Windows 10 TP Contains Keylogger

Discussion in 'Windows 10' started by JBenal, Oct 6, 2014.

  1. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    You are correct nice find :D
     
  2. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    16,226
    84,914
    340
    You are kidding, right?
     
  3. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    ..............
     
  4. Hadron-Curious

    Hadron-Curious MDL Guru

    Jul 4, 2014
    3,730
    603
    120
    Lol... I am not. It is a rhetorical question though. I am pointing to the date. That there is something we might learn about why Microsoft didn't update it. Mine is different without the DNS part(line 22 to 29) though. :biggrin:
     
  5. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    Regardless of the Date being used in the host file. The host file is very much still relevant and can be used regardless.
     
  6. Hadron-Curious

    Hadron-Curious MDL Guru

    Jul 4, 2014
    3,730
    603
    120
    Mine doesn't have everything that is in abbodi1406's post. Maybe I need to add some files. :p

     
  7. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,209
    982
    90
    #48 LiteOS, Oct 8, 2014
    Last edited: Oct 8, 2014
    C:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl


    use by the system ,permistion cant be changed

    i think its basically in the kernel

    edit
    also coremessaging disabled make os stuck on starting up
     
  8. badboy77

    badboy77 MDL Novice

    Mar 1, 2008
    25
    5
    0
    i dont have that file or any file on that directory

    and yes, i have "show all files..." selected and "hide protected files..." disabled
     
  9. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    I have an idea... Try copying the file to the desktop. If that doesn't work we could live boot with linux to see what's going on with it.
     
  10. Garbellano

    Garbellano MDL Addicted

    Aug 13, 2012
    947
    248
    30
    well edb.log is interesting to see. Nothing relevant
     
  11. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    But now I know what exactly is being reported to Microsoft.
     
  12. xano

    xano MDL Member

    Jan 28, 2011
    118
    32
    10
    And what is it? LOL
     
  13. xano

    xano MDL Member

    Jan 28, 2011
    118
    32
    10
    Ok, missed that. Thank you. :biggrin:
     
  14. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,209
    982
    90
    #57 LiteOS, Oct 9, 2014
    Last edited: Oct 9, 2014
    Windows Server 10 have it too :\ cant compere


    it can be deleted but when refreshing its coming back

    its really build in the kernel or something

    edit

    i did same compere to windows server 2012 r2
    found same files
    coremessageing and cloud related ....

    edit:

    after delete 2 services and deny system from accessing autologger-....etl file

    i think there no more keylogger :)
     
  15. xtreme 008

    xtreme 008 MDL Novice

    May 9, 2011
    9
    0
    0
    I have deleted both dmwappushsvc, diagtrack files from System32. Now both services has stopped running :D . Now I wanna know whether I am free of tracking or not :busted_cop::busted_cop::busted_cop::eek: Capture.png