Keylogger removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by MarkoLUFC, Oct 6, 2013.

  1. MarkoLUFC

    MarkoLUFC Private E-2

    Hey guys, I'm new here, I was going to post in the welcome forum but it's a little urgent, was hoping you'd be able to help me with removing a keylogger

    I haven't managed to complete a virus scan yet, my scanner crashed half way through, and Microsoft's MRT was taking about 5 hours and wasn't getting anywhere. I'm considering running it over night after attempting another full virus scan.

    So basically, I haven't found the keylogger yet but I know it's there, as people in South Korea keep logging in to my Twitter and Facebook accounts, after I've changed the password on this machine.

    RogueKiller report dump:

    -----------------------------------------------------

    RogueKiller V8.7.1 _x64_ [Oct 3 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.adlice.com/forum/
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Mark [Admin rights]
    Mode : Scan -- Date : 10/06/2013 22:09:49
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 3 ¤¤¤
    [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Scheduled tasks : 0 ¤¤¤

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

    ¤¤¤ External Hives: ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts




    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) (Standard disk drives) - ST3500418AS ATA Device +++++
    --- User ---
    [MBR] 4b868d190574aa2c63212bf267c2365e
    [BSP] ed7d75d556a8e8a2306fa2db1e3ce6c2 : Windows XP MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476929 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) (Standard disk drives) - ST3160023AS ATA Device +++++
    --- User ---
    [MBR] 39bdd95356941540a4307d92fc08b8e9
    [BSP] 275afb90563d046e197708fdd7e5d4dd : Windows 7/8 MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 152485 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    +++++ PhysicalDrive2: (\\.\PHYSICALDRIVE2 @ IDE) (Standard disk drives) - HDT722525DLA380 ATA Device +++++
    --- User ---
    [MBR] 6ff35d1d867943498b9fb7c70ddcb173
    [BSP] 1a3dd7d9b856b018dc22324106968dc4 : Windows XP MBR Code
    Partition table:
    0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 238464 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[0]_S_10062013_220949.txt >>

    -----------------------------------------------------

    So yeah, any tips for making sure this thing is off my system? Normally I would just flatten my install, but I fancy the challenge of doing it the right way instead of what is essentially the "have you tried turning it off and on again?" of virus removal.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds