C:\WINDOWS\System32\ikhcore.log

Discussion in 'Malware Help (A Specialist Will Reply)' started by Planetsunshine, Dec 9, 2006.

  1. Planetsunshine

    Planetsunshine Private E-2

    After running full system scans using my 3 different malware programs (PC Tools Spyware Doctor, Webroot Spy Sweeper, and Spybot Search and Destroy) with no problems found, I ran HijackThis with log and found NO suspicious entries (I am quite familiar with the process and file entries)...But on defragging drive C, one file remained fragmented...The file as titled above...Is this a left-over from a keylogger-and-dialer that may have been removed in an earlier malware scan? --or-- Is it a legitimate log file for a known legitimate program?...If the former I'd like to remove it.

    TIA

    Bruce
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what that file is for? Did you try looking at it in Wordpad to see what is in the file? It may give you a hint on what it is for? Can it be renamed? Can it be moved to a different folder?
     
  3. Planetsunshine

    Planetsunshine Private E-2

    chaslang...

    Thanks for your reply...To answer your questions, Yes the file can be moved and yes it can be renamed...I did open it in Notepad before I posted my first inquiry but I didn't understand what was being logged...It seems to log some process activity and service descripter table entires, kernels loaded included Security Kernel Started, system call manager verifying system call, NtCreateKey, NtDeleteKeyValue, NtCreateProcessEx (real:memory=805a4516:baf6056e), etc...These entries and others in slightly different content are repeated over and over, again.

    I'm beginning to think it is an internal log for my anti-virus program (MacAfee) or one of my anti-spyware programs as named in my first posting.

    A Google search shows some forum postings (mostly in German or other-than English languages) that would suggest others have questioned its relevance to malware...I don't really know insofar as the English translations are somewhat cryptic so I can't really understand what the substance of the discussions are...Perhaps its a harmless log as I don't have any functional problems with my computer's performance at the moment...I hope so.


    Bruce
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try moving it to another folder and then reboot your PC! See if it comes back. If it does not come back right away, check after running some normal everyday applications and procedures to see if it comes back. Also note if anything complains about the file being missing, you can just move it back.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds