IPB

Welcome Guest ( Log In | Register )

 
Closed TopicStart new topic
> keylogger
dex
post 10.12.2006 07:33
Post #1


Advanced Member
***

Group: Members
Posts: 133
Joined: 15.07.2006




hello,

when i installed the latest version of kis it detected my synTP.sys as keylogger..... i add it on trusted thinking that its one of my driver, hope i did the right thing, if not how can i remove it back... pls advice, thanks...

This post has been edited by dex: 10.12.2006 07:35
Go to the top of the page
 
+Quote Post
Whizard
post 10.12.2006 09:09
Post #2


Professional
***************

Group: Moderators
Posts: 17898
Joined: 19.11.2005
From: Toronto/Canada




That driver belongs to Touchpads. What is the path to make sure smile.gif


--------------------
Networking and Security Guru
~^Whizard^~
Go to the top of the page
 
+Quote Post
biyahero
post 10.12.2006 09:54
Post #3


Advanced Member
****

Group: Members
Posts: 480
Joined: 22.10.2006




QUOTE(Whizard @ 10.12.2006 16:09)
That driver belongs to Touchpads. What is the path to make sure smile.gif
*


Speaking of Keyloggers, I decided to reinstall Webroot Spysweeper since apparently Don is using it without problems and my subscription is still good for a few more months, and now KIS detects what it is calling a Keylogger as a file from Webroot... C:\WINDOWS\system32\drivers\sskbfd.sys which if I hold my mouse over that file says it is a "Spy Sweeper Keyboard Filter Driver". So I figured it was OK and added it to my Trusted Applications List. However, I continue to get warning about it from KIS and now it is multiple times in my Trusted Applications List. Shouldn't KIS stop warning me about it once I have added it to the trusted applications list?
Go to the top of the page
 
+Quote Post
nickyboy4
post 10.12.2006 10:17
Post #4


Advanced Member
****

Group: Members
Posts: 338
Joined: 27.09.2005
From: Long Island NY USA




QUOTE(biyahero @ 10.12.2006 02:54)
Speaking of Keyloggers, I decided to reinstall Webroot Spysweeper since apparently Don is using it without problems and my subscription is still good for a few more months, and now KIS detects what it is calling a Keylogger as a file from Webroot... C:\WINDOWS\system32\drivers\sskbfd.sys which if I hold my mouse over that file says it is a "Spy Sweeper Keyboard Filter Driver".  So I figured it was OK and added it to my Trusted Applications List.  However, I continue to get warning about it from KIS and now it is multiple times in my Trusted Applications List.  Shouldn't KIS stop warning me about it once I have added it to the trusted applications list?
*

I have this exact problem with my logitech mouse setpoint software, add it to trusted but get the pop up for keylogger after every reboot or startup???


--------------------
Norton drove me here, thanks Norton!
Go to the top of the page
 
+Quote Post
dex
post 10.12.2006 10:44
Post #5


Advanced Member
***

Group: Members
Posts: 133
Joined: 15.07.2006




QUOTE(Whizard @ 10.12.2006 09:09)
That driver belongs to Touchpads. What is the path to make sure smile.gif
*


thanks for the reply, it was located at system32/drivers/synTP.sys..... here is my screenshot.



This post has been edited by dex: 10.12.2006 10:47
Go to the top of the page
 
+Quote Post
Don Pelotas
post 10.12.2006 11:46
Post #6


Global Moderator
***************

Group: Global moderators

Posts: 25601
Joined: 7.04.2005




All these in this thread should be added to the exclusion in the popup you get.


--------------------
Go to the top of the page
 
+Quote Post
dex
post 10.12.2006 13:56
Post #7


Advanced Member
***

Group: Members
Posts: 133
Joined: 15.07.2006




thanks Don
Go to the top of the page
 
+Quote Post
ARMOR
post 10.12.2006 18:52
Post #8


Advanced Member
***

Group: Members
Posts: 57
Joined: 8.12.2006
From: GREECE-MACEDONIA




I had this keylogger and i added in trusted zone
its correct move isnt it????

\Driver\eabfiltr


--------------------
KASPERSKY SAPIENS
Go to the top of the page
 
+Quote Post
Don Pelotas
post 10.12.2006 19:00
Post #9


Global Moderator
***************

Group: Global moderators

Posts: 25601
Joined: 7.04.2005




QUOTE(ARMOR @ 10.12.2006 17:52)
I had this keylogger and i added in trusted zone
its correct move isnt it????

\Driver\eabfiltr
*

Yes, it's the keybord on your HP.


--------------------
Go to the top of the page
 
+Quote Post
ARMOR
post 10.12.2006 19:06
Post #10


Advanced Member
***

Group: Members
Posts: 57
Joined: 8.12.2006
From: GREECE-MACEDONIA




THANX


--------------------
KASPERSKY SAPIENS
Go to the top of the page
 
+Quote Post
biyahero
post 11.12.2006 04:10
Post #11


Advanced Member
****

Group: Members
Posts: 480
Joined: 22.10.2006




QUOTE(Don Pelotas @ 10.12.2006 18:46)
All these in this thread should be added to the exclusion in the popup you get.
*


Don I just rebooted and got the popup again, and the choices were to Allow it... which I did... or "Deny" which oddly I think was greyed out.... maybe because it was already in the Trusted Zone (Exclusion Mask list section)?

Then in the bottom of the box was a checkbox to add it to the trusted zone, which I did not check since it is already IN the Trusted Zone.

I tried manually adding it to the "Trusted Applications" List since it was already in the "Exclusions Mask" list, but that didn't work since apparently KIS only allows you to add exe files to that list and this is a sys file.

This post has been edited by biyahero: 11.12.2006 04:30
Go to the top of the page
 
+Quote Post
Don Pelotas
post 11.12.2006 08:31
Post #12


Global Moderator
***************

Group: Global moderators

Posts: 25601
Joined: 7.04.2005




You should have added it, my mouse/keybord software also asks twice.


--------------------
Go to the top of the page
 
+Quote Post
biyahero
post 11.12.2006 14:34
Post #13


Advanced Member
****

Group: Members
Posts: 480
Joined: 22.10.2006




QUOTE(Don Pelotas @ 11.12.2006 15:31)
You should have added it, my mouse/keybord software also asks twice.
*


Thanks Don. I added it again just now when it asked again when I rebooted.
One odd thing... I noticed this time when it asks, if you click add to Trusted, what it adds says:

Object Name: \Driver\SSKBFD
Verdict Mask: Keylogger system32\drivers\sskbfd.sys
checking task: selected task Proactive Defense

Whereas the first time I had added it, I noticed that the object name said \Driver\SSKBFD when the real directory the file is located in is name Drivers with an "s" and not Driver, so when it asked me the second time... thinking the reason it had asked me again was the path to the object name was wrong because of the omission of the "s" in the "\Driver\SSKBFD ", instead of adding it a second time I edited the original entry to have an object name of the real path to the file:
C:\WINDOWS\system32\drivers\sskbfd.sys

and not that entry in the Exclusions now says:

Object Name: C:\WINDOWS\system32\drivers\sskbfd.sys
Verdict Mask: Keylogger
checking task: selected task Proactive Defense

Nevertheless it asked me again when I rebooted, so this time I just added it again, and now I have one entry that says:

Object Name: C:\WINDOWS\system32\drivers\sskbfd.sys
Verdict Mask: Keylogger
checking task: selected task Proactive Defense

and the one I just added says:

Object Name: \Driver\SSKBFD
Verdict Mask: Keylogger system32\drivers\sskbfd.sys
checking task: selected task Proactive Defense

I just rebooted again and it didn't ask me again, so I guess that works. Thanks!

This post has been edited by biyahero: 11.12.2006 14:37
Go to the top of the page
 
+Quote Post
Lucian Bara
post 11.12.2006 14:40
Post #14


True legend
***************

Group: Moderators
Posts: 52487
Joined: 28.01.2006
From: Timisoara, Romania




Hello
no it's correct \Driver\SSKBFD is not the same as c:\windows\system32\drivers\sskfbd.sys
\driver is used to define the fact that it's a loaded driver and sskbfd is it's name. so the way kav added it is correct.


--------------------
Go to the top of the page
 
+Quote Post
biyahero
post 18.12.2006 08:47
Post #15


Advanced Member
****

Group: Members
Posts: 480
Joined: 22.10.2006




QUOTE(lucianbara @ 11.12.2006 21:40)
Hello
no it's correct \Driver\SSKBFD is not the same as c:\windows\system32\drivers\sskfbd.sys
\driver is used to define the fact that it's a loaded driver and sskbfd is it's name. so the way kav added it is correct.
*


Thanks Lucian for explaining the difference!

When I get back to that machine I will change the "c:\windows\system32\drivers\sskfbd.sys" back to "\drivers\sskfbd.sys" to match the second entry.
Go to the top of the page
 
+Quote Post
jin_akanishi
post 17.07.2008 21:20
Post #16


Newbie
*

Group: Members
Posts: 4
Joined: 17.07.2008




my kis reconises the game battlefield 2142 the bf2142 exe process as a keylogger i have also read in news that the game came with spyware and adware from the games manufatures for ingame advertisments,my question is should this legal copy legitimate game be allowed as a trusted app considering my kis system is reconising it as a threat
Go to the top of the page
 
+Quote Post
Lucian Bara
post 17.07.2008 21:21
Post #17


True legend
***************

Group: Moderators
Posts: 52487
Joined: 28.01.2006
From: Timisoara, Romania




hello
no it's not because of that. it's because battlefield, like any game that uses direct3d, also uses dinput. dinput can be used for capturing keystrokes by a kelogger as well, since this is a behavioural alert, kis will alert in both cases, games and keyloggers. in this case you can add it to the trusted zone.


--------------------
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 22.11.2009 03:23