[dba-Tech] keylogger ?

John Bartow john at winhaven.net
Sat Jan 1 15:03:06 CST 2005


Mike,
Don't always trust spyware detectors as being 100% correct in refferrring to
software as unwanted/unneeded. I have radmin show up in spyware dtections
quite a bit. It is a remote access program that I installed. (The potential
for abuse is always present with a remote access host of any kind - this is
something one needs to understand and prevent via security settings.) Some
keyloggers are put there on purpose. They are monitors and may be because of
some parental oversight program that keeps tabs on what your computer is
being used for. Do you have any of those installed? I don't know anything
about BlazingTools keylooger but am just advising that you should check into
it before assuming the spyware scan is correct. I recommend disabling it via
the spyware detectors' "quarantine" function or via "msconfig" and then
deleting it when you're sure. Note that some programs can get around
msconfig's methods of disabling (and some get around the spyware detector's
methods too.) You should always rescan after restarting your system.

HTH
John B. 

-----Original Message-----
From: dba-tech-bounces at databaseadvisors.com
[mailto:dba-tech-bounces at databaseadvisors.com] On Behalf Of Mike Tope
Sent: Saturday, January 01, 2005 10:50 AM
To: Discussion of Hardware and Software issues
Subject: [dba-Tech] keylogger ?

List
A couple of times lately I have discovered BlazingTools Perfect KeyLogger on
our family pc.

Windows 98; I have now disabled Internet Explorer (in ZoneAlarm) but it
wasn't in common use before. Anyone know how the keylogger gets in there ?
And how I can stop it ?

Msconfig shows it up as c:\windows\system\bpk.exe in the startup tab. But we
don't startup very often (for Windows98). That's a legacy of a duff power
supply, that taught us not to switch it off in case we can't switch it on
again. (The power supply has gone, but the habit remains.)

So just because the keylogger files are dated two days ago doesn't
necessarily mean it's running. If you go to their website (BlazingTools are
quite open about it - http://www.blazingtools.com/bpk.html) you learn that
it can run completely invisibly so I can't be sure whether it's been
activated or not.

I just ran Ad-Aware and Spybot S&D and neither detected it.

It's a problem because my wife won't do the shopping if she thinks her
credit card number is being logged.

Any hints anyone ?
Mike Tope

_______________________________________________
dba-Tech mailing list
dba-Tech at databaseadvisors.com
http://databaseadvisors.com/mailman/listinfo/dba-tech
Website: http://www.databaseadvisors.com






More information about the dba-Tech mailing list