Stopping James Bond

Discussion in 'Software' started by lrs52200, Oct 5, 2008.

Thread Status:
Not open for further replies.
  1. lrs52200

    lrs52200 Private E-2

    Hi all-

    I've got a user who appears to have installed a keylogger on a business machine & may have compromised sensitive data. I want to limit this person's access severely. I do not want this person to be able to install/uninstall programs or disrupt any keylogger program that I might install to watch what this person is doing.
    Any suggestions?
     
  2. Maxwell

    Maxwell Folgers

    Which Operating System?
     
  3. bigbazza

    bigbazza R.I.P. 14/12/2011 - Good Onya Geek

    While you are waiting for a more expert solution, you might like to check out Covert Ops programs at http://www.majorgeeks.com/downloads6.html

    I haven't had the need for them, so can't suggest what program/s is/are best. Others will reply here, I hope. :) Bazza
     
  4. lrs52200

    lrs52200 Private E-2

    Thank you for replying, and I apologize for not including the operating system....
    Windows Vista....and it is a possibility that he may also have placed keyloggers on the other 2 machines which are running XP Pro.
    :(

    I just want to stop him from doing any additional harm.....
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :wave lrs52200

    :confused How is this person getting access to the machines?
     
  6. lrs52200

    lrs52200 Private E-2

    Unbelievably, the employer has allowed him unlimited access because they didn't understand what he was doing. They hired him as a laborer but when he claimed that he went to school for computers, they began allowing him to run their IT department. Unfortunately, their knowledge of computers is limited to turning it on and clicking their 'favorite' links that he bookmarked for them. They have completely relied on him for several years to run 2 of their companies that are housed in the same location. He acts as the "IT" guy - and does various other jobs for them. I can actually see their eyes glaze over when I speak to them about keyloggers, remote access, administrative privileges, and so on. I am slowly getting them to understand the security threat he poses and they've given me permission to do what is necessary to stop him. But I do not know if I will be able to get them to agree to cut him off completely and take all of our 25+ computers to an IT person to have them checked.
    To put things in perspective, the employer actually believed that if they broke his computer by 'accidentally' dropping it off his desk, that that would end his access to their company & client information. So that's what I'm up against.
    The guy clearly knows more than I do about computers, but there's got to be a way I can do some damage control until such time as I'm able to get the employer to fully understand what he's doing to them. I only know that he installed a keylogger because he bragged about it. I think he's also been tape recording conversations in the office when he's away because he knew - verbatim - a conversation that happened between me and one other person (who also wants this guy fired so I know he didn't tell him what we spoke about).
    I've got to remove that keylogger without damaging data. It doesn't appear to be a hardware device since there is nothing extra plugged in between the keyboard and tower. If I click on task manager I know that it might be there - but I also know that some keyloggers claim not to be able to be seen by task manager.
    I want to know how to limit his access to everything on the computer except for Quick Books & MS word. I don't want to him to be able to download anything from the internet, use email, install any programs, delete any files, folders, or programs.........I want to set a user account for him with extremely limited access to the computer.
    (I've only been working for the company about 3 weeks) and he knows I have some working knowledge about computers.....he already sees me as a threat to his job so I'm sure he'll try to cover his tracks.
    Can you help me figure out how to deal with this guy?

    In closing, I just want to say that you guys are wonderful and I appreciate so very much the advice you offer. Thank you.:)
     
  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) Because of liability concerns... I would suggest that you run an online scan, i.e http://www.kaspersky.com/virusscanner in the presense of one of "the bosses"; then run the READ & RUN ME FIRST. Malware Removal Guide, post the requested logs along with the Kaspersky report in a new thread in the Malware Removal Forum.

    *Posted by permission

    Good Luck!
     
    Last edited: Oct 7, 2008
  8. lrs52200

    lrs52200 Private E-2

    Thank you! I'm on it - hopefully one of the bosses will be there tomorrow and I can get this started.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're very welcome!

    dr.m ;)
     
  10. Meekiecheese

    Meekiecheese Private First Class

    I was doing a search and came across this post. The problem was fascinating! What happened? Was the person fired? How did you resolve this? Thank you.
     
  11. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    Hi:) This thread is over a year old and the original poster hasn't logged in for about the same time.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds