PDA

View Full Version : "Phoenix" keylogger 11-25 update



halbert
2005-11-28, 14:11
Good morning folks - I run my S&D scans religiously every weekend, and have been doing so for quite some time. I almost always have received a "no entries found" response message.

With the 11-25 update detection patterns, I've been flagged with having "Phoenix".. Researching this states it's a keylogger program shown in c:\windows\setup1.exe.

This setup file (setup1.exe) was indeed in my windows directory, shows an installation date of 2-13-05, and say it's a "Visual Basic 6.0 Toolkit Setup" file.

Is this a legit keylogger detection that the 11-25 pattern found on my machine? It's found it on all 3 of my pc's since the 11-25 pattern update, one of which I am very restrictive on internet access (very controlled internet access on this system due to business applications I use on this machine..i.e., I do no internet browsing on this machine).

If anyone may be able to assist, would appreciate. Thank you -

spybotsandra
2005-11-28, 14:40
Hello,

Please have a look at this link in our forum:

http://forums.spybot.info/showthread.php?t=620&highlight=Phoenix

Best regards
Sandra
Team Spybot

halbert
2005-11-28, 16:17
ahhh, thank you Sandra. It's funny how these things happen as last Thur, my password for Yahoo email access stopped working. This has never happened before. Rather than contacting Yahoo, I went ahead and changed my password.

Then I found this keylogger, and thought...oh no.. I've been hacked! Needed to change all my passwords anyway..so no harm.. Thank you again for the followup -