Fixed: MalWarrior TacOnlyOne

fkidd

New member
For some reason spybot is detecting malwarrior at this registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TacOnlyOne

using: --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
latest updates as of today.

Nothing in this folder but RokuRadioSnooper which is used by roku soundbridge software.
 
Getting the same results

I just did the update to my 1.5.2.20 and scanned.
I'm also showing the same "MalWarrior" infection and I have never downloaded it.
After scanning with two other anti-spyware programs they report no infections.


Windows XP SP2 fully updated.
 
Hello,
Indeed it is a false positive and will be fixed with our next update scheduled for Wednesday.:oops:

Thank you for reporting!

regards,
Markus
 
Well, It's Back. HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TacOnlyOne

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TacOnlyOne

Just got this today, don't know what to do about it. An earlier post here said it was fixed. So, do I actually have something to worry about?
Or do I delete this from SB window.
Appreciate any advice. Thank You.
:red:
 
Actually,if you're quoting from MisterW's post above,that's dated as being posted March 25th.
 
:laugh: S'okay,the date is easy to miss. :) The Team Spybot folks will probably see this anyways,come Monday.
 
Jazzmad,

Please open Spybot Search & Destroy > Help > About and let us know version and date of definitions.

Best regards.
 
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TacOnlyOne

Running XP with SP2 installed with PC. Dell Dimension 5150
SB S&D 1.5.2

Date of definitions? Sorry. Don't know but right now I'm not certain SB is running correctly. Odd today, it says there are no updates, last one was several days ago. ? I haven't run a scan since the above TacOnly thing came up. Yeah, am a bit lost here.

Whoops ... def. update. sorry. it says , 23/07/2008.
Five days ago? Should have been another update I think.
 
Last edited:
hello,

thank you for reporting this issue.
As it appears the same false positive occurs with "WinSpywareProtect" , this will be corrected with the updated scheduled for tomorrow.
 
Yup... I just got this, for a program I uninstalled a while back, URLsnooper, which appears to be a reputable program...
Code:
http://www.donationcoder.com/Software/Mouser/urlsnooper/

WinSpywareProtect: [SBI $23F3357B] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TacOnlyOne

"URLSnooper"=dword:003502e2
 
Back
Top