Re: Spyware which tracks keystrokes?

From: Dulcie (pasirochma_at_hotmail.com)
Date: 03/24/04


Date: Wed, 24 Mar 2004 14:38:53 -0000


"Susan" <none@this.time> wrote in message
news:1061rklh8i4uoea@corp.supernews.com...
>
> Without installing any software to find it for you, you can probably see
> the running eBlaster executable by doing <ctl-alt-del>.

What would it be called on the 'Close Program' list? Any idea? I don't
know what half the things listed in the <ctl-alt-del> window are, tho some
are obvious.

> Alternately, you can run msinfo32:
> Start>run>(type msinfo32)>enter
> If you are given the choice to choose "Advanced", then do so.
> Expand: "Software Environment" and highlight "Running Tasks".
> Look for the executable here. <

Interesting!

> eBlaster may be a combination of these files:
> rmashlex.dll, nvrcr32.dll, eblaster.exe; msrac32.exe, ebsetup.exe,

I guess an ordinary search would dig those out then...

> it also creates these registry keys:
>
> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
> ShellServiceObjectDelayLoad\XmLdrKLocation =
> {0C887F38-5178-43DA-B9F0-B856141FCDA4}

>snip>

How do I find registry keys?

Many thanks Susan - I appreciate all that info :o)



Relevant Pages

  • RE: SMS 2.0 Client not installing
    ... client and you should be fine. ... | Most of the computers are installing the SMS client without any problems ... | CClientSiteCfgArray - Registry key found for site XXX $$<Tue Aug ...
    (microsoft.public.sms.admin)
  • Re: Generic Host Process for Win32 Services crashing
    ... turn off System Restore before running the virus checkers. ... >>> Registry keys) did not work; I have updated them on this and am ... >>> could be installing Service Pack 2. ...
    (microsoft.public.windowsxp.general)
  • Re: Regedit Wont Open
    ... installing this program: ... > you to delete or edit registry keys and so forth, ... You will see the download link for Reghance ... >> It worked fine up until recently but now it doesn't work anymore. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: naive bind question
    ... I'm working through an old-ish book on web programming. ... pages of instructions on installing and running bind8 for use on a ... I looked at dig and also nslookup. ...
    (Debian-User)
  • Re: Recommended Updates for SBS2003
    ... I agree (everyone knowing Susan here)! ... For your second question, you're better off installing ... > patches at once so that if something goes wrong, ... > but it really is high praise for her dedication to the security of the SBS ...
    (microsoft.public.windows.server.sbs)