Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 23rd, 2005, 05:26 PM
Holden4th Holden4th is offline
Regular Poster
 
Join Date: Mar 2005
Posts: 65
Question Spyware Doctor False positive

MY freeware copy of spyware doctor picked this up during a scan and despite running NOD32 as well as Ewido in safe mode with System restore turned off both failed to find it. A quick google confirmed that this is definitely a trojan though exactly what it does I'm not sure.
  #2  
Old September 23rd, 2005, 05:39 PM
The Hammer's Avatar
The Hammer The Hammer is offline
Very Frequent Poster
 
Join Date: May 2005
Location: Toronto Canada
Posts: 2,760
Default Re: NOD32 missed repsamo trojan

Quote:
Originally Posted by Holden4th
MY freeware copy of spyware doctor picked this up during a scan and despite running NOD32 as well as Ewido in safe mode with System restore turned off both failed to find it. A quick google confirmed that this is definitely a trojan though exactly what it does I'm not sure.
Upload the file here. http://virusscan.jotti.org/ It may be a FP. Or you could try here: http://www.virustotal.com/flash/index_en.html

Last edited by The Hammer : September 23rd, 2005 at 05:53 PM.
  #3  
Old September 23rd, 2005, 05:46 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,264
Default Re: NOD32 missed repsamo trojan

If you can reproduce this find or if you have it available would you mind showing the location SpywareDoctor found this possible malware Please.
  #4  
Old September 23rd, 2005, 11:18 PM
Holden4th Holden4th is offline
Regular Poster
 
Join Date: Mar 2005
Posts: 65
Default Re: NOD32 missed repsamo trojan

Quote:
Originally Posted by Bubba
If you can reproduce this find or if you have it available would you mind showing the location SpywareDoctor found this possible malware Please.

I've restored from quarantine and this is what shows up in the log

Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved##{5E2121EE-0300-11D4-8D3B-444553540000} High

These were all in the registry.

What is this?
  #5  
Old September 23rd, 2005, 11:26 PM
rumpstah's Avatar
rumpstah rumpstah is offline
Frequent Poster
 
Join Date: Mar 2003
Posts: 478
Default Re: NOD32 missed repsamo trojan

Hi Holden4th:

If you have (had) an ATI video card, then this is most likely a false positive.

Do not worry, you are not infected, those registry keys are merely used by ATI's menu.

All they change is when one right clicks on the desktop one no longer sees the option for ATI Catalyst Control Center, that is all.


Quote:
Originally Posted by Holden4th
I've restored from quarantine and this is what shows up in the log

Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKCR\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000} High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\InprocServer32 High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\ProgID High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\Programmable High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\TypeLib High
Trojan.Repsamo HKLM\Software\Classes\CLSID\{5E2121EE-0300-11D4-8D3B-444553540000}\VersionIndependentProgID High
Trojan.Repsamo HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved##{5E2121EE-0300-11D4-8D3B-444553540000} High

These were all in the registry.

What is this?
__________________
There are only 10 types of people in the world: Those who understand binary and those who don't... CSA
  #6  
Old September 24th, 2005, 06:03 PM
Holden4th Holden4th is offline
Regular Poster
 
Join Date: Mar 2005
Posts: 65
Default Re: NOD32 missed repsamo trojan

Yes, I do have an ATI video card. After I deleted the (repsamo) files from my registry my ATI Catalyst Control desktop icon wouldn't work - not surprising considering. This prompted me to go to the ATI website and upgrade to the latest drivers so there is a positive spin off for all this.

Thanks for your help.
  #7  
Old September 24th, 2005, 06:48 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,264
Default Re: NOD32 missed repsamo trojan

Quote:
Originally Posted by Holden4th
This prompted me to go to the ATI website and upgrade to the latest drivers so there is a positive spin off for all this.
Glad it all worked out for ya. I have also taken the Liberty to edit the title and move the thread to a more appropriate Forum in hopes that the Spyware Doctor folks will drop by and notice the False positive you have found.

It seems other Anti-Spyware programs have had ATI False positive issues in the past reported on other Forums but with different names.

MS Antispyware F/P?

Mzs.spoolserver32, probable false positive

Last edited by Bubba : September 24th, 2005 at 07:06 PM.
  #8  
Old September 27th, 2005, 09:00 PM
pctools pctools is offline
Infrequent Poster
 
Join Date: Nov 2004
Posts: 28
Default Re: Spyware Doctor False positive

Hi all,

I am from PC Tools, maker of Spyware Doctor.

Apologies for any inconviences caused due to the false positive. Thank you all for highlighting this as we take false positives seriously.

We have fixed this issue with our latest live update: Refdb 3.03130

If you are a registered customer, simply perform a Live Update within Spyware Doctor to ensure you have the latest update. Then perform a full scan and fix checked.

However if you are using the free version, the updates are two versions behind. Please be patient as we have regular updates.

Should you still have further problems with Spyware Doctor, you can also contact us directly at: http://www.pctools.com/contact/suppo...pyware-doctor/

Thank you.

Regards,

PC Tools
 

Wilders Security Forums > Security Software > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 03:35 PM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums