"ghost" is typing on my XP machine

From: Mickey Perlstein (pitronot@msn.com)
Date: 07/03/02


From: "Mickey Perlstein" <pitronot@msn.com>
Date: Wed, 3 Jul 2002 13:04:43 -0700


>-----Original Message-----
>On a regular basis somebody or some program is sending
>keystrokes to my machine. Whatever is being sent doesn't
>make sense. it is stuff like "they may be a man of the
>two". Before the characters appear a few underlined dots
>show up then the words replace the underlined dots.
>I've enabled the firewall option that my Network card has
>but that didn't help. I have Windows XP Professional
>installed. Windows Messenger is installed but the typing
>occurs even when Messenger is not running. Any ideas on
>how to fix this would be very appreciated.
>.

First I'd like to say "THAT'S HILLERIOUS!!!" really wierd.

Now to investigate:

we need to isolate the problem.

As I understand it here are two complainers:
Fabian, and JO.

First we remote the hacker part:

When this happens, immediately pull the plug out of the
wall (if modem, pull out of rj11 jack if LAN)
If the problem persists, there is no hacker (at least no
back door)

If no hacker (BackDoor) step 2:

Run msconfig (Start - Run.. MSCONFIG )

STARTUP tab
-----------
remove all the processes you don't recognize, and even
remove some you do (uncheck them)

SERVICES tab
------------
click, HIDE ALL MICROSOFT SERVICES Uncheck all Services
you don't recognize

WIN.INI Tab
-----------
check if you have a load or boot section , clear it too
(you need to click on the (+) sign to open the options.

SYSTEM.INI
----------
Same as WIN.INI

Goto the START - PROGRAMS - STARTUP
------------------------------------

Check all the files there
Files can be located be right clicking the file and
clicking properties, then Read the file location.

If you don't know it. it might be bad.

**** Write down all you changed, at least where if not
what.

Run the PC for a few days like this in our private
little "debug/diagnostic mode"

If problem doesn't persist, you are looking for one of the
services/files in your PC, that you contracted (what is
known as a trojan hourse.)

A program that claims to do one thing and actually does
another.

It is very simple to create the program you speak of, and
it isn't mallicious so No AntiVirus Program would detect
it, as it does nothing to the system.

Well I hop this helps.

If it doesn't Email me, it might be a bigger, more indepth
problem.

I would like to know:
pitronot@msn.com
Mickey Perlstein
Microsoft Certified Systems Administrator for Windows 2000



Relevant Pages

  • Re: Cant connect to the internet
    ... In the Startup tab, ... I ran the Network Diagnostics on the laptop. ...
    (microsoft.public.windowsxp.network_web)
  • Re: MSCONFIG and Startup
    ... > all the cryptic programs that are in the Startup tab in ... > There's also a services tab that I'd like to get figured ... The different tabs in MSCONFIG refer to where in the computer the programs ... from the registry keys that control ...
    (microsoft.public.windowsxp.security_admin)
  • RE: 2000 professional - Not logging in
    ... Copy msconfig from a windows xp or windows 2003 machine and run it on this ... Go to the startup tab and disable all the third party startup items. ... Try disabling the related services ...
    (microsoft.public.win2000.general)
  • Re: Shell Icon Hidden Window...what is this?
    ... Do you have MusicMatch Jukebox installed? ... Click on the Startup tab and click in the checkbox ... In addition, when you use the msconfig utility, you receive a message after ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: XP Sys Restore doesnt work
    ... Sounds like this hacker has corrupted some sys files. ... try this start run type in sfc /scannow ... > I cant do that because its Tab is disappeared from ... >computer properties. ...
    (microsoft.public.windowsxp.general)