Computing.Net > Forums > Security and Virus > External Spying on my PC

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

External Spying on my PC

Reply to Message Icon

Original Message
Name: bluesband
Date: September 7, 2003 at 21:30:51 Pacific
Subject: External Spying on my PC
OS: Win 2000
CPU/Ram: 1 Mhz/256k
Comment:

Websites surfed on my computer are being watched by an outsider. I know this because my girlfriend knows with amazing accuracy where I have been surfing. Generally she has no access to my computer but may have had access sometime in the past. I've run Ad-Aware, and Spyware Blaster, and checked the running processes but don't seem to have anything out of the norm running. I don't know if it makes a difference, but I use a cable modem and use a SpyWare Guard firewall.

Comments on how outsiders may track websurfing activities and what to do to prevent this witn my new computer?


Report Offensive Message For Removal


Response Number 1
Name: efabes
Date: September 8, 2003 at 10:13:01 Pacific
Reply: (edit)

Can she connect to you from offsite (and check your history)? She could have your ip address. Maybe she set up your pc for remote access?

Download a free firewall (sygate or zone alarm) and configure it not to allow file sharing or remote access. You should have a firewall and updated AV protection with cable internet anyway.

Or, have some risky fun. Do NOT install a firewall and start visiting sites concerning wedding planning, wedding rings, expensive vacations, S&M etc.



Report Offensive Follow Up For Removal

Response Number 2
Name: suzi
Date: September 8, 2003 at 21:12:04 Pacific
Reply: (edit)

You can scan for keyloggers with Spybot Search & Destroy. It may not find all keyloggers but it does target some.

Or you can run HijackThis and see everything that's starting on your system.

HijackThis!

Download, unzip and run the program, copy and paste the log into your reply here.


Report Offensive Follow Up For Removal

Response Number 3
Name:
Date: September 9, 2003 at 10:44:51 Pacific
Reply: (edit)

bluesband,

"... Generally she has no access to my computer but may have had access sometime in the past ..."

With that said, if the computer is running. I could compile you a list of your surfing habits, in less than 30 seconds. With no other software but, what is installed on it. Might be a long list, better make that, one minute :-)

efabes,
I like your risky fun :-)


Report Offensive Follow Up For Removal

Response Number 4
Name: bluesband
Date: September 10, 2003 at 16:09:29 Pacific
Reply: (edit)

In the past I was a Match.com member. From there she has employed a firm to track any dating sites I may have subsequently visited. If I so much as go to Yahoo personals she will know. I have a strong suspicion that my yahoo messenger also falls prey to her trap. She claims the trace is done from outside my house with no software installed on my PC.

Does anyone understand how such a trace can be accomplished? Perhaps through my static IP address because of the digital cable set-up I use.

Thoughts on how to become a stealth surfer?


Report Offensive Follow Up For Removal

Response Number 5
Name: bluesband
Date: September 10, 2003 at 17:54:24 Pacific
Reply: (edit)

Below is the run from Hijackthis. Comments?


Logfile of HijackThis v1.97.0
Scan saved at 5:53:38 PM, on 9/10/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Sygate\SPF\Smc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\efax\HotTray.exe
C:\Program Files\Common Files\efax\Dllcmd32.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\CAM Development\CAM UnZip\cuz.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\HijackThis.exe

O1 - Hosts: 217.116.231.7 aimtoday.aol.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\Smc.exe -startgui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpyCop ScanCheck] C:\Program Files\Spycop\Perl.exe /LASTSCAN
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: eFax.com Tray Menu.lnk = C:\Program Files\Common Files\efax\HotTray.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\Common Files\efax\Dllcmd32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8} (Snapfish Fix Photo Control) - http://www.snapfish.com/SnapfishImageEditor.cab
O16 - DPF: {544EB377-350A-4295-9BEB-EAB8392E09C6} (MSN Money Charting) - http://fdl.msn.com/public/investor/v13/invinstl.exe
O16 - DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349} (Pixami/Snapfish Upload UI Control) - http://www.snapfish.com/SnapfishUploader.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37613.8420138889
O16 - DPF: {A4639D2F-774E-11D3-A490-00C04F6843FB} (IEAnimBehaviorFactory Class) - http://download.microsoft.com/download/vizact2000/Install/10/WIN98Me/EN-US/msorun.cab
O16 - DPF: {AA59BA6E-B44F-4514-AB3C-0C1DD2306FC3} (MSN Money Charting) - http://fdl.msn.com/public/investor/v12/invinstl.exe
O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (Plotwon Control) - http://www.investors.com/member/ocx/plotwon.ocx
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) - http://autos.msn.com/components/ocx/autopricer/autopricer.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/ym/yiebio5_1_6_0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab


Report Offensive Follow Up For Removal


Response Number 6
Name: yeorgos
Date: September 20, 2003 at 11:02:19 Pacific
Reply: (edit)

it is your ADService.exe and ADUserMon.exe


Report Offensive Follow Up For Removal

Response Number 7
Name: eecdivad
Date: October 10, 2003 at 07:00:09 Pacific
Reply: (edit)

Hey Dude. Get a new girlfirend. That one would totally freak me out!!


Report Offensive Follow Up For Removal

Response Number 8
Name: blueberryfreckle
Date: October 18, 2003 at 05:29:30 Pacific
Reply: (edit)

Hi! ADService.exe and ADUserMon.exe are part of Iomega's Auto Disk feature. They allow software applications to be run directly from an Iomega Zip® disk. They are required if you wish the applications to launch on insertion of a disk.

I agree with eecdivad that you need a new girlfriend.

As for stealth surfing, try a program that allows you to use anonymous proxy servers. I used MultiProxy previously but it no longer works for me. Of such programs, GetAnonymous 1.2 is highest rated on download.com. But it is not free. Others leave users unsatisfied, including Multiproxy. Search "anonymous proxy".


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software