PerfectKeylogger detected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by CrashCat, Oct 19, 2012.

  1. CrashCat

    CrashCat Private E-2

    I tried a small program (DW.EXE) from a friend that was supposed to be safe, but the next reboot after running the program (which seemed to do what it was supposed to) my Teatimer (Spybot S&D resident) was triggered. It said it found PerfectKeylogger in a wallpaper switcher program that I've had for months without any problem (John's Background Switcher). I can't paste the exact line because it's been cleaned out of the log, probably from the CCleaner step. But after the first reboot when I disabled UAC I did not get any more detections from Teatimer. I followed all instructions in the Readme post, the logs are attached.

    Here is the virustotal result for the file I think started the problem:
    https://www.virustotal.com/file/095...cf69861430cb9a9bdd05e7c0e787ee40f69/analysis/

    Let me know what I should try next. I am out on vacation for the next few days so the computer will be off anyway, but I figured I should get this out in case someone can peek at it.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    What's inside of this folder?
    C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1

    Now run RogueKiller again and attach the latest log.
     
  3. CrashCat

    CrashCat Private E-2

    Oh right, I totally forgot I had turned on selective startup to turn off that annoying Comcast app. I will just uninstall it, EasySolve hasn't solved anything for me way back when I installed it anyway. :)

    The 188F1432-103A-4ffb-80F1-36B633C5C9E1 folder doesn't have anything important, it looks like some installer for software on a movie DVD, must have installed when I watched one a while ago and I didn't know it was hiding out there. There is a "GEARDIFx.exe" file and an x86 folder that has what looks like your typical installer junk. Think I can get rid of it? There's also a {429CAD59-35B1-4DBC-BB6D-1DB246563521} folder with a "DIFxInstallLog.txt" that sounds like it's from the same thing, and a blue-marked (hidden) {2A431ABB-67CA-4DA3-A5A5-E9E83C97BDBC} folder with the Active Worlds installer (which I also think I could get rid of).

    Doesn't seem like anything important so I'm fine with blowing all three of those away. Going to reboot and uninstall that Comcast garbage and rerun the Roguekiller, I'll reply again.
     
  4. CrashCat

    CrashCat Private E-2

    Here's the new RogueKiller log. Anything I need to get rid of? I don't see anything mentioned that looks like anything I desperately need, just a bunch of media apps.

    I did see that Remote Potato thing that I don't use anymore is on there, I used it back when I was fiddling with Windows Media Center and it seemed to be taking up memory so I uninstalled it through Control Panel. Sorry if that messed anything up but I figured it should just go since it's not being used. I tried scanning again after I uninstalled that so that's why there's a 2 and a 3, you can skip to the 3 if you want though.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What is this please?

    [TASK][SUSP PATH] IHUninstallTrackingTASK : CMD /C DEL C:\Users\Ben\AppData\Local\Temp\IHU2C7C.tmp.exe -> FOUND

    and in relation to what I asked about:
    Nah, leave them be.
     
    Last edited: Oct 22, 2012
  6. CrashCat

    CrashCat Private E-2

    It's not anything I set up myself, but the task on scheduler that corresponds to this is set to run one time, at 4:54 PM yesterday. Going by the times on the RK reports it was just before I ran those. Seems like a weird task for sure.

    edit: actually looking at the first RK report there's a similar line on that one:
    [TASK][SUSP PATH] IHUninstallTrackingTASK : CMD /C DEL C:\Users\Ben\AppData\Local\Temp\IHUA89D.tmp.exe -> FOUND
    Neither one of those EXEs is hanging around in there anymore though. What should I do?
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 2 detections:

    • [TASK][SUSP PATH] IHSelfDeleteTASK : CMD /C DEL C:\Windows\TEMP\IHUC19A.tmp.exe -> FOUND
    • [TASK][SUSP PATH] IHUninstallTrackingTASK : CMD /C DEL C:\Users\Ben\AppData\Local\Temp\IHU2C7C.tmp.exe -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.
    Now rescan with RogueKiller and attach the new log.
     
  8. CrashCat

    CrashCat Private E-2

    Ok, there was a new version of Roguekiller so I picked that up. The program notified me when i tried scanning the first time today so that is why there's no report 4. I can attach it if you want but it doesn't look any different really. Report 5 is from deleting the items and Report 6 is after the reboot. For the moment it looks like those items stayed gone. Should I rescan some other day and see if it shows up again?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes. and then if they still do not show which I expect they will not you can follow the final steps below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  10. CrashCat

    CrashCat Private E-2

    Yep, those items did not come back. I did notice MalwareBytes reporting an occasional unauthorized connection to Skype, is this normal?

    2012/10/25 00:35:25 -0500 BEN-PC Ben IP-BLOCK 121.10.20.18 (Type: incoming, Port: 45754, Process: skype.exe)

    It doesn't happen very often, and I'm thinking probably it'll also get picked up and blocked if I put in a software firewall.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If it's blocking then it's doing its job :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds