Help - Search - Members - Calendar
Full Version: BPS SpywareRemover false positives
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Ad-Aware SE Resolved/Inactive Issues
mogojohn
SE1R120 24.08.2006 picks up the following registry entries that are all associated with xceed backup - no references at all to BPS. I think they are false positives and have not yet deleted them.


BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{02dcd054-ecfd-11d2-a5cd-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f3-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f4-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f5-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f6-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f7-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f8-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{40b0e2f9-0def-11d3-9cce-0060082ae372}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{8c1ca457-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{8c1ca459-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{8c1ca45b-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{8c1ca45d-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{02dcd053-ecfd-11d2-a5cd-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{02dcd055-ecfd-11d2-a5cd-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{7d211ce0-3776-11d2-b1ea-00104b9e0750}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8c1ca456-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8c1ca458-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8c1ca45a-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{8c1ca45c-f430-11d2-a5d1-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{cda1ca00-8b5d-11d0-9bc0-0000c0f04c96}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{cda1ca02-8b5d-11d0-9bc0-0000c0f04c96}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{cda1ca04-8b5d-11d0-9bc0-0000c0f04c96}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{d44f1b20-f80f-11d2-a5d2-00105a9c91c6}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{decc98e1-ec4e-11d2-93e5-00104b9e078a}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : interface\{eb61db30-b032-11d0-a853-0000c02ac6db}

BPS SpywareRemover Object Recognized!
Type : Regkey
Data :
TAC Rating : 3
Category : Misc
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{072c4de1-ecf3-11d2-a5cd-00105a9c91c6}
spike-nz
Hi mogojohn,

Please see my reply (and LS CalamityJane's posts connected to it), in this thread:

Ad-Aware (incorrectly) thinks Actsplash OCX is BPS Spyware Remover

Regards,

Spike
mogojohn
Thanks Spike

QUOTE(spike-nz @ Aug 25 2006, 02:18 PM) *
Hi mogojohn,

Please see my reply (and LS CalamityJane's posts connected to it), in this thread:

Ad-Aware (incorrectly) thinks Actsplash OCX is BPS Spyware Remover

Regards,

Spike
spike-nz
You are welcome, mogojohn,

Please see this post by LS Stoffe:
- http://www.lavasoftsupport.com/index.php?showtopic=2981
QUOTE
SE1R120 25.08.2006 is now availiable, new definition file for Ad-Aware SE.
This fixes a False Positive in BPS SpywareRemover
MD5 checksum is 4ac6cc4c1ef1f87c63d415f56cd59685

Regards,
Spike
tupaia
[quote name='spike-nz' date='Aug 25 2006, 01:05 PM' post='15206']


Yesterday, one of my computers had 2 critial objects,registry entries, reported as being associated with BPS and a secoind had 5 keys identified. I assume that these are all associated with the same "false positive" issue.

However, after downloading todays new defintions, one computer is clean but the other continues to report 3 critical objects, as follows..

BPS SPYWAREREMOVER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : interface\{cda1ca00-8b5d-11d0-9bc0-0000c0f04c96}
obj[1]=Regkey : interface\{cda1ca02-8b5d-11d0-9bc0-0000c0f04c96}
obj[2]=Regkey : interface\{cda1ca04-8b5d-11d0-9bc0-0000c0f04c96}

Assuming this is another example of a false positive,I hope this can be corrected in the definitions file.
spike-nz
Hi tupaia,

Yes, the re-released SE1R120 25.08.2006 fixes the false-positive effect - the one that flags BPS is SE1R120 24.08.2006

Regards,

Spike
Searcher22
Hi All

I also had this reported and quarantined

ArchiveData(auto-quarantine- 2006-08-27 00-57-14.bckp)
Referencefile : SE1R120 25.08.2006
======================================================

BPS SPYWAREREMOVER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : interface\{7d211ce0-3776-11d2-b1ea-00104b9e0750}
obj[1]=Regkey : interface\{cda1ca00-8b5d-11d0-9bc0-0000c0f04c96}
obj[2]=Regkey : interface\{cda1ca02-8b5d-11d0-9bc0-0000c0f04c96}
obj[3]=Regkey : interface\{cda1ca04-8b5d-11d0-9bc0-0000c0f04c96}



Note it is the most current dated definitions. I have never knowingly installed the BPS product and just incase this is still/really a false positive I have restored the entries.

Can anyone throw some more light on this and is there any way of IDing what those registry entries are really associated with if not BPS ?

TIA smile.gif
Mueggli
Regkey : interface\{cda1ca00-8b5d-11d0-9bc0-0000c0f04c96}
is definitively a a false positive!

On my System, it was created due Install GetFoldersize over one year ago!

Scanned with:
Ad-Aware SE Build 1.06r1
Using definitions file:SE1R120 25.08.2006
spike-nz
Hi All,

Despite the False-Positive fix in SE1R120 25.08.2006, I am sure that the Research Team are monitoring this and other posts in Lavasoft Support Forums > Lavasoft - General Support > False Positives, and will be adjusting accordingly.

To quote LS CalamityJane:
QUOTE
Thanks for reporting these. We have apparently got more than they realized. I've sent a heads-up to the Research Team to please revisit these topics that have been posted since the Build 145 was released earlier today
Meanwhile, I recommend you do not quarantine or delete them. These are very like false

A little patience, and all will be solved smile.gif

Regards,

Spike
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.