Keylogger and Other Malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by smit6577, Nov 6, 2008.

  1. smit6577

    smit6577 Private E-2

    Hey, I started getting these windows security pop -ups for some kind of keylogger and I went through the windows vista cleaning procedures and found a bunch of other forms of malware. Any suggestions? Attached below are the logs. Thanks in advance for the help.
     

    Attached Files:

    Last edited: Nov 6, 2008
  2. smit6577

    smit6577 Private E-2

    Here's the last logs..
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to let you know we are currently reviewing your logs and will get back to you with a set of instructions as soon as we possibly can. Thankyou for your patience :)

    Kes
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    HI

    Can I ask what programs were giving you the warning regarding the keylogger?


    Also...you ran scans in safe mode...could you run everything again please in normal mode? And upload the logs to us here.

    Thanks
    Kes13!
     
  5. smit6577

    smit6577 Private E-2

    My windows security center was giving me the key logger pop up. I've also been getting one where a message box pops up asking me if I want to download some anti virus program, which links to a page that automatically starts downloading whether click yes, no, cancel, or the close button.

    I only ran scans in safe mode for combofix and mg. Can I skip redoing sas, mbam, and spybot?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes skip Spybot Search and Destroy, MBAM and SAS.
    Ensure you are in normal mode now for the following:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Thanks
    kes13!
     
  7. smit6577

    smit6577 Private E-2

    Alright here are the logs.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1) You are running two different Anti-Virus which is not a wise idea due toboth softwares fighting for control over system files which in turn leads to much inner conflict and system instability.

    Please tell me is your Norton360 a free trial or paid for software? If it is paid for please uninstall PCTools Anti Virus4.0 and keep Norton360 and if it is just a trial please uninstall Norton360 and keep PCTools Anti Virus 4.0.

    Towards the end of the thread I will give you a link for the Norton removal Tool and some basic instructions for running it.

    2) Please go to add and remove programs and unsinstall the following software:

    • Java(TM) 6 Update 3

    Reboot your machine and install the current version available here at the below link:

    Java Runtime 6

    3) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)


    After clicking Fix exit HJT.

    4) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Users\Tom Smith\AppData\Local\Temp

    5) Now Run Ccleaner!


    6) Please navigate to C:\Windows\SavePOH64.exe

    I would like for you to right click on the SavePOH64.exe file and re-name it to SavePOH.exe.old

    As a result of doing this I would like for you to tell me if you receive any error messages and let me know if anything out of the usual happens after doing the above.


    7) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Thanks :)
    Kes13!
     
  9. smit6577

    smit6577 Private E-2

    Here are the MG logs. I didn't encounter any problems with your instructions and everything is running smoothly.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please re read my step 1 in post #8 regarding Anti-Virus and let me know whether your Norton360 is paid for or a free trial.

    Your latest MGLogs are incomplete. Did you let it run till it told you it was finished? Did you get an error message when it ran.

    Use windows explorer to find and delete:
    C:\ProgramData\xqkcebzs.dik

    Now tell me exactly what problems you are having.
    Thanks
    Kes
     
    Last edited by a moderator: Nov 10, 2008
  11. smit6577

    smit6577 Private E-2

    I tried to remove Norton 360. You didn't include a link for the Norton removal Tool and instructions for running it in your last post.. though I have an older version of symantec antivirus which hasn't expired so I'm not sure what to do?

    The MGlog might have had error messages but it was completed: it got t the screen that says click any button to close.

    I don't seem to be having trouble with anything else.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I didn't want to include the Norton Removal Tool until I know for sure what is happening with your Anti Virus situation.

    You have three different Anti Virus there, and should only be using one.
    What I want to know is was your copy of Norton360 a Free Trial? (I suspect so if you are telling me you have Symantec AntiVirus which hasn't yet expired)

    Thanks
    Kes
     
  13. smit6577

    smit6577 Private E-2

    Yes Norton 360 is a trial version. It expired then I downloaded what my college offers, which is an older version of Symantec anti virus.

    If this is any help, the only logs that were posted after I deleted/tried to delete Norton 360 and PCTools anti virus are the MGtool logs. At least PCTools should be removed because I went to the control panel and uninstalled it and restarted my computer, and it's not showing up in my add/remove program list.

    Also, I ran Mgtools again and the following error messages came up:

    File fixcf.exe doesn’t exist.
    Userinfo.bat not recognized as internal or external command, operable program, or batch file.
    Shownew.bat not recognized as internal or external command, operable program, or batch file.
    Getunkeys.bat not recognized as internal or external command, operable program, or batch file.
    Getrunkeys.bat not recognized as internal or external command, operable program, or batch file.
    The C:MG\temp\GRKflag.text exists. Deleting it!

    Attached are the logs from this.
     

    Attached Files:

    Last edited: Nov 10, 2008
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) Use this link for the Norton Removal Tool and instructions for running it. I suggest you run in twice.

    http://service1.symantec.com/support/norton360.nsf/docid/2006112909122875

    2) Now I would like for you to delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip.

    3) Visit this link below for some excellent freeware anti-virus, only choose one to download and install it.

    How to Protect yourself from malware

    4) Re-download MGTools.exe and run it afresh.

    5) Attach the MGlogs.zip into your next post after doing all of the above.

    Thanks
    Kes13!
     
  15. smit6577

    smit6577 Private E-2

    While running MGtools.exe I got this error message:

    For some reason your system denied access to the Hosts file. If any hijacked domains are in this file, Hijack This may Not be able to fix this.

    If that happens, you need to edit the file yourself. To do this, click Start, Run and type.

    Notepad C:Windows\System32\diverse\etc\hosts

    And press Enter. Find the line(s) Hijack This reports and delete them. Save the file as ‘hosts.’ (with quotes), and reboot.

    Also I have a question about spyware compatibility. I uninstalled Norton 360 and Symantec, and then reinstalled Symantec Anti virus, which I believe only covers anti virus protection and not spyware protection? In Windows Security Center under the malware protection tab it lists Symantec and says Symantic AntiVirus is turned on, and Tamper Protection is on in the Symantec configuration settings though I'm not sure if tamper protection is a real-time malware defender. So my question is, considering that, would it be a good idea to download and use Comodo BOClean Anti-Malware ?
     

    Attached Files:

  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you do what I previously asked in step 2 above?

    Did you then do the below?
    Did you not run the Norton Removal Tool?

    Did you disable all anti-virus and spyware programs before running MGTools? DId it just stop and not proceed or did you stop it yourself?

    If you could answer these questions that would be great :)

    Thanks
    Kes
     
    Last edited by a moderator: Nov 12, 2008
  17. smit6577

    smit6577 Private E-2

    I did everything you asked, except I didn't disable my spyware/antivirus program; however, I stopped MGtools myself when it read something like "click any button to close."
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please re-run MGTools this time making sure you have disabled your Anti Virus and any Anti-Spyware apps and when it finishes, attach the log it produces. Also run Combo again.

    Did you run the Norton Remoal Tool ok?

    Thanks
    Kes:)
     
    Last edited by a moderator: Nov 12, 2008
  19. smit6577

    smit6577 Private E-2

    Yah I had no problems with the Norton tool.
     
  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Great :) So just combofix and MgTools to be done now, first as mentioned do disable all anti-virus and anti-spyware apps before doing so. I will be here waiting :)
     
  21. smit6577

    smit6577 Private E-2

    Alright so I disabled everything though spybot is showing up as "snooze" which I guess means it's off. The same thing happened while running MGtools and the first error message said hijackthis is already running. Here are the logs.
     

    Attached Files:

  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Check your task manager to see if it is still running and right click and end hijackthis.exe process.

    Then run Combofix as requested and re run MGTools (again make sure anti spyware and antivirus are disabled before doing so)

    Thanks
    Kes
     
    Last edited: Nov 12, 2008
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Step 2: Disabling User Account Control



    Now we need to make sure to turn off UAC ( UAC = User Account Control )

    1. Click Start, and then click Control Panel.
    2. In Control Panel, click User Accounts.
    3. In the User Accounts window, click User Accounts.
    4. In the User Accounts tasks window, click Turn User Account Control on or off.
    5. If UAC is currently configured in Admin Approval Mode, the User Account Control message appears. Click Continue.
    6. Clear the Use User Account Control (UAC) to help protect your computer check box, and then click OK. If it is already uncheck, then you should also notice a red shield with an X in it located in your system tray. Ignore any mesages about UAC being disabled.
    7. Click Restart Now to apply the change right away. (Restart even if you did not make the above change, we need to be sure that a reboot has occurred since the first time that UAC was disabled.)

    NOTE: DO NOT CONTINUE UNTIL UAC has been disabled and you have rebooted.




    Did you make sure all the above was done before running the tools?
     
  24. smit6577

    smit6577 Private E-2

    Okay I did everything you listed here are the logs.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    1) Please use Windows Explorer to find and delete the following file:

    C:\ProgramData\xqkcebzs.dik

    2) Delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    and finally....

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  26. smit6577

    smit6577 Private E-2

    I have a problem with step 2). I can't open C:Documentsandsettings I get an error message that states access is denied. I'm using my administrative account.

    Also, If I disable "tamper protection" on my symantc antivirus should it be alright for me to download and use Comodo BOClean Anti-Malware for real-time spyware protection?
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you sure you are logged on as administrator?
    Code:
    Users on this computer:
    Is Admin? | Username
    ------------------
              | adminfree
       Yes    | Administrator [B][U](Disabled)[/U][/B]
              | Guest
       Yes    | Tom Smith
    
    I am not familiar with tamper protection in symnatec....but it may be the cause of your issue.

    I would suggest that you post in the software section regarding those questions. :)
     
  28. smit6577

    smit6577 Private E-2

    I'm not sure what screen you're referring to, but I went to control panel/user accounts and family safety/user accounts, and on the right of the screen it shows my account as

    Tom Smith
    Administrator
    Password Protected

    Can you tell me how to enable administrator account if it is disabled? I'm not sure if it is?
     
  29. smit6577

    smit6577 Private E-2

    .. I did some resaerch and apparently Vista, which is what I'm using, has a limited admin account and a real administrator account that's hidden. I figured out how to enable it here: http://lifehacker.com/341521/enable-vistas-administrator-account

    but now I can't find the C:/programdata using the real administrator account.
     
  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    Hi there

    Can you make sure that your machine is set to show hidden files and folders if it isn't already?

    If you don't know how to do this here are some instructions:
    • Go to start > computer> organise > folder and search options > open the "view" tab under "hidden files and folders" select to show hidden files and folders.
    • Also uncheck Hide protected operating system files (Recommended)

    Once you have done this please navigate to the following to empty your temp files:

    C:\Users\Tom Smith\AppData\Local\Temp

    Thanks
    Kes13!
     
    Last edited: Nov 15, 2008
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As explained above regarding emptying your temps, you just need to ensure that you have hidden files and folders showing :) I explained how to do that above also.

    So make sure you delete the below in red after checking you have hidden files and folders showing:

    C:\ProgramData\xqkcebzs.dik

    Then use the same steps I gave to reverse the process after you're done to hide them again.

    Kes13!
     
  32. smit6577

    smit6577 Private E-2

    Alright, now I just need to delete C:\Documents and Settings\%username%\Local Settings\Temp, I can't find that using my administrator account, while I can find it but not acess it in my other account.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do not worry about the "Access denied" message you are getting when attempting to open C:\Documents and Settings\Tom Smith\Local Settings\Temp. It is normal that you are receiving the access denied message as we are using Vista....I get the same.

    We already emptied your temps when you did the below:


    Are you having any further malware problems?

    Thanks
    Kes
     
  34. smit6577

    smit6577 Private E-2

    No I'm not having any other problems. Thanks again for all the help.
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds