i`ve been keylogged

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by kamta, Aug 11, 2004.

  1. kamta

    kamta Private E-2

    ok first my symantec kept popping up this message

    http://img.photobucket.com/albums/v59/kamta/helpme.jpg

    i downloaded search and destroy and ran it a few times...it deleted about 70 files
    but now symantec is always saying "Scanning 1 email" and it keeps sending out one email every few mins
    how do i get rid of this?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. kamta

    kamta Private E-2

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Have it fix everything it finds. Was it able to fix the key logger?
    Did you run the other items too?

    Is your problem resolved?
     
  5. kamta

    kamta Private E-2

    ok i did everything on the website u gave me
    i dont get the symantec pop up anymore
    but how can i be absolutely sure the keylogger is gone?

    this is a link hijackthislog i did after i used all the stuff from the url you gave me
    i dont know if someone can check it out and tell me if everything is safe??

    http://www.geocities.com/navindrakamta/hijackthis.log
     
  6. kamta

    kamta Private E-2

    i used the website to analyse my log..
    it has a few nasty programs..
    tv media is one..but when i go to search for tv media..it isnt there
    another one is explorer in my system folder..
    when i go to search for it there..its not there
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay follow the steps below:

    Click Start, and then click Run. (The Run dialog box appears.)
    Type, or copy and paste, the following text:

    regsvr32 /u C:\PROGRAM FILES\TV MEDIA\TvmBho.dll

    then click OK. If a dialog box confirming this action appears, click OK.
    Now run HijackThis and put check marks on the items below but DO NOT CLICK FIX YET:
    R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)
    R3 - URLSearchHook: (no name) - {707E6F76-9FFB-4920-A976-EA101271BC25} - C:\PROGRAM FILES\TV MEDIA\TvmBho.dll
    O4 - HKLM\..\Run: [TV Media] C:\PROGRAM FILES\TV MEDIA\TVM.EXE
    O4 - HKLM\..\RunServices: [explorer] C:\WINDOWS\SYSTEM\explorer.exe
    O4 - HKLM\..\RunOnce: [TV Media] C:\PROGRAM FILES\TV MEDIA\TVM.EXE
    O4 - HKCU\..\RunOnce: [TV Media] C:\PROGRAM FILES\TV MEDIA\TVM.EXE
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm

    Now exit ALL Internet Explorer (or other browser) sessions and click Fix in HijackThis.

    Now reboot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650

    Now use Windows Explorer and navigate to and delete:

    C:\PROGRAM FILES\TV MEDIA <---- The whole directory
    C:\WINDOWS\SYSTEM\explorer.exe
    C:\WINDOWS\SYSTEM\explorer.dll <---- from the keylogger. Let's make sure it's gone.

    Now reboot in normal mode and let's where you stand. All the TVMedia items and the bogus explorer.exe should be gone from your HJT log.
     
  8. kamta

    kamta Private E-2

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's okay! That just means the dll file was not registered. Continue with the rest of the steps.
     
  10. kamta

    kamta Private E-2

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like the same log to me. Are you sure you did the steps correctly? Did you enable viewing of hidden files and folders?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You really should post your log here as an attachment. Just name it with a .txt extension and upload it. Doing it the way you are gives us no history mechanism.
     
  13. kamta

    kamta Private E-2

    umm..everytime i make a new log..i replace the old one with it (i save over it)
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bad idea. That's why I want you to post them here as text attachments. So we can have a running history. At any rate. Your log has not changed. It does not look like you executed the steps I gave you correctly.

    You did not answer my previous questions:

    "Looks like the same log to me. Are you sure you did the steps correctly? Did you enable viewing of hidden files and folders?"
     
  15. kamta

    kamta Private E-2

    umm..right now its a .log file
    how do i change it to .txt?
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it is not really a "bad idea" to overwrite the logs on your PC as long as you have been attaching each one here as I requested.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use Windows Explorer to rename it. RIght Click on it and select Rename. Then change the extension from log to txt.
     
  18. kamta

    kamta Private E-2

  19. kamta

    kamta Private E-2

    ok i think i got it now
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Now you have given me an updated log file and the items are all fixed. Your previous log did not show that anything had been done.

    By the way the settings for enabling Hidden files and folders you have made is correct but it would also be better to Uncheck the "Hide file extensions for known file types" options too. Otherwise you would only see a file like TvmBho.dll as TvmBho That could result in your telling me (or someone else) you could not find the file.

    The link I sent you to told you to uncheck that option.
     
  21. kamta

    kamta Private E-2

    soo everything is fixed?
    (and is there a way i can be absolutely sure so i can resume to playing runescape?)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything that showed in your HJT log is fixed. I have no idea what runescape is and it is the first time your are mentioning it. Why are you now worried about that?
     
  23. kamta

    kamta Private E-2

    thats the only reason i was keylogged in the firstplace
    www.runesape.com
    its a online game
    you should check it out
    its a highly competitive game..people hack you to steal your password and your stuff because they are too lazy to work hard for it themselves
    my character is worth a couple million (runescape money)
    the person who sent me the keylogger is another player on runescape (i have his msn..now is there anyway i can get back at him? :p ,a buddy of mines alrdy said he`d spam his email)..lol
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not play games nor do I have the time for them.

    Bad idea to play games that allow stuff like this to occur. You are going to windup with more problems like this again.

    Also we do not like talk like this here:

    " (i have his msn..now is there anyway i can get back at him? :p ,a buddy of mines alrdy said he`d spam his email)..lol"

    This is a Tech Forum. Not a hacking forum!
     
  25. kamta

    kamta Private E-2

    its actually some cambridge student designed the game in his spare time..then he made a company and employed a whole lot of people
    its a fairly big game now..
    only thing is..the cheaters are better than the game staff :S
    thanks alot for your help chaslang :D
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds