PDA

View Full Version : Possible Keylogger


j4cks0ne23
10-03-2007, 03:18 AM
I'm worried that I might have a possible keylogger of some sort on my computer. I recently had one of my accounts stolen (Steam Account)...it's not 100% sure yet, but I'm pretty sure a program either stole my password, or some random person somehow guessed my username and password...which I think is unlikely.

I've run BitDefender scans and it's come up with nothing major, just adware and some cookies.

I've heard of people using HijackThis and posting up a process log, so if anyone could take a look at it, I'd appreciate it.

Logfile of HijackThis v1.99.1
Scan saved at 10:20:25 PM, on 10/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
J:\WINDOWS\System32\smss.exe
J:\WINDOWS\system32\winlogon.exe
J:\WINDOWS\system32\services.exe
J:\WINDOWS\system32\lsass.exe
J:\WINDOWS\system32\svchost.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\system32\spoolsv.exe
J:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
J:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
J:\WINDOWS\System32\nvsvc32.exe
J:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
J:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
J:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
J:\WINDOWS\System32\svchost.exe
J:\WINDOWS\Explorer.EXE
J:\PROGRA~1\MOZILL~1\FIREFOX.EXE
J:\WINDOWS\system32\RUNDLL32.EXE
J:\WINDOWS\system32\RunDll32.exe
J:\WINDOWS\Dit.exe
J:\Program Files\iTunes\iTunesHelper.exe
J:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
J:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
J:\WINDOWS\System32\svchost.exe
J:\Program Files\iPod\bin\iPodService.exe
J:\Program Files\uTorrent\uTorrent.exe
J:\WINDOWS\system32\fscagent.exe
J:\WINDOWS\system32\wuauclt.exe
J:\Documents and Settings\David Hwang\Desktop\hijackthis_sfx.exe
J:\Documents and Settings\David Hwang\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - J:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - J:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - J:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - J:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Ask Toolbar BHO - {F4D76F01-7896-458a-890F-E1F05C46069F} - J:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL (file missing)
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - J:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
O3 - Toolbar: Ask Toolbar - {F4D76F09-7896-458a-890F-E1F05C46069F} - J:\Program Files\AskPBar\bar\1.bin\ASKPBAR.DLL (file missing)
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - J:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE J:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE J:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] J:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "J:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "J:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "J:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [BDAgent] "J:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "J:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKCU\..\Run: [MSMSGS] "J:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - Global Startup: Microsoft Office.lnk = J:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Download Link Using Mega Manager... - J:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://J:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - J:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - J:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - J:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - J:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - J:\Program Files\Messenger\msmsgs.exe
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - J:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - J:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - J:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - J:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - J:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - J:\WINDOWS\System32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - J:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - J:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)


Also, it's probably important to note that the programs fscagent.exe is apart of clubbox, which I use to download videos. I know that this program is safe, because I've had it for over 2 years, and never had a problem.

brianhonaker
10-04-2007, 02:34 PM
There is nothing in the log that would indicate a keylogger. That doesn't mean that it isn't there, but it certainly doesn't look like it. By the way, if someone was running a packet sniffer remotely, you would never know it. (Most passwords are send over an IPSec tunnel, which would make me think that someone capturing your password is unlikely.)

j4cks0ne23
10-06-2007, 09:43 AM
oh, ok, thanks. but i have another question/issue.

i'm not completely sure if it's a windows malfunction, or maybe a virus that's on my computer, but at certain times, i can't double-click any desktop icons. and i know that this has nothing to do with my mouse, or any of those features, because i'll be able to do everything normally for a short while, then suddenly, out of the blue, none of my desktop icons work. none of the icons in the taskbar work either, such as minimize, or any shortcuts there. is this a microsoft glitch or a virus/adware/spyware issue?

currently i run Avira Premium Security Suite, and Ad-Aware 2007 Professional, and none of them have found any sort of trojan or anything.

one other thing that could potentially be the problem might be because of my AV program. i had to reinstall Avira after BitDefender was having issues w/ my pc. could my current AV program be causing some of these random glitches?

i'm really hoping i don't have to reformat and re-install windows, cuz that's just a pain.