PDA

View Full Version : FP? Zlob.DNSChanger.Rtk



mvjordan
2008-01-15, 09:46
Hi, I may have a False Positive.

- Windows XP Professional
- IE 7
- FireFox 2.0.0.8
- I am running SpybotSD 1.5.1.15.
- I have downloaded all updates and been fully immunized.
- I ran Spybot in Safe Mode and the result is the same.

The FP occurs after a fix of the Scan result. The symptoms have been cleaned (see thread "Zlob.DNSChanger.Rtk constantly appears after removal by Spybot" in malware removal forum) but I still see the entry when I scan with SpybotSD:

--- Search result list ---
Zlob.DNSChanger.Rtk: [SBI $FE3023DF] Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System=...KDTKZ.EXE...


A Smitfraud scan after the cleaning process did not find the previously present process: KDTKZ.EXE. But Spybot does??

MisterW
2008-01-15, 13:32
Hello,
Would it be possible that you send us the file KDTKZ.EXE to detections(at)spybot.info ? (at=@) So we could have a look on it

regards,
Markus :cowboy:

mvjordan
2008-01-16, 08:48
Hi,

This is the link to the cleaning thread in Malware removal...
Zlob.DNSChanger.Rtk... (http://forums.spybot.info/showthread.php?t=22391)

I have sent a screenshot of regedit with the key in question, and the version of the file that Backlight renamed .ren ...