|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
External Spying on my PC
|
Original Message
|
Name: bluesband
Date: September 7, 2003 at 21:30:51 Pacific
Subject: External Spying on my PC OS: Win 2000 CPU/Ram: 1 Mhz/256k
|
Comment: Websites surfed on my computer are being watched by an outsider. I know this because my girlfriend knows with amazing accuracy where I have been surfing. Generally she has no access to my computer but may have had access sometime in the past. I've run Ad-Aware, and Spyware Blaster, and checked the running processes but don't seem to have anything out of the norm running. I don't know if it makes a difference, but I use a cable modem and use a SpyWare Guard firewall. Comments on how outsiders may track websurfing activities and what to do to prevent this witn my new computer?
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: efabes
Date: September 8, 2003 at 10:13:01 Pacific
|
Reply: (edit)Can she connect to you from offsite (and check your history)? She could have your ip address. Maybe she set up your pc for remote access? Download a free firewall (sygate or zone alarm) and configure it not to allow file sharing or remote access. You should have a firewall and updated AV protection with cable internet anyway. Or, have some risky fun. Do NOT install a firewall and start visiting sites concerning wedding planning, wedding rings, expensive vacations, S&M etc.
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: suzi
Date: September 8, 2003 at 21:12:04 Pacific
|
Reply: (edit)You can scan for keyloggers with Spybot Search & Destroy. It may not find all keyloggers but it does target some. Or you can run HijackThis and see everything that's starting on your system. HijackThis! Download, unzip and run the program, copy and paste the log into your reply here.
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name:
Date: September 9, 2003 at 10:44:51 Pacific
|
Reply: (edit)bluesband, "... Generally she has no access to my computer but may have had access sometime in the past ..." With that said, if the computer is running. I could compile you a list of your surfing habits, in less than 30 seconds. With no other software but, what is installed on it. Might be a long list, better make that, one minute :-) efabes, I like your risky fun :-)
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: bluesband
Date: September 10, 2003 at 16:09:29 Pacific
|
Reply: (edit)In the past I was a Match.com member. From there she has employed a firm to track any dating sites I may have subsequently visited. If I so much as go to Yahoo personals she will know. I have a strong suspicion that my yahoo messenger also falls prey to her trap. She claims the trace is done from outside my house with no software installed on my PC. Does anyone understand how such a trace can be accomplished? Perhaps through my static IP address because of the digital cable set-up I use. Thoughts on how to become a stealth surfer?
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: bluesband
Date: September 10, 2003 at 17:54:24 Pacific
|
Reply: (edit)Below is the run from Hijackthis. Comments? Logfile of HijackThis v1.97.0 Scan saved at 5:53:38 PM, on 9/10/2003 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\Program Files\Sygate\SPF\Smc.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\WINNT\System32\svchost.exe C:\PROGRA~1\Iomega\System32\AppServices.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\System32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\Program Files\Iomega\AutoDisk\ADService.exe C:\WINNT\Explorer.EXE C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe C:\PROGRA~1\NORTON~1\navapw32.exe C:\Program Files\Iomega\AutoDisk\ADUserMon.exe C:\Program Files\Iomega\DriveIcons\ImgIcon.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\efax\HotTray.exe C:\Program Files\Common Files\efax\Dllcmd32.exe C:\Program Files\SpywareGuard\sgmain.exe C:\Program Files\SpywareGuard\sgbhp.exe C:\WINNT\System32\svchost.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\CAM Development\CAM UnZip\cuz.exe C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe O1 - Hosts: 217.116.231.7 aimtoday.aol.com O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [SpyCop ScanCheck] C:\Program Files\Spycop\Perl.exe /LASTSCAN O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB O16 - DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8} (Snapfish Fix Photo Control) - http://www.snapfish.com/SnapfishImageEditor.cab O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349} (Pixami/Snapfish Upload UI Control) - http://www.snapfish.com/SnapfishUploader.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37613.8420138889 O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} (IEAnimBehaviorFactory Class) - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab O16 - DPF: {AA59BA6E-B44F-4514-AB3C-0C1DD2306FC3} (MSN Money Charting) - http://fdl.msn.com/public/investor/v12/invinstl.exe O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (Plotwon Control) - http://www.investors.com/member/ocx/plotwon.ocx O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://autos.msn.com/components/ocx/autopricer/autopricer.cab O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
Name: blueberryfreckle
Date: October 18, 2003 at 05:29:30 Pacific
|
Reply: (edit)Hi! ADService.exe and ADUserMon.exe are part of Iomega's Auto Disk feature. They allow software applications to be run directly from an Iomega Zip® disk. They are required if you wish the applications to launch on insertion of a disk. I agree with eecdivad that you need a new girlfriend. As for stealth surfing, try a program that allows you to use anonymous proxy servers. I used MultiProxy previously but it no longer works for me. Of such programs, GetAnonymous 1.2 is highest rated on download.com. But it is not free. Others leave users unsatisfied, including Multiproxy. Search "anonymous proxy".
Report Offensive Follow Up For Removal
|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
|
|
|