PDA

View Full Version : Nurech in Bitcomet ?



Diabolo
2007-03-06, 15:47
Hi,

When I scan my computer with SpyBot 1.4 (with latest definitions), the following "problem" is found :

Nurech: User settings (Registry value, nothing done) HKEY_USERS\S-1-5-21-606747145-725345543-111207290-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\*\upnp.exe


I have found the following key in the registry :

[HKEY_USERS\S-1-5-21-606747145-725345543-111207290-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache]
"C:\\Program Files\\Communication\\BitComet\\tools\\UPNP.exe"="UPNP config tool for BitComet"


Bitcomet 0.84 is installed in my computer.

The "UPNP config tools for Bitcomet" (UPNP.exe) is a part of Bitcomet.

So, is this a false positive ?

Or does Bitcomet contain the Nurech worm ?

Thanks.

MisterW
2007-03-06, 17:20
The detection for Nurech has been adjusted and I can confirm that it was a false positive. :oops:

A fixed detection file will be released on Wednesday. :bigthumb:

regards
Markus

Diabolo
2007-03-06, 17:49
Thanks a lot for your quick reply !

:bigthumb:

yman25
2008-09-15, 14:30
You can use the new version of limewire which is faster and users can now use web proxies to route their downloads to protect their identity.

one eyed rider
2008-09-22, 20:24
dont use limewire. use utorrent instead

tashi
2008-09-22, 20:33
You can use the new version of limewire which is faster and users can now use web proxies to route their downloads to protect their identity.


dont use limewire. use utorrent instead

A huge amount of users with infections produced by the use of P2P fill up our malware forums, which is why we have these stickies:


File Sharing, otherwise known as Peer To Peer. (P2P) (http://forums.spybot.info/showthread.php?t=282)
Particularly post #4, http://forums.spybot.info/showpost.php?p=218503&postcount=4

Regards.

md usa spybot fan
2008-09-22, 20:51
yman25:
one eyed rider:

I am confused by both of your comments in a year and a half old thread posted in False Positives (http://forums.spybot.info/forumdisplay.php?f=16) forum concerning a false positive in the detection for the Trojan "Nurech".

Are you indicating that a false positive has returned in the detection for the Trojan "Nurech" or just picking random threads to post recomendations for P2P products because Diabolo (http://forums.spybot.info/member.php?u=19666) was using Bitcomet a year and a half ago?