PeterSfa
2007-01-24, 14:44
I geting a False Positive on the registrykey for Oreans. (Hupigon)
When I investigated it with google, at first its looked like a backdoor. But then I realized that the oreans32.sys located in the system32\drivers folder and mentioned in the report from spybot is a legitime process.
Ok, it is not legitime in the way that I have authorized the installation or been able to choose, and it was a pain in the *** to get rid of. I succeded with the removal tough.
It is also known that some backdoors can use this driver to help hide and protect itself. But in this case it was one of my softwarevendors who tried to protect his software. I was forced to enable the oreans32.sys again.
I feel it to be wrong if spybot reacts and reports on the existens of this this registrykey and file. Despite its ability to protect spywares.
I think that spybot should only report if it also finds other known spyware registrykeys or processes.
Any other coments on this?
When I investigated it with google, at first its looked like a backdoor. But then I realized that the oreans32.sys located in the system32\drivers folder and mentioned in the report from spybot is a legitime process.
Ok, it is not legitime in the way that I have authorized the installation or been able to choose, and it was a pain in the *** to get rid of. I succeded with the removal tough.
It is also known that some backdoors can use this driver to help hide and protect itself. But in this case it was one of my softwarevendors who tried to protect his software. I was forced to enable the oreans32.sys again.
I feel it to be wrong if spybot reacts and reports on the existens of this this registrykey and file. Despite its ability to protect spywares.
I think that spybot should only report if it also finds other known spyware registrykeys or processes.
Any other coments on this?