Exclusions just wont work with ardamax keylogger. HELP?

I want to have keylogger for personal/security reasons only.

And i know it is detected as trojan because it has trojan engine, so i added path in:
Settings->Exclusions, and
REAL-TIME SHIELDS->File System Shield->Expert Settings->Exclusions

even in scan settings (quick scan and full system scan)

There should be no mistakes in path because i selected folder using Avast (i didn’t type it).

So, when i install ardamax keylogger (with Avast off) it works fine,
but when i turn on Avast it just deletes POL.exe, and its not even in “virus chest”.

And just in case, here is report from www.virustotal.com:
http://www.virustotal.com/file-scan/report.html?id=4cf4bf2b7d2bb4215e255e1f2b1238ad989f3c8a98ebfd5cb033bccf32fedaa0-1293237723

Thanks

  1. Excluding the whole folder is leaving too large a hole in security.

You should specifically exclude the file. Open the file system shield exclusions again and edit the path, change the * bit at the end to \pol.exe.

Next you should ensure the exclusions options include Read (R) Write (W) and Execute (X) otherwise it would be picked up if they aren’t all checked.

  1. Avast doesn’t delete as its primary action unless you either have the options set to delete or set to Ask and choose delete at that point.

  2. I don’t really know what is detecting this or when as you don’t say. Ardamax being a hidden resource to try and do its sneaky key-logging may be being detected by the anti-rootkit scan 8 minutes after boot or by the file system shield in installation.

If you can do a screen shot of just the avast alert window, that will answer that particylar question.

Thanks for quick reply.

I didn’t mentioned that i tried adding the exact file \pol.exe with RWX all checked.
And Avast is set to ask me what to do.

I had a couple of alerts, but they stopped showing up.

hmmm… now i leaved Avast disabled, and waited to see what will happen with pol.exe, and it just
disappeared, with no alert.

I don’t have “anti-rootkit scan” or something like that, just SUPERAntiSpyware,
but that’s not problem for sure.
And i use Windows 7…

EDIT:

I disabled Windows Defender, and for now, it works fine!

So if someone have same problem, try adding folder/file to Windows Defender,
or disable it to see if that is the problem.

And -DavidR, thank you very much! :slight_smile:

You’re welcome.

Avast has anti-rootkit scanning built in and runs 8 minutes after boot (or on certain on-demand scans) and this is why I asked about a screen shot of the alert as it hasn’t been clearly identified exactly what is alerting.