MEMSWEEP2: is it really a Trojan? Did I actually get rid of it?

Discussion in 'Malware Help (A Specialist Will Reply)' started by lanulos, Dec 22, 2007.

  1. lanulos

    lanulos Private E-2

    I recently discovered a hidden service MEMSWEEP2 (which was listed as stopped) on my laptop using a2-HijackFree, linked to a file 70.tmp in system32, which was not actually visible in system32. I tried anyway to delete it at a dos prompt (which returned "file not found") and then I rebooted. After that the MEMSWEEP2 reference changed to 3E.tmp.

    A search turned up these threads:http://forum.emsisoft.com/Default.aspx?g=posts&t=1914 and also here at majorgeeks at http://forums.majorgeeks.com/showthread.php?t=113335.

    It was said to be a keylogger. Complicated and time-consuming procedures for getting rid of it were presented. I thought, "Well, maybe it's time to get that new hard drive I was thinking about". But then I tried something simple: I disabled the process MEMSWEEP2 in HijackFree and then used the Uninstall option. I then used Registrar Registry Manager to find and delete all references to MEMSWEEP2 in the registry. Contrary to what was said in the above links, I did not have to take "ownership" of these keys to delete them. After rebooting, the service MEMSWEEP2 and all the registry references were gone.

    It can't really have been that easy to get rid of a keylogger, can it? Isn't it likely it is still hiding, if it is malware? How can I detect suspicious IP accesses? I played around with PeerGuardian2 but I don't know how to tell which tell which IP address are bad.

    Any advice anyone can give me will be appreciated. Let me know what logs you would like me to attach. I'm still very suspicious of the laptop and inclined to go the painful winXP clean install route.
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds