republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
3202
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2
AuthorAll Replies


Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

2 edits

BOClean FP?

BOClean flags Startuprun as a trojan. More info on Startuprun can be found here: »www.nirsoft.net/utils/strun.html

What's wrong with this program? I've been using it for ages and don't want to miss it. Surely an FP; I've added strun.exe to BOClean's Program Excluder.

I've just sent the file in question to the BOClean support team. Let's wait and see.


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire
kudos:13

Good that you sent it to them to check. It has to be fp

Cudni



Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to Buddel
Results from Jotti:
- Dr. Web: Found Tool.StartupRun.122
all the other apps didn't find anything.

Results from Virus Total:
- eSafe: suspicious Trjan/Worm
- Fortinet: suspicious
- The Hacker: Aplicacion/Riskware.Tool.StartupRun.122
all the other apps didn't find anything.

Hm...



Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire
kudos:13

it often happens with nirsof tools
»Re: a2 Free support forums

also NAV would tag it on occasion

Cudni



TonyKlein
Premium
join:2001-07-02
Netherlands

4 edits

reply to Buddel
The detection is intentional. I had a brief exchange with Kevin McAleavey regarding BC's detection of Nirsoft's ServiWin, and he replied:

quote:
NirSoft is also known as "PROAGENT" and have been in the trojan-making business for quite some time. We've covered Nirsoft stuff in the past only to be yelled and whined at and ultimately removing most of those detects. This time though, we need to detect all of Nirsoft's stuff as a result of this

(link removed)

... and a number of others now where the Nirsoft stuff is actively being used to compromise systems as NO antivirus detects any of this.
I understand the point he's making, and for my part I added serviwin.exe to BC's Program Excluder.
--
Tony


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire
kudos:13

so it will flag it regardless of any other malware files being absent?

Cudni



TonyKlein
Premium
join:2001-07-02
Netherlands

said by Cudni:

so it will flag it regardless of any other malware files being absent?
Yes it will; I don't think there really is an alternative, as there will always be the possibility of brand new malware using a NS application to do its thing.
--
Tony


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire
kudos:13

Sure, good to know thanks. Nirsoft tools can always be excluded if downloaded purposely and flagged if not.

Cudni



Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to Buddel
Thank you both for your help. As I mentioned above, I added Startuprun to the Program Excluder, so the fact that BOClean regards this file as a trojan shouldn't be a problem for me anymore.



Martinus
Premium
join:2001-08-06
EU

reply to Buddel
If you want a better tool than Nirsoft's - and one that doesn't get flagged -, get Autoruns from the former Sysinternals.

It's the most comprehensive StartUp information tool and manager out there.



jbob
Reach Out and Touch Someone
Premium
join:2004-04-26
Little Rock, AR

reply to Buddel
Fwiw I had to put all my Nirsoft utilities in a separate folder and exclude the folder from my AV detection.



Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to Martinus

said by Martinus:

If you want a better tool than Nirsoft's - and one that doesn't get flagged -, get Autoruns from the former Sysinternals.

It's the most comprehensive StartUp information tool and manager out there.
I'll give it a try. Thank you, Martinus.


Martinus
Premium
join:2001-08-06
EU

said by Buddel:

I'll give it a try. Thank you, Martinus.
No problem. Just, get it while you can. Now that Sysinternals has been acquired by Microsoft, the future of those utilities may be uncertain.

Happy New Year!


Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to Buddel
Just downloaded it. All the best for 2007, Martinus.



fatness
subtle
Janitor
join:2000-11-17
fishing
kudos:13
Host:
Bright House Netwo..
Earthlink DSL
TekSavvy
Forum Feature Requ..
Need Site Help

reply to Martinus

said by Martinus:

If you want a better tool than Nirsoft's - and one that doesn't get flagged -, get Autoruns from the former Sysinternals.
That's a newer version than I was using. Thank you.
--
Me, I want a hula hoop..


altermatt
Premium
join:2004-01-22
White Plains, NY
Reviews:
·Verizon FiOS

reply to Buddel
I use (and love) NirSoft's Cookie View. Never knew they were also in "the trojan business". I'm assuming that Cookie View is still ok? othing malicious going on? It's easy to exclude it from being detected by BOC; just want to make sure that stuff from there is ok, since I haven't found an alternative to Cookie View that I like as much.
--
The truth of a thing is the feel of it, not the think of it. -- Stanley Kubrick



Nancymca
Security Goddess, retired.
Premium
join:2001-09-30
Voorheesville, NY
Reviews:
·Verizon Online DSL

1 edit

reply to Buddel
We've reluctantly had to add *ALL* of Nirsoft's tools for detection as a result of a nasty new "USB system thief" package made up of all their stuff since it's all automated and hidden by Nirsoft's NIRCMD module into a nice little kit that will grab ALL of the information off a machine (passwords, you name it) and uses THAT module to spread the infection to any removable media plugged into an infected machine. No choice but to cover it.

Nirsoft is an old trojan creator known for the PROAGENT series of trojans and while their "utilities" weren't dangerous, they've become so now. If you're planning on using that, about the only thing you can do is restore the file, right click on the BOClean traybar icon, select "EXCLUDER" and you can then drag the icon for that program to the excluder. Do a system reboot (this is a security measure in our design) and BOClean will let you run that in the future without triggering.

(edit: URL removed)
--
Ten years of Privacy and Protection

www.privsoft.com
www.nsclean.com



Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to Buddel
Hi Nancy, thank you very much for your e-mail. Happy New Year.



Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire
kudos:13

reply to Nancymca

said by Nancymca:

Nirsoft is an old trojan creator known for the PROAGENT series of trojans and while their "utilities" weren't dangerous, they've become so now.
If you don't mind clarifying, so the person or persons claiming to have created the utilities here are also in the business of creating malware?
»www.nirsoft.net/

Cudni
--
Some are born to failure, others achieve it, all deserve it.
Help yourself so God can help you.
MVP, Microsoft Windows Security 2006


Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to Buddel
Hi Martinus, I'm now running both autoruns and Process Explorer. I must say I like what I have seen so far. The information provided by these programs are very detailed, so I do think these tools are keepers. Again, thanks for the info.


Saturday, 11-Feb 14:11:57 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online! © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics