[H]ard|Forum  

Go Back   [H]ard|Forum > Real Life Stuff > [H]ard|OCP Front Page News

Reply
 
Thread Tools Search this Thread
  #1  
Old 05-25-2007, 03:17 PM
Steve Property Of HardOCP, 40.7 Years
 
Steve is offline
Keylogging Trojan Dodges Anti-virus Detection

A new variant of the Russian Trojan Gozi, armed with keylogging functionality, is making the rounds again. What makes this time different is that the Trojan can scramble itself to avoid detection by your anti-virus software.

Quote:
The Trojan is believed to have been spreading since April 17. Like the original, which was discovered earlier in 2007, the new version of Gozi steals data from encrypted SSL (Secure Sockets Layer) streams. The latest variant was uncovered May 7 by Don Jackson, a security researcher at SecureWorks in Atlanta.
__________________
http://www.HardOCP.com
  #2  
Old 05-25-2007, 04:28 PM
GTAKillingPassion n00bie, 3.3 Years
 
GTAKillingPassion is offline
Red face Not good

I have Nod32 but I will restart and try to do a scan in safemode.
  #3  
Old 05-31-2007, 04:23 AM
PleasantlyBlue [H]ardness Supreme, 3.7 Years
 
PleasantlyBlue is offline
Question

How does a pc get infected with this? Through surfing, email attachments, or some other means?
  #4  
Old 05-31-2007, 10:49 AM
Ockie *** Self Proclaimed Storage King ***, 5.5 Years
 
Ockie is offline
Technically, isn't all new viruses, worms, trojans, or exploits undetectable by anti virus systems? It's a matter of hours and somone will have a patch that will catch this.
  #5  
Old 05-31-2007, 06:23 PM
Phelptwan [H]ardness Supreme, 8.1 Years
 
Phelptwan is offline
I thought good ones could take a look at files and say "this looks like a virus, lets stop it and ask the user about it.".
__________________
if you're normal the crowd will accept you, but if you're deranged the crowd will make you their leader. -Titus

<cuss words not allowed in sigs>

How come every time honest citizens do something with guns, politicians call it a "recipe for disaster", but when criminals do something with guns, it's a "potentially dangerous situation."
  #6  
Old 05-31-2007, 06:40 PM
onetwenty8k 2[H]4U, 3.8 Years
 
onetwenty8k is offline
With enough encryption and packing and EP changing, anything can become UD.
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 07:37 PM.


Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright 2000 - 2010 KB Networks, Inc.