Keystrokes Logged

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by declaredinsane, Apr 24, 2009.

  1. declaredinsane

    declaredinsane Private E-2

    My pc tools threatfire keeps killing and quarantining keystroke logs. It shows files but doesnt say what is causing it.
     

    Attached Files:

  2. Corporal Punishment

    Corporal Punishment Administrator Staff Member

    From these logs - nothing is standing out, however, we need the rest of the logs from the readme - specifically, the mgtools logs.

    What file and path specifically is threatfire saying is bad?
     
  3. declaredinsane

    declaredinsane Private E-2

    Under Denied Tab it says, Keystrokes Logged C:\program files\internet explorer\explorer.exe.
    Under Quarantined Tab it says, threat activity: keystrokes logged.
    C:\Users\Jake\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PCJV8LH8\GOOGLE_COM[2].HTM

    Then there are more files like that.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are all clean. Perhaps Threatfire is just recognizing normal web activity when you use IE and are entering data into forms on pages as keylogging. Just emptying your browser cache will easily remove stuff like this.

    You do have a few minor things to do.

    First I see Norton 360 in your installed program list but it does not really appear to be running in your logs. Did you uninstall it? Does your PC Tools software have an antivirus program?

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 14
    Java(TM) 6 Update 3
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME


    Now let's remove a left over from Spy Sweeper and Symantec

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

    After clicking Fix, exit HJT.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Admin\Local Settings\temp
     
  5. declaredinsane

    declaredinsane Private E-2

    It wont fix the O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing). But I did do everything else. Should I just allow the threat under threatfire?

    Thank so much
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Lic NetConnect service
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'. If it is already Stopped or Disabled, just continue on.
    • Click OK until you get back to Windows.
    • Next, run C:\MGtools\analyse.exe which is really HijackThis, but instead of scanning, click on the None of the above, just start the program button at the bottom of the choices.
    • At the lower right, click on the Config button
    • Then click the Misc tools button
    • Select Delete an NT Service
    • Copy/pasteCLTNetCnService into the box that opens, and press OK
    • If you receive any error messages just ignore them and continue.
    • Now exit HJT but do not reboot when it tells you it needs to. We will do that further down after running HJT again to fix some other items.

    Yes.
     
  7. declaredinsane

    declaredinsane Private E-2

    That worked. I have no idea about the keystrokes, should i just grant it access?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. declaredinsane

    declaredinsane Private E-2

    Everytime I run the scans they come back negative.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What scans are you referring to? I did not ask you to run anything, but negative sounds like that is what you want. ;)
     
  11. declaredinsane

    declaredinsane Private E-2

    I've ran all the programs from mgtools, spyware dr. antivirus, superantispyware, spybot, spysweeper, malwarebytes.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so we are all finished since they are all clean you should complete my final instructions given in message # 8.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds