I think i have a keylogger

Discussion in 'Malware Help (A Specialist Will Reply)' started by grunty, Oct 20, 2007.

  1. grunty

    grunty Private E-2

    well i clicked on a link in another forum and it took me to a webpage, when my mcafee virus protection started saying harmfull scrift blocked, trojan found and removed loads of times, so i exited the site within about 15 seconds, after which i saw other people post it was a keylogger and got worried
    so i read the READ & RUN ME FIRST post here about how to remove malware and follwed all of the steps exept using PandaActiveScan.

    but i am still not sure if i have a keylogger or not, and i dont want to type any important passwords till im 100% sure, is their any way i can find this out

    thanks.
     
  2. grunty

    grunty Private E-2

    Logs

    The logs that i got when doing the READ & RUN ME FIRST steps.
     

    Attached Files:

  3. grunty

    grunty Private E-2

    and the Getrunkey and Shownew ones
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why not?

    Also you forgot to attach a HijackThis log as requested in the READ ME.

    I see no signs of any problems other than what CounterSpy already removed. However your ShowNew log appears to be incomplete did you edit the log to cut off information either knowingly or unknowingly.
     
  5. grunty

    grunty Private E-2

    hi,
    When i went onto Pandaactive scan i wasnt sure what to do. :eek:
    i went on it again after and clicked scan my computer (was this right?) and have attached the log it gave

    i also redid the the Shownew tool and got the new log, im not sure why it didnt show it all last time, im dont realy understand most of this :eek:

    and i have also added the Hijack this log as it said in step 7


    (i have also noticed boxs popping up when i open some applications, mainlly MSN, which say something along the lines of C://WINDOWS/system32/(different file names here) is not a valid windows image please check this against your installation disklett,
    could theese be related or is this something totally different

    thanks for your help.
     

    Attached Files:

    Last edited: Oct 21, 2007
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to give exact word for word examples including the filenames. You logs do not show any malware issues. You could be having problems related to your Windows installation (or other software) itself.

    I do have some minor things for you to do thoug. First uninstall the CounterSpy trial since we are finished with it. Then delete the below folders which could be left behind:
    C:\Documents and Settings\Dan\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 8
    Java(TM) 6 Update 2
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  7. grunty

    grunty Private E-2

    Hi,
    The exact message i got last was ''The Application or DLL c:\WINDOWS\system32\avicap32.dll is not a valid windows image plese check this against your installation disklett''

    i uninstalled counterspy and deleted the below files too:
    C:\Documents and Settings\Dan\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users.WINDOWS\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    i uninstalled:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 8
    Java(TM) 6 Update 2
    Viewpoint Media Player

    aswell

    i ran hijackthis and fixed the lines you said

    and i ran AFT cleaner fine,


    all this went ell and i have attached the new hijackthis and shownew files


    Things seem to be working fine now, should i be safe to type in passwords now?

    thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a malware issue. If this is still happening you will have to work this in the Software Forum. avicap32.dll is a module that contains functions for the Windows API that is used to capture AVI movies and video from web cameras and other video hardware.


    Your logs were fine all along so based on that your were safe from the beginning.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    2. After doing the above, you should work thru the below link:
     
  9. grunty

    grunty Private E-2

    hi,

    thanks for all the help checking my system, good to know i didnt get infected after all :D
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds