Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 12th, 2005, 10:26 AM
webyourbusiness's Avatar
webyourbusiness webyourbusiness is offline
Very Frequent Poster
 
Join Date: Nov 2004
Location: Throughout the USA and Canada
Posts: 2,584
Default dumador keylogger protection?

In case anyone's interested - NOD32 already has protection from Dumador keylogger- search for dumador here:

http://www.nod32usa.com/nod32-updates/

Dumador info here:

http://abcnews.go.com/Technology/PCW...ory?id=1029067

cheers

Greg

Last edited by webyourbusiness : August 12th, 2005 at 10:28 AM. Reason: found I'd typo'd...
  #2  
Old August 12th, 2005, 10:55 AM
rothko's Avatar
rothko rothko is offline
Frequent Poster
 
Join Date: Jan 2005
Location: UK
Posts: 579
Default Re: dumador keylogger protection?

thanks for the info, greg.

to quote from the abcnews article:

The Srv.SSA-KeyLogger is so new, says Sunbelt, that few antivirus vendors have developed definitions to remove the threat from infected machines. Srv.SSA-KeyLogger appears to be a variant of existing forms of keystroke-stealing Trojan Horses, called Dumador or Nibu.

if nod32 detects dumador, will it definately detect srv.ssa-keylogger?
__________________
kiss my pig
  #3  
Old August 12th, 2005, 11:27 AM
lotuseclat79 lotuseclat79 is offline
Very Frequent Poster
 
Join Date: Jun 2005
Posts: 1,958
Default Re: dumador keylogger protection?

Checking the Trend Micro Whatsnew files for PC-Cillin updates I have received, it appears that PC-Cillin Internet Security 2005 has had dumador protection since Aug 7th.

-- Tom

P.S. Went back to check earlier files and Trend Micro has been protected since 11/26/2003 in update 690 from BKDR_DUMADOR.A, and up to 8/8/2005 for update 2-763 from BKDR_DUMADOR.AN, BKDR_DUMADOR.AX.
  #4  
Old August 12th, 2005, 11:52 AM
rothko's Avatar
rothko rothko is offline
Frequent Poster
 
Join Date: Jan 2005
Location: UK
Posts: 579
Default Re: dumador keylogger protection?

but the threat in the article is Srv.SSA-KeyLogger, just because the variants are in the signature database does that mean this one is definately protected against?
__________________
kiss my pig
  #5  
Old August 12th, 2005, 11:58 AM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: dumador keylogger protection?

Quote:
Originally Posted by lotuseclat79
Checking the Trend Micro Whatsnew files for PC-Cillin updates I have received, it appears that PC-Cillin Internet Security 2005 has had dumador protection since Aug 7th.

-- Tom

P.S. Went back to check earlier files and Trend Micro has been protected since 11/26/2003 in update 690 from BKDR_DUMADOR.A, and up to 8/8/2005 for update 2-763 from BKDR_DUMADOR.AN, BKDR_DUMADOR.AX.

That's nice, but I'm pretty certain that the post is about Srv.SSA-KeyLogger - which is a new variant of the older "dumador" threats you are posting about.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #6  
Old August 12th, 2005, 12:03 PM
Detox's Avatar
Detox Detox is offline
Global Moderator
 
Join Date: Feb 2002
Location: Texas, USA
Posts: 8,507
Default Re: dumador keylogger protection?

Quote:
Originally Posted by rothko
but the threat in the article is Srv.SSA-KeyLogger, just because the variants are in the signature database does that mean this one is definately protected against?

Hm I had read the first post incorrectly myself

I see tons of "dumador" entries but can't find an SSk - but then Eset might have called it dumador.something like the other older versions I dunno.
__________________
"The price of freedom is eternal vigilance."
- Thomas Jefferson
  #7  
Old August 12th, 2005, 12:42 PM
webyourbusiness's Avatar
webyourbusiness webyourbusiness is offline
Very Frequent Poster
 
Join Date: Nov 2004
Location: Throughout the USA and Canada
Posts: 2,584
Default Re: dumador keylogger protection?

it's actually a good point - that ssa.keylogger MIGHT not be detected explicitly in signatures, but heuristics should (yes - should), detect it as unknown pe. Perhaps someone in Eset can confirm...

if you think you mis-read my OP - you might not have - I did have it posed as a question, as I was mis-typing dumador when I was searching at first...
  #8  
Old August 12th, 2005, 04:24 PM
rothko's Avatar
rothko rothko is offline
Frequent Poster
 
Join Date: Jan 2005
Location: UK
Posts: 579
Default Re: dumador keylogger protection?

Quote:
Originally Posted by webyourbusiness
it's actually a good point - that ssa.keylogger MIGHT not be detected explicitly in signatures, but heuristics should (yes - should), detect it as unknown pe. Perhaps someone in Eset can confirm...
yeah i'd really like to know the answer to this too
__________________
kiss my pig
  #9  
Old August 17th, 2005, 05:51 AM
rothko's Avatar
rothko rothko is offline
Frequent Poster
 
Join Date: Jan 2005
Location: UK
Posts: 579
Default Re: dumador keylogger protection?

hiya, anyone have an answer to this? thanks, lee
__________________
kiss my pig
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:39 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums