<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>NAV2003 &#x26; PWSteal.Banpaes in Security</title>
<link>http://www.dslreports.com/forum/r13437872</link>
<description></description>
<language>en</language>
<pubDate>Thu, 10 Dec 2009 05:15:39 EDT</pubDate>
<lastBuildDate>Thu, 10 Dec 2009 05:15:39 EDT</lastBuildDate>

<item>
<title>Re: NAV2003 &#x26; PWSteal.Banpaes</title>
<link>http://www.dslreports.com/forum/remark,13442730</link>
<description><![CDATA[<A HREF="/useremail/u/191317"><b>bcool</b></A> : The hooklib.dll library in the Softes Windows Cleaner 2005 installation is a legitimate component of a global keyboard hook procedure which implements the usage of hotkey shortcuts in the application.  However, there is something in the makeup of the .dll file that triggers two(2) antiVirus scanners to tag it a PWSteal variant.<br><br>I suppose the Windows Cleaner 2005 author can contact Symantec, for instance, about the false positive?<br><br>Oh well, I've disabled the Global hotkey feature so that I can keep the hooklib.dll <B><I><U>off</U></B></I> of my computer just for good measure.<br><br>FWIW<br><SMALL>--<br>"in flagrante delicto"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13442730</guid>
<pubDate>Thu, 19 May 2005 00:22:36 EDT</pubDate>
</item>

<item>
<title>Re: NAV2003 &#x26; PWSteal.Banpaes</title>
<link>http://www.dslreports.com/forum/remark,13438112</link>
<description><![CDATA[<A HREF="/useremail/u/191317"><b>bcool</b></A> : Thanks.  I can tell you now that the file in question, <B>hooklib.dll</B> was installed by Windows Cleaner 2005.  What its actual function is - I don't know.  For now I'm keeping the .dll off of my machine until more is revealed.<br>I'm headed over to Softes Windows Cleaner 2005 forum to see what's up. <br><SMALL>--<br>"in flagrante delicto"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13438112</guid>
<pubDate>Wed, 18 May 2005 14:34:55 EDT</pubDate>
</item>

<item>
<title>Re: NAV2003 &#x26; PWSteal.Banpaes</title>
<link>http://www.dslreports.com/forum/remark,13437910</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : It can be a legitimate dll. I think NAV is flagging it because:<br><br>&raquo;<A HREF="http://securityresponse.symantec.com/avcenter/venc/data/w32.sowsat.b@mm.html" >securityresponse.symantec.com/av&middot;&middot;&middot;@mm.html</A><br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13437910</guid>
<pubDate>Wed, 18 May 2005 14:10:22 EDT</pubDate>
</item>

<item>
<title>NAV2003 &#x26; PWSteal.Banpaes</title>
<link>http://www.dslreports.com/forum/remark,13437872</link>
<description><![CDATA[<A HREF="/useremail/u/191317"><b>bcool</b></A> : 1.)When NAV alerts of virus found and indicates that the file was automatically deleted <B>does NAV also place the file in Quarantine without saying so</B>?<br><br>2.) NAV2003 cites a .dll file @ <I>x</I>:\program files\softes\windows cleaner 2005\<U>hooklib.dll</U> as infected with a catch-all PWSteal variant.  Kaspersky labels it Trojan-Spy.win32.keySend.b of which there is no specific description.<br><br>3.)After a battery of scans and technical diagnoses: I'm confident my system exhibits not one single attribute of any kind of infection at all! My HJT log is pristine! So my question is this?  Does anyone know if <B>hooklib.dll</B> is a legitimate file in the Softes "Windows Cleaner 2005" installation for Windows XP?<br><br>4.)I had just run LiveUpdate yesterday and this morning Giant AntiSpyware was running a system-wide scan when I believe while scanning the <B>hooklib.dll</B>, NAV2003 was triggered and gave the virus alert.  It's the only explanation in my mind for the sudden alert in auto-protect <B>when there is no (I repeat) <I>no</I> trace of any nefarious code anywhere (registry or not) to execute or support this hooklib.dll.</B>  And besides, there's no documentation that any variant of this password stealing trojan would pick the "Windows Cleaner 2005" folder to drop a nasty .dll into.<br><br>5.)I've read reports that Symantec NAV has been issuing some false positives on this variant.  I regret that I don't have the hooklib.dll file anymore.  First, NAV2003 indicated that it had deleted the file. Not even thinking to check Quarantine, I proceeded to run a standalone virus scanner that uses Kaspersky definitions.  It detected a trojan in the NAV2003 Quarantine folder(<I>Trojan-Spy.win32.keySend.b</I>) and immediately deleted it.  So there you have it.<br><br>What a nuisance these false positives can be sometimes.<br><SMALL>--<br>"in flagrante delicto"</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13437872</guid>
<pubDate>Wed, 18 May 2005 14:05:24 EDT</pubDate>
</item>

</channel>
</rss>
