help with an undetectable keylogger

Stuff that don´t fit in the other categories.
Post Reply
User avatar
Swan
Knight of the Sword
Knight of the Sword
Posts: 827
Joined: 18 Oct 2006, 16:00
17
Contact:

help with an undetectable keylogger

Post by Swan »

I downloaded a game, and whenever I start it up, a warning pops up from my firewall Zone Alarm informing me that there is suspicious file that may log keystrokes and websites browsed. Ok.

So, I scan the file with my AV, no results. I run a rootkit scan and nothing. Why the hell is not appearing, sure it has been detected, but it cant be found.


Thanks guys.

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

what is the name of the file? :-k

User avatar
Swan
Knight of the Sword
Knight of the Sword
Posts: 827
Joined: 18 Oct 2006, 16:00
17
Contact:

Post by Swan »

dont mean to sound dense BB, but what file?

This phantom keylogger, or the file that seems to contain it?

Its a game file.

As i said, Zone Alarm pops up, informs me of this suspicious file and I tell it to halt its movement. :S:S

User avatar
bad_brain
Site Owner
Site Owner
Posts: 11636
Joined: 06 Apr 2005, 16:00
19
Location: In your eye floaters.
Contact:

Post by bad_brain »

hmm...ok....what is the name of the game exe that causes the alert then?
maybe I can find something about false alerts in context with it or sth like that...

User avatar
Nerdz
The Architect
The Architect
Posts: 1127
Joined: 15 Jun 2005, 16:00
18
Location: #db_error in: select usr.location from sucko_member where usr.id=63;
Contact:

Post by Nerdz »

Sometimes, because game are comunicating directly with a server, it's behavior is like one of a keylogger and they firewall think it is one...
Give a man a fish, you feed him for one day.
Learn a man to fish, you feed him for life.

User avatar
Losing_grip
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 485
Joined: 22 Apr 2007, 16:00
16
Location: Behind Socks5

Post by Losing_grip »

Im also using ZoneAlarm Internet Security Suit , The first time i launched the game called "Freestyle"(Street Basketball Game) ZA Alert me that it's trying to monitor keystroke etc. and i just put it on trusted list since i dont think a huge company will put keylogger in its game. :wink:

p99
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 291
Joined: 14 Oct 2006, 16:00
17
Location: Some hippy's van
Contact:

Post by p99 »

Ok the firewall doesn't scan the file for a key logger. It looks for a program that does something similar to one. Like hooking the keyboard and then sending it to a remote ip. Typical keylogger behavior that is also typical mmporg behavior.

Baron just be sure that your game is a largely known one and downloaded from the official site.

User avatar
Losing_grip
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 485
Joined: 22 Apr 2007, 16:00
16
Location: Behind Socks5

Post by Losing_grip »

Why dont you try to scan the game for rootkits , keylogget , trojan etc.
or even try to sandbox that stuff

User avatar
rambo
Fame ! Where are the chicks?!
Fame ! Where are the chicks?!
Posts: 232
Joined: 29 Jun 2007, 16:00
16
Contact:

Post by rambo »

Phantom 2.0 -the Best Keylogger ! - GovernmentSecurity.org

COuldn't dig up anymore information - The forum is down for maintnience i'd check back there and ask around if i was you..

Post Reply