mapsedge: Me at Stone Bridge Coffee House (Default)
[personal profile] mapsedge
There's a story here, I'll try to sum up quickly:

A friend of ours recently committed suicide, leaving a wife and five year old daughter. As a part of his decline to that act, he went through a paranoid stage and installed a keylogger called (we think) Spectre on his wife's computer. Now that she is a single mom, she needs to work from home but the software interferes with the functioning of her scanner, network connection, fax, etc.

I have Googled and Bing'd till I'm blue in the fingers, but the two reputable guides I found for removing it (websites that didn't just try to sell me more software) didn't do me any good. The registry keys and dll files they suggested weren't there, but when I hit the login access keys (ALT+CTRL+SHIFT+S), the login screen came up, so I KNOW it's there.

I've installed a HOSTS file with a suspected domain shit-canned.

I've installed WinPatrol, but it doesn't list any processes or startup entries that look suspicious.

I've installed and run SuperAntiSpyware, but it found nothing.

Question: Is there a freeware tool for Windows that allows me to identify a window - the login screen, for instance - and identify its parent process?

Question: Is there a freeware tool for Windows XP that monitors and logs outgoing TCP/IP traffic? This software phones home periodically with screenshots and captured data, so there is definitely outgoing traffic. I need, at the very least, to kill those packets.

Question: any other helpful advice?

Worse come to worst, I can slam the harddrive and reinstall the OS, assuming she can find her original install disc. I've got a "borrowed" copy of XP, but no idea if it actually works or not, or if it does if she'd be able to get security updates, etc.

Date: 2009-12-11 04:51 (UTC)
From: [identity profile] thebruce.livejournal.com
I'm assuming you did try the obvious, control panel-add/remove software and it didn't show up. Try changing his password and logging in as him and see if there's something there. Otherwise try logging in as him and check the startup folder for all users for a hidden file.

The malware removal tool du jour is "Malwarebytes". You may have luck there. It has worked minor miracles.

If the license key is available, then a re-install and a quick call to Microsoft to activate (tell 'em you're re-installing) will clear that issue up, probably with less time and fuss than anything else. Good luck.

Date: 2009-12-11 05:05 (UTC)
ext_167746: Slice of the City (Default)
From: [identity profile] theslice.livejournal.com
Question: Is there a freeware tool for Windows that allows me to identify a window - the login screen, for instance - and identify its parent process?

How about WinID available at http://www.softpedia.com/get/Programming/Debuggers-Decompilers-Dissasemblers/WinID.shtml

or if you have Visual Studio available to install, Spy++ is good.

Question: Is there a freeware tool for Windows XP that monitors and logs outgoing TCP/IP traffic? This software phones home periodically with screenshots and captured data, so there is definitely outgoing traffic. I need, at the very least, to kill those packets.

I like WireShark (http://www.wireshark.org/download.html) because of its nifty color-coded output AND it's multi-platform!

Question: any other helpful advice?

Also, might want to try RootKit Revealer (http://technet.microsoft.com/en-us/sysinternals/bb897445.aspx) and/or HijackThis (http://free.antivirus.com/hijackthis/) which sniff out keylogger-type things.
Edited Date: 2009-12-11 05:06 (UTC)

Date: 2009-12-11 05:09 (UTC)
From: [identity profile] akaashben.livejournal.com
Ya, what they said up there... :-)

Date: 2009-12-11 05:11 (UTC)
From: [identity profile] joegoda.livejournal.com
Did you happen to pull up this in your search?
http://www.kephyr.com/spywarescanner/library/spector/index.phtml

For process viewers, I tend to like this one:
http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

It's ProcessViewer, and I've been a loyal fan since I before Windows 5 (2000) came on the scene.

Date: 2009-12-11 15:03 (UTC)
From: [identity profile] sablessam.livejournal.com
From Donnie's tech guys at the hospital:
download CCleaner or aka crapcleaner from internet.
Get into the computer in "Safe Mode" and work from there.
If your friend installed Spectre as the administrator,
getting in thru safe mode will let you get around.

Date: 2009-12-11 17:35 (UTC)
From: [identity profile] jehosefatz.livejournal.com
For traffic monitoring and packet interrogation, I'd recommend Ethereal. There's an installation caveat for XP, and I don't remember what it is, but it is tremendously good.

-J

June 2023

S M T W T F S
    123
45678910
11121314151617
1819 2021222324
252627282930 

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 19th, 2025 17:54
Powered by Dreamwidth Studios