Beware of Key Logger residing on your Flash Drive
Last Sunday, I was forced to use the computer of one of the computer café (Iantech Cafe) here in Maasin City because Reems Cafe was closed. And I found out that the computers were installed with Key Loggers.
Well. We all know that Key Logger is a program designed to record which keys are pressed. It can be a legitimate program used by the cafe administrator as surveillance but most of the times it’s malicious one.
Checked the Flash Drive
Since all computers of that cafe including their cafe timer were installed by this, so I withdrawn from using the computer and went home to check my flash drive for possible infection. My accounts on different blogs will be compromised if I will continue using a computer installed with key loggers.
And here’s the result:
(1) Bootex.Log
I found a hidden file on the root directory of the flash drive with filename: BOOTEX.LOG. When I open the log file it contains this message: “Checking File system on E: One of your disks needs to be checked for consistency. You may cancel the disk check but it is strongly recommended that you continue. Windows will now check the disk. …”
There’s no wonder why the bootex.log contains this message because normally, the bootex.log is a log file written when the scandisk run. The only question is: why is it that bootex.log is saved on my flash drive when in fact I don’t run scandisk to check the flash drive nor the Windows automatically check the flash drive for error using the scandisk command?
(2) Recycler folder
I found a hidden directory with directory name: RECYCLER. The folder “Recycler” is hidden and can be viewed when browsing it using the Windows Explorer. To view it, you must use the DOS Prompt and use the “dir /a” command.
FYI, the folder called Recycler is a windows folder which is associated to the Recycle Bin. Each of the Windows XP user has assigned folder on the Recycler folder. Once the Recycle Bin of one of the users is emptied, the folder in the Recycler which is assigned to that user will be emptied too.
Now, if you emptied all of the Recycle Bin of all the accounts in your Windows XP, but the Recycler is not being emptied, then it only means that your Windows XP is infected by any malware.
(3) INFO.EXE
Inside the folder “Recycler” INFO.EXE is saved there. This file is not a legitimate file of the Windows XP. Usually, it is used by worms, virus, or any malware in activating themselves.
Thus, this finding warns me that the Key Loggers I found on those computers are malicious Key Loggers.
(4) DESKTOP.INI
The DESKTOP.INI file is the 2nd file inside the folder “Recycler”. It contains this registry command: [.ShellClassInfo] CLSID= <645ff040-5081-101b-9f08-00aa002f954e>
How to detect these files?
Just like what I said above, these files can’t be viewed when using the Windows Explorer even if you set its option to view hidden files. You can only view it when you’re at the DOS prompt.
Here’s what to do:
- Click START then click RUN. And type on the dialogue box “COMMAND” and then click OK.
- Then a window with black background will appear. At the command prompt (here in my computer it says: “C:\Docume~1\Reems6>“) type E: (E: if your flash drive is assigned as drive E:. If it is assigned as drive D: then type D: on the command prompt) and then press the ENTER key. Then the command prompt will now be “E:\>“.
- Then type “dir /a” and press the ENTER key. The content of your flash drive will now appear similar to what appeared here:
- Check for the files and folder I mentioned above. If your flash drive contains those files and folder, then that flash drive is already infected by Key Logger.
Note about Key Loggers
Remember that Key Loggers will record what keys are pressed, and then the data will be send to the remote servers. In other words, your passwords might be collected by this program and then send them to someone who has access to the remote servers. Thus, your accounts might be compromised.
Similar posts:
- How To Remove Worm@W32.Resik From Your PC and Flash Drive
- How to View the Hidden Files of Worm@W32.Resik Worm?
- How To Delete the Hidden Files of the Resik Worm?
-
Sign up for PayPal and start accepting credit card payments instantly.
As the world's number one online payment service, PayPal is the fastest way to open your doors to over 150 million member accounts worldwide. -
Promote your product to high quality, targeted websites and blogs.
Find effective, influential blogs and highly targeted audiences to advertise.Choose to display your ad across entire blog networks to maximize your exposure to a wide audience.
Related Post
- Pinay Scandal
- How To Remove Worm@W32.Resik From Your PC and Flash Drive
- Are You an IM User? Beware of An Spyware Spying You!
- How To Delete the Hidden Files of the Resik Worm?
- How to View the Hidden Files of Worm@W32.Resik Worm?
- Make PhP10,000 Online By Making Proudly Pinoy Logo
- Naruto Anime Episode 186
- Interlock Prevent Drunk to Drive Car
- Ohh My… It’s Down!
- Digg Members Revolted
- What is SEO?
- Hey DAVE! What’s DAVE?
- Nokia N70 3G Phone
- Blogging Time Management
- Banner Management
- The Nokia 5610 XpressMusic for Pinoy
- www.sss.gov.ph static information
- sss gov.ph SSS Online Inquiry
Recently Commented
- Krista Ranillo - Manny Pacquiao Scandal
- Angel Locsin
- October 2009 New Teachers Oath Taking, Other Issues
- SSS Disability Benefits
- SSS Sickness Benefits
- AdMob To Join Google
- How to Avail SSS Maternity Benefits?
- Podcasting: What's this?
- Manny Pacquiao Wins, Washed Out Cotto From His Head
- Link Baiting - Fishing: Newbie SEO Attacks Experts
- How Important is the PageRank?
- Licensure Examination for Teachers (LET - October 2009) Result
- Jollibee Scandal: Spread the Word?
- Naruto Series Blog, Making Live Again
- Google PR, Halloween 2009 Update


































is using keylogger legal or not?
@jimmg: I think you already know what keylogger is and or is it legal or not because your name is linked to your keylogger site.
I think you are just spamming here.
Bootex.log is a file created by chkdsk.exe when it is run; its results are rolled into the main log after the system finished booting. If chkdsk.exe is interrupted, bootex.log can become corrupted. When chkdsk.exe runs again, it tries to write to bootex.log, which is, unfortunately, now corrupt. It doesn’t know this until after the check; so even though it was deleted by chkdsk.exe, it was written to in the mean time and is therefore still corrupt.
You need to do a bit of research before you go claiming that it’s a keylogger. It’s people like you who make certain parts of the internet untrustworthy.
I know what bootex.log is and what is keylogger. when I say that the computers of that cafe were installed with keylogger its because the I checked the computers for keylogger.