[Rd] spyware detected (PR#8270)

Duncan Murdoch murdoch at stats.uwo.ca
Tue Nov 1 17:06:43 CET 2005


On 11/1/2005 10:18 AM, kin.chan at yale.edu wrote:
> Gentlemen:
> 
> I ran a spyware sweep on my computer after installing:
> 
> 10/07/2005  03:25 PM        27,230,914 R-2.2.0-win32.exe
> 
>>From the cran website.
> 
> Spy Sweeper 4.0.3 with the latest definition files found
> 
> Directory of C:\Program Files\R\R-2.2.0
> 
> 11/01/2005  09:27 AM           668,938 unins000.exe
> 
> To have the golden eye signature.  This is serious if indeed the uninstall
> program contains the golden eye monitor program.
> 
> Please look into this and update me with developments.

unins000.exe is the uninstaller for R.  If your "Spy Sweeper" thinks 
there's something wrong with it, you'll have to tell us what.

According to Symantec's web site

http://securityresponse.symantec.com/avcenter/venc/data/spyware.goldeneye.html

the spyware "adds the value:

"AGSeyApp"="<installation path>\AGSeyApp.exe"

to the following registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the spyware runs when you start Windows."

I don't see that registry key in the machine that built the installer, 
so this looks like a false alarm.  If I were you I'd contact the writers 
of "Spy Sweeper" with a bug report.

Duncan Murdoch



More information about the R-devel mailing list