I ran a-squared today and it gave me this:
detected: Trace.File.SC Keylog
c:\documents and settings\my user name\application data\microsoft\internet explorer\quick launch\main.lnk
So I googled the above information and found this from Symantec:
http://www.symantec.com/securi...080515-5409-99&tabid=2
Now here's the thing: while a-squared did find one of the files listed above, that being %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Main.lnk, it didn't find ANY of the others above. When I looked for the reg files above, I found none (one kind of odd thing is that I don't even have an HKEY_ALL_USERS listing in my registry).
So does this mean this was a false positive? Why would I have the "Main.lnk" file but none of the others?
I'd be grateful for any and all input anyone can offer!
detected: Trace.File.SC Keylog
c:\documents and settings\my user name\application data\microsoft\internet explorer\quick launch\main.lnk
So I googled the above information and found this from Symantec:
http://www.symantec.com/securi...080515-5409-99&tabid=2
When Spyware.SCKeyLogger is installed, it performs the following actions:
1. Creates the following files:
* %ProgramFiles%\SC-KeyLog PRO DEMO\Main.chm
* %ProgramFiles%\SC-KeyLog PRO DEMO\Main.exe
* %ProgramFiles%\SC-KeyLog PRO DEMO\Uninstall.exe
* %System%\[RANDOM CHARACTERS].dat
* %System%\[RANDOM CHARACTERS].dll
* %System%\[RANDOM CHARACTERS].exe
* %SystemDrive%\[RANDOM CHARACTERS].exe
* %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Main.lnk
* %UserProfile%\Desktop\Main.lnk
* %UserProfile%\Start Menu\Programs\SC-KeyLog PRO DEMO\Documentation.lnk
* %UserProfile%\Start Menu\Programs\SC-KeyLog PRO DEMO\Main.lnk
* %UserProfile%\Start Menu\Programs\SC-KeyLog PRO DEMO\Uninstall.lnk
Notes:
* %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
* %System% is a variable that refers to the System folder. By default this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
* %SystemDrive% is a variable that refers to the drive on which Windows is installed. By default, this is drive C.
* %UserProfile% is a variable that refers to the current user's profile folder. By default, this is C:\Documents and Settings\[CURRENT USER] (Windows NT/2000/XP).
2. Creates the following registry subkeys:
HKEY_ALL_USERS\Applications\main.exe
HKEY_ALL_USERS\Software\SC-KeyLog PRO
HKEY_CLASSES_ROOT\.kla
HKEY_CLASSES_ROOT\klafile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SC-KeyLog PRO
3. Creates the following registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run\[RANDOM CHARACTERS]
Now here's the thing: while a-squared did find one of the files listed above, that being %UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Main.lnk, it didn't find ANY of the others above. When I looked for the reg files above, I found none (one kind of odd thing is that I don't even have an HKEY_ALL_USERS listing in my registry).
So does this mean this was a false positive? Why would I have the "Main.lnk" file but none of the others?
I'd be grateful for any and all input anyone can offer!