Am i clean after keylogger, HJT-log incl

Discussion in 'Malware Help (A Specialist Will Reply)' started by artfullDODGER33, May 9, 2009.

  1. artfullDODGER33

    artfullDODGER33 Private E-2

    Kaspersky IS 2009 recently informed me there was a keylogger on my system.
    KIS 2009 didnt seem to be able to shut it down, so i am unsure if any data was uploaded.
    anyway i installed several anti-spyware utilities and ran it then removed and installed another.
    nowi am fairly sure i have rid my hdd of infection.
    i read and followed the speed uppc thread (most i was doing regular anyway.
    i read and followed the malware removal thread. and installed SAS, malwarebytes, Combofix and Mtools (logs attatched).
    there were no infections found that i am aware of but would like a more tech minded person to confirm this though, i would appreciate any assistance.
    i have deleted all system restore points as indicated from thread if no infections wre found.
    also, whats the chances that some of my data made it past KIS 2009 firewall and app filter etc
     

    Attached Files:

  2. artfullDODGER33

    artfullDODGER33 Private E-2

    sorry heres the cobofix log file i think i posted the instructions that i had copied and pasted oop's lol
     

    Attached Files:

  3. artfullDODGER33

    artfullDODGER33 Private E-2

    Tell me if i have sucessfully removed the keylogger and heur virus which kis 2009 identified

    as i am not sure and will end up doing a full re-install of xp-home to be sure .........where are the malware experts i cant pm anyone as i have less than 50 posts

    please advise....... Please please
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You should have read the email you received when you signed up and also read the notes when you ran the cleaning procedure. They both referred you to the below link:

    Don't Bump! It Only Hurts You!!!

    Every post, bumps your place in the queue and cause more delay in getting an answer.

    And now because you did not attach the requested log from MGtools, we still cannot provide you proper help. You need to attach the C:\MGlogs.zip file that was requested. However I will tell you that the logs you have posted do not show any signs of infections.
     
  5. artfullDODGER33

    artfullDODGER33 Private E-2

    Firstly i had not read the dont bump your post until after my 2nd reply or 3rd post......FOR THIS I APPOLOGISE

    my second post was neccesary as i had posted the wrong file for combofix in the inital thread/post.......I MAKE NO APPOLOGY FOR THIS

    My third was unecesary SORRY

    in heindsight at the time i had not read the "BUMP" notice thing

    I had thought that members some malware experts some regular people like me randomly posted their thoughts or interperatations of the log files.......... I WAS WRONG.......AGAIN....SORRY

    I had not realised there was a set process for working through them by yourselves but rather it eas randomly done by "that looks interesting" double-click that.

    SO AGAIN I APPOLODISE

    I WOULD HAVE 2 DAYS AGO BUT DIDNT WANT TO BUMP MY THREAD....AGAIN !!!! AS WARNED IN THE BUMP NOTICE THINGBY .

    So here is the attatchment you requested.
    i am aware looking through you're forum thread that you are bombarded with 30+ requests for help daily ........

    SO I THANK YOU FOR TAKING THE TIME TO REPLY TO MINE DURING YOUR SPARE TIME......AS THIS IS UN-PAID WORK I TAKE MY HAT OFF TO YOU.....HAVE YOU CONSIDERED ONE OF THE SITES WHERE PEOPLE ARE CHARGED FOR TECH SUPPORT
    (MAYBE YOU COULD EARN SOME EXTRA CASH}

    THANX AND SORRY ONCE AGAIN

    artfullDODGER33 :wave
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Like your other logs, the MGlogs.zip file is also clean. You should however do the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix, exit HJT.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  7. artfullDODGER33

    artfullDODGER33 Private E-2

    just a quick thank-you i have ran the hjtMGtools thing and removed the 2 files or "entries" you highlighted.

    i am working through removing the excess programmes etc as advised and will read through the posts as advised in order to protect myself better on the web[if we all did this maybe your work-load would reduce !!!]

    although i will say that the last 2 years have been a steep learning curve when it comes to PC/network security, with viruse's and malware being apparantly everywhere [who would have guessed i hardly knew what a virus was never mind malware] ,,,,,shit now i read about kernnel-rootkits what manipulate the interaction between native/windows API's so as not to be detected by the majority of system security scans........how do you deal with that ????

    I SUPPOSE WE SHOULD ALL STAY OFF THE P2P AND BEWARE OF FREEBIES AS SOME PEOPLE ARE DL'ING SECURITY PRODUCTS FROM TORRENTS EG " AVG-8-PRO-CRACKED-TILL-2018" ...ARE PEOPLE SILLY OR WHAT.??..WHY DO THE UPLOADERS UL FOR FUN ???....I THINK NOT, SOME MAYBE MOST TO GET MALWARE ON YOUR PC N SHIT !!!.....AS FOR PORN...FORGET IT !!!

    AUTHORITIES SHOULD BE MORE PRO-ACTIVE THOUGH COS AT MOMENT THE OWNICE IS ON THE CONSUMER TO KNOW BETTER, THATS WRONG

    TRYING TO STEAL YOUR PERSONAL SHIT ...THATS BAD

    THANX AGAIN CHASLANG ...:pM80 ;):-D
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds