Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.
Reply
Old 10-28-2009, 02:44 AM   #1 (permalink)
JRPuja's Avatar
 
Newb Techie

Join Date: Oct 2009

Location: United States

Posts: 5

JRPuja is on a distinguished road

Unhappy Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

Hello all,

I have been in a password battle war for the past few days. I finally got the impression that they were doing so to get at my Myspace password, after a reset was requested. I canceled my Yahoo, as well as my Myspace. Since my Myspace has been canceled I have received no other other password resets. I am pretty sure I know who is doing this, but I have no way to prove it without an ip adress from who was changing the passwords other than me.

I am suspicious that it would be a keylogger, considering the rapid speed at which the passwords would change back and forth. I ran Avira, Malwarebytes, and a-squared, but this was NOT in safemode. I have hijack this, which I am sure will be requested.

Any help would be more than appreciated. Thanks so much.
JRPuja is offline   Reply With Quote
Old 10-28-2009, 07:32 AM   #2 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

run malwarebytes and post its log
__________________
Osiris is offline   Reply With Quote
Old 10-28-2009, 07:36 AM   #3 (permalink)
Antec-User's Avatar
 
Papa Chester

Join Date: Sep 2008

Location: Afghanistan Campaign Veteran

Posts: 633

Antec-User is on a distinguished road

Send a message via MSN to Antec-User
Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

I'm running a key scrambler on my browser.. Peerguardian used to have it for the web browsers too.
__________________
<---- If You enjoyed my ramblings, or if I've helped you, Check me...
Antec-User is offline   Reply With Quote
Old 10-28-2009, 10:28 PM   #4 (permalink)
JRPuja's Avatar
 
Newb Techie

Join Date: Oct 2009

Location: United States

Posts: 5

JRPuja is on a distinguished road

Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

Here is the Safemode log (ran it last night) of Malwarebytes. I also ran a safemode 30 day trial of Zone Alarm Extreme Security. (Can't get AVG 9 to connect to the net. My friend is having the same problem with that)

Malwarebytes' Anti-Malware 1.36
Database version: 2031
Windows 5.1.2600 Service Pack 3

10/28/2009 9:19:41 AM
mbam-log-2009-10-28 (09-19-41).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 263017
Time elapsed: 1 hour(s), 13 minute(s), 43 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Antec- That is something I need to look into after all other steps have been taken. Thank you so much for the suggestion
JRPuja is offline   Reply With Quote
Old 10-28-2009, 11:04 PM   #5 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

Run combofix as well
__________________
Osiris is offline   Reply With Quote
Old 10-28-2009, 11:13 PM   #6 (permalink)
Ste
Ste's Avatar
 
Not Worth The Explanation

Join Date: Aug 2005

Location: Mount Prospect, IL

Posts: 8,902

Ste will become famous soon enoughSte will become famous soon enough

Send a message via ICQ to Ste Send a message via AIM to Ste Send a message via MSN to Ste
Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

Might as well use spywareblaster and spybot search and destroy.

And regularly delete broswer private information combined with CCleaner.

Couldn't hurt.
__________________
lvl Infinite Schizoid

Read The Rules!!
Power Supply Guide
Intel Overclocking Thread
AMD Overclocking Thread
Other Important Threads
There may come a day when you realize more than you wanted, there will be no reprive from the Infinity.
Because I am very busy I may not always reply to a post or thread in which I have helped you in once before, if you still need help just contact me via PM or messenger.
Ste is online now   Reply With Quote
Old 10-29-2009, 12:37 AM   #7 (permalink)
JRPuja's Avatar
 
Newb Techie

Join Date: Oct 2009

Location: United States

Posts: 5

JRPuja is on a distinguished road

Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

\I also found a txt I made of an infected file that could not be repaired or quarantined that I made awhile ago, being lazy I did nothing about it. It is: C:\Documents and Settings\*name hidden*\Local Settings\Temporary Internet Files\Content.IE5\M0BDT6L9\PortalServe[1].

Right before the running of Combofix I received an error it said something along the lines of: Error Registry2 (it flashed somewhat fast so I could not get the full name).

Do you want the log? My only problem with posting it publicly is that my first and last name is in documents users folders.

I will run more anti-malwares that were mentioned tonight, but I thought I heard the Search and Destroy was filled with spyware itself...maybe I heard wrong.I have a few friends who are comp tech, and a prof coder brother and sometimes I get conflicting reports. None are in the area right now and they are super busy. I Didn't want to bother them, and am very happy to be finding such helpful responses here.

Edit- Did run CCleaner in the past 3 days.
JRPuja is offline   Reply With Quote
Old 10-30-2009, 12:24 AM   #8 (permalink)
JRPuja's Avatar
 
Newb Techie

Join Date: Oct 2009

Location: United States

Posts: 5

JRPuja is on a distinguished road

Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

I have a question about this running on startup. It is 'potentially dangerous' in the Security Task Manager.
It is 'runservice.exe'. I read that it is harmless, unless in the windows folders themselves.

It is 1.5 MB in the C:\\WINDOWS\runservice.exe.
The text in the file is:
This program cannot be run in DOS mode.
Service failed.
LoadLibrary failed.
Service Pack 3
----------------
Service
LicCtrlService
s error d
RegisterEventSourceA
ReportEventA
DeregisterEventSource
wsprintfA
GetVersionExA
LoadLibraryA
SGetProcAddress
GetLastError
.data
.rdata
.text
Rich

Is this something to be concerned about? Also The anti-keylogger program, how does that effect computer performance?

Thank you in advance.
JRPuja is offline   Reply With Quote
Old 10-30-2009, 12:33 AM   #9 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,217

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

Yes remove it ASAP

It could be part of a E-Licensing program as well
__________________
Osiris is offline   Reply With Quote
Old 10-30-2009, 05:58 AM   #10 (permalink)
JRPuja's Avatar
 
Newb Techie

Join Date: Oct 2009

Location: United States

Posts: 5

JRPuja is on a distinguished road

Default Re: Suspected Keylogger, battling over Aim/yahoo/Myspace passwords.

Thank you so much! It is deleted.
JRPuja is offline   Reply With Quote
 
Reply

Tags
keylogger, malware, passwords, spyware, virus

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On