I decided to investigate why Kaspersky kept deleting Netcut.
I submitted Netcut to Online analysis by Kaspersky and they report that one of the files extracted by the setup is malware called Trojan.Win32.Snojan.crhx.
I have also put it onto Virus total and 8 out 72 engines detected malware. All 8 flagged it as a Win32.Trojan. McAFee says it behaves like a Win32 autorun trojan.
Any ideas what’s causing these detections on your app?
netcut has a service that auto run , aips. aips try to restart netcut_windows.exe when PC start to have IP address. there are 3 reason we need aips
1. Aips run as service so it can run netCut at administrator right , netcut need this right to function. simple as that.
2. Netcut build-Defender need to start when system have IP.
3. When in case netcut_windows program crash, aips will restart it. this ensure the ongoing function (lock,speed control, arp protection).
we have no idea how kaspersky works. some of the user already contact kaspersky support report the false postive. you can help to do the same if you like netCut to co-work with Kaspersky. the more user report to Kasperksy, the faster they will response and address this.
netCut has been working running in industry over 20 years. due to it’s nature it need those system level access .