PDA

View Full Version : Spyware Doctor False positive


Holden4th
September 23rd, 2005, 05:26 PM
MY freeware copy of spyware doctor picked this up during a scan and despite running NOD32 as well as Ewido in safe mode with System restore turned off both failed to find it. A quick google confirmed that this is definitely a trojan though exactly what it does I'm not sure.

The Hammer
September 23rd, 2005, 05:39 PM
{QUOTE-> MY freeware copy of spyware doctor picked this up during a scan and despite running NOD32 as well as Ewido in safe mode with System restore turned off both failed to find it. A quick google confirmed that this is definitely a trojan though exactly what it does I'm not sure. <-QUOTE}Upload the file here. http://virusscan.jotti.org/ It may be a FP. Or you could try here: http://www.virustotal.com/flash/index_en.html

Bubba
September 23rd, 2005, 05:46 PM
If you can reproduce this find or if you have it available would you mind showing the location SpywareDoctor found this possible malware Please.

Holden4th
September 23rd, 2005, 11:18 PM
{QUOTE-> If you can reproduce this find or if you have it available would you mind showing the location SpywareDoctor found this possible malware Please. <-QUOTE}

I've restored from quarantine and this is what shows up in the log

Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved##{5E2121EE-0300-11D4-8D3B-444553540000} High

These were all in the registry.

What is this?

rumpstah
September 23rd, 2005, 11:26 PM
Hi Holden4th:

If you have (had) an ATI video card, then this is most likely a false positive.

Do not worry, you are not infected, those registry keys are merely used by ATI's menu.

All they change is when one right clicks on the desktop one no longer sees the option for ATI Catalyst Control Center, that is all.


{QUOTE-> I've restored from quarantine and this is what shows up in the log

Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved##{5E2121EE-0300-11D4-8D3B-444553540000} High

These were all in the registry.

What is this? <-QUOTE}

Holden4th
September 24th, 2005, 06:03 PM
Yes, I do have an ATI video card. After I deleted the (repsamo) files from my registry my ATI Catalyst Control desktop icon wouldn't work - not surprising considering. This prompted me to go to the ATI website and upgrade to the latest drivers so there is a positive spin off for all this.

Thanks for your help.

Bubba
September 24th, 2005, 06:48 PM
{QUOTE-> This prompted me to go to the ATI website and upgrade to the latest drivers so there is a positive spin off for all this. <-QUOTE}Glad it all worked out for ya. I have also taken the Liberty to edit the title and move the thread to a more appropriate Forum in hopes that the Spyware Doctor folks will drop by and notice the False positive you have found.

It seems other Anti-Spyware programs have had ATI False positive issues in the past reported on other Forums but with different names.

MS Antispyware F/P? (http://www.broadbandreports.com/forum/remark,14077741~reverse=0;days=10;root=security;mode=full?r=499)

Mzs.spoolserver32, probable false positive (http://forums.net-integration.net/index.php?showtopic=25900)

pctools
September 27th, 2005, 09:00 PM
Hi all,

I am from PC Tools, maker of Spyware Doctor.

Apologies for any inconviences caused due to the false positive. Thank you all for highlighting this as we take false positives seriously.

We have fixed this issue with our latest live update: Refdb 3.03130

If you are a registered customer, simply perform a Live Update within Spyware Doctor to ensure you have the latest update. Then perform a full scan and fix checked.

However if you are using the free version, the updates are two versions behind. Please be patient as we have regular updates.

Should you still have further problems with Spyware Doctor, you can also contact us directly at: http://www.pctools.com/contact/support/guide/spyware-doctor/

Thank you.

Regards,

PC Tools