KVIrc icon indicating copy to clipboard operation
KVIrc copied to clipboard

Windows Defender detects "kvimy.dll" module as keylogger.

Open mantarray opened this issue 1 year ago • 1 comments

Hello. I installed KVIrc Quasar today, and after trying to log onto a server, Windows Defender detected a Keylogger trojan in a file named kvimy.dll

Detected: TrojanSpy:Win32/Keylogger

Afected items: C:\Program Files\KVIrc\modules\kvimy.dll

Windows Defender was able to delete the file. Should I be worried? Is this a false positive? I can't find any info on "kvimy.dll" and I'm a bit worried. Thanks!

mantarray avatar Aug 27 '24 06:08 mantarray

Hi, i can confirm this is a false positive, as this already happened in the past. Kvimy.dll is a kvirc module that exports a $my.idle() function that checks for user idle time. This is done by checking for user activity on the keyboard/mouse, and this unfortunately resembles how some keylogger works. I'll take a look if i can fix it in some way, thank you for reporting the issue.

ctrlaltca avatar Aug 27 '24 06:08 ctrlaltca