Computing.Net > Forums > Security and Virus > trojan keylogg

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

trojan keylogg

Reply to Message Icon

Name: macattack03
Date: May 19, 2009 at 12:35:49 Pacific
OS: Windows Vista
Product: Hp pavilion dv6000 / NOTEBOOK
Subcategory: Viruses
Comment:

I've scanned over and over the infection is still here and its driving me MAD!! Please help here is the file I know that is on my computer along with others

Trojan-GameThief.Win32.Nilage.ezr

located c:\windows\system32\config.exe


used spyware a&d
malware bytes
avg free
symantec free by the military

nothing has cleaned my computer I've lost my world of warcraft due to this horrible keylogger I need some help please



Sponsored Link
Ads by Google

Response Number 1
Name: jdk (by neoark)
Date: May 19, 2009 at 12:43:05 Pacific
Reply:

Hi,
Can you please post your AVZ log:

1) To create the logfile, download AVZ by clicking HERE. Please save this file to your desktop or "My Documents" folder.

2) Next, unpack the file to a new folder using the Compressed (zipped) folders wizard built into Windows XP/Vista, or a zip utility of your choice.

3) Once you have unpacked the contents of the zip archive, please launch the file AVZ.exe by double clicking on it or right clicking and selecting Open.
Note: If you are running Windows vista launch AVZ.exe by right clicking and selecting Run as Administrator

You should now see the main window of the AVZ utility. Please navigate to File->Custom Scripts. Copy the script below by using the keyboard shortcut CTRL+C or the corresponding option via right click.

begin
ExecuteStdScr(3);
RebootWindows(true);
end.

Paste the script into the execution window by using CTRL+V keyboard shortcut, or the "paste" option via the right click menu. Click on Run to run the script, the PC will reboot. After the reboot the LOG subfolder is created in the folder with AVZ, with a file called virusinfo_syscure.zip inside. Upload that file to rapidshare.com and paste the link here.

Image Tutorial

--------------------------------------------
To Private Message me Click Here


0

Response Number 2
Name: macattack03
Date: May 19, 2009 at 13:09:59 Pacific
Reply:

http://rapidshare.com/files/2349264...


here is the link i just would like to also add that i have scanned the computer using windows defender i believe this is another infected file

c:\windows\system32\kb123386.exe


0

Response Number 3
Name: jdk (by neoark)
Date: May 19, 2009 at 13:41:03 Pacific
Reply:

Run this script in AVZ same way as before. Your computer will reboot.


begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
 TerminateProcessByName('C:\Windows\system32\lpad32.dll');
 QuarantineFile('C:\Windows\system32\lpad32.dll','');
 QuarantineFile('C:\Windows\system32\KB123386.EXE','');
 DeleteFile('C:\Windows\system32\KB123386.EXE');
 DeleteFile('C:\Windows\system32\lpad32.dll');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

After your reboot follow these steps:

Attach a Combofix log, please review and follow these instructions carefully.

Download it here -> ComboFix

Before Saving it to Desktop, please rename it to something like 123.exe to stop malware from disabling it.

Now, please make sure no other programs are running, close all other windows and pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) until after the scanning and removal process has taken place.

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan. Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt, please attach it to your next post.

--------------------------------------------
To Private Message me Click Here


0

Response Number 4
Name: macattack03
Date: May 20, 2009 at 02:44:38 Pacific
Reply:

the bleepingcomputer link doesnt work it takes me to a broken page please relink it thanks


0

Response Number 5
Name: jdk (by neoark)
Date: May 20, 2009 at 05:21:30 Pacific
Reply:

Link fixed try again.

--------------------------------------------
To Private Message me Click Here


0

Related Posts

See More



Response Number 6
Name: macattack03
Date: May 20, 2009 at 07:25:54 Pacific
Reply:

here is the file from the combofix scan

http://rapidshare.com/files/2352169...


Thank you so much for your time and help


0

Response Number 7
Name: jdk (by neoark)
Date: May 20, 2009 at 07:44:24 Pacific
Reply:

Run this script in AVZ you PC will reboot:


begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('c:\windows\system32\cas.bat','');
DeleteFile('c:\windows\system32\cas.bat');
QuarantineFile('c:\windows\SA41289D5.tmp','');
DeleteFile('c:\windows\SA41289D5.tmp');
QuarantineFile('c:\users\Brandon\AppData\Local\Temp\catchme.dll','');
DeleteFile('c:\users\Brandon\AppData\Local\Temp\catchme.dll');
BC_ImportAll;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

After Your PC reboots. Rerun Combofix from Response number 3 and repost combofix log.

--------------------------------------------
To Private Message me Click Here


0

Response Number 8
Name: macattack03
Date: May 20, 2009 at 08:43:53 Pacific

Response Number 9
Name: jdk (by neoark)
Date: May 20, 2009 at 10:24:14 Pacific
Reply:

Please follow these steps in order:

1) Run this script in AVZ:


begin
CreateQurantineArchive('c:\quarantine.zip');
end.

2) A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\quarantine and upload both it and C:\quarantine.zip to a filehost such as http://rapidshare.com/ Then, Private Message me the Download link to the uploaded file.

3) Lastly, uninstall Combofix by: pause Antivirus/Sypware programs (http://www.bleepingcomputer.com/forums/topic114351.html Programs to disable) > Start > run > type combofix /u > ok. Or Start > run > type 234 /u > ok.

4) Also, if you use Windows System restore, turn it off > reboot.

Download and run Kaspersky AVP tool:

http://devbuilds.kaspersky-labs.com...

Once you download and start the tool select all the objects/places to be scanned and hit Scan. Fix what it detects and at the end of the scan post screen shot/log of detected items that is fixed and which it could not fix.

Then turn system restore back on, if you wish; this to remove malware from system volume information files. How to turn it off/on: http://support.kaspersky.com/faq/?q... Let me know if your antivirus still detects anything and is unable to get rid of it.

5) Install, update and run full scan with Malwarebytes' Anti-Malware. Attach malwarebyte full scan log, but Please Don't fix anything yet, until the log is reviewed. You can also use superantispyware from superantispyware.com.

--------------------------------------------
To Private Message me Click Here


0

Response Number 10
Name: jdk (by neoark)
Date: May 21, 2009 at 04:21:55 Pacific
Reply:

Please continue with step 5. After you finish step 5 report back if your original problem is solved or not. Thanks

--------------------------------------------
To Private Message me Click Here


0

Response Number 11
Name: macattack03
Date: May 21, 2009 at 09:08:19 Pacific
Reply:

im not getting anything with malware, spybot, and the av i have installed so im thinking we fixed the problem thanks for your help


0

Response Number 12
Name: macattack03
Date: May 21, 2009 at 09:26:04 Pacific
Reply:

just noticed another problem with my notebook after running the fix software and rebooting an then double checking everything with the av, malware and spybot i no longer have a cd rom drive in my computer and when i put in a cd rom its not detecting it ??


0

Response Number 13
Name: jdk (by neoark)
Date: May 21, 2009 at 09:31:56 Pacific
Reply:

Go to Control Panel --> Add/Remove hardware and see if it found any new hardware.

--------------------------------------------
To Private Message me Click Here


0

Response Number 14
Name: macattack03
Date: May 21, 2009 at 22:16:33 Pacific
Reply:

did you get my last pm about it is saying that it detects the drive however there is the error symbol on it and once you uninstall and reinstall it is saying the problem is with the registry or a damaged file


0

Response Number 15
Name: jdk (by neoark)
Date: May 22, 2009 at 04:01:09 Pacific
Reply:

Did you get my message asking you go post screen shot of it and aslo go to Administrative tools --> Computer Management --> Device Manager --> Select the hardware thats not working --> right click properties --> select Details tab and post screen shot of it.

--------------------------------------------
To Private Message me Click Here


0

Response Number 16
Name: macattack03
Date: May 22, 2009 at 06:52:18 Pacific
Reply:

nope i never got that message but here it is now i think some how we didnt get each other's last message

http://rapidshare.com/files/2359656...


0

Response Number 17
Name: jdk (by neoark)
Date: May 22, 2009 at 08:01:22 Pacific
Reply:

Click on detail tab and take screenshot again.

--------------------------------------------
To Private Message me Click Here


0

Response Number 18
Name: macattack03
Date: May 22, 2009 at 08:15:36 Pacific

Response Number 19
Name: jdk (by neoark)
Date: May 22, 2009 at 08:29:06 Pacific
Reply:

From that Tab select "Hardware Ids" Take another screen shot.

--------------------------------------------
To Private Message me Click Here


0

Response Number 20
Name: macattack03
Date: May 22, 2009 at 08:54:14 Pacific

Response Number 21
Name: jdk (by neoark)
Date: May 22, 2009 at 09:05:03 Pacific
Reply:

Try this first before we try Manual Regedit. Uninstall CD drive from device manager (right clikc in device manager uninstall Completely) completely including drivers. Then go to http://onecare.live.com/site/en-Us/... & http://onecare.live.com/site/en-Us/... Run those scans. After that go to add/remove new hardware and reinstall the CD drive. Also its advisable to do the scan with AVP to remove leftover files.

--------------------------------------------
To Private Message me Click Here


0

Response Number 22
Name: macattack03
Date: May 22, 2009 at 11:30:14 Pacific
Reply:

as im letting these programs run is it safe to try to run any programs on my computer without having any more problems i.e world of warcraft i dont have a keylogger or anything right ??


0

Response Number 23
Name: jdk (by neoark)
Date: May 22, 2009 at 11:39:15 Pacific
Reply:

Run kaspersky and Eset online antivirus scanners to be sure.

--------------------------------------------
To Private Message me Click Here


0

Response Number 24
Name: macattack03
Date: May 22, 2009 at 11:54:16 Pacific
Reply:

which are those the same you posted before can u post links so i make sure i run the right ones thank you again for your help


0

Response Number 25
Name: jdk (by neoark)
Date: May 22, 2009 at 11:58:43 Pacific
Reply:

1) http://www.eset.com/onlinescan/

2) http://usa.kaspersky.com/products_s...

--------------------------------------------
To Private Message me Click Here


0

Response Number 26
Name: macattack03
Date: May 22, 2009 at 13:49:18 Pacific
Reply:

I have discovered that the quickest and easiest fix for the dvd rom drive missing is @ this link I do want to thank you again for all your help

http://support.microsoft.com/kb/314060


0

Response Number 27
Name: jdk (by neoark)
Date: May 22, 2009 at 13:59:32 Pacific
Reply:

No problem Please scan with Response Number 25 then scan with superantispyware. This is to remove leftovers from keylogger. Post results of scan to rapidhsare.com.

--------------------------------------------
To Private Message me Click Here


0

Response Number 28
Name: macattack03
Date: May 23, 2009 at 06:49:51 Pacific
Reply:

didnt get anything showing up with the first link and for some reason kasperspy was giving me problems and then when trying to download superantispyware it gave me an error message too not sure if its the internet here in iraq for downloading or what because they have weird restrictions and downloading limits out here


0

Response Number 29
Name: jdk (by neoark)
Date: May 23, 2009 at 06:57:28 Pacific
Reply:

What kind of problem with kaspersky and error message with superantispyware you got?

--------------------------------------------
To Private Message me Click Here


0

Response Number 30
Name: macattack03
Date: May 23, 2009 at 10:59:25 Pacific
Reply:

i dont remember what kaspersky was saying but the other one was an error about an h:/ drive or something not found i think im good the computer is acting alot better and i've tried out one of my wow accounts nothing bad so far keep our fingers crossed


0

Sponsored Link
Ads by Google
Reply to Message Icon

My Computer Online Scan -... system restore wont let m...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: trojan keylogg

trojan keylogger www.computing.net/answers/security/trojan-keylogger/791.html

Trojan-keylogger.win32.agent help www.computing.net/answers/security/trojankeyloggerwin32agent-help/26609.html

Virus/Trojan/Keylogger HELP! www.computing.net/answers/security/virustrojankeylogger-help/18408.html