Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: System Spy -- Key Logger |
|---|---|
| Date: | Wed, 24 Nov 2004 10:40:05 -0600 |
On Mon, 22 Nov 2004, Roger Padilla Jr wrote:
All,
I was wondering if anyone has some information on a particular piece of
spyware called "System Spy -- Key Logger". It is not detected by either
Ad-aware or Spybot -- it is being identified by Pest Patrol's free online
scanner. I have tried numerous searches to isolate the nature of the
payload and delivery mechanism. There are a number of Spyware companies
that do have it registered in their threat databases, and they all classify
System Spy as a key logger. So far my research has typically resolved to
gambling sites and a number of Spying software programs that can be
purchased or downloaded. There are at least three computers I have come
across that have been identified as having this particular spyware. Any
help would be appreciated.
Your post piqued my interest, so I ran PestScan myself. I got quite a few false positives.
I combed through the results and it seems to me that PestScan will give a positive when it finds a file of the same name as a file used by a piece of spyware.
For example, I got a positive for System Spy, too. The only thing I could find on my system that matched with Pest Patrol's descriptive data for this spyware was under "File Analyses". The file name was setup.inf. It's not surprising that I had a file of this name on my system. And it wasn't the System Spy file.
Can anyone help to confirm this "false positive by file name only" scenario?
Thanks!
-- Using Opera's revolutionary e-mail client: http://www.opera.com/m2/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Strange Spyware or virus or processes, Babar Shafiq Nazmi |
|---|---|
| Next by Date: | RE: System Spy -- Key Logger, Brunner, Mark |
| Previous by Thread: | System Spy -- Key Logger, Roger Padilla Jr |
| Next by Thread: | RE: System Spy -- Key Logger, Brunner, Mark |
| Indexes: | [Date] [Thread] [Top] [All Lists] |