Results 1 to 2 of 2

Thread: Klez piggy-backed in winkey?

  1. #1
    Senior Member
    Join Date
    Jul 2003
    Posts
    114

    Exclamation Klez piggy-backed in winkey?

    I've been using winkey -http://www.copernic.com/winkey/ for quite a whyle now. It's a simple keyboard combination shortcut creator.

    The problem is when i run tauscan,the cleaner, ad-aware and Norton 2004 AV (all updated), it gives me nothing, no spyware/worm/etc... but spybot S&D gives me a a Klez warning on both winkeys registry key and on the .exe file itself.

    I searched for any false positives related to this proggie but i only found that spybot gives a false positive on Klez if you're runnig WeBlocker, nothign related to Winkey.


    I figure out that i got nothing to worry about because the AV would have gone crazy if i had been infected with Klez, but this does concern me. Anyone familiar with the issue?

  2. #2
    Master-Jedi-Pimps0r & Moderator thehorse13's Avatar
    Join Date
    Dec 2002
    Location
    Washington D.C. area
    Posts
    2,885
    What I would do is look at the actual payload characteristics and compare them to what Spybot is hitting on. If they are different, then you know that Spybot is generating false positives.

    This is typically how I weed out false positives and then submit the issue to the developer (or I simply fix the source code myself).

    Hope this helps.

    --TH13
    Our scars have the power to remind us that our past was real. -- Hannibal Lecter.
    Talent is God given. Be humble. Fame is man-given. Be grateful. Conceit is self-given. Be careful. -- John Wooden

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •