Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Magic PS- Yahoo Password Stealer

Status
Not open for further replies.

Sapient2003

Technical User
May 8, 2002
74
US
Magic-PS is a key logger that only affects Yahoo Messenger users. It's purpose it to log and send the user's password to another Yahoo Chat member through a private message sent by the victim's Yahoo Messenger. It disables Yahoo Messenger's Save Password feature, so you are required to type in the password. Signs of infection include a fast Yahoo Messenger private message window that opens and closes uplon login.

Removel:
Please note that the removal of Magic PS differs depending on the options the attacker choose: Disable Taskmgr xp-2k, Disable regedit, and Disable Msconfig. I will try to cover everything.

Step 1- Look for suspicious processes
Magic PS has a default filename list that users can choose from within the program that generates the key logger.

regsvr.exe spool_32.exe spool_32.exe svchost .exe
winzip_32.exe MsTask .exe winzip_try.exe spoolsvr.exe
ExpIorer.exe taskmgr_32.exe system_32.exe intranet.exe
norton.exe regclean.exe starter .exe iexpIore.exe
regscan_32.exe osa .exe

Note that these are just the default names. The user can choose any filename he wants. In this case, you will have to rely on other means of detecting it. If your Task Manager is enabled, look for a process that is running under your Windows user account that is using about 3,416k in memory. This alone doesn't mean it is Magic PS, however.

To make sure the suspected process is in fact Magic PS, you should run a memory editor on the process. I suggest WinHack 2 ( Extract the contents of winhack2.zip and open WinHack2.exe. Under the Edit a Game's Memory tab, you will see a Process drop down box with currently running processes. Choose the process that took about 3,416k in memory and click on the Edit Memory tab. You will see a search box, enter: magic-ps. If found, this is the right process. Close it with Task Manager, if enabled. If the Task Manager is disabled, you will have to use a third-party process viewer/terminator. You can download one at Note that you need to close the process before you can delete Magic PS.

Step 2- Removing Magic PS
After the Magic PS process is closed, click on the Start Menu, go to Search, and click on For Files and Folders. Click on the All files and folders button. Enter "Magic_w" without the quotes in the A word or phrase in the file text box and click search. Delete all entries.

Step 3- Fixing taskmanager, regedit, and msconfig

--Sapient2003 - sapient@sapient2003.com
"The worst insecurity is believing you are too secure."
 
Sapient2003,
[tab]Could you please post this in Forum760, too?

James P. Cottingham
[sup]
There's no place like 127.0.0.1.
There's no place like 127.0.0.1.
[/sup]
 
Re step 2
If magic-ps always has files/folders revealed by search for "magic_w", wouldn't an easier way to find out if your computer has it be to just do the search first? This seems much easier than the winhack step.
 
Magic Password removal tip part 2>> the post is excellent but missing a few key steps including the key registry file to delete in order for MPS to not start up over and over again>>>

Here it is >>
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{6M8A6G00-3I18-11C0-821H-444200140P0S} "StubPath"

IF U DO NOT DELETE THIS REGISTRY KEY MPS WILL CONTINUE TO BOOT UP CAUSING NUMEROUS HEADACHES

Also, a 3rd party program task magaer which is able to quarentine the MPS file is very useful
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top