Unchecky Compromised?

Is Unchecky Compromised?

  • Yes

    Votes: 3 17.6%
  • No

    Votes: 9 52.9%
  • Unchecky What?

    Votes: 5 29.4%

  • Total voters
    17
  • Poll closed .

upnorth

Level 68
Thread author
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
Anyone getting certificate errors when trying to access the https version of the unchecky site? Heimdal only blocks the http version.
The real certificate is from Comodo and Heimdal PRO does also block the https version at least on my machine.

Curious enough I downloaded the software from the main source and installed it on a VM ( Virtual Machine ) just briefly to see if I could find anything suspicious. It creates a service called " unchecky_svc.exe " along with a child process " unchecky_bg.exe " and initially when first time started calls back to a Amazon server in Ashburn, Virginia USA. Quttera.com flags it with a reference that seams to be blacklisted but a quick check on that seams to be false or simply old information.

After about 30 minutes when I couldn't see any other outbound connections etc I killed the test. The one thing I did found odd was 3 checkboxes in the About page. Was for some reason impossible to uncheck and I never could understand what they where.
 
Last edited:
D

Deleted Member 3a5v73x

The one thing I did found odd was 3 checkboxes in the About page. Was for some reason impossible to uncheck and I never could understand what they where.
Just a Pacman style joke, checkboxes doesn't do anything. :D Just like Windscribes.
FcconXMIUJPwrC7nSugkXaPvsykJ7HY2EJ_FjE83o4s.png
 

LDogg

Level 33
Verified
Top Poster
Well-known
May 4, 2018
2,261
On a regular basis, probably not. It's there I guess encase I forget to untick a box when reinstalled or updating software. Which I have a tendency to do xD

~LDogg
 

Kyle_Katarn

From KC Softwares
Verified
Developer
Sep 28, 2013
585
I agree with Heimdal about kc-softwares, it's crazy they are even allowed to advertise their scareware even at MT. Not even talking about redirects from in-software to mysterious 3th party vendor pages to download drivers from and fake Java download pages. I feel for souls installing Sumo/Dumo on systems without using any adblocker.

That's not true. There is mysterious 3th party vendor pages, neither fake Java download page linked to our products.... Are you using genuine SUMo binaries ?
 

Kyle_Katarn

From KC Softwares
Verified
Developer
Sep 28, 2013
585
Same is true if you use SUMo, kc-softwares.com is blocked,

VokkdW.png


Anyway if one think is a false positive can surely unblock I think,

I usually do a double check with Heimdal and PiHole,

the final response is given to urlscan.io, analyzing all the info given from that nice service

Not sure how false-positives are handled, because surely is a false positive,

maybe @Kyle_Katarn too should be informed (y)

I have to admit Heimdal catch some things PiHole didn't and same PiHole catch some things Heimdal didn't, so added together they make a very nice layer :)

Thanks for letting me know. Hopefully it seems to be blocking kc-softwares.com only, which is our backup server.... Is SUMo still working correctly despire this on your system ?
 

upnorth

Level 68
Thread author
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
Do we still think that Unchecky is compromised? If not I may just reinstall it.

~LDogg
The poll gives a pretty good view and with the latest whitelist from Heimdal Security, I personal would now consider it safe enough but download the software from the main site as I suspect previous found infections came from unknown or less known sources.

Unchecky - Keeps your checkboxes clear
 
Last edited:

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top