Forum Moderators: phranque

Message Too Old, No Replies

W32 Randex virus question

         

osucowgirl

3:35 am on Aug 15, 2004 (gmt 0)

10+ Year Member



There was a virus that was discovered on my harddrive called w32 randex. It was a keylogging virus which logged everything and put it in a file called ntfsvi.txt
Here is my question: I need to know IF THIS IS POSSIBLE? My husband and I read this file that had stored our keylogging. It started logging on May 30 and ended on July 5. There are things that the keylogger had in it that we did not type. In fact, we were not home during the time and date that was logged. Is there anyway possible that some outside person planted this incriminating information into our keylogger? I am trying to rule out possibilities and trying to locate who and how this could happen. I don't understand the virus and how it works. I do know that it supposedly records all keys stroked on the computer; however, there are things that we typed that were not on the keylog and then there are things on the keylog that could not have possibly been typed on our computer unless someone broke into our house which did not happen. Is there anyway possible that the keylogger could be wrong? I have win2000 and yahoo dsl.

macrost

6:09 am on Aug 15, 2004 (gmt 0)

10+ Year Member



osucowgirl,
Welcome to WebmasterWorld! I am sorry to hear about the keylogger experience, those are never fun. I have done some research into this worm that you have, and it doesn't have keylogger abilities that I have read. Here's a link to a variant. Do you know what type of variant you had?

[securityresponse.symantec.com...]

outrun

7:05 am on Aug 15, 2004 (gmt 0)

10+ Year Member



W32.Randex.ATX

[securityresponse.symantec.com...]

And is usually sent by an attacker via IRC, although it can be installed on a weak patched Windows XP /2000 system.

regards,
Mark