I think i have a keylogger but nothing found

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by i8p, Jul 15, 2011.

  1. i8p

    i8p Private E-2

    I received a notification that my yahoo account had been compromised so after changing the password, I performed a boot time scan with avast and found the following issues:
    OtherMalware-gen
    HTMLDownloader-F[Trj]
    JS:Downloader-ANV[Trj]
    Win32:Mirc-Z[PUP]

    I am worried that I may have had (or still have) a keylogger. I realized that my firewall had been turned off as well (not by me) and I had to reboot to turn it back on. I quarantined the offending files and then followed the instructions posted here to first prepare my computer (including removing java, deleting those quarantined files, etc) and then I ran the various scan tools.

    SuperAntiSpyware found nothing. I can't find any tools specifically for JS:downloader-ANV cleaning and admittedly didn't look for specific tools for the other viruses yet (though I did look through your list of add/remove software items).

    I am attaching the log files of everything else.
    Is there a probability that there may still be an active keylogger on my system?

    /I apologize for asking for help as a first time poster :noob
     

    Attached Files:

  2. i8p

    i8p Private E-2

    BTW: The yahoo notification was not in an email, but instead, when i was logging in, it said it had been compromised and to change my password. I checked the url and it looked legit.
     
  3. i8p

    i8p Private E-2

    Forgot to mention that I am running windows 7 64 bit but that probably shows up in the logs anyway, right?
     
  4. thisisu

    thisisu Malware Consultant

    Welcome to Major Geeks!

    I will be reviewing your logs. Please be patient as there is a lot of information to review :)
     
  5. thisisu

    thisisu Malware Consultant

    No malware in your logs so far. Let's do a couple more scans.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller

    Also please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  6. i8p

    i8p Private E-2

    Looks clean. no warning messages. I am a little spooked by some processes called ActivIdentity and Andrea filters APO access service but they may be related to something I installed since I last looked at my processes.

    Attached is the log from Kaspersky but I can't find the one for the MBRCheck in the folder where I ran the program or in the C drive.
     

    Attached Files:

  7. thisisu

    thisisu Malware Consultant

    MBRCheck.txt should be on your Desktop. You have so many desktop icons though I can see why it would be hard to find it :-D
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds