Help - Search - Members - Calendar
Full Version: 007 Keylogger, is this true?
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
forluvish
Help me pelase I have got very strange problem regarding keylogging spyware.

One day t scanned my PC using Spyware Doctor (hereafter, SD), found 12 dangerous registry values, 4 are related to "007 keylogger" and the other 8 are related to "Virtual bounce". Tried to remove those registries on SD. As soon as I deleted the registry, my PC request me to provide Windows 2003 install CD to replace TAPICFG.EXE etc. So I prodived the CD and end the SD. Reboot my system and give one more scan, then again the same result, 12 dangeorus registry values discovered exactly the same I deleted just before.

Next time, I deleted the entire registry line one by one by my hand. Ala!...Scaning after reboot shows the same result again!!.

I tried to scan my PC using several different spyware program, Spy sweeper, Spy aware, Petpatrol, etc. as well as several Anti Virus program, including Kaspersky, SAV, RAV, F-Prot. None of them found the problem and any other suspicious thing in my system, but still SD reports me there IS keylogging related registry in my system.

PS: I can not find any suspicious program running on my system. checked with window default taks manager as well as security task manager program.

Anyway,
here is the registry SD reported as 007 keylogging related registry value. Please see the registry and give me your idea, any idea will be appreciated.

My OS is Windows 2003 Standard.

--------------------------

[HKEY_CLASSES_ROOT\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}]

[HKEY_CLASSES_ROOT\InetCtls.Inet.1\CLSID]

[HKEY_CLASSES_ROOT\InetCtls.Inet\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{48E59293-9880-11CF-9754-00AA00C00908}]


[HKEY_CLASSES_ROOT\Interface\{48E59291-9880-11CF-9754-00AA00C00908}]
@="IInet"

[HKEY_CLASSES_ROOT\Interface\{48E59291-9880-11CF-9754-00AA00C00908}\ProxyStubClsid]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{48E59291-9880-11CF-9754-00AA00C00908}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_CLASSES_ROOT\Interface\{48E59291-9880-11CF-9754-00AA00C00908}\TypeLib]
@="{48E59290-9880-11CF-9754-00AA00C00908}"
"Version"="1.0"


[HKEY_CLASSES_ROOT\CLSID\{48E59293-9880-11CF-9754-00AA00C00908}\TypeLib]

[HKEY_CLASSES_ROOT\Interface\{48E59291-9880-11CF-9754-00AA00C00908}\TypeLib]

[HKEY_CLASSES_ROOT\Interface\{48E59292-9880-11CF-9754-00AA00C00908}\TypeLib]

[HKEY_CLASSES_ROOT\TypeLib\{48E59290-9880-11CF-9754-00AA00C00908}]
LoPhatPhuud
Download *Hijack This!* (current version is 198.2)
http://www.computercops.biz/downloads-file-328.html
http://www.tomcoyote.org/hjt/

Unzip to a folder other than your Desktop or the Temp folder. Then, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that and copy & paste its contents here.

Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the contents of the scan results.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.