Keylogger or network monitor?

Discussion in 'Malware Help (A Specialist Will Reply)' started by colorblind, Sep 10, 2006.

  1. colorblind

    colorblind Private E-2

    I believe someone gained axcess to my computer at work and may have installed a keylogger or some form of network monitoring software in order to watch my activities. -yes, it's a long and ugly story. I've used spysweeper and am currently running all the scans requested before installing hi-jack this. Yet am I wasting my time? Many have told me I should simply wipe out the hard drive and start fresh. Then again the culprit could be monitoring the peer to peer network with network monitoring software. There may actually be nothing installed on my hard drive. How should I proceed? Thanks for the help.

    I know its a weird dilema yet I have to put up with this for only 2 more months. Thanks again.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please describe what you mean by "my computer" and "at work"?
    Is this a company owned PC or is it your personal PC?
    If it is a company owned PC and your employer installed a keylogger. Then speak to your employer as it is illegal for you or us to help you remove the keylogger if there is one. In addition, if your employer installed a good commercial keylogger, they cannot normally be removed and in some cases may not even be detected.
     
  3. colorblind

    colorblind Private E-2

    Thanks for the help. The business is a two person partnership, in which one of the partners has decided to leave. I am the partner which is going to stay and maintain the business. I don't have it in me to fire 15 employees and shut down a profitable business. In other words I own all the computers. I want to make sure that once my soon to be ex partner is gone that no key loggers/spyware remain. Is it possible to detect a good commercial keylogger? As i've stated it may have simply been a network monitoring program installed on his computer. I just want to play it safe. Should I wipe out the hard drive once he is gone and locks changed? Or is their a way to be sure that their is no key loggers remaining? Every scan I've done so far is negative. I can post any logs you want. Thanks again for the help.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can't you just ask your partner/ex-partner if he installed anything? Don't you trust him? Do you have the Administrator passwords to the PCs? Keyloggers are designed to not be detected. They will not even show in Add/Remove programs. Sometimes a rootkit detection program may find some components of them but they are not always so straight forward to remove. It would be easier to uninstall them but you need to know they are there and how to do this (come with the documentation for them).


    The best I can suggest is for you to run our standard cleaning steps (given below) and then we will see what we can detect.

    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. colorblind

    colorblind Private E-2

    As requested, I am having trouble uploading the bd scan, here is what i have for now, thank you for the help.
     

    Attached Files:

  6. colorblind

    colorblind Private E-2

    Here is the hijack this file.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto Add/Remove Programs and uninstall all of the below but read the notes!

    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_01
    Java 2 Runtime Environment, SE v1.4.2_03
    Java 2 Runtime Environment, SE v1.4.2_05
    Java 2 Runtime Environment, SE v1.4.2_06
    Personal Antispy <--- only uninstall if it is the Free version. Did you install this on purpose?
    Spy Sweeper <--- only uninstall if it is the Free version. Otherwise keep it. But if it is a paid version, uninstall Windows Defender instead.
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player (Remove Only)

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    I do not see any keyloggers but they would not normally show anyway like I said before.

    You could try running the below to see if it finds any super hidden rootkit like files that a keylogger may use.

    Now download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of the BlackLight log.
     
  8. colorblind

    colorblind Private E-2

    I have removed the programs you requested. The personal anti spy I believe I removed before, it does not show up in add remove programs. I believe I had installed that as a trial unit when I was looking for problems.

    I ran the blbeta scan and it did not find anything. I will attach the log. Where do I go from here? Thanks again for all your help.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's good!

    No where (accept the link below)! We are done. I don't see anything to worry about.

    You're welcome.

    If you are not having any other malware problems, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds