Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Counterspy said I have SpyKeySpy keylogger on my home PC but...

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
roseBudd Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:22 AM
Original message
Counterspy said I have SpyKeySpy keylogger on my home PC but...
I used a 30 day trial of CounterSpy but never bought. It was still useful because it would sometimes popup with the name of something and I could use Trend Micro Housecall or AdAware or manually remove afer googling the name.

So yesterday it popped up saying I had SpyKeySpy, but being unpaid wouldn't do anthing about it. So I ran TrendMicro Housecall which found nothing. AdAware reported nothing but cookies.

I searched both hardrives for any files with part of SpyKeySpy names including hidden & system, nothing. Searched the registry in RegEdit for

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpyKeySpy
HKEY_LOCAL_MACHINE\SOFTWARE\SoftArtStudio\sks32_11
HKEY_LOCAL_MACHINE\SOFTWARE\UDShellR32
HKEY_LOCAL_MACHINE\SOFTWARE\Wise Solutions\Wise Installation System\Repair\C:\Program Files\sks32\INSTALL.LOG


Nothing. Did CounterSpy lie to me to try to get me to buy?
Printer Friendly | Permalink |  | Top
ancient_nomad Donating Member (474 posts) Send PM | Profile | Ignore Sat Nov-10-07 10:32 AM
Response to Original message
1. Post this in the DU Computer Help and Support Forum....
Here is the link

http://www.democraticunderground.com/discuss/duboard.php?az=show_topics&forum=242


They will be able to help you, they are a great group!

I hope this helps you!
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:34 AM
Response to Original message
2. Likely not.
CounterSpy is considered "best of breed" by a lot of smart folks. I suspect that this was either a false positive or it found something the others don't detect. What is the name of the file it's calling a nasty?
Printer Friendly | Permalink |  | Top
 
roseBudd Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:38 AM
Response to Reply #2
3. It's a keystroke logger called SpyKeySpy...
Here is Symatecs info page

http://www.symantec.com/security_response/writeup.jsp?docid=2005-061314-1331-99&tabid=3

setup_spykeyspy.exe sks32proc.exe sks32serv.dll sks32hdrv.dll

I do download from UseNet & did get some RAR files last week.
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:46 AM
Response to Reply #3
5. All things considered, then...
You likely have a keylogger in there. Get it out. Now. The Russian Business Network is behind most, if not all of this keylogger activity. They are big, bad and have their own huge network infrastructure and they exist to steal your banking data. All of it.

Get that thing out of there and change the passwords on your banking accounts.
Printer Friendly | Permalink |  | Top
 
roseBudd Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 11:09 AM
Response to Reply #5
8. Just opened CounterSpy & it looks like it did quarantine the keylogger
Edited on Sat Nov-10-07 11:21 AM by rosebud57
even though it appeared to be doing nothing without a registration number. So I gues that explains why neither TrendMicro Housecall or my meticulous search turned up any of the known files.

So if CounterSpy unregistered runs every night at 2am and found this logger yesterday, the only event I can attribute this to is DLing 17 Wicked mp3s from alt.binaries.mp3.musicals the night before.
Printer Friendly | Permalink |  | Top
 
PSPS Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:39 AM
Response to Original message
4. It's a commercial product
SpyKeySpy is a commercial 'nanny' product, usually used by a parent to monitor a child's computer activity.

http://www.softartstudio.com/spy/spykeyspy.html

You can manually remove it, likely in safe mode. The files and registry keys associated with it are described here:

http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453094277
Printer Friendly | Permalink |  | Top
 
CountAllVotes Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:51 AM
Response to Original message
6. try switching to Firefox
Edited on Sat Nov-10-07 10:51 AM by CountAllVotes
I did and I had CounterSpy on my PC. I don't have it any longer because I do not need it.

link to download Firefox/Thunderbird: www.mozilla.com


IE really does suck.

:kick:
Printer Friendly | Permalink |  | Top
 
Warpy Donating Member (1000+ posts) Send PM | Profile | Ignore Sat Nov-10-07 10:59 AM
Response to Reply #6
7. Firefox will attract the same kind of malware eventually
as it becomes more popular, so switching isn't a permanent solution.

The best thing to do is keep antivirus and antispyware programs up to date and run them regularly, less often if you're a casual surfer, more often if you download a lot of stuff from iffy sites.

MSIE is a hacker magnet, no doubt about it.
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Sun Nov-11-07 12:42 AM
Response to Reply #7
9. It's ActiveX.
Most of those nasties are pushed onto machines with ActiveX. Firefox doesn't use ActiveX anywhere.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 12:13 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC