Results 1 to 9 of 9

Thread: keylogger? trojan?

  1. #1
    Senior Member
    Join Date
    Aug 2005
    Location
    scotland
    Posts
    639
    Thanks
    5
    Thanked
    37 times in 34 posts

    keylogger? trojan?

    A friend asked me to look at their pc as their bank account had twice been illegally accessed and the bank claimed their pc must have a virus on it. They also do online shopping with their credit cards and there has been no rogue activity on their credit cards.

    They have XP fully patched, running up to date mcafee suite, using a firewalled NAT router. A full scan of mcafee finds nothing. Nothing suspicious in msconfig and the firewall program exceptions are as expected.

    I took their hard drive out and put it in one of my systems as a slave. Ran latest versions of avg, spybot, adaware and superantispyware - found 1 tracking cookie. I am at the point where I just don't believe it's some malware/trojan/virus on their pc that has allowed their bank details to be grabbed but their credit card details have been left alone. If I'd found a bunch of virus's and other crap on their pc I'd be thinking it was something on their pc but all the scans found absolutely nothing bar 1 tracking cookie. They say they only use the pc for email, online banking and buying from amazon, they never open emails from people they don't know and looking at their browser history I'd have to agree that they really don't visit many websites and definately none that are remotely dodgy.

    Thoughts?

  2. #2
    NOT Banned
    Join Date
    Jan 2007
    Posts
    5,905
    Thanks
    412
    Thanked
    278 times in 253 posts

    Re: keylogger? trojan?

    I'd do a reinstall and then set up back to how it was, tell them not to run any programs downloaded from the internet or install anything and see how it goes. You can't really catch viruses from emails as it'd have to exploit something in the software which the scanners and firewalls would probably catch. It's running .exe or .scr files which can cause trojans/keyloggers to embed themselves in your system but even those are easily detected by A/V Software.

  3. #3
    Zzzzzzz sleepyhead's Avatar
    Join Date
    Nov 2007
    Posts
    2,514
    Thanks
    373
    Thanked
    292 times in 162 posts

    Re: keylogger? trojan?

    My guess is their log in details have been compromised (depending on HOW it is logged in) or whether they use a wireless router and that has somehow been compromised.

    Can your friend change ANY of the log in requirements, ie change password or unique word or something?

  4. #4
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    385 times in 314 posts

    Re: keylogger? trojan?

    are you sure they havn't been phished ?

    no phones calls from "the bank" ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  5. Received thanks from:

    sleepyhead (18-06-2008)

  6. #5
    Zzzzzzz sleepyhead's Avatar
    Join Date
    Nov 2007
    Posts
    2,514
    Thanks
    373
    Thanked
    292 times in 162 posts

    Re: keylogger? trojan?

    Quote Originally Posted by Moby-Dick View Post
    are you sure they havn't been phished ?

    no phones calls from "the bank" ?
    That was the term I couldn't think of..."phished". Thanks for that.

  7. #6
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: keylogger? trojan?

    If it is a trojan or keylogger, the reason you find nothing suspicious in msconfig or the firewall exceptions list is because the Trojan/Keylogger is more than likely injecting itself into a legit application that requires internet access - Thus you do not see a random application in the exceptions list.

    Get them to run hijackthis - http://www.trendsecure.com/portal/en...kthis/download

    Click "Do a system scan and save log file"
    ***Do not click 'Fix Checked' or delete anything from within Hijackthis!***

    Post the contents of the Log file here and ill analyze it. Usually it pop's up in here otherwise there are many more steps that can be manually taken (higher success rate).

    Also dropping me a PM when you have posted your log file would be helpful.

    As a side note - A complete reformat is advisable in circumstances such as these, although it's always worth giving a removal a shot.

  8. Received thanks from:

    killie99 (18-06-2008)

  9. #7
    Senior Member
    Join Date
    Aug 2005
    Location
    scotland
    Posts
    639
    Thanks
    5
    Thanked
    37 times in 34 posts

    Re: keylogger? trojan?

    Thanks for the replies.
    I'll try "Hijackthis" but they've gone on holiday this morning for 2 weeks so as soon as they get back I'll run it and post the log.

    I suspected phishing but they are adamant they have never told anyone their details over the phone or in an email and I have no reason not to believe them. The fact that I can find nothing at all odd on their pc and their browsing history for the last 20 days has nothing out of the ordinary (no p0rn, or dodgy downloading sites) is the reason I don't think it's anything on their pc as I can't see how some malicious code could have got on there - more likely someone at their bank is at it if you ask me. They have disabled their internet banking for the mean time, which I think is the sensible thing to do.

    The wireless part of their router is disabled so that's not the source either. They live on their own, no kids or other relatives have access to the pc.

    It's not a big job to reload everything, they've only got about 4 programs other than XP on it but it's the not knowing where the problem is that irks me.

    Anyway, thanks for the replies and I'll get back with the hijack log.

  10. #8
    Registered+
    Join Date
    Jun 2008
    Posts
    21
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: keylogger? trojan?


  11. #9
    Senior Member
    Join Date
    Jan 2008
    Location
    Q2DM1
    Posts
    259
    Thanks
    7
    Thanked
    20 times in 20 posts
    • Viper81's system
      • Motherboard:
      • Asus P8Z77-V PRO
      • CPU:
      • Intel i5 3570K
      • Memory:
      • 16Gb Corsair XMS3 1600MHz
      • Storage:
      • Many
      • Graphics card(s):
      • Asus 1Gb 6950
      • PSU:
      • Corsair 650W
      • Case:
      • Antec P182
      • Operating System:
      • Win 7 x64
      • Monitor(s):
      • 25.5" HP W2558HC
      • Internet:
      • Tin Can and String

    Re: keylogger? trojan?

    Just to add to the paranoia .. I'd throw in a root kit check, the sysinternals tool is supposed to be quite good:

    http://technet.microsoft.com/en-us/s.../bb897445.aspx

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Can't kill process. Trojan virus.
    By Jonny in forum Help! Quick Relief From Tech Headaches
    Replies: 4
    Last Post: 16-04-2006, 11:19 AM
  2. ID theft automated using keylogger Trojan
    By Matt1eD in forum General Discussion
    Replies: 10
    Last Post: 09-08-2005, 11:50 PM
  3. Mobile trojan in the wild
    By 0iD in forum Smartphones and Tablets
    Replies: 2
    Last Post: 10-01-2005, 01:33 PM
  4. "Badparty-A" trojan warning
    By Paul Adams in forum Software
    Replies: 3
    Last Post: 17-04-2004, 04:05 PM
  5. A Trojan Horse I Just Can't Get Rid of...
    By pickers in forum Software
    Replies: 3
    Last Post: 12-04-2004, 12:21 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •