Unknown sneaky keylogger (HELP!)

Discussion in 'Malware Help (A Specialist Will Reply)' started by SulpherDragon, Jun 19, 2008.

  1. SulpherDragon

    SulpherDragon Private E-2

    Hi, ive come across a very very sneaky keylogger. Its logging every site I visit in IE to C:\Documents and Settings\Anthony\Local Settings\Temp\$.ficn$

    Ive noticed other people with it, this guy got his solved, or at least he thinks he does. http://forums.majorgeeks.com/showthread.php?t=152593&highlight=at+wit's+end

    Ive opened Process Explorer and noticed the following habits. Nothing happens until i run IE, but when i do, another process called IE is created as a child of that. Then soon after, Kaspersky notices it trying to call "iexplore -tt 2068", the parameter -tt is always the same and the number is always the PID of the IE process. This happens every 10-20 seconds from then on.

    Kaspersky also notes that its making loads of registry entries, ive checked these out and it seems like its trying to propogate via USB drives, its changing loads of autorun parts.

    SuperAntispyware found a few malwares but their all old things from previous XP backups, ive never even gone into them since, this is a 2 month old XP install with SP3.

    Ive followed the FAQ's, I still have this keylogger. Searches dont turn up anything. Please help!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this system part of a business?

    You need to not use cracks:
    C:\Documents and Settings\Anthony\Desktop\WRACKBPC.v3.0.0.Beta
    C:\Documents and Settings\Anthony\Desktop\WRACKBPC.v3.0.0.Beta.rar
    Please remove them.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. SulpherDragon

    SulpherDragon Private E-2

    Thanks very much for trying to help, but ive solved the problem. Its a long story but ive been chasing a malware that never existed. The logs that were being made were part of an addon i was using (and have been for a long time), a recent undocumented version update was logging certain details of websites to C:\Documents and Settings\Anthony\Local Settings\Temp\$.ficn$

    And on a side note:
    These are not cracks. And this is my personal computer.

    Sorry to have botherd you, I value the time youve spent trying to help me. Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds