Slashdot Mirror


Samsung Keylogger Stories a False Alarm

Trailrunner7 writes "The panic that arose yesterday about Samsung allegedly shipping laptops that contained a pre-installed keylogger turns out to have been a complete mistake after further investigation by security researchers and the company itself. In fact, the controversy was the result of a false positive from one commercial antimalware suite and nothing else. Several outlets reported on Wednesday that Samsung laptops had been found to contain a keylogger known as StarLogger right out of the box from the factory. However, upon closer inspection by security companies, the folder on the laptops that supposedly contained the malware was actually a directory that is part of Windows' multi-language support."

3 of 183 comments (clear)

  1. Re:epic FAIL by cf18 · · Score: 5, Interesting
    Indeed.

    - an antivirus software that rise alarm base on a two letter directory name inside \Windows , even when it is empty.

    - a "security researcher" that take the alarm at face value and never check if is actually there, check if the process run, what kind of content it was logging and where it is sending them.

    - a low level support manager confirm the software's existence, probably thinking about the fan speed and temperature monitoring software.

  2. Hold on a second. by Conspiracy_Of_Doves · · Score: 1, Interesting

    Where did this quote come from, then?

    monitor the performance of the machine and to find out how it is being used

  3. Wife's Laptop by Cytlid · · Score: 3, Interesting

    My wife has a Samsung R580 which is almost a year newer than the laptops the guy mentioned in the article. I was going to scan it with some decent rootkit programs (like f-secure blacklight or rootkit revealer) only to find out some of my favorites don't work with 64bit Win7. I wrote to the guy who wrote the article, asking about the name of the "commercial security scanner" he installed. He never replied back. I booted my wife's laptop into Linux last night using a Live CD, and performed some find commands for supporting files of the StarLogger program (which showed up in a google search). Nothing. I was thinking if this was true, hers was exempt because it was almost a year older. Turns out, I find out today, I did more research than this supposedly "phd security expert" had.

    --
    FLR