Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

Keylog-Spc

Mar 24, 2004 6:57AM PST

Date Discovered: 3/6/2004
Date Added: 3/24/2004
Origin: Unknown
Length: 80,384 bytes
(may vary)
Type: Trojan

Virus Characteristics

This detection is for a Win32 keylogging trojan written in Borland Delphi. It bears the following characteristics:

it is intended to log keystrokes on the victim machine
it contains its own SMTP engine to email the logged data to the hacker
the threat is likely to be received via a spammed email message encouraging the recipient to click on a link. This directs the recipient to a web page which contains a script trojan (most likely VBS/Inor ) intended to drop the keylogging trojan on the victim machine.
The trojan logs keystrokes together with the window title of the application in which the keystrokes were entered.



Indications of Infection

Existence of the files/Registry key detailed below.
Unexpected outgoing SMTP traffic (port 25) to:
smtp.mail.ru


http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=101131

Discussion is locked