Discussion started by equinox, Feb 4, 2008.

  equinox

    equinox

    Feb 4, 2008
    Hello all,

    I hope this is the correct place to post this message & the correct "Forum" for my security concerns.

    My apologies in advance if this is not the right place.
    My apologies in advance for the length of this post.

    I have suspicions that my PC has some type of spyware on it.
    Not the kind that is obtained by visiting some website, but rather
    the kind that is commercially purchased like the following:
    PC Pandora
    I Spy Now
    Spector Pro
    Remote Logger

    The type of software a person would purchase to monitor the husband or wife if they suspected them of cheating etc, or an employer who has suspicions of a worker.

    From the reading that I have done, it is my understanding that this type of software will not be picked up by antivirus programs and programs such as spybot, ad-aware etc.

    This is because these are commercially purchased programs rather than rouge spyware - browser hijackers etc. And the anti-virus software does not look for it.

    I have all of the above and nothing ever comes up other than routine cookies etc. Scanning with these programs never seems to eliminate my PC's behavior.

    My system is:
    Win 2000 Pro (Updated regularly)
    McAfee Antivirus (provided via Comcast) updated daily - installed since Comcast first offered it.
    Spybot (Updated with each run) – Installed since PC built
    Ad-Aware (Updated with each run) - Installed since PC built
    Outlook express - email

    My symptoms are as follows:

    Symptoms began 3 months ago (around the time I received an email with a resume (MS Word Doc) from an “at the time” trusted person.

    Outgoing email now takes excessive time to "send" just a simple text email, whereas before it did not take this long,
    The same is true for receiving.

    Out of the blue - when I am using the PC or not (more often not) the hard drive goes into a massive data access activity. The only thing that stops this is unplugging the Ethernet cable. It is not McAfee related or around the times of scheduled McAfee tasks.

    As of late - at random websites are completely unavailable – specifically when I am searching how to check for / remove spyware. (I get 404 errors when clicking on Google links)
    My other PC can access these sites fine when this system cannot.

    On 5 occasions, when away from the PC, I have walked into the room and witnessed applications opening / closing on their own. The mouse was NOT moving on it’s own.

    General sluggish behavior that cannot be fixed by all of the methods I have used with success in the past.

    Where to go from here?

    It seems that most “Security Fourms” are related to browser hijackers and other spyware.
    I have not been able to easily find a fourm that deals with commercial spy, remote monitoring, types of software how to detect & find it, how to remove it, how to track it.

    Is this the correct place to ask for assistance?
    If not, could someone point me in the right direction?

    Questions that I have:

    If my suspicions are correct and my system is remotely being monitored,
    Can I find out where the monitoring is taking place? Or by whom? Or who installed it?
    Some require access to a PC, others it seems can be installed remotely.
    Can this type of software infect or remotely be placed upon all of the computers on my network? (Currently just the 2)

    Can the software be remotely removed so that no trace is left of its presence, or the fact that it was even there?

    Is this fixable? If so, how and where do I start?

    My goal is to obviously find if my suspicions are correct, if so, I need to find
    Who did this as well.

    I still have the original email.

    And yes, the person that sent me the email with the resume, is of concern now, they were not at the time.

    I can explain privately, but if my suspicions are real, I would rather not give my knowledge away by posting the circumstances online.

    I have found this thread on your forum that seems to be close. Is this the right direction?

    https://www.wilderssecurity.com/showthread.php?t=47446&highlight=comercial spyware

    If this is the correct place to start, please let me know what to do from here.
    If not – my apologies, and maybe a pointer in the right direction?

    Thank you in advance,
  Bubba

    Bubba

    Apr 15, 2002
    The malware cleaning forums listed in the below quote which is from this Announcement thread, are all versed in recognizing not only malware but even those programs some refer to as "potentially unwanted applications", keyloggers, surveillance software, etc. Having said that, I would suggest picking one of those sites and posting their reuqired info. Understand that whichever one you choose might not be able to offer immediate assistance due to the enormous workload those volunteers face each and every day. Staying with one and not posting it other sites will be a benefit also since most of the malware cleaning sites have volunteers that visit numerous sites to assist.

