Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 27th, 2008, 06:18 AM
greenfly's Avatar
greenfly greenfly is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 43
Default ESS don't see Ardamax Trojan . Why?

I have downloaded one aplication on my desktop computer were i have installed KIS 0.7. In fase of download KIS stopped the download because the file was infected with Ardamax Trojan.

On my laptop , were i have installed ESS , i tryed to download the same file , and ESS had non see anything.. I have send the infected file to virustotal and Jotty to analyse ,, there is the photo in att.

I runned the infected file, and ESS >nothing.

In HJT log i found and clean a lot of infected temp files......

I feel disappointed.....

Edit: Screenshot removed per the forum policy

Last edited by Marcos : June 27th, 2008 at 07:48 AM.
  #2  
Old June 27th, 2008, 07:44 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: ESS don't see Ardamax Trojan . Why?

Again, it's mostly an installer with encrypted files attached. It's very likely that the keylogger itself would be detected upon extraction when the files are decrypted.
  #3  
Old June 27th, 2008, 07:55 AM
greenfly's Avatar
greenfly greenfly is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 43
Default Re: ESS don't see Ardamax Trojan . Why?

Quote:
Originally Posted by Marcos
Again, it's mostly an installer with encrypted files attached. It's very likely that the keylogger itself would be detected upon extraction when the files are decrypted.

Noup... i have installed the program,, nothing detected.

edit : sorry, now the infected files are detected......,, but is to late > i'm allready infected.....maad
  #4  
Old June 27th, 2008, 08:03 AM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: ESS don't see Ardamax Trojan . Why?

Quote:
Originally Posted by greenfly
I have downloaded one aplication on my desktop
Was that "aplication" the Ardamax Keylogger program ?
  #5  
Old June 27th, 2008, 08:05 AM
greenfly's Avatar
greenfly greenfly is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 43
Default Re: ESS don't see Ardamax Trojan . Why?

Yap....
  #6  
Old June 27th, 2008, 08:08 AM
ASpace
 
Posts: n/a
Default Re: ESS don't see Ardamax Trojan . Why?

Quote:
Originally Posted by greenfly
Noup... i have installed the program,, nothing detected.

edit : sorry, now the infected files are detected......,, but is to late > i'm allready infected.....maad


Pictures say it all
Attached Thumbnails
Click image for larger version

Name:	1.png
Views:	4
Size:	128.1 KB
ID:	200951  

Click image for larger version

Name:	3.png
Views:	3
Size:	51.6 KB
ID:	200953  

Attached Images
 
  #7  
Old June 27th, 2008, 08:09 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: ESS don't see Ardamax Trojan . Why?

http://www.ardamax.com/downloads/setup_akl.exe a variant of Win32/KeyLogger.Ardamax application connection terminated - quarantined Threat was detected upon access to web by the application: C:\Program Files\Opera\Opera.exe.
  #8  
Old June 27th, 2008, 08:12 AM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: ESS don't see Ardamax Trojan . Why?

Quote:
Originally Posted by greenfly
but is to late > i'm allready infected.....maad
Is it now "detected" because you re-adjusted your settings to monitor Potentially unsafe applications, which is enabled by default ?

Last edited by Bubba : June 27th, 2008 at 08:18 AM.
  #9  
Old June 27th, 2008, 08:16 AM
greenfly's Avatar
greenfly greenfly is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 43
Default Re: ESS don't see Ardamax Trojan . Why?

Is not that program , I have downloaded "Fraps" from Rapidshare. I'm not sure that i can post the link Rules.....maybe in private??
Attached Thumbnails
Click image for larger version

Name:	22.jpg
Views:	3
Size:	293.3 KB
ID:	200954  

  #10  
Old June 27th, 2008, 08:26 AM
ASpace
 
Posts: n/a
Default Re: ESS don't see Ardamax Trojan . Why?

We can see the "thing" is detect . Boot in Safe Mode and run a scan (Start -> Program -> ESET -> ESET Smart Security) . Confirm with YES and the ESET Command line scanner will start scanning and cleaning

However , if you suspect something is undetected or there is a problem in its cleaning , send information to ESET ThreatLab -> samples@eset.com .
  #11  
Old June 27th, 2008, 12:54 PM
greenfly's Avatar
greenfly greenfly is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 43
Default Re: ESS don't see Ardamax Trojan . Why?

Can't boot in safe modeXP, because i have Dualboot with Vista ,and there is no options to enter in XP safe mod,, only Vista safe mod on which i have AVG free installed...
  #12  
Old June 27th, 2008, 01:09 PM
ASpace
 
Posts: n/a
Default Re: ESS don't see Ardamax Trojan . Why?

You can boot in XP Safe Mode:

1st way:
Just after you choose your OS (a.k.a. Microsoft Windows XP) , start pressing multiple times F8 , which will lead you to the Advanced menu where you can choose to enter Safe Mode . The fact you have mode than one OS installed doesn't really matter

2nd way:
Open Start -> Run -> type msconfig , press ENTER . In the "boot" tab , check "Safe boot" (you can change other options , too) , confirm the changes and restart . This way you'll enter Safe Mode . In order to start in Normal mode again , you must uncheck the "Safe boot" in msconfig.


Another way to clean the XP partition is to enter Windows Vista and run ESET Online scanner from www.eset.com/onlinescan
Make sure to first run IE7 as administrator
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET Smart Security « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:53 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums