There are suspicious CLSID reg. Is this virus or something?
投稿日: 2020-12-07 | 09:02 · 返信 7 · パーマリンク · 翻訳:
Hello. Sorry for the weird question.
In my computer, There are suspicious CLSID registry as below.
%SystemRoot%\system32\[random length and letters].dll
Location: HKCR\CLSID\{4A805FB7-07D5-9F24-EC3C-3932E5493B9F} (fixed location)
In system32 dir, there are no such dll file as said in registry above.
And this value is created again with new [random_name].dll if that registry value be removed.
Also it seems like there are no issue on my computer for year.
At one time, I tried to catch that file using powershell's file create event detect, but failed.
I also tried NPE, but nothing there.
Anyone who know about this registry value?
Re: There are suspicious CLSID reg. Is this virus or something?
投稿日: 2020-12-10 | 04:56 · パーマリンク
I removed NIS fully as I can and reinstalled it today. And still registry was there.
But, a time NIS is reinstalled, new registry entry value was there which uuid start with D.
And, after license is updated automatic, it seems NIS create another registry entry which same one before.
So, there was 2 registry with random letters. One is same as 4A805FB7-07D5-9F24-EC3C-3932E5493B9F.
It might be changed by user account or license user have.
Actually I still worry, but I also think that would be no problem.
Thank you for reply on my post again.