Total control, worms, Keylogging HELP!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pamelaj, Jul 6, 2005.

  1. pamelaj

    pamelaj Private E-2

    KEYLOGGER on my COMP - scrambler.sys

    hi

    i know for a FACT that i have keylogger software on my comp.

    people have gotten into my email, my accounts, etc.

    the one file that i can find is scrambler.sys

    what should i do first?
     
  2. ANHEDONIC

    ANHEDONIC Will Title For Food

  3. pamelaj

    pamelaj Private E-2

    Re: may i post my log now?

    hi

    may i please post my hijackthis log now?? or where should i post it?

    I found that the keylogger has it setup on my computer to also send themself
    emails from the data they are collecting.

    I have ZoneAlarm, AntiVir Guard, and Spy Protector on my computer, but they still go through somehow.

    Also, there are some logs that shows that my computer is successfully being remotely controlled and i have NO IDEA how to fix this.

    thanks
     
  4. pamelaj

    pamelaj Private E-2

    My Log

    okay i saw below that you said to post my findings here.

    here is my log.
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: My Log

    pamelaj,

    One of your main problems is that you have 3 antivirus programs running. This is NOT recommended as running more then one antivirus program will cause conflicts on your computer.

    You must pick ONE antivirus and uninstall the other two. After you complete this reboot and post a fresh HJT log.
     
  6. pamelaj

    pamelaj Private E-2

    Re: KEYLOGGER on my COMP - scrambler.sys

    so i shouldnt run Spy Doctor for keylogging and Grisoft AVG at the same time??

    what about ZOne alarm?

    Thanks,
     
  7. pamelaj

    pamelaj Private E-2

    New Log

    is this log better?
     

    Attached Files:

  8. pamelaj

    pamelaj Private E-2

    I also have THIS PROBLEM

    this folder CONTINUES TO SHOW UP in my EMAIL BOX under TRASH folder

    and it CANNOT BE DELETED PERMANENTLY...........it keeps COMING back over and over again.

    file name is: MSIMGSIZ.DAT

    I also found some logs that said that my computer was being connected to remotely???
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Re: I also have THIS PROBLEM

    pamelaj,

    You still have more than one AV installed. You have AVG & Avast! installed, pick one of these and uninstall the other. ZoneAlarm is fine as long as this is your ONLY firewall.

    After you pick one AV & Firewall, reboot and post a fresh HJT log.
     
  10. pamelaj

    pamelaj Private E-2

    okay...but one question

    if i use the AVG 7.0 virus PLUS the AVG firewall

    should i uninstall ZONE ALARM? still?

    thanks
     
  11. pamelaj

    pamelaj Private E-2

    Re: KEYLOGGER on my COMP - scrambler.sys

    also, my yahoo messenger wont run with AVG 7.0 plus the AVG firewall up. Any way to fix this??
     
  12. pamelaj

    pamelaj Private E-2

    KEYLOGGER help...still waiting

    hi, is there anyone else who can check my log below that i posted.

    i know the spyware and keylogging is continuing on my computer because

    now there is a FOLDER in my email called MSIMGSIZ.DAT and I cant delete it. I think someone is now monitoring my emails.

    Please help.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: okay...but one question

    You must use only one firewall and only one antivirus application. So if you are keep AVG with the firewall, you must uninstall ZoneAlarm.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: KEYLOGGER on my COMP - scrambler.sys

    Did you give the application permission to pass thru the firewall? You should look how you had it setup in ZoneAlarm to work.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: KEYLOGGER help...still waiting

    BJ already looked at your log and wanted you to remove one of the AV programs. MSIMGSIZ.DAT is valid file (not a folder) that is typically associated with Internet Explorer. Where is yours located (give the full path)? It could also be related to other things like Total Control. See: http://www3.ca.com/securityadvisor/pest/pest.aspx?id=27271
     
  16. pamelaj

    pamelaj Private E-2

    they are located HERE...the MSIMGSIZ.DAT files

    My MSIMGSIZ.DAT folder is located here in all of these folders below and some are MSIMGSIZ.DAT.sbd

    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer\Trash.sbd

    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer

    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer

    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer\Trash.sbd

    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Internet Explorer

    NOTE: I have also have tvdebug.log in C:\WINDOWS\Internet Logs

    I seriously think someone is remotely controlling my computer.

    I am going to go KILL the things you asked, and be right back to post a new log.
     
  17. pamelaj

    pamelaj Private E-2

    YAHOO - to chasalang

    Well i deleted ZONE ALARM

    and cannot find any way to give AVG 7.0 permission for Yahoo. Note that Yahoo works, however, if the firewall is disabled.
     
  18. pamelaj

    pamelaj Private E-2

    Help Total Control Is Running

    Etrust SPYWARE encyclopedia is running - TOTAL CONTROL

    how do i get rid of this ???

    am i being monitored???
     
  19. pamelaj

    pamelaj Private E-2

    i was directed here to post from the security forum by chasalang.

    i have big problems

    i have the following appearing: MSIMGSIZ.DAT these are located in my trash folder in my Mozilla email, they are located in my internet explorer folder.

    I also have iexplore.exe trying to always run and then it runs this:

    Etrust Encyclopedia Spyware -TOTAL CONTROL I dont know what this is?

    when i when to the task kill, and tried to kill it.............some worms started being listed as processes running...

    my emails have been broken into, my passwords changed.......

    Please help? I have hijack this and I have followed all of the STICKY THREAD NOTES to do before posting a log.
     
  20. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: they are located HERE...the MSIMGSIZ.DAT files

    Those are all valid files.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: YAHOO - to chasalang


    You have to allow the program to have Internet access. Most firewalls (especially when first installed) popup a message the first time it sees any new (to it) application run and it will ask about allowing it to have internet access. You must have denied it. Or you need to do it manually.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Help Total Control Is Running

    What do you mean "Etrust SPYWARE encyclopedia is running - TOTAL CONTROL "? This makes no sense.


    Let's see a new HJT so we can determine where you stand with removing excess antivirus applications. I saw Avast, AVG7, and Symantect at one point. If you are not down to one antivirus application yet, do not post a log until you have uninstalled all but one AV.
     
  24. pamelaj

    pamelaj Private E-2

    Yes I downloaded tools and did the on line scans, and here are the results of the ON-LINE TROJAN SCAN below, it found THESE:

    c:\documents and settings\all users\application data\antispyinfo\mwso (adware. toolbar).

    c:\documents and settings\all users\application data\antispyinfo\mwss
    (adware. toolbar).

    c:\documents and settings\owner\cookies@statcountet(1).txt trace. tracking

    c:\program files\mozilla firefox\plugins\NPMywebs.dll
    (adware.toolbar).

    c:\windows\system32\f3PSSavr.scr
    (adware.toolbar).


    ALSO>>>>>>>>>>>>>my NEW LOG IS ATTACHED. Thank you So much.
     

    Attached Files:

  25. pamelaj

    pamelaj Private E-2

    Re: KEYLOGGER on my COMP - scrambler.sys

    okay...but what I meant was this: In the Task Manager WINdow, under APPLICATIONS RUNNING, last night, it said that Etrust Encylcopedia Spwyare was running......im not sure what it mean (unless my internet wasn't closed??)

    heres my new log.

    thank you for your time, and for your help.
     
  26. pamelaj

    pamelaj Private E-2

    Last edited: Jul 10, 2005
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: KEYLOGGER on my COMP - scrambler.sys

    Attach the log like you did in previous messages. Give it a different name than prevous ones.
     
  28. pamelaj

    pamelaj Private E-2

    Re: KEYLOGGER on my COMP - scrambler.sys

    My log
     
  29. pamelaj

    pamelaj Private E-2

    Re: KEYLOGGER on my COMP - scrambler.sys

    i cant get this log to post

    is the site not accepting logs?

    let me try again
     
    Last edited: Jul 10, 2005
  30. pamelaj

    pamelaj Private E-2

    Re: KEYLOGGER on my COMP - scrambler.sys

    Log Log Log Log
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are still in the Spyware Forum. I did not tell you to go anywhere else. Why are you starting a new thread. I'm merging you back to the other thread.

    Why are you still worrying about these files. I told you there is nothing wrong with them. They are valid Windows files.

    Also you do not have anything named: Etrust Encyclopedia Spyware -TOTAL CONTROL running. Total Control has nothing to do with Etrust. Where is it that you think you see Total Control and tell me exactly what you see. If you are referring to MSIMGSIZ.DAT, please read my messages again. This is not a problem.

    You still have Avast and AVG installed. Uninstall Avast now! Do not continue to ask for help unless you are going to follow instructions.
     
  32. pamelaj

    pamelaj Private E-2

    im sorry, i got lost. i always get in trouble here....its so confusing.

    heres my new log.

    thanks.

    i removed avast.
     

    Attached Files:

  33. pamelaj

    pamelaj Private E-2

    as far as TOtal Control...i found out that i had internet explorer open reading about it.......so it showed up as a running process/page.

    forget about it.

    thank you.



     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like Avast did not completely uninstall. You still have a service entry.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to avast! iAVS4 Control Service (or that is not found look for aswUpdSv )Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    avast! iAVS4 Control Service

    If that does not work, use the short name: aswUpdSv

    You will probably be told to reboot here, so reboot.
    And check to see if the below line is now gone from your HJT log.

    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (file missing)

    Other than that, you are clean.
     
  35. pamelaj

    pamelaj Private E-2

    okay i did everything you said, and it worked.

    heres my log for verification.

    hopefully i am clean thanks to you.

    my sincere respect to you.
     

    Attached Files:

  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Yes your all clean now. To help keep it that way make sure you go thru the steps in the below thread and perform the steps that you have not already done. For example, you can skip the antivirus and firewall steps since you already have them.

    How to Protect yourself from malware!
     
  37. pamelaj

    pamelaj Private E-2

    i have one problem with a program running since all of these adjustments.

    I use a SECURE program on line to transcribe work in for a local hospital and all of my keys are not working on this site.

    This site allows me to access pop up menus for doctor rosters, etc.

    the site is https://secure.bayscribe.com/cgi/tr and I access this program on line every day to type data into.

    the only problem I am having is this: When I am on line accessing this program, I should be able to press the "A" key to insert data.........and this is not working now. This is a required process for my work to submit successfully to their server.

    Could it be that I have blocked partial access to them through AVG 7.0???
    I cannot figure out how to configure this.

    I did go into AVG settings and add all of the .exe files from the program I use which is on my computer and allowed access to all .exe files, but it still does not work. I even told AVG to allow access to some of the .dll files from this program folder on my computer, but it still does not work.

    any ideas?

    I think i may have block partial network into this program?
     
  38. pamelaj

    pamelaj Private E-2

    the other thought is

    possibly while using Hijack this? something was disabled that would

    allow me to work on this server??

    thanks for listening.
     
  39. pamelaj

    pamelaj Private E-2

    ALSO, my help and support wont launch, which is where i can access

    my system restore if i need to undo any changes?

    Its my Hewell Packard System restore, it will not launch.
     
  40. pamelaj

    pamelaj Private E-2

    im sorry but my Help & SUpport Program will not even open

    I have no way to UNDO what has been done

    as far as System Restore now not working, and Help & Support not launching.

    SOmething needs to be undone.........to resolve this program.

    I hope you can help me resolve this last issue on my computer.

    I believe Hijack this or something else you had me do, has stopped access to a NT service that allows the HP Help & Support to Run, and also my program that i use for work.

    Its my only income to use that program and I cannot work.

    Im so sorry to hound you.
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    All I had you do with HijackThis is remove a left over service from the Avast antivirus application that you no longer needed. We did not remove anything else.

    You seem to be confusing HP Help & Support with System Restore. System Restore is part of Windows XP. When you ran the READ ME FIRST, the very first step was to disable system restore. If you did that, you would now need to go back and enable system restore. But there will be no old system restore points. That is the purpose behind disabling system restore. We are trying to remove old restore points that may contain malware because they could cause your PC to become reinfected.

    There is no reason anything we have done should be blocking you from pressing the 'A' key on your keyboard and having it sent to the site you are connecting to.

    There really is no such thing as a partial blocking of sites via your firewall. You could try disabling your firewall and see if it helps. You could also going back to step 7 of the How to protect thread, but instead of using those settings, try clicking Restore Defaults.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds