Page 1 of 1

Adaware has fallen! Can't be trusted anymore

Posted: 2005-02-16 04:57am
by Faram
DSL Reports

This is the first post in that thread -images.

Lavasoft have seen the last cash from me now.
Hi All:

Mike Healan of and Suzi of Spyware Warrior have early word on some puzzling new developments on the anti-spyware front -- see:

Don’t Drink the WhenU Kool-Aid

Leading Antispyware Vendors Quietly Drop WhenU Detection

At the heart of this strange tale is WhenU, the well-known adware vendor that struck a controversial deal with anti-spyware maker Aluria late last year:

»WhenU Enters the Anti-Spyware Market

I should note that Mike's and Suzi's reports are based on some routine testing that I performed with the latest version of BearShare, a popular P2P file sharing application that bundles WhenU Save.

Here's what we know:

1) Lavasoft has Removed WhenU from its Detections Database

Lavasoft removed WhenU's applications from their definitions database sometime in the last month -- it looks like it was probably the Feb. 5 update, but it might have been earlier. It was certainly done after the Dec. 29th update, because WhenU's SaveNow is confirmed detected with that definitions database.

The problem is that nowhere did Lavasoft announce this significant change publicly. It certainly didn't appear in any of their recent update announcements, where removals are typically disclosed:




This failure to disclose the removal of WhenU from the Ad-aware detections database to Lavasoft's customers is a serious matter. Whatever one thinks of the de-listing, it should have been disclosed and Lavasoft should have offered an explanation for this change in policy in a clear, public manner. It did not. Instead, it slipped the change into its detections database and failed to inform users, even after users began to complain that WhenU was not being removed, such as this Lavasoft customer did here:


2) Pest Patrol has Removed WhenU from its Detections Database

It also appears that Pest Patrol removed WhenU from its detections database, though the situation here is a bit murkier. With the latest definitions Pest Patrol 5 does not flag any of the WhenU Save files. Strangely enough, it does flag a number of WhenU Registry keys, but erroneously labels them as BargainBuddy, Mirar Toolbar, and PurityScan. A sample chunk from a Pest Patrol 5 scan log:

said by PPv5Log.txt:2/13/2005-4:11:05 PM,29692390,-1630934736,Detected,BargainBuddy,Adware,453068324,key "hkey_local_machine \software\whenusave" value "iptomsa_url",-1,
2/13/2005-4:11:07 PM,29692390,-1607404736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "uninstalltag_rs",-1,
2/13/2005-4:11:07 PM,29692390,-1607304736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "urlchangecount",-1,
2/13/2005-4:11:07 PM,29692390,-1607304736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "timeddbupdate_rs",-1,
2/13/2005-4:11:07 PM,29692390,-1607304736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "heartbeattime",-1,
2/13/2005-4:11:07 PM,29692390,-1607204736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "msa",-1,
2/13/2005-4:11:07 PM,29692390,-1607204736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "maxpopups_rs",-1,
2/13/2005-4:11:07 PM,29692390,-1607204736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "iptomsatime_rs",-1,
2/13/2005-4:11:07 PM,29692390,-1607204736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "src_url",-1,
2/13/2005-4:11:07 PM,29692390,-1607104736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "himp_url",-1,
2/13/2005-4:11:07 PM,29692390,-1607104736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "brandskin_url",-1,
2/13/2005-4:11:07 PM,29692390,-1607104736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "brandstrip_rs",-1,
2/13/2005-4:11:07 PM,29692390,-1607004736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "brandstrip_url",-1,
2/13/2005-4:11:07 PM,29692390,-1607004736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "db_incomplete",-1,
2/13/2005-4:11:07 PM,29692390,-1607004736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "db_server_update",-1,
2/13/2005-4:11:07 PM,29692390,-1607004736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "db_stamp_rs",-1,
2/13/2005-4:11:08 PM,29692390,-1604494736,Detected,PurityScan,Adware,453073488,key "hkey_classes_root \wusn.1" value "wusn_id",-1,
2/13/2005-4:11:13 PM,29692390,-1551924736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "brandstrip_rs" data "24",-1,
2/13/2005-4:11:13 PM,29692390,-1551924736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "brandstrip_url" data "",-1,
2/13/2005-4:11:13 PM,29692390,-1551824736,Detected,NN_Bar,Toolbar,453077032,key "hkey_local_machine \software\whenusave" value "src_url" data "",-1,

As you can see from one of the attached screenshots, Pest Patrol still detects BearShare, the host application, which is an odd arrangement indeed.

The situation is just as confused on the Pest Patrol web site, where the "Most Prevalent Pests" as of 2/13/04 listed 4 WhenU applications:


If you click the names on that page for more information, you'll get next to nowhere, as the most obvious pathways to Pest Patrol's write-ups on WhenU's applications are now broken. The pages can still be found, as Suzi notes -- they're just not findable using the research page search function.

There are some tantalizing hints on Google that WhenU's de-listing was disclosed on this page:


That de-listing seems to have happened with an earlier update that is no longer detailed on the above web page. Even if it was disclosed on that page, the change certainly was not prominently announced, nor do we have a public explanation for Pest Patrol's decision to de-list WhenU.

3) Aluria Security Center 4.0 Detects WhenU as Spyware

In what is surely the strangest twist in this whole story, Aluria's recently released Security Center 4.0, which incorporates the latest version of its standard anti-spyware application Spyware Eliminator, *does* detect WhenU Save as "spyware" (see the second attached screenshot above). This comes as a surprise because Aluria recently declared WhenU to be "Spyware-SAFE":


It also partnered with WhenU to offer an adware-supported anti-spyware application called UControl:


Why Aluria's anti-spyware application would be flagging WhenU as "spyware" at the precise moment when Lavasoft and Pest Patrol are de-listing WhenU is puzzling.

We don't know at this point why Lavasoft and Pest Patrol apparently decided to de-list WhenU from their defintions databases, though we strongly suspect that these decisions are in reaction to a new notice and disclosure screen for WhenU Save that was recently added to the BearShare installation process (see the third attached screenshot above).

Full Disclosure:

In the course of my work on spyware and adware issues I routinely talk with a number of companies, individuals, and organizations, including anti-spyware vendors of all sorts. I also have occasion to exchange views with adware and spyware vendors, as readers of this forum will be well familiar with:

»Opinions, please: eBates MoeMoneymaker

As it happens, I became familiar with the new notice/disclosure screens for WhenU that were just recently incorporated into the latest installation of BearShare from several discussions with Avi Naider of WhenU. In fact, it was in the process of reviewing this new BearShare installation that I stumbled across the anomalous behavior with Ad-aware, Pest Patrol, and Aluria reported above.

Although I, like Mike Healan, regard the new notice/disclosure screens incorporated into BearShare to be a significant improvement on the installation process previously used in BearShare, I cannot recommend that anti-spyware vendors de-target WhenU's applications at this time for a number of reasons.

More importantly, though, I am very disappointed that anti-spyware vendors might have de-listed WhenU's applications without publicly and forthrightly announcing and explaining those changes to their users. Anti-spyware vendors are in a business that places a premium on trust, and it is critical that they be forthright with their customers -- many of them the victims of unscrupulous commercial behavior -- at every step of the way. When anti-spyware vendors de-list an adware application like WhenU from their detections, they have a duty to report that change in policy to their users. At the present point in time, it appears that Lavasoft and Pest Patrol did not fulfill this obligation to their users, and that is unfortunate.


In closing I should also note that I have asked Lavasoft about its removal of WhenU from the Ad-aware detections database -- see:


At this time I have received no response from Lavasoft, though I look forward to both Lavasoft and Pest Patrol providing users a forthright explanation of their targeting policies for WhenU and any recent changes they might have implemented in those policies.


Eric L. Howes

Posted: 2005-02-16 05:17am
by General Zod
*duly notes and goes about uninstalling ad-aware*

Posted: 2005-02-16 05:34am
by Faram
Lavasofts defence:
Lavasoft does not cooperate with WhenU!
As a result of recent rumours and speculation by members of the privacy community and the public at large, Lavasoft wants to make clear that it has not and would not collaborate with any companies that have produced content detected by Ad-Aware. Ad-Aware products are designed purely for scanning and removing of suspicious content (at the user’s discretion) and Lavasoft would not ally with adversaries under any circumstances.

WhenU was indeed removed from the database by research in the last definition file. This however was due to WhenU not scoring more than 2 TAC points at the time, 3 points being the minimum score to be included in the database. More information on the Threat Assessment Chart can be found at
The TAC report will be reviewed in more detail by our R&D department and in case it turns out that the removal was incorrect, WhenU will naturally be reintroduced to the database.

For further information, please contact

If you remove a product from the detection base and do not inform anyone untill you are caught. That smells like BS to me.

Sorry but all your hard earned trust over years just flew out the door.

Posted: 2005-02-16 08:45am
by InnocentBystander
Meh, Adaware is just one of several programs needed to keep a clean computer.

Posted: 2005-02-16 09:49am
by Vohu Manah
Note to self, install second anti-spyware app at first opportunity when I have access to my parent's computers.

Posted: 2005-02-16 05:38pm
by Mayabird
Dammit! Well, there's still Spybot S&D and HijackThis...

While I'm here can anybody suggest any other good (free) antispyware programs?

Posted: 2005-02-16 05:53pm
by White Haven
It has fallen into shadow... </Galadriel>

Spysweeper isn't free, but there's a free trial if you need a spare weapon battery for an engagement or two. Been playing with the Microsponge beta a bit, and it seems worthy, so if you run XP you might want to give it a look.

Posted: 2005-02-16 05:55pm
by Gerard_Paloma
Spyware Blaster and Bazooka Scanner are two good ones.

Posted: 2005-02-16 06:35pm
by Sharpshooter
[Lewis Black]Son of a bitch!!![/Lewis Black] I knew something was wrong when that shit kept showing back up, and now I know why - Lavasoft signed a fucking pact with the enemy!!! :evil:

Posted: 2005-02-16 06:40pm
by White Haven
Russia*scribblescribble* AdAware has signed a pact with the aliens and withdrawn funding from XCOM.

NOOO! Say it ain't so!

Posted: 2005-02-17 07:10am
by Mange
IMO, Ad-Aware isn't the most effective anti-spyware out there, but it's sufficient.

BTW, what is WhenU?

Posted: 2005-02-17 11:30am
by Sharpshooter
Mange the Swede wrote:BTW, what is WhenU?
They're the sons of bitches who make and distribute certain adware systems.

Posted: 2005-02-17 11:37am
by Stormbringer
Sharpshooter wrote:
Mange the Swede wrote:BTW, what is WhenU?
They're the sons of bitches who make and distribute certain adware systems.
Which is as helpful as saying that water is wet. I think he's looking for something a bit more substantive than "its adware."

Posted: 2005-02-17 11:39am
by Stormbringer
Faram wrote:Lavasofts defence:
Lavasoft does not cooperate with WhenU!
As a result of recent rumours and speculation by members of the privacy community and the public at large, Lavasoft wants to make clear that it has not and would not collaborate with any companies that have produced content detected by Ad-Aware. Ad-Aware products are designed purely for scanning and removing of suspicious content (at the user’s discretion) and Lavasoft would not ally with adversaries under any circumstances.

WhenU was indeed removed from the database by research in the last definition file. This however was due to WhenU not scoring more than 2 TAC points at the time, 3 points being the minimum score to be included in the database. More information on the Threat Assessment Chart can be found at
The TAC report will be reviewed in more detail by our R&D department and in case it turns out that the removal was incorrect, WhenU will naturally be reintroduced to the database.

For further information, please contact

If you remove a product from the detection base and do not inform anyone untill you are caught. That smells like BS to me.

Sorry but all your hard earned trust over years just flew out the door.
I'm inclined to at least accept it for now. It would have been nice if they made it know but I could see why they wouldn't make notice of it. Untill otherwise proven or it becomes a pattern, I'm inclined to accept their explanation for the time being.

Posted: 2005-02-17 11:41am
by Faram
Stormbringer wrote:I'm inclined to at least accept it for now. It would have been nice if they made it know but I could see why they wouldn't make notice of it. Untill otherwise proven or it becomes a pattern, I'm inclined to accept their explanation for the time being.
In this case I hope you are right.

But they lost a hell of a lot of goodwill and I am not reinstalling aaw anytime soon.

Posted: 2005-02-17 11:43am
by Mange
Stormbringer wrote:
Sharpshooter wrote:
Mange the Swede wrote:BTW, what is WhenU?
They're the sons of bitches who make and distribute certain adware systems.
Which is as helpful as saying that water is wet. I think he's looking for something a bit more substantive than "its adware."
Yeah, that was what I meant, like what it does and if there are any telltale signs that your computer is infected by it.

I searched the 'Net and found the info I was looking for.

Posted: 2005-02-17 12:59pm
by Ace Pace
Unless it suddenly becomes apprent that they do not pick up most spyware, I'll still use it as my main cleaner, its fast, reliable, and easier to use then Spybot.

Also, it maneged to completly kill a CWS infection, which I'm not sure S&D can do.

Posted: 2005-02-17 01:05pm
by White Haven
...people still use any one single cleaner? :wtf:

Adaware, Spybot, Spysweeper, and CWShredder, followed by a HijackThis enema, then we get serious.

Posted: 2005-02-17 01:06pm
by Ace Pace
White Haven wrote:...people still use any one single cleaner? :wtf:

Adaware, Spybot, Spysweeper, and CWShredder, followed by a HijackThis enema, then we get serious.
SpySweeper? please detail.

Also, recently I can't find CWS Shredder alone, only packaged with another program, links to it again? :)

Posted: 2005-02-17 01:09pm
by White Haven
Webroot Spysweeper. It's not free, but load the trial up then nuke it off, works pretty well. As for Shredder, I'm at work, so I can't go hunting around right now. The official site has it solo, just have to root around. Course if you nuke temp and temporary internet files out, you lay the smackdown on a lot of problems, and some can be killed from add/remove programs.

Posted: 2005-02-17 03:43pm
by Stormbringer
Faram wrote:
Stormbringer wrote:I'm inclined to at least accept it for now. It would have been nice if they made it know but I could see why they wouldn't make notice of it. Untill otherwise proven or it becomes a pattern, I'm inclined to accept their explanation for the time being.
In this case I hope you are right.

But they lost a hell of a lot of goodwill and I am not reinstalling aaw anytime soon.
I hope I am too. I like Adware even though I primarily use Spybot S&D primarily. I'm going to keep what Lavasoft has done in mind and if it becomes a trend then I will cease using it. There are better ways of handling this but frankly I'm willing to forgive an ocassional clerical error.

Posted: 2005-02-17 04:48pm
by Vendetta
Adaware is still good enough for most people.

By 'most people' I mean the people I get to talk to.

The people who, when they scan their computers with Adaware will frequently find 800+ critical objects.

You know, the ones who use IE.