Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

vicious spyware - HELP!

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
TheFarseer Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:46 PM
Original message
vicious spyware - HELP!
I have a program showing up in memory called keyplay.exe I sent Spybot S&D after it and it didn't find it. I sent spysweeper after it and it found it but can't remove it. spysweeper says that it is in a folder called "font" but it's not in that folder. When I run a start menu search on it, it doesn't find it. It shows up on processes in task manager using about 15,000-18,000K but you can't shut it down from there. Anyone have any other bright ideas?
Printer Friendly | Permalink |  | Top
Mizmoon Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:48 PM
Response to Original message
1. When it gets too bad, you might have to re-install windows
Sometimes you have too much spyware gumming things up and it just can't be undone.

You can use Firefox instead and just uninstall MSIE. The spyware is written for microsoft products, so not using their products helps a great deal.
Printer Friendly | Permalink |  | Top
 
AverageJoe Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:50 PM
Response to Original message
2. I use ad aware, a free download from lavasoft
It seems to work pretty well, though it wouldn't get rid of spyware from something called "brilliant digital." I ended up having to reformat the hard drive to clean it out. Sheesh.

Anyhow, you might give ad aware a try. Good luck!
Printer Friendly | Permalink |  | Top
 
molly Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:50 PM
Response to Original message
3. It's probably version 5 of Spectorsoft's Eblaster
Edited on Tue Oct-12-04 01:58 PM by molly
http://www.spectorsoft.com/products/eblaster_windows/help/v50/webhelp/activity_report_descriptions/application_summary.htm

Do you know who sent it to you?

on edit......forgot to tell you this.....

Stealth Technology
eBlaster does not show up as an icon, does not appear in the Windows system tray, does not appear in Windows Programs, does not show up in the Windows task list, cannot be uninstalled without the eBlaster password YOU specify, and eBlaster does not slow down the operation of the computer it is recording. eBlaster does not initiate connections to the Internet and will only forward email and send activity reports when the monitored computer is already connected to the Internet.

It is also illegal to install it unless you are an employer or family member. The install file can be named ANYTHING the installer wishes. It must be either an exe or zip file.

Printer Friendly | Permalink |  | Top
 
TheFarseer Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 02:13 PM
Response to Reply #3
12. Sorry for breaking the law!
I assure you it was unintentional. If it's showing up in memory, it's draining resources right? It's not really doing anything bad except that and not allowing me to get rid of it. You seem to know what you are talking about. How am I going to specify a password to get rid of it? Thanks in advance.
Printer Friendly | Permalink |  | Top
 
molly Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 02:21 PM
Response to Reply #12
14. Whoever installed it on your computer needs to give you
the password or phrase and it will uninstall itself. It can be installed remotely, BTW with an exe or zip file - named anything the installer wants to name it - like "iloveu.exe" - you get my drift. Once you've clicked on that file, it will self install on your computer. If you can go back thru your emails and see who sent you that file, you can threaten them - unless it is a wife or husband. If it is your wife or husband, you have problems anyway.

I was having problems and did some research. I am/was a mainframe person - this was not my forte.
Printer Friendly | Permalink |  | Top
 
texas1928 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:51 PM
Response to Original message
4. I use spybot and Ad Aware together.
Run Ad Aware and then when it finishes fix what needs to be fixed then reboot, it will run again by itself and repair things that could not be removed before.
Printer Friendly | Permalink |  | Top
 
TheFarseer Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:57 PM
Response to Reply #4
8. In my experience
spybot S&D and ad aware find the exact same things. Maybe it was just coincidence. Do they find different stuff for you?
Printer Friendly | Permalink |  | Top
 
texas1928 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 02:04 PM
Response to Reply #8
11. Spybot does not fix registery entries like ad aware does.
it does best on a reboot.
Printer Friendly | Permalink |  | Top
 
alvis Donating Member (665 posts) Send PM | Profile | Ignore Tue Oct-12-04 01:54 PM
Response to Original message
5. Try searching your registry for it.
If you feel comfortable changing the registry, try looking for it in there.
Printer Friendly | Permalink |  | Top
 
meegbear Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:54 PM
Response to Original message
6. Did a google search on keyplay.exe
only 1 link came up ... and it's Microsoft.

Keyplay.exe is a sample that inserts a buffer into the hardware key event stream for the purpose of increasing/pacing the key buffering in general. The calls can be used for filtering or injecting new keys.

http://support.microsoft.com/default.aspx?scid=%2Fsupport%2Fddk%2Fwinddk%2FSamples%2Fdefault.asp
Printer Friendly | Permalink |  | Top
 
GoBlue Donating Member (930 posts) Send PM | Profile | Ignore Tue Oct-12-04 01:55 PM
Response to Original message
7. google keyplay.exe
appears to be a microsoft device driver.
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:58 PM
Response to Original message
9. The file is probably hidden which explains why you can't see it
Edited on Tue Oct-12-04 01:58 PM by ET Awful
Spysweeper can't delete it because it's running. I would reboot in safe mode, then run your spysweeper again.
Printer Friendly | Permalink |  | Top
 
TheFarseer Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 02:15 PM
Response to Reply #9
13. How do I boot up in safe mode?
I know it's not hard, I've seen people do it, but never done it myself.
Printer Friendly | Permalink |  | Top
 
WannaJumpMyScooter Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Oct-12-04 01:58 PM
Response to Original message
10. what makes you think it is spyware.... is it accessing the internet
or causing any harm?
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 18th 2024, 08:46 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC