Keylogger.Trojan in explorer.dll, impossible?

Discussion in 'Malware Help (A Specialist Will Reply)' started by keyloggertrojan, Jan 17, 2005.

  1. keyloggertrojan

    keyloggertrojan Private E-2

    I have a keylogger in my explorer.dll, which is always running, even in safe mode
    how do i delete the file?
    i tried system restore and that was a waste of time
    norton doesnt know what to do, adaware didnt help
    i havent tried hijackthis but it's probably pointless, because it wont be able to delete the file
    i need to know if i can delete it upon roboot..because that seems like its the only way

    any help?
     
  2. keyloggertrojan

    keyloggertrojan Private E-2

    any thoughts...i have a logfile if u need it
     
  3. tigerray00

    tigerray00 Specialist

  4. keyloggertrojan

    keyloggertrojan Private E-2

    Ok, well here's my logfile


    Edit by chaslang: Inline, incorrectly run HJT log deleted
     
    Last edited by a moderator: Jan 18, 2005
  5. keyloggertrojan

    keyloggertrojan Private E-2

    I've tried everything
    the location is simply impossible to delete while my computer is runn9ing..
    so i want to know if i can use a program to delete the explorer.dll while my computer is rebooting
    This makes sense...so where can i find a program to do it?
    i heard about killbox, but i can't find a good,sound download for it.
    please help
     
  6. tigerray00

    tigerray00 Specialist

    Did you attempt every step in the link I posted earlier?
     
  7. tigerray00

    tigerray00 Specialist

    You'll have to rerun Hijack This.
    This time make sure you close all windows, including you browser, and turn off all programs, including the ones in the system tray.
    Run Hijack This.
    Then save the Hijack This log as a text (.txt) file.
    Come back to the forums and attach the text file(click Manage Attachment at the bottom) to a new post. Do not paste it inline like you did with the other one.
    Chaslang, or one of our other experts will come and help you go over the Hijack This file.:)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Keyloggertrojan,

    This is part of the problem:

    O4 - HKLM\..\Run: [explorer] C:\WINDOWS\system32\explorer.exe

    A valid explorer.exe runs from c:\windows\explorer.exe

    But you did not run all the steps of the READ ME and you ignore the guidelines about how HJT logs are to be posted and where it is suppose to be run from (installed) and what should be shut down before running it.
     
  10. tigerray00

    tigerray00 Specialist

    My appologies, Chas.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! It's just that we will not know that a user has even posted a log unless we are actively working the thread. And it's been very busy here. I have a lot of outstanding threads keeping me busy and PP is the same (overloaded). If the user posts a log after you request one and PP or myself do not know about it, who do you think the user is waiting for an answer from. From you obviously.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds