PDA

View Full Version : Netsys ?



Darkness123
2006-05-29, 16:41
Netsys
Settings
HKEY_CLASSES_ROOT\CLSID\{7B87A1E1-481A-47A5-B58F-BB140DCC930}

I do not know if this is a False Positive or not, I will continue to Google it.

Darkness123
2006-05-29, 17:32
I found my answer at http://www.2-spyware.com/review-thespywareshield.html

"The entry associated with Eventlog (HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7B87A1E1-481A-47A5-B58F-BB1430DCC930}) was actually related to Serv-U, a legitimate FTP server."

I am guessing Serv-U could be used by trojans or something but I think I installed Serv-U while ago. (I installed Spybot yesterday and only did a full scan today.)

MisterW
2006-05-30, 11:41
Hello Darkness123,

Often Malware tries to use the same entrys like other "good" application do and so it can be very difficult to remove only "bad programs. Indeed the classid (HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7B87A1E1-481A-47A5-B58F-BB1430DCC930}) is used by a serv-U and so we decided to remove it from our detection.

Thank you very much for reporting this F/P! The fix will be published with the next update on friday!

Best regards
Markus :bigthumb: