stuck with a key logger, i cant shake it.

Discussion in 'Malware Help (A Specialist Will Reply)' started by martino229, Jul 11, 2008.

  1. martino229

    martino229 Private E-2

    I have found a key logger on my system and i ran a hijackthis to see what was going on i also ran a MAM and a Avast scan as well as an ad-aware. this is my hijackthis log


    Logfile of HijackThis v1.99.1
    Scan saved at 6:22:03 PM, on 7/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)

    Edit by chaslang: Inline, outdated, HJT log removed. READ & RUN ME sticky not followed.



    heres my Malwarebyte's log file

    Malwarebytes' Anti-Malware 1.20
    Database version: 941
    Windows 5.1.2600 Service Pack 2

    6:02:22 PM 7/11/2008
    mbam-log-7-11-2008 (18-02-22).txt

    Scan type: Quick Scan
    Objects scanned: 43962
    Time elapsed: 21 minute(s), 11 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\Bellerose\rundll32.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


    what can i do now? thanks for any help.
     
    Last edited by a moderator: Jul 12, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What keylogger did you find? Where did you find? What did you find it with? What were the file names?

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. martino229

    martino229 Private E-2

    thank you very much for your response!

    I found the file using the Security task manager program, the name of the file was Down(0)ow.dll I deleted it there ran Malwarebyte's. Right now i am running super Anti-spyware and following the guide you posted, i will report it when i get done.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is the wrong order. Don't start over but please follow instructions in the order written from now on. There are important reasons for the order.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds