Welcome, Guest

Go Back   TechieHQ - Computer Help Forum · » Operating Systems · System Security
Reload this Page Keylogger

Keylogger

System Security File System security, OS Security, software firewalls and any other type of security topics reside here.

Reply
 
Thread Tools Display Modes
  #1  
Old Jun 22nd, 05, 8:06 PM
sh4d0w1ink92's Avatar
sh4d0w1ink92
Jr. THQ member
Posts: 79
Status: Offline
 
From: Jersey
Joined: Jun 2004
Rep: sh4d0w1ink92 is on a distinguished road to becoming a computer geek
Keylogger

Well my so called 'friend' told me to get on AIM to look at some picture and not thinking twice i accepted it without looking at the file type... it was an exe. So I open it and it gives me some error, so I just tell him to forget about it, that it wont open up. Next day people are messaging me saying they hate me for scamming them (people on my friends list from Runescape) Even though I hadn't been on in about a week... I go to login and it says invalid username or password (yes, I know I had the username and password right) Basically, I wanna know if there is any way to know FOR SURE that the keylogger has been removed from my computer so I can attempt to get my password from the game and change it (my mother's credit card pin number is required, that's why I'm so hesitant) If anyone can help it'd be greatly appreciated.
Reply With Quote
Advertisement
  #2  
Old Jun 22nd, 05, 11:58 PM
Ogden2k's Avatar
Ogden2k
Photojournalist
Posts: 6,977
Status: Offline
shield_mod.giftechie.gif
 
From: Maine, USA
Joined: Dec 2002
Rep: Ogden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mind
xbl.gifflickr.gif
Keyloggers can be hard to detect at times. Post your Hijackthis log here and we should be able to pick it up.



__________________
Learn about the man behind the screen @ Ogden2k.net
Reply With Quote
  #3  
Old Jun 23rd, 05, 12:21 AM
sh4d0w1ink92's Avatar
sh4d0w1ink92
Jr. THQ member
Posts: 79
Status: Offline
 
From: Jersey
Joined: Jun 2004
Rep: sh4d0w1ink92 is on a distinguished road to becoming a computer geek
Here you are Sir

Logfile of HijackThis v1.99.1
Scan saved at 6:19:29 PM, on 6/22/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\AlienGUIse\wbload.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\syssys\svchost.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Conquer 1.0\Conquer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.219\Hi jackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = 168.94.74.68:8080
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.d ll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.d ll
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunOnce: [MicrosoftAntiSpywareCleaner] C:\Program Files\Microsoft AntiSpyware\gcASCleaner.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?link...67&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1114272780671
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O20 - Winlogon Notify: WB - C:\Program Files\AlienGUIse\fastload.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Reply With Quote
  #4  
Old Jun 23rd, 05, 1:48 AM
spike228's Avatar
spike228
STS 44
Posts: 2,202
Status: Offline
shield_mod.giftechie.gif
 
From: Honolulu, Hawaii
Joined: Jul 2004
Rep: spike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to behold
do you remeber what the file name was?



__________________
Spike
Reply With Quote
  #5  
Old Jun 23rd, 05, 2:57 AM
sh4d0w1ink92's Avatar
sh4d0w1ink92
Jr. THQ member
Posts: 79
Status: Offline
 
From: Jersey
Joined: Jun 2004
Rep: sh4d0w1ink92 is on a distinguished road to becoming a computer geek
Umm no I don't, sorry. It might have been something to the effect of bankpic or somethin... not sure though. Didn't get a good look at it...
Reply With Quote
  #6  
Old Jun 23rd, 05, 5:23 AM
spike228's Avatar
spike228
STS 44
Posts: 2,202
Status: Offline
shield_mod.giftechie.gif
 
From: Honolulu, Hawaii
Joined: Jul 2004
Rep: spike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to behold
i'm not too familiar with keyloggers but here's something that looks suspicious.

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

not sure what it is so scan it or something



__________________
Spike
Reply With Quote
  #7  
Old Jun 23rd, 05, 2:05 PM
Ogden2k's Avatar
Ogden2k
Photojournalist
Posts: 6,977
Status: Offline
shield_mod.giftechie.gif
 
From: Maine, USA
Joined: Dec 2002
Rep: Ogden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mindOgden2k has a brilliant tech mind
xbl.gifflickr.gif
C:\Program Files\Conquer 1.0\Conquer.exe

That's the only thing that does not sound right to me. Are you sure that you didn't just have a simple password?



__________________
Learn about the man behind the screen @ Ogden2k.net
Reply With Quote
  #8  
Old Jun 23rd, 05, 7:29 PM
spike228's Avatar
spike228
STS 44
Posts: 2,202
Status: Offline
shield_mod.giftechie.gif
 
From: Honolulu, Hawaii
Joined: Jul 2004
Rep: spike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to beholdspike228 is a splendid one to behold
Quote:
Originally Posted by James
C:\Program Files\Conquer 1.0\Conquer.exe

That's the only thing that does not sound right to me. Are you sure that you didn't just have a simple password?
i went ahead and looked that up. its a game. but i find it a little odd that he has a game, and a download manager running while scanning for these things.



__________________
Spike
Reply With Quote
  #9  
Old Jun 23rd, 05, 8:38 PM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
Here is some spyware:
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll

Here is an explination, and how to rid your computer of it:
http://www3.ca.com/securityadvisor/p...x?id=453077947



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
  #10  
Old Jun 23rd, 05, 8:53 PM
Cryptoboats's Avatar
Cryptoboats
Ban Stick
Posts: 1,325
Status: Offline
shield_mod.giftechie.gif
 
From: Norfolk, VA
Joined: Jun 2005
Rep: Cryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geeknessCryptoboats has much to be proud of his / her geekness
You might want to consider getting rid of this resource hog as well:
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

This is not malicious, but eats up processor. It is used with microsoft office, and starts during boot up. It claims it helps open the office suite faster, but it doesn't help enough to make a difference, and it does slow down your boot up enough to

Here is also a quick write up of it:

http://www.auditmypc.com/process/osa9.asp



__________________
A wise man can learn more from a foolish question than a fool can learn from a wise answer. ~Bruce Lee
Reply With Quote
Reply

Tags
keylogger


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
keylogger problem Supra System Infection Support 7 Mar 22nd, 05 6:55 PM


All times are GMT +1. The time now is 5:38 PM.