Results 1 to 21 of 21
  1. #1
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893

    Help. KeyLogger Problem

    When I run SpyWare Detective it tells me I have a Ghost Key Logger in Windows/prefetch/ntvdm.exe-1a10a423.pf

    Ntvdm is the DOS 16bit emulator and should be located in system32 file.

    Do I have a problem or not ?

    I deleted it 2 days ago and it has reappeared today.

  2. #2

    R.I.P.


    dirtydog's Avatar
    Join Date
    Jun 2005
    Last Online
    @
    Location
    Pattaya Jomtien
    Posts
    58,763
    I think you do have a problem, it was probably binded with another program that you downloaded, you then click exe and it sets up the keylogger and the program, you then delete the keylogger but it keeps coming back every time cos it is still binded with another program, all you got to do is find the program it is binded to

  3. #3
    Thailand Expat
    aging one's Avatar
    Join Date
    Nov 2005
    Last Online
    @
    Posts
    22,714
    Quote Originally Posted by dirtydog
    all you got to do is find the program it is binded to
    That does not sound easy at all. Shit how many programs are on a typical computer?

  4. #4

    R.I.P.


    dirtydog's Avatar
    Join Date
    Jun 2005
    Last Online
    @
    Location
    Pattaya Jomtien
    Posts
    58,763
    easiest is to check the sizes of the latest programs downloaded and check they aint 40kb bigger or more than they should be.

  5. #5
    befuddled
    danbo's Avatar
    Join Date
    Jul 2005
    Last Online
    10-08-2008 @ 10:57 PM
    Location
    Hatty Town
    Posts
    3,451
    This is a good site with loads of info and programs.

    http://www.spywareinfo.com/

  6. #6
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893
    OK, I have found it.

    If I run Ntvdm which is a microsoft application and resides in the system32 folder then it installs a keylogger in the prefetch.

    So, what do I do next ?

  7. #7

    R.I.P.


    dirtydog's Avatar
    Join Date
    Jun 2005
    Last Online
    @
    Location
    Pattaya Jomtien
    Posts
    58,763
    open up the program in total commander and delete the keylogger bits.

  8. #8
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893
    I have downloaded and run two other anti-keyloggers and they have found nothing.

    The ntvdm file is 410k.
    There is also another copy of it in service pack2 at 410k

    Can someone check their version and see if it is also 410k

    Thanks

  9. #9

  10. #10
    Khun Marmite
    RDN's Avatar
    Join Date
    Nov 2005
    Last Online
    19-03-2016 @ 06:03 PM
    Location
    ราไวย์, ภูเก็ต
    Posts
    3,165
    Quote Originally Posted by Thetyim
    I have downloaded and run two other anti-keyloggers and they have found nothing.

    The ntvdm file is 410k.
    There is also another copy of it in service pack2 at 410k

    Can someone check their version and see if it is also 410k

    Thanks

  11. #11
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893
    Thanks, RDN.
    Mine is also 419,840 bytes

    So I think my problem is solved now, thanks

  12. #12
    Thailand Expat lom's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    on my way
    Posts
    11,453
    Here for reading Thetyim :

    http://www.spywarewarrior.com/rogue_anti-spyware.htm

    Ad-Aware/Ad-Watch from Lavasoft is the only one I trust.

  13. #13
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893
    Thanks IOM.
    I already have AdAware, but that doesn't spot keyloggers does it ?

  14. #14

    R.I.P.


    dirtydog's Avatar
    Join Date
    Jun 2005
    Last Online
    @
    Location
    Pattaya Jomtien
    Posts
    58,763
    it dont spot binded key loggers

  15. #15
    Thailand Expat lom's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    on my way
    Posts
    11,453
    No, Thetyim but if you read the web site you'll find out that there are houndreds of spyware 'detecting' programs on the market only fooling the user.

    They all find something which isn't there so you can buy their 'removal' program.
    Many of them do a 'Windows security warning' that looks almost like
    Microsofts own popup. Sure you really have a keylogger installed ?

  16. #16
    Thailand Expat lom's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    on my way
    Posts
    11,453
    Btw, this is what Symantec thinks of Spyware Detective

    http://www.symantec.com/avcenter/ven...detective.html
    Last edited by lom; 08-05-2006 at 11:21 PM.

  17. #17
    Thailand Expat lom's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    on my way
    Posts
    11,453

  18. #18
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893
    I don't think that is the same SpyWare Detective as mine.
    Mine is part of Advanced System Optimizer from SysTweak Inc

    I have been running ASO for about a year and it never found a key logger before.
    I have replaced my ntvdm file with a fresh one and everything seems Ok now.

  19. #19
    Khun Marmite
    RDN's Avatar
    Join Date
    Nov 2005
    Last Online
    19-03-2016 @ 06:03 PM
    Location
    ราไวย์, ภูเก็ต
    Posts
    3,165
    Quote Originally Posted by Thetyim
    I don't think that is the same SpyWare Detective as mine.
    Mine is part of Advanced System Optimizer from SysTweak Inc

    I have been running ASO for about a year and it never found a key logger before.
    I have replaced my ntvdm file with a fresh one and everything seems Ok now.
    Is your new NTVDM.exe file the same size as the one you had before - and that I have now?

    I actually DO have a keylogger installed. I installed it. It's called "Keylogger Pro" from Panterasoft. It's quite useful for remembering the last 5 MB I've typed. The current log file goes back to October last year.

  20. #20
    Have you got any cheese Thetyim's Avatar
    Join Date
    Jan 2006
    Last Online
    @
    Location
    Mousehole
    Posts
    20,893
    My NTVDM file is exactly the same size as yours 419840 bytes but is a slighlty smaller size on disk.

    I do not know how big the old one was as I deleted quick.

  21. #21
    Khun Marmite
    RDN's Avatar
    Join Date
    Nov 2005
    Last Online
    19-03-2016 @ 06:03 PM
    Location
    ราไวย์, ภูเก็ต
    Posts
    3,165
    OK, cheers.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •