View Single Post
  #19  
Old 01-05-2006, 11:13 PM
Panda_man
 
Posts: n/a
Default Re: WMF Exploit question

Well ,ok.Seems normal.

I sent the file for analyze to Panda as it was suggested by TruPrevent so I
am waiting for a reply from them and will keep you informed ,Dave.


Panda_man
--
Prevention is always better than cure !
Panda TruPrevent - the most intelligent technology to combat unknown malware
http://www.pandasoftware.com
http://free.hit.bg/fightmalware/homepage_en.htm




"David H. Lipman" wrote:

> From: "Panda_man" <Pandaman@discussions.microsoft.com>
>
> | Dave ,Panda TruPrevent technologies blocked KIX32.exe in your AV-CLS folder
> | as dangerous operation which tries to modify host files...
> |
> | Any comments/ according to Panda and ICSA labs ,TruPrevent have 0 % false
> | positives/...
> |
> | Panda_man
>
> Kix32.exe is the nterpreter. It loads script in the form of .KIX. It will make sure that
> the .\etc\hosts file is empty and other things to make sure that malware has not altered the
> OS such that that the utility can not go to the respective AV vendors web sites and download
> the needed files.
>
> I suggest that Panda is mis-interpreting that activity. Since KiXtart is interpreted code,
> it is open source and one can examine the KIX files and see there is NO malicious activity
> being performed.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
>

Reply With Quote