Hi,
I have just downloaded Spybot 1.4 after seeing a suspicious entry in HKLM/MS/Windows/Run registry key that turned out to be harmless, but Spybot claims that I am infected with pieces of "NiceSpy." It seems that all of the CLSIDs that it marks as pieces of "NiceSpy" are in fact classes from JMail, a programmable mail class. For example, the key HKEY_CLASSES_ROOT\CLSID\{F812B147-0E26-4222-8EE4-9F753CD2B39C} actually corresponds to a JMail POP3 Object. As far as I can tell, there are no reports of JMail itself being infected with malware, rather it seems that malware manufacturers install JMail to send/receive mail for tracking purposes. For example, I see that W32.Aprilcone.A@mm also uses JMail as does NiceSpy and Email-Worm.Win32.Dushit.a
Please take a look into this issue further. :scratch:
I have just downloaded Spybot 1.4 after seeing a suspicious entry in HKLM/MS/Windows/Run registry key that turned out to be harmless, but Spybot claims that I am infected with pieces of "NiceSpy." It seems that all of the CLSIDs that it marks as pieces of "NiceSpy" are in fact classes from JMail, a programmable mail class. For example, the key HKEY_CLASSES_ROOT\CLSID\{F812B147-0E26-4222-8EE4-9F753CD2B39C} actually corresponds to a JMail POP3 Object. As far as I can tell, there are no reports of JMail itself being infected with malware, rather it seems that malware manufacturers install JMail to send/receive mail for tracking purposes. For example, I see that W32.Aprilcone.A@mm also uses JMail as does NiceSpy and Email-Worm.Win32.Dushit.a
Please take a look into this issue further. :scratch: