I remember installing Winpooch 0.6.4 on WinXP Pro SP2. I received alerts of Reg:SetValue for explorer.exe against CommonStartup. Not so often, but at least once a day, randomly. I believe this is an example of false positive, as this happened even in a clean and fresh OS (Winpooch is the first and the only application installed). Is there anybody else having this problem too? Or it´s just me and my infected PC?
I´m still using 0.6.4 now (sorry, upgrading is not easy for me here), and these alerts are still there. So I ask: Is it safe if I delete the particular rule myself? What is actually this rule trying to protect? Thanks.