Re: Spyware which tracks keystrokes?

From: Susan (none_at_this.time)
Date: 03/24/04


Date: Tue, 23 Mar 2004 20:32:18 -0500

On Tue, 23 Mar 2004 11:26:18 -0500, dulcie wrote:

> Have just read an unnerving article about something called 'EBlaster'
> which is sold at http://www.spectorsoft.com/ this program can be loaded
> onto your computer and can track all your keystrokes: all your emails
> from any email address, incoming and outgoing + send a copy of it all to
> another person. Presumeably that would include passwords too! Someone
> would have to get this software onto your machine in the first place,
> but that's not difficult if they have physical access to it - and
> (apparently) it's undetectable - if you look in your files/programs list
> you won't find it. does anyone know how you might (a) prevent this
> being put on the first place, and (b)detect it if it's already there?
> I've now been totally put off setting up an internet bank account!
>
> Thanks.
> Dulcie

Without installing any software to find it for you, you can probably see
the running eBlaster executable by doing <ctl-alt-del>. While it is a goal
of any virus/trojan author to elude detection here, a commercial program
like eBlaster should be listed.
 
Alternately, you can run msinfo32:
Start>run>(type msinfo32)>enter
If you are given the choice to choose "Advanced", then do so.
Expand: "Software Environment" and highlight "Running Tasks".
Look for the executable here.

If you want someone else's program to look for it, and clean it if
necessary, then consider Bazooka Adware and Spyware Scanner (free).
 
http://www.kephyr.com/spywarescanner/index.html
 

Technical:
 
eBlaster may be a combination of these files:
     rmashlex.dll, nvrcr32.dll, eblaster.exe; msrac32.exe, ebsetup.exe,
 
it also creates these registry keys:
 
      HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
       ShellServiceObjectDelayLoad\XmLdrKLocation =
        {0C887F38-5178-43DA-B9F0-B856141FCDA4}
 
      HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\
        {6A6A1EAE-13E1-4DC7-8014-B7677EF6D47A}

      HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\
        {0C887F38-5178-43DA-B9F0-B856141FCDA4}

      HKEY_LOCAL_MACHINE\Software\CLASSES\CLSID\
        {2BE166ED-F16C-46DE-B623-3575FD985D6D}

-- Susan
  sazy



Relevant Pages

  • Re: Sending & Receiving Error - Outlook 2002
    ... I authenticate both outgoing and incoming mail servers. ... on "larger" emails. ...
    (microsoft.public.outlook)
  • Re: Email getting stuck in Outbox
    ... > McAfee Personal Firewall plus installed on my Dell XP. ... > Looking for assistance as my emails with pic's and normal ... particularly the outgoing mail. ... and can lead to problems if the interaction with Outlook and the AV program ...
    (microsoft.public.outlook)
  • A few questions
    ... I have all the emails (outgoing and incoming) from a certain account in ... Sorry for being picky but the indent space of the thread is to small. ...
    (microsoft.public.outlook)
  • Re: Delegate
    ... You could use an outgoing rule (Tools>Rules, "Outgoing" tab). ... give us any details about the way you proceed to reply your boss's emails. ... Do you actually use his email account for that? ...
    (microsoft.public.mac.office.entourage)
  • Re: [SLE] rejected email to list
    ... On Wednesday 29 June 2005 12:14 pm, Art Fore wrote: ... > Why do some emails go through and others not with no change in outgoing ...
    (SuSE)