Hi strange
Maybe we have some few threats with single lines within registry...?
Also with a check within Symantec kb it is so....
http://securityresponse.symantec.com/avcenter/venc/data/pwsteal.rivarts.html
Compare it with Spyfalcons recognition but no RTP block...
Where do you put RTP blocks ? registry or files ?
regards
plun
Category:
Potentially Unwanted Software
Description:
This program has potentially unwanted behavior.
Advice:
Review the alert details to see why the software was detected. If you
do not like how the software operates or if you do not recognize and
trust the publisher, consider blocking or removing the software.
Resources:
clsid:
HKLM\SOFTWARE\CLASSES\CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}
typelibversion:
HKLM\SOFTWARE\CLASSES\TYPELIB\{244B730E-D899-4E38-9428-03D1143242E0}\1.0
regkey:
HKLM\Software\SpyFalcon
regkey:
HKLM\SOFTWARE\CLASSES\TYPELIB\{244B730E-D899-4E38-9428-03D1143242E0}\1.0
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{B7C685F0-1804-4382-A8EF-17D33DF97069}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{5B861FB8-903C-4996-B1D3-E9A86ED4BBCF}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{B7C685F0-1804-4382-A8EF-17D33DF97069}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{37B9988B-1997-41F4-A832-DAE42CC3F7C2}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{3261F690-1CA4-4839-928B-F4F898B74EB7}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{255CDDA3-576B-44C9-B944-46EAC18D5D6F}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{23D80835-4A3A-4572-9F5F-3F24A7A28AE5}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{200BD3A6-A02B-4BAC-A364-A9D8017E3C4E}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{1694E5C6-9E1F-4C3B-B79A-828C2FC40003}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{163469FD-6009-48E2-AD8C-47BB2E0D88BE}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{8C803228-BD61-4744-8B79-949E3F512DDC}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{0FBBBC44-296D-4A2F-AF45-BE1EE387F569}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{001501E7-C970-4CB1-9740-E055BF3DDFD6}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{8C803228-BD61-4744-8B79-949E3F512DDC}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{850300D6-D53B-4720-9372-6D31B85537E1}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{850300D6-D53B-4720-9372-6D31B85537E1}
regkey:
HKLM\SOFTWARE\CLASSES\CLSID\{330A77C2-C15A-43B5-055C-B4E35EAED279}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{701E8C3A-7910-4CCD-A9F8-7B9A5F5B3947}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{6876543E-DA55-4F90-9CD2-5ED380D9516C}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{701E8C3A-7910-4CCD-A9F8-7B9A5F5B3947}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{6876543E-DA55-4F90-9CD2-5ED380D9516C}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{5B861FB8-903C-4996-B1D3-E9A86ED4BBCF}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{37B9988B-1997-41F4-A832-DAE42CC3F7C2}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{3261F690-1CA4-4839-928B-F4F898B74EB7}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{255CDDA3-576B-44C9-B944-46EAC18D5D6F}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{23D80835-4A3A-4572-9F5F-3F24A7A28AE5}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{20C59F9F-33CB-4B1B-AFB6-B710DB845709}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{1694E5C6-9E1F-4C3B-B79A-828C2FC40003}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{163469FD-6009-48E2-AD8C-47BB2E0D88BE}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{0FBBBC44-296D-4A2F-AF45-BE1EE387F569}
regkey:
HKLM\SOFTWARE\CLASSES\INTERFACE\{20C59F9F-33CB-4B1B-AFB6-B710DB845709}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{001501E7-C970-4CB1-9740-E055BF3DDFD6}
interface:
HKLM\SOFTWARE\CLASSES\INTERFACE\{200BD3A6-A02B-4BAC-A364-A9D8017E3C4E}
typelib:
HKLM\SOFTWARE\CLASSES\TYPELIB\{244B730E-D899-4E38-9428-03D1143242E0}
file:
C:\Program\spyfalcon\SpyFalcon.url
file:
C:\Program\spyfalcon\blacklist.txt
file:
C:\Program\spyfalcon\ignored.lst
file:
C:\Program\spyfalcon\Lang\English.ini
file:
C:\Program\SpyFalcon\SpyFalcon.exe
file:
C:\Program\spyfalcon\sf.ini
file:
C:\Program\spyfalcon\msvcp71.dll
file:
C:\Program\spyfalcon\msvcr71.dll
file:
C:\Program\spyfalcon\syg.db
folder:
C:\Program\spyfalcon\Quarantine\
folder:
C:\Program\spyfalcon\Logs\
folder:
C:\Program\spyfalcon\Lang\
folder:
C:\Program\spyfalcon\