Re: cant find or remove perfection keylogger

From: Malke (malke_at_nospoonnotreally.com)
Date: 01/31/05


Date: Mon, 31 Jan 2005 05:23:03 -0800

Beyonder wrote:

> I hope someone can help with this.
>
> I seem to have this "perfection keylogger" installed on my system
> somehow. but none of the utilties I've run can seem to find it or
> remove it. seems to have been installed by adware or trojan or worm
> through IE.
>
> I fouhd it through some notice because norton antivirus 2005 pro
> popped up with a message saying that "perfection keylogger" could not
> send an email because the email was too large. that was the only way I
> knew it even existed.
>
> but norton 2005 pro even with the latest updates, intelligent updater,
> spybot, spyware doctor, ad aware SE Pro, and microsoft anti-spyware,
> none of these utilities will even FIND this thing, let alone remove
> it.
>
> does anyone have a way of finding this stupid thing and removing it?
> please send email ASAP
>
> i already have to change every password I use because of this. even
> though the email was blocked, who knows what was leaked. and even
> though I know the email it was sending to was invalid, its still
> better safe than sorry.
>
> funny thing is, internet firewall, zone alarm and norton internet
> security wont stop this thing. Only way I finally prevented it totally
> is to put an access rule on my router. so now its totally impossible
> for any logger or other software to send email at all.
>
> of course I can send email, but the access control is done in a way
> that a logger never could.
>
> any help would be appreciated! ASAP! thanks!

In ZA's logs and programs list, do you find anything about this malware?
Something that would allow you to locate it? Try running HijackThis and
post your log at one of the permitted sites (not this newsgroup) below.
I suggest the Aumha forums since the people there are friendly and
extremely expert.

http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Jim
Eshelman
http://aumha.net - forums
http://spywarewarrior.com/viewforum.php?f=5 - Spyware Warrior HijackThis
forum
http://www.wilderssecurity.com/
http://forums.tomcoyote.org/

Also please note that although I am very sympathetic to your plight,
crossposting to so many newsgroups is not a good idea. Usually four is
the top limit.

Malke

-- 
MS MVP - Windows Shell/User
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"


Relevant Pages

  • Re: IE6 Problems
    ... by A NOVICE WHO POSTS THE LOGS TO THE HIJACKTHIS FORUMS FOR OTHERS TO SORT ... Before HijackThis we were doing it just fine; HJT made it easier for ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: IE6 - MSHTML.DLL browser keeps crashing!
    ... It is one of the most valuable troubleshooting tools and it can often point to still existing residual files that are left behind or broken by the malware or even sometimes removal tools. ... If you have already posted a HijackThis log, please post the link here in this thread to the forum where you posted it so that we can take a look and see what is happening and follow along with the progress. ... If you have not yet done so, please install and run the HiJackThis in Safe Mode with Hidden files enabled, create a log and post it to one of the following forums. ... Then,>> after the automatic updates updated the system, the problem came>> back. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: FYI: Security Problems Plague XP SP2 via Symantec/McAfee
    ... ZoneAlarm PRO. ... Also, ZoneAlarm ... :>> Norton System Security, Norton Utilities, etc. are another thing ... :>> Symantec has definitely lost their reputation in the past 5 years or so. ...
    (microsoft.public.windowsxp.general)
  • Re: IE7 Uninstall & regedit
    ... That's what those specialty forums are for. ... Looked for the WORM and could not find it in safe mode. ... Apart from the cmd and other shortcuts not working Symantec will not ... Forums to Interpret HijackThis Logs: ...
    (microsoft.public.windowsxp.general)
  • Re: Ok, so Im a lazy moron - Explorer crashes at startup
    ... >> Reboot into Windows. ... >> run HijackThis (no other windows open) and save the log. ... >> AumHa Forums ...
    (microsoft.public.windowsxp.general)