possible spyware question

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by crazybelgium, Aug 18, 2004.

  1. crazybelgium

    crazybelgium Private E-2

    I believe that I may have some sort of keylogger or other information grabber active upon my system because of constantly decreasing disk space. Is there any way to find if I do have some sort of keylogger or system monitoring tool active, when it isn't caught by spybot or adaware?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use updated versions of Ad-aware SE and SpyBot?
    Do you have an virus scan application that is up to date?

    Run these online scans (select Auto Clean as appropriate):
    http://housecall.trendmicro.com/housecall/start_corp.asp
    http://www.pandasoftware.com/activescan/com/activescan_principal.htm
    http://www.ravantivirus.com/scan/
    http://www.bitdefender.com/scan/license.php
    http://www.windowsecurity.com/trojanscan/

    Tell me if they find anything and if you still have a problem. If you are still having a problem, go thru the rest of the items in the below thread that you have not yet run (make sure you check that you are using the correct versions, by clicking on the links to see what version is downloadable):
    http://forums.majorgeeks.com/showthread.php?t=35407
     
    Last edited: Aug 18, 2004
  3. crazybelgium

    crazybelgium Private E-2

    Yes, yes, and yes. Can do, thank you. I'll try that.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, let me know the results when you finish!
     
  5. crazybelgium

    crazybelgium Private E-2

    Only one trojan found, and that was actually found by Avast! while an online scan was trying to scan my system recovery points, so I deleted those. Other than that, nothing found. I'll wait and see if it was just the system recovery points, I lowered the amount of space from 12 to 3 percent of my HD.

    Thanks for your help, and for the links, chaslang.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you had virus/trojans/malware problems (which you did/do) you really need to disable system restore to avoid them coming back from an older restore point. This does remove all your restore points but those restore points most likely contain all your problems.

    Post a HijackThis log as an attachment and I will look at it.
     
  7. crazybelgium

    crazybelgium Private E-2

    Okay, I'll post it.

    And I did remove the restore points. Figured that was the best way to insure the trojan was gone.
     
  8. crazybelgium

    crazybelgium Private E-2

    Hijack This log attached.
     

    Attached Files:

  9. crazybelgium

    crazybelgium Private E-2

    Arrgh, sorry, didn't fully read the instructions. Here's the good log, from a proper scan.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At the beginning of this thread you said you did all of this: http://forums.majorgeeks.com/showthread.php?t=35407

    It does not look like it. I still see MS Java running. I believe if you had put in the Microsoft Critical Updates that would have been disabled. Did you go to MS update and check for updates and download all Critical Updates?

    Also, do you still use GhostSurf?
     
  11. crazybelgium

    crazybelgium Private E-2

    I have all currently available critical updates, as of right now. I just rechecked, and there was nothing to dl for updating this PC.

    No, I don't still use GhostSurf, I uninstalled it a while ago because it was causing big problems with this computer.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, then lets fix the GhostSurf stuff and a couple others first. Run HijackThis and put checks on the following but DO NOT click fix until you exit ALL browsers sessions:

    O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - (no file)
    O8 - Extra context menu item: Allow personal info to reach this site - file://C:\Program Files\GhostSurf\info.allow.html
    O8 - Extra context menu item: Allow popups on this site - file://C:\Program Files\GhostSurf\popup.allow.html
    O8 - Extra context menu item: Allow this advertisement - file://C:\Program Files\GhostSurf\menu.allowimg.html
    O8 - Extra context menu item: Block personal info from this site - file://C:\Program Files\GhostSurf\info.block.html
    O8 - Extra context menu item: Block popups on this site - file://C:\Program Files\GhostSurf\popup.block.html
    O8 - Extra context menu item: Block this advertisement - file://C:\Program Files\GhostSurf\menu.blockimg.html
    O9 - Extra button: GhostSurf Privacy Center - {578FC4E3-151E-456c-AF8E-B63061EFE228} - C:\Program Files\GhostSurf\LaunchPCC.exe (file missing)
    O9 - Extra 'Tools' menuitem: GhostSurf Privacy Center - {578FC4E3-151E-456c-AF8E-B63061EFE228} - C:\Program Files\GhostSurf\LaunchPCC.exe (file missing)
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/bestfriends/retro64_loader.dll
    O18 - Filter: text/html - (no CLSID) - (no file)

    Reboot and post a new HJT log.

    By the way do you use a Proxy server or any special procedures from your ISP to connection to the internet. I'm wondering about this line:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212
     
  13. crazybelgium

    crazybelgium Private E-2

    Not currently, I only have a wireless hub, because this is a laptop and I have cable internet.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay fix the R1 line too. That could be part of the key loggger.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you know what this is:
    C:\Program Files\SB\sb.exe

    Is it a game?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. crazybelgium

    crazybelgium Private E-2

    As far as I can tell, that folder is non-existent. I tried typing that into the adress bar in windows explorer, and received the "404 file not found" error.

    New log:
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  19. crazybelgium

    crazybelgium Private E-2

    I do have viewing of hidden files and folders enabled, as well as system files and folders, and I tried typing that into my firefox adress bar as "file://C:/Program Files/SB/" and was told that that file was non-existent as well. The same for "file://C:/Program Files/SB/sb.exe", or as firefox puts it "This file could not be found."
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to look for it. Not FireFox or Internet Explorer. And do not type it into the address bar. Just navigate to it using your mouse. It would not be a good idea to put c:\Program Files\SB\sb.exe into the address bar when you do not know what it the application is for. You would wind up actually running the program which could be a virus or trojan.

    I don't recall ever seeing "404 file not found" on Windows Explorer only Internet Explorer.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If that still comes up with nothing, have HijackThis fix that line too.
     
  22. crazybelgium

    crazybelgium Private E-2

    I tried Firefox because Windows Explorer didn't show it. And the actual error was:

    "The page cannot be displayed"

    Follwing your advice, I'll remove it.
     
  23. crazybelgium

    crazybelgium Private E-2

    Last log for the evening, I'll check back in the morning.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Two more things:

    1) Do you know for a fact that you need this Broadjump stuff.
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

    I always have people uninstall it (from Add/Remove Programs). And if the cannot then just fix those lines in HJT and then delete the C:\Program Files\BroadJump folder after rebooting.

    It has been know to cause problems with resource like you were having. See
    this and scroll down to BJCFD.EXE and read:
    http://www.answersthatwork.com/Tasklist_pages/tasklist_b.htm

    2) Uninstall MS Java and install Sun Java. How to do that is in this
    thread by Major Attitude:
    http://forums.majorgeeks.com/showthread.php?t=25834
     
  25. crazybelgium

    crazybelgium Private E-2

    If I remember correctly, my wireless card is from Broadcom, so I may need that, I'm not sure.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well check for yourself but I did not think it was needed for proper operation. But I cannot answer that for sure. Only you can. I think they install but do not need it.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait a minute are Broadjump Foundation and Broadcom even related???
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And it is considered spyware?
     
  29. crazybelgium

    crazybelgium Private E-2

    I'll tell you what - I'll make a system restore point, then uninstall it. If it kills my wireless, I'll restore to that point. If it works, I'll just keep working.
     
  30. crazybelgium

    crazybelgium Private E-2

    It worked. Broadjump is not needed for the functionality of integrated Broadcom wireless cards.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There ya go!! So if you have taken care of the MS Java removal. We should be done I assume?
     
  32. crazybelgium

    crazybelgium Private E-2

    Looks like it! Again, thank you very much for your help, and your patience with me. :)
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds