Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old May 22nd, 2005, 06:38 AM
Nik's Avatar
Nik Nik is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jun 2003
Location: Thessaloniki
Posts: 760 Nik User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 Days 9 h 23 m 55 sec
Reputation Power: 6
Send a message via Google Talk to Nik
Question Stange Keylogges detected.

I have a dsl modem/router and i have only
enabled port redirection/forwardinf at router's port 80 to the internal
host of mine 10.0.0.1.

I thought it was safe because the only info that could past from my
modem/router to my local pc would be a web page request like
www.nikolas.tk

By running several spyware/virus scans i noticed 3-4 different keyloggers
on my computer for example one was names Keyboard Spectator Pro, another
was names Captain Mnemo etc.

My question is how would one could manage to install all these kind of
spywares/keyloggers to my pc the minute that i have a hardware firewall
and the only port forwarding rule i have enabled is

dsl port 80 => 10.0.0.1 that my web server is running on?

Is it possible to inject some kind of spyware/keylogger through a webpage
request?

Iam using SP@
__________________
What is now proved was once only imagined!

Reply With Quote
  #2  
Old May 22nd, 2005, 08:43 AM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
CAUTION: Loderator Moose
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2004
Location: some starry place (india)
Posts: 3,431 oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 21 h 34 m 19 sec
Reputation Power: 156
Short Answer: Yes. There are plenty of known exploits using port 80 and pages served through port 80. most of them are browser related.

It is in fact possible to install and inject malware through a http webpage. one common route is microsofts activeX which is known entry point for several types of malware. improperly patched IE and windows systems are also susceptible to javascipt based attacks. it all depends on which sites you visit and how safe are your browsing practices. In general you should be very careful what activeX components you allow a website to run on your computer. Browsers are often the target route for spyware/hijackers/adaware/dialers/trjans/virii to get installed onto your system.

please see the following links for more detail on these topics:
Understanding these kind of infections
Keep your computer safe
How do i get infected

You should use your windows hosts file to block dangerous and known-to-be-bad sites. the windows hosts file is located at c:\windows\system32\drivers\etc\ for windows NT based systems (xp,nt,2000,2003). What it does is, basically, tell your browser that any requests for the sites blacklisted in the host file, should be directed bask to the computer (127.0.0.1) itself rather than to the internet, effectively protecting you. you can also add this list to your router, using whatever firmware the router provides you.

Excellent tips from another moderator concerning the use of a hosts file:
Quote:
Originally Posted by Tom Myboy
****************************************************************

IE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

http://www.staff.uiuc.edu/~ehowes/resource.htm#IESPYAD

****************************************************************

MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer

http://mvps.org/winhelp2002/hosts.htm

****************************************************************
All are very small free programs. Occasionally check for updates.

****************************************************************

Check for updates for Windows and Internet Explorer every week or so. Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/

****************************************************************



Stay away from porn and warez sites and you will in general have a trouble free surfing experiance.
Please update IE as far as possible and google around for the changes in the default setting of IE you should make to help keep your system clean.

nearly 90 % of all infections are aimed at IE, so switching to another browser like Mozilla Firefox or Opera or netscape will improve your security. Also these browsers, escpecially Firefox come out with security patches very fast, so your are better protected. I reccomend Firefox.

a good place to review information on all kinds of security issues is here:

www.cert.org

If you do have several keyloggers on your system it is likely that there are other malware programs on your system that have not been detected and continue to exist on your system. please download Hijackthis from the link provided in my signature and post a log in this thread form the experts to go through. they will let you know if you have any malware still on your system. the forum stickies are also a worthy read.

If you desire more information on a particular browser vulnerbility or attack, please dont hesitate to post and ask your questions.. knowledge is power in the long battle against malware
cheers
__________________
Nigel
..Seeking code free nirvana...
Nigel Fernandes Blog
Never argue with fools. They will bring you down to their level and beat you with experience.


Manchester United Forever

Last edited by oneMSBi : May 22nd, 2005 at 08:57 AM.

Reply With Quote
  #3  
Old May 22nd, 2005, 10:03 AM
Nik's Avatar
Nik Nik is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jun 2003
Location: Thessaloniki
Posts: 760 Nik User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 Days 9 h 23 m 55 sec
Reputation Power: 6
Send a message via Google Talk to Nik
Thank you one MSBi for your suggestions.

Actually i ahve sP@ and iam using Firefox v1.0.4 and Apaceh v2.0.45 but i do visit warez sites and downlaod from p2p apps like eMule.

I use SpySweeper v4, i just switched today from Microsoft's Antispyware and the former found 4 more infections threats than the latter.

Whats your suggestion about AntiSpyware Software for XP use?

Also i wonder if someone can deleberately use my webpage url to injext and install keyloggers.

Also before a few days i found this:

http://10.0.0.138/upnp/control/wancic

probably a variant of bAT/KillFiles trojan

10.0.0.38 is my internal router lan ip , the rest i dont know.

can you please explain that to me and how i might be infected with that?

Reply With Quote
  #4  
Old May 22nd, 2005, 10:49 AM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
CAUTION: Loderator Moose
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2004
Location: some starry place (india)
Posts: 3,431 oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 21 h 34 m 19 sec
Reputation Power: 156
there are 3 issues heer which seemed to be getting merged.

First:
If you are running a website and using apache as your webserver, and you are concerned with the secuirty of your website/webserver then the best thing to do is regularily check the pache development site for secuiryt updates, and patches. keep an eye their website for vulnerability announcement. because they are open source, they usually detect and patch weaknesses quite fast. for more details, the apache forum here on devshed is a good place for your queries.
Concerning the ability of a hacker to deface your website, or compromise it in such a way so as to infect the visiters to website, well this is out of my knowledge area to be honest. for a good understanding of such an issue, you should post in the Security Policies forum.

Second:
Concerning your computers security due to threats from the surfing you do, well i would reccomend caution and prudence on your part as an internet user. I'm not a big fan of warez, so if you must use them, please be picky about the sites you use. do not allow them to install anything onto your machine while you are surfing. If you must use p2p, then i would suggest you try shareaza, but the primary danger here is that the very files traded on these networks commonly have trojans or virii embedded in them. certain software like edonkey and kazaa also come bundled with spyware and adware. use them with caution
For antivirus software you can use, well on the freely available side i reccomend AVG (see my sig for a link). this forum's stickies have a few more Antivirus software suites mentioned. AVG should sufice for most of the home users needs. Update them regularily.
For a good freely available firewall, i reccomend ZoneAlarm. its very efficient and effective. the Pro version is paid, and also comes highly reccomended. please update it as often as possible.
Spybot's search and Destroy, Ad-aware, Spyblaster, and Spygaurd are all decent freeware programs you should download and run to help you clean out your system (although they are aimed at IE users). the combination of Zonealarm-AVG-Spybot-Adaware should keep you pretty safe from most internet and browser malware. Its good to see you use firefox. that will greatly help secure your pc.

Third:
I do not anything about that file you mentioned. my googling came up with the same page you probably saw. I strongly suggest you download Hijackthis from the link provided in my signature and post a hijackthis log here, so that we can check and see if you have any more malware on your pc. I will look out for more information on the file you mentioned. maybe another user here on his forum will have more knowledge on that file
cheers

Last edited by oneMSBi : May 22nd, 2005 at 10:52 AM.

Reply With Quote
  #5  
Old May 22nd, 2005, 11:24 AM
LinuxPenguin's Avatar
LinuxPenguin LinuxPenguin is offline
fork while true;
Dev Shed God 1st Plane (5500 - 5999 posts)
 
Join Date: May 2005
Location: England, UK
Posts: 5,535 LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)LinuxPenguin User rank is General (90000 - 100000 Reputation Level)  Folding Points: 11590 Folding Title: Novice Folder
Time spent in forums: 1 Month 3 Weeks 1 Day 19 h 30 m 28 sec
Reputation Power: 1008
If you're running Apache, then I would recommend going back to 1.3.3 as its the most rock solid tested server out there.

For security on top of that, I compiled a complete list of everything you should have to make windows safe.

http://forums.devshed.com/attachmen...tachmentid=7710

Reply With Quote
  #6  
Old May 22nd, 2005, 11:41 AM
Nik's Avatar
Nik Nik is offline
Contributing User
Dev Shed Novice (500 - 999 posts)
 
Join Date: Jun 2003
Location: Thessaloniki
Posts: 760 Nik User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 2 Days 9 h 23 m 55 sec
Reputation Power: 6
Send a message via Google Talk to Nik
Thank you all, actually with spysweeper i have now deleted all the security threats.

Reply With Quote
  #7  
Old May 22nd, 2005, 12:45 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
CAUTION: Loderator Moose
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2004
Location: some starry place (india)
Posts: 3,431 oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 21 h 34 m 19 sec
Reputation Power: 156
i would not rely on individual clean up tools giving you a clean bill of health , as you have experianced first hand the effects of that. (as soon as you tried something other than microsfts antispyware you found all this right ?) i still advise you to post a hijackthis log here, so that we may go over it.
If you do not intend to run hijackthis and if you have no more queries, please post back and let us know. i will then close this thread seing as you seem to have sorted out any questions you had
have a nice day.

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Stange Keylogges detected.


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT