iTnews
  • Home
  • News
  • Technology
  • Security

Samsung's laptop keylogger a 'false alarm'

By Liam Tung
Apr 1 2011 5:49AM
Follow google news

Scan mistook folder of Slovene language files.

Korean electronics giant Samsung today confirmed that it did not install keyloggers on two of its laptops as claimed by an IT consultant yesterday. 

Samsung's laptop keylogger a 'false alarm'

"The statements that Samsung installs keylogger on R525 and R540 laptop computers are false," it said in a statement on Thursday afternoon. 

Yesterday US IT magazine Network World published a claim by Canadian IT consultant Mohamed Hassan that a Samsung support officer confirmed keylogging software called StarLogger was there “to find out how the computer is being used.”

The claim was reminiscent of the 2005 Sony security fiasco in which the record label planted a rootkit on its music CDs to protect its copyright. 

But Samsung had done nothing of the sort. It and a host of security vendors have pointed to the GFI-owned Sunbelt security software, VIPRE, for delivering a false reading or "false positive".

“Our findings indicate that the person mentioned in the article used a security program called VIPRE that mistook a folder created by Microsoft’s Live Application for a key logging software, during a virus scan,” said Samsung.

VIPRE had mistakenly associated a folder named "SL" in Microsoft’s Live Application multi-language support folder as StarLogger -- a known and recorded piece of malware.

The "SL" was not the keylogger, but a folder denoting the Slovene language.  

“Depending on the language, under C:\windows folders "SL" for Slovene, "KO" for Korean, "EN" for English are created,” Samsung explained. 

Searching for “SL” in the root of the Windows directory was a “very bad idea”, according to Mikko Hypponen, chief research officer at Finnish antivirus firm F-Secure.

Hypponen yesterday said he found “all this is a bit hard to believe,” noting that it and many other AV vendors detect StarLogger as "Trojan.Generic.5223315".

"We have not seen any kind of peak of StarLogger reports," he said.

“Unfortunately Mohamed Hassan (CISSP) who did the original analysis did not double check his findings and blamed Samsung instead. Apparently he did not look at the contents of the "SL" folder at all,” Hypponen wrote today. 

Alex Eckelberry, general manager of GFI security has posted an admission that its software was at fault. 

"The detection was based off of a rarely-used and aggressive VIPRE detection method, using folder paths as a heuristic," he said, referring to behavioural-based techniques used to detect malware. 

"These types of detections are seldom used, and when they are, they are subject to an extensive peer review and QA process." 

But Eckelberry points out that many AV products use this technique.

"It’s not common knowledge, but folder path detections are actually used by a good number of antimalware products, but are generally frowned upon as a folder that looks clearly like one for malware has the potential of generating just this kind of result — a false positive."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
antivirusfalsefsecuregfipositiverootkitsamsungsecuritysonysunbelt

Related Articles

  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
  • Marathon OAIC investigation finds Optus breached 51,000 customers' privacy Marathon OAIC investigation finds Optus breached 51,000 customers' privacy
Join our WhatsApp Channel

Partner Content

From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Promoted Content From test case to control tower: How DXC and ServiceNow are governing enterprise AI at scale
Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
Promoted Content Onel Consulting Strengthens Its White-Glove Services With Strategic COO Appointment
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies

Sponsored Whitepapers

When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Researchers build self-replicating AI worm with BYO LLM

Researchers build self-replicating AI worm with BYO LLM

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.