What kind of keylogger is this?

What kind of keylogger is this?

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
What kind of keylogger is this? betty889125 10-22-2006
Posted by on October 22, 2006, 7:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
(see image link below as I can't attach a *.txt file to this group).

http://i13.tinypic.com/40l2t81.jpg


When I found my IE 6 browser refusing to open several browsers at a time,
I did a ctrl-alt-delete and found two SERVICES processes. I also saw that
my IEXPLORE.exe file would still be open as a memory hog (130 mg) even
after closing all open browser screens. After using Crapcleaner to clean
the temp files and cache, I ran a services.msc command and noticed this
Key*** service, which I knew I never had before. The attached image link
shows half of the places I found where it appeared in my registry.
Obviously, Crap Cleaner deleted the exe file in the temp directory.
When I was in services, I disabled it (it was set to "manual").


I've searched all over Google and can't find any references to it.

Hijackthis picked it up as an 023 item - Unknown owner - \LOCALS~1\Temp
\exe (file missing)

Before I delete all the registry references to it, would anyone here know
of any site that discusses it?





Posted by David H. Lipman on October 22, 2006, 7:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| (see image link below as I can't attach a *.txt file to this group).
|
| http://i13.tinypic.com/40l2t81.jpg
|
| When I found my IE 6 browser refusing to open several browsers at a time,
| I did a ctrl-alt-delete and found two SERVICES processes. I also saw that
| my IEXPLORE.exe file would still be open as a memory hog (130 mg) even
| after closing all open browser screens. After using Crapcleaner to clean
| the temp files and cache, I ran a services.msc command and noticed this
| Key*** service, which I knew I never had before. The attached image link
| shows half of the places I found where it appeared in my registry.
| Obviously, Crap Cleaner deleted the exe file in the temp directory.
| When I was in services, I disabled it (it was set to "manual").
|
| I've searched all over Google and can't find any references to it.
|
| Hijackthis picked it up as an 023 item - Unknown owner - \LOCALS~1\Temp
| \exe (file missing)
|
| Before I delete all the registry references to it, would anyone here know
| of any site that discusses it?
|



Please submit a sample of "keygodsx.exe" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition,
unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.

It uses RootKit techniques so I suggest using Gmer.
http://www.gmer.net/



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on October 22, 2006, 8:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>| (see image link below as I can't attach a *.txt file to this group).
>|
>| http://i13.tinypic.com/40l2t81.jpg
>|
>| When I found my IE 6 browser refusing to open several browsers at a
>| time, I did a ctrl-alt-delete and found two SERVICES processes. I
>| also saw that my IEXPLORE.exe file would still be open as a memory
>| hog (130 mg) even after closing all open browser screens. After
>| using Crapcleaner to clean the temp files and cache, I ran a
>| services.msc command and noticed this Key*** service, which I knew I
>| never had before. The attached image link shows half of the places I
>| found where it appeared in my registry. Obviously, Crap Cleaner
>| deleted the exe file in the temp directory. When I was in services, I
>| disabled it (it was set to "manual").
>|
>| I've searched all over Google and can't find any references to it.
>|
>| Hijackthis picked it up as an 023 item - Unknown owner -
>| \LOCALS~1\Temp \exe (file missing)
>|
>| Before I delete all the registry references to it, would anyone here
>| know of any site that discusses it?
>|
>
>
>
> Please submit a sample of "keygodsx.exe" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners. That will give you an idea what it is and who recognizes it.
> In addition, unless told otherwise, Virus Total will provide the
> sample to all participating vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL... mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
> It uses RootKit techniques so I suggest using Gmer.
> http://www.gmer.net/
>
>
>

I'd like to submit the file, except that I ran Crap Cleaner even before I
knew it was on the system. Crap Cleaner deleted it.
I'm going to run the above rootkit program as well as Sysinternals and a
few others.

Do you think it's time for Multi A-V? Is is safe to run these online
scanners rather than downloaded the signatures like Multi-AV does?
Don't the online scanners record every filename on your computer?
Secondly, isn't there stuff they can't find because of one's firewall?

I have McAfee's SiteAdvisor as a BHO, use IE-Spyad and have a HOSTS file,
plus use Avast and a firewall. Still, it's amazing how these things
infiltrate a computer. I was reading on one of the security sites that
Spyware problems are soaring.

I wonder if it pays to change the name of your computer, sign on name,
password, and release and renew IP addresses on a regular basis.

Someone better inform the media soon how serious a problem this is
becoming. Any guesses as to how many home computers are seriously
infected around the world?

(Please excuse my crossposting, but I'm incensed at my violation of
privacy with this spyware/malware/trojan problem and I feel that the more
individuals who read about this particular keylogger, if that's what it
is, the better.)

Posted by David H. Lipman on October 22, 2006, 8:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| I'd like to submit the file, except that I ran Crap Cleaner even before I
| knew it was on the system. Crap Cleaner deleted it.
| I'm going to run the above rootkit program as well as Sysinternals and a
| few others.
|
| Do you think it's time for Multi A-V? Is is safe to run these online
| scanners rather than downloaded the signatures like Multi-AV does?
| Don't the online scanners record every filename on your computer?
| Secondly, isn't there stuff they can't find because of one's firewall?
|
| I have McAfee's SiteAdvisor as a BHO, use IE-Spyad and have a HOSTS file,
| plus use Avast and a firewall. Still, it's amazing how these things
| infiltrate a computer. I was reading on one of the security sites that
| Spyware problems are soaring.
|
| I wonder if it pays to change the name of your computer, sign on name,
| password, and release and renew IP addresses on a regular basis.
|
| Someone better inform the media soon how serious a problem this is
| becoming. Any guesses as to how many home computers are seriously
| infected around the world?
|
| (Please excuse my crossposting, but I'm incensed at my violation of
| privacy with this spyware/malware/trojan problem and I feel that the more
| individuals who read about this particular keylogger, if that's what it
| is, the better.)

I have more confidence in Gnmer that RootKit Revealer so I suggest using it
first.

Sure, you can use my Multi AV Scanning Tool. The McAfee module alone knows
hundreds of
Keylogging Trojans. Additionally, you never know what else any of the modules
might find.

I really do NOT know what you had. I looiked in virus libraries and could not
find it. It
may be new or it may be an old one that is using new names for Registry keys and
files.

I would assume the worst. That is you need to immediately redo *all* passwords
that have
been used on that PC. Online Banking, Forum accounts, Quicken, -- every and all
of them.
Chaning ther name of the computer is waste of time. The PC name is meaningless.
Getting a
new IP address is also worthless. I do suggest that if you are on Broadband,
get and use a
Cable/DSL Router sucgh as the Linksys BEFSR41.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by on October 22, 2006, 8:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

> I have more confidence in Gnmer that RootKit Revealer so I suggest
> using it first.

I just used it and can't make head or tail from it.
Secondly, Drwatson appears about 2nd use and closes it.

Right now, I see that the gmer.exe file is still running in my task
manager, yet I can't see the program, nor can I close it.

The same goes for sysinternals.com Process Explorer.

When I ran the Rootkit scan, I saw a load of things scrolling by,
but I didn't see anything marked "hidden" like his FAQ's show (unless I'm
reading the FAQ's wrong). I did see some of the MJ's and some TCP/IP
things floating by. I thought I was getting very advanced, but I'm not
sure what boxes s/b checked, nor how many of the 50+ services in the other
tab I see that I should research. There's quite a few I'm not sure about.

I'm going to delete all references to the "keylogger(?)" in my registry
now, and then run a multitude of security programs - including Multi-AV.

I hope that whatever it is is only in my system partition or registry,
because I have a very large hard drive, and also use a large, multi-
partitioned external drive on occasion.

To scan all those partitions with Multi-AV might take the rest of the
winter - LOL! Usually, these bugs are in the OS directory, registry,
documents and settings, or program files on the main partition.

Similar ThreadsPosted
What kind of malware does this? June 14, 2008, 4:08 pm
Keylogger? June 8, 2006, 11:16 pm
Keylogger resistance May 23, 2006, 2:35 am
Don't want alert re keylogger April 18, 2007, 12:10 am
False Positive on Keylogger??? June 10, 2006, 11:38 am
Keylogger Detection & Removal? February 6, 2008, 4:11 pm
SpySweeper dected Perfect Keylogger. Now what? November 30, 2006, 12:33 pm

The site map in XML format XML site map

Contact Us | Privacy Policy