{"id":2498,"date":"2008-12-09T12:56:39","date_gmt":"2008-12-09T19:56:39","guid":{"rendered":"http:\/\/lee.org\/blog\/?p=2498"},"modified":"2008-12-09T13:03:14","modified_gmt":"2008-12-09T20:03:14","slug":"fing-keyloggers","status":"publish","type":"post","link":"https:\/\/www.lee.org\/blog\/2008\/12\/09\/fing-keyloggers\/","title":{"rendered":"F&#8217;ing Keyloggers"},"content":{"rendered":"<p>I still don&#8217;t know how but I got a keylogger malware on my computer. Apparently I&#8217;ve had &#8220;HellzLittleSpy&#8221; on my computer for maybe 2 weeks. Grr! So I&#8217;m off to change all my passwords and crap. Maybe I&#8217;ll still have to reinstall Windows too.<\/p>\n<p>I noticed that every evening around 7 or 8pm my computer got wonky. iexplore.exe would start and consume a lot of CPU (20-80%) for minutes at a time. I couldn&#8217;t &#8220;kill\/end process&#8221; iexplore.exe but I could &#8220;end process tree&#8221; it. But it would restart in a few seconds.<\/p>\n<p>Then my computer talked to me. A couple nights ago it said something in Japanese with an announcers voice. Last night there was a 5 second clip that sounded like a porn movie. First a few seconds of modern but cheesy &#8220;ba dum dum dum&#8221; on a Casio and then some &#8220;Oo, ahh!&#8221; noises. I went away from my computer for a few minutes last night and this website was showing in my browser: <a href=\"http:\/\/sms.7988.net\/goto?q=qm&#038;company=9ying&#038;9vuid=53662\">http:\/\/sms.7988.net\/goto?q=qm&#038;company=9ying&#038;9vuid=53662<\/a><\/p>\n<p>To test a theory, I uninstalled Vuze\/Azureus last night and my computer flipped out. Now I can only boot in safe mode. I ran Spybot in safe mode and it found HellzLittleSpy. I had previously run Spybot but it hadn&#8217;t detected the malware.<\/p>\n<p><strong>Update<\/strong>: Spybot also found the following that is a keylogger. :-(<\/p>\n<p>{F03BDE84-4DB2-4DAB-B350-B07E6B918021} ()<br \/>\n          location: HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\<br \/>\n          BHO name:<br \/>\n        CLSID name:<br \/>\n              Path: C:\\Program Files\\Internet Explorer\\<br \/>\n         Long name:       JvtnNt64.987<br \/>\n        Short name:<br \/>\n    Date (created): 12\/9\/2008 8:54:18 AM<br \/>\nDate (last access): 12\/9\/2008 11:01:10 AM<br \/>\n Date (last write): 12\/9\/2008 8:54:18 AM<br \/>\n          Filesize:              49789<br \/>\n        Attributes: hidden sysfile archive<br \/>\n               MD5: 8D596C51291946C6D0AFAB926C21F801<br \/>\n             CRC32:           02B3C9BE<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I still don&#8217;t know how but I got a keylogger malware on my computer. Apparently I&#8217;ve had &#8220;HellzLittleSpy&#8221; on my computer for maybe 2 weeks. Grr! So I&#8217;m off to change all my passwords and crap. Maybe I&#8217;ll still have to reinstall Windows too. I noticed that every evening around 7 or 8pm my computer [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-2498","post","type-post","status-publish","format-standard","hentry","category-geekery"],"_links":{"self":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts\/2498","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/comments?post=2498"}],"version-history":[{"count":0,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/posts\/2498\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/media?parent=2498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/categories?post=2498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lee.org\/blog\/wp-json\/wp\/v2\/tags?post=2498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}