Page 1 of 2 12 LastLast
Results 1 to 10 of 17

Thread: Protexis.MOD

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    Dec 2007
    Posts
    2

    Default Protexis.MOD

    Spybot detected Protexis.MOD on my computer. I let Spybot fix it, but can someone give me any more details about this keylogger? Where does it come from? What does it do besides capture keystrokes ( I assume for banking websites, etc)? How can I tell if it got anything off my computer?

  2. #2
    Junior Member
    Join Date
    Dec 2007
    Posts
    1

    Default Seconded

    I have no idea but I second your question. The directories in question -- C:\ProgramData\Protexis , C:\ProgramData\Protexis\DL and C:\ProgramData\Protexis\State -- were all empty. A Google search returned only a small number of hits -- none very enlightening.

  3. #3
    Junior Member vsparky's Avatar
    Join Date
    Sep 2007
    Location
    Scottsdale
    Posts
    1

    Default

    Quote Originally Posted by seekaybee View Post
    I have no idea but I second your question. The directories in question -- C:\ProgramData\Protexis , C:\ProgramData\Protexis\DL and C:\ProgramData\Protexis\State -- were all empty. A Google search returned only a small number of hits -- none very enlightening.
    me too ...exactly

    anyone?
    Last edited by tashi; 2007-12-21 at 01:24. Reason: Commercial signature removed, as per faqs.

  4. #4
    Senior Member honda12's Avatar
    Join Date
    Nov 2007
    Location
    UK
    Posts
    682

    Default

    hmm this may just be a coincidence, but spybot just happened to detect the same keylogger today when I scanned!

    Merry Christmas

  5. #5
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    As the topic is getting longer, I have moved it to the false positives forum (just in case), and will bring to the attention of a detective.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  6. #6
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hello,

    it appears that Protexis is the publisher of the qwertystudio MOD Keylogger while qwertystudio is the actual vendor. Since it is safe to assume that Protexis also publishes other software we will consider the Protexis folders as false positives. The Keylogger will also be renamed to Qwertystudio.MOD . This will take effect with the update scheduled for next wednesday .
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  7. #7
    Junior Member
    Join Date
    Dec 2007
    Posts
    1

    Default

    Spybot detected this virus on my computer as well...

  8. #8
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    @darkblitz

    your Hijackthis log does not show any items that are related to the keylogger.



    The detection update from 2007-12-26 should not flag the protexis folders anymore.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  9. #9
    Junior Member
    Join Date
    Jan 2008
    Posts
    1

    Question false positive for qwertystudio.MOD?

    spybot s&d reported detection of qwertystudio.MOD, but i think it's a false positive.

    OS: Windows XP Home, SP2
    Browsers: Firefox 2.0.0.11, Internet Explorer 7
    Spybot S&D Version: 1.4.
    Latest update: 2008-01-02
    False positive occurred in a Scan Result

    Qwertystudio.MOD: Web page (File, nothing done)
    C:\Documents and Settings\bunnyhero\Local Settings\Application Data\Protexis\UserSettings.xml



    i looked inside the reported file. the contents of UserSettings.xml are:

    <USER_SETTINGS><PROXY><SERVER IP="" Port="" /><AUTHENTICATION UserName="" Password="" /></PROXY></USER_SETTINGS>

    and that's it.

  10. #10
    Member of Team Spybot Buster's Avatar
    Join Date
    Oct 2005
    Location
    Bochum/Germany
    Posts
    389

    Default

    Hello bunnyhero,

    thanks for reporting this. Looks like we missed this file. This will be fixed by the next update.
    "The advantage of wisdom is that you can always act the fool. The opposite is quite tough."

    K. Tucholsky

    _______________________________________________________________

    Please help us improve Spybot and download our distributed testing client.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •