486a1d39deb0004aaab</guid>
		<dc:creator>Dexter</dc:creator>
		<slash:comments>5</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Dexter/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Tech Off - IE8 picked up spyware (too quickly)</title>
		<description><![CDATA[<p><blockquote><div class="quoteUser">joechung said:</div><div class="quoteText">
<p>Hmm, a spyware detector included in Google Pack claims that a Baidu BHO is spyware.</p>
<p>Baidu is a popular search engine in China, more popular than Google China.</p>
<p>There seems to be a conflict of interest here...</p>
</div></blockquote>Actually, <a href="http://vil.nai.com/vil/content/v_140258.htm">McAfee detects it too</a>...&nbsp; it's classic adware, installing a useless toolbar and creating unwanted connections to other internet servers (possibly transmitting personal data to those
 servers).<br /><br />If you don't see the toolbar, you don't have it installed.&nbsp; Chalk this one up to a poorly-programmed spyware scanner.<br /></p>]]></description>
		<link>http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/9c7dc42f050e488d8a899deb0004aad3#9c7dc42f050e488d8a899deb0004aad3</link>
		<pubDate>Wed, 25 Mar 2009 13:41:50 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/TechOff/462138-IE8-picked-up-spyware-too-quickly/9c7dc42f050e488d8a899deb0004aad3#9c7dc42f050e488d8a899deb0004aad3</guid>
		<dc:creator>JonathonW</dc:creator>
		<slash:comments>5</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/CannotResolveSymbol/Discussions/RSS</wfw:commentRss>
	</item>
</channel>
</rss>