Перейти к содержимому


Фото
- - - - -

Keyloggers


  • Please log in to reply
6 ответов в этой теме

#1 victor43

victor43

    Newbie

  • Posters
  • 5 Сообщений:

Отправлено 15 Январь 2010 - 22:08

I am a user of Nod32 version 4 and have enabled the checkbox for potentially unsafe applications and have a keylogger installed on my system. I have run a scan of my entire system and nothing was detected during the scan.

My question is why does Nod32 not find this keylogger ?

Could it be because its hidden so well on the file system that it does not get scanned ?

Could it also be that it does get scanned but its byte code does not display malicious activity ?
Could it be also be that it goes get scanned but there is no history/signature of the file that it evades detection as a threat ?

I would really like to know how could it be saved on the file system either as a hidden file or as an alternative data stream or using another advance method.

Comments could be appreciated and thanks in advance

#2 risl

risl

    Member

  • Posters
  • 228 Сообщений:

Отправлено 15 Январь 2010 - 22:42

Why are you asking NOD32 issues on a Dr.Web forum?

#3 drumut

drumut

    Member

  • Members
  • 325 Сообщений:

Отправлено 15 Январь 2010 - 23:07

You should ask this on Nod32 official forum. We don't use Nod32 because the reason you post in your topic, it can't even find keyloggers.
OS : Debian Sid , all i have all i need!

#4 victor43

victor43

    Newbie

  • Posters
  • 5 Сообщений:

Отправлено 15 Январь 2010 - 23:33

Sorry for the confusion. Yes I do have Nod32 installed and working but I have run a scan using the download for DrWebCureIt and it also did not detect anything. I've also downloaded a copy of the trial version of Dr Web for Windows though not installed but installing as we speak while Nod32 is being uninstalled.

Please advise

#5 userr

userr

    Newbie

  • Members
  • 16 310 Сообщений:

Отправлено 15 Январь 2010 - 23:37

victor43
cureit writes log file here - "c:\Documents and Settings\<username>\Doctorweb\cureit.log"
pls zip the file cureit.log and attach it here

#6 drumut

drumut

    Member

  • Members
  • 325 Сообщений:

Отправлено 15 Январь 2010 - 23:39

If it is a test keylogger and you know it please send it to dr.web https://vms.drweb.com/sendvirus/

Also you should check it by virustotal.com and give us some informations.
OS : Debian Sid , all i have all i need!

#7 victor43

victor43

    Newbie

  • Posters
  • 5 Сообщений:

Отправлено 16 Январь 2010 - 01:03

I just wanted to clearify that I believe there is a keylogger on my system but do not know of its whereabouts.

Прикрепленные файлы:

  • Прикрепленный файл  CureIt.log   385,85К   115 Скачано раз