I have a MalWare problem - Key Logger.

Discussion in 'Malware Help (A Specialist Will Reply)' started by otter_60, Mar 29, 2006.

  1. otter_60

    otter_60 Private E-2

    Hi Major,

    I try to practice very safe-surfing, but recently I've been surfing off the beaten path, and it looks like I've picked-up something nasty. I noticed unexpected Ethernet traffic on my Router and discovered that I had the "NGC" Key-logger on my Win2K PC.

    I've tried to do everything in the "Read & Run Me First? post; however, I had a couple of problems. I couldn't get Microsoft Windows Defender installed, so I didn't run that, and I kept getting the Blue-Screen of Death during the BitDefender scan.

    I have attached the HJT Panda ActiveScan logs and was wondering if you could take a look at them.

    Also, do you know of any tools that I could use to:

    1. See what program is doing the sending? I didn't see it in the Task List.
    2. Monitor my LAN traffic to see who is sending what to whom?

    Thanks,
    o
     
  2. otter_60

    otter_60 Private E-2

    No, I'm not a total Bone-Head.

    I had the attachments uploaded and ready to go before I started entering my original post. Then I got distracted, and my session timed-out, so I had to re-enter my post. Luckily I was able to cut-and-paste my original post into the new post window, but I forgot to re-attach my log files.

    I tried editing my original post to attach the files, but I got a server error. Now I'm getting "upload errors" when I try to attach the files, so I may have to try another PC.

    Thanks,
    o
     
  3. otter_60

    otter_60 Private E-2

    Log Files Attached

    Note that I did not use the infected PC for my original post, but I went to a different PC, and now I can upload files. They are attached.

    Thanks again for your help,
    o
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Log Files Attached

    Welcome to Majorgeeks!

    Looks like you have this:

    http://www.symantec.com/avcenter/venc/data/backdoor.irc.aladinz.f.html

    Also another reference is: http://www3.cai.com/securityadvisor/pest/pest.aspx?id=453076437


    Did you setup the below proxy server?

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxysrv.ext.ray.com/proxy


    Please run the below to procedures and attach the two requested logs.

    Running Spy Sweeper

    Running Ewido Anti-Malware


    After running the above two scans and attaching the logs, let me know if there has been any change in your status.
     
  5. otter_60

    otter_60 Private E-2

    Hi chaslang,

    First, thank you very much for your help.

    I think that proxy server is OK. I think I needed it to access the www when I was telecomuting via a VPN. Fortunately, I only did that once a couple of months ago.

    I ran Spy Sweeper, Ewido AM, and HJT - Logs are attached.

    The problem still seems to be there.

    I am currently using Verizon and the Yahoo Anti-Mal-Ware software that comes bundled with it. Do you know if there should be zero (0) internet traffic if I'm not doing anything (i.e., no internet-related applications open)? I think that in the past this was the case.

    Thanks again,
    o
     

    Attached Files:

  6. otter_60

    otter_60 Private E-2

    Hi Chaslang,

    One other thing. Some my applications are now taking very long to start now. Windows takes at least a minute longer than usual to start. Windows Explorer and Internet Explorer takes 30-40 seconds longer to start. Any ideas?

    Thanks,
    o
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have cable or DSL, there will also be some internet traffic. When you say you have no internet-related applications open, are you sure. You have a few things that are running in the background. For example:


    C:\Program Files\Outlook Express\msimn.exe
    O4 - Startup: Folding @ Home.lnk = C:\Program Files\Folding@Home\winFAH.exe

    Is the below R0 line your expect start page?
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/__users/_Dan/www-browser-home-page/Dan-www-browser-home-page-for-ie-00.html

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: ATINotify - logonnfy.dll (file missing)

    After clicking Fix, exit HJT.


    Now boot in safe mode and delete the below folder:
    C:\WINDOWS\system32\config\mouse

    Then reboot in normal mode and tell me how things are working.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Adding protection software will slow things down. Sort of a necessary evil. And from your log, it appears you have no firewall yet. You need a software firewall.

    However now that we have run scans with Spy Sweeper and Ewido. You should uninstall them and reboot. This should speed things up a little.
     
  9. otter_60

    otter_60 Private E-2

    Hi chaslang,

    I won't be able to try your latest suggestions on the infected machine until later tonight.

    Regarding the internet-related applications:

    The Folding @ Home client, winFAH.exe, only uses the internet about once every 48 hours when it uploads its latest results to its server and then downloads a new work-package from its server. Also, I've killed this app, and I still see the internet traffic.

    Regarding my home page:
    Yes, that is simple, static, page that has my most frequently-used links listed on it. I generally use it instead of Favorites.

    Regarding the software firewall:
    I thought that by using a router, the NAT function indirectly acted as a firewaal. Am I missing something? If so, do you have any suggestions for firewall software?

    Do you know anything about this process that is running on my PC:

    ScsiAcc.exe

    I don't know why, but I have a funny feeling about it?

    Thanks again,
    o
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but as I said you still have other stuff running and your hardware is always phyically connected (if you are using cable or DSL) and sending packets periodically.


    You still need a software firewall. The hardware firewall is a great thing to have but it is not sufficient. Tell me how many times you have received a message from your hardware firewall asking you if a particular application should be allow access to the internet from your PC. Do you think that a hardware firewall knows the name of every legit and every piece of malware software that exists or will exist in the future. And does it know which folder the program should be running from on your PC so it can know the difference between (for example) a good svchost.exe and a bad svchost.exe.

    Firewalls and all things you need to do are covered in another sticky thread that I normally post in my final message after removing all malware. The link is:

    How to Protect yourself from malware!

    I overlooked this the first time! I thought I saw ScsiAccess.exe.
    The one you have is unknown. The closest thing I can find to it is a process from Merge eFilm. Does the below mean anything to you:

    O23 - Service: eFilmProcessManagerNT - Unknown - C:\Program Files\Merge eFilm\eFilm\efPMNT.exe
    O23 - Service: ScsiAcc - Unknown - C:\Program Files\Merge eFilm\eFilm\SCSIACC.EXE

    One of the services is the same name but it is running from a different folder than you have.
     
  11. otter_60

    otter_60 Private E-2

    Hi chaslang,

    I had a software firewall when I was running Norton AV, then I switched to the Verizon/Yahoo Mal-ware Suite of tools, and I didn't realize that I didn't have a software firewall anymore. I will get one immediately.

    No, I don't recognize any of that.

    I did the following as you suggested:
    I did the above, and I didn't see any change.

    I had the HJT Log attached to my post, but then had the following problem:
    1. It usually takes me a while to create a post, because I try to get the words right.
    2. When I hit the "Submit Reply" Button, I guess my session had timed-out, so it took me to a Login Screen.
    3. I logged-in, but got an error that said the Thread Id was incorrect and to contact the Sys Admin.
    4. I went to the Sys Admin page, but it wasn't obvious what to do there, so I am doing it here.
    5. From that point-on, I couldn't attach a log file.
    6. I had the same problem the other day.
    7. So I went to a different PC to do my post and attach the Log. That worked the other day, when I had this problem, but today I can't attach a file from this PC either.
    I'll see if it lets me attach a Log File in a little while after I reboot everything.

    Another question, Do you know why the following would show-up twice in the HJT Log under "Running processes":?

    C:\WINNT\system32\Ati2evxx.exe

    Thanks,
    o
     
  12. otter_60

    otter_60 Private E-2

    HJT Log Attached

    HI chaslang,

    I just waited a while, and now I can attach the HJT Log file. Note that I had logged-out between sessions.

    o
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well we could try stopping and disaabling the below service if you want.

    O23 - Service: ScsiAccess - Unknown owner - C:\WINNT\system32\ScsiAcc.exe

    Then you can see if you have any problems running anything. Let me know if you want to try this.

    Did you send a message to the Admins? I have never had a session time out on me. Even when I left one up unattended thru the weekend.

    No I don't know why it would be running twice. Seems to be seen running twice on the internet many times. You would be better off asking about this in the Software Forum.
     
  14. otter_60

    otter_60 Private E-2

    Yes, I'd like to try that. How do I do it?

    Also, I installed the Zone Alarm firewall, and the following program is trying to access the internet:

    C:\WINNT\system32\services.exe
    Is that normal?

    Thanks,
    o
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is a valid Windows process! Here is a quote from ZoneLabs:
    This comes from: ZoneAlarm Products and Windows Internet Connection Sharing (ICS)

    For the ScsiAcc.exe service, try the below.

    Click on Start, then Run ... type services.msc into the box that opens up, and press OK. On the page that opens, scroll down to Service Hosts ... then right click the entry, select 'Properties' and press Stop Service. When it shows that it is stopped, next please set the Start-up Type to Disabled. Press OK until you get back to Windows.

    Now reboot your PC and check to see how things are working with this Service disabled.
     
  16. otter_60

    otter_60 Private E-2

    Hi Chaslang,

    Sorry for taking so long to get back to you. A few other things have popped-up that I had to take care of. I've been so paranoid with this PC that I went-out and bought another very inexpensive PC so that I can use it until I get the "Problem PC" straightened-out. I'm going to reformat the HD of the Problem PC and start-over so that I can reserve that PC for all sensitive work (e.g., online banking).

    I'll re-read your Pos on how to protect that machine, and also limit how I use it (e.g., no surfing off the beaten path).

    Thanks again for all of your help!

    Many blessings to you and your family.

    o
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely and wisely. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds