Re: Keylogger.Trojan

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 05/18/05


Date: Wed, 18 May 2005 09:47:46 -0400

From: "ImNewb" <ImNewb@discussions.microsoft.com>

| Hi.... I need help here... Yesterday, when I turned on my PC, I got pop up
| from Norton Anti Virus 2003 that C:\Windows\System32\mdmm.dll infected by
| Keylogger.Trojan and NAV can't clean it also access to the file is denied. I
| already try turn off system restore, delete all cookies and temp. files.
| Restart my PC in safe mode then using housecall.trendmicro complete scan,
| Spybot S&D, TSD-3. Nothing can clean the trojan.
| But, trendmicro detected the trojan in C:\Windows\System32\explorer.dll (
| same with McAfee ) and not in mdmm.dll... How can this happen ? Anybody can
| help me how to clean this trojan ? Thanks in advance. Oh, anyway im using
| WinXP Home Edition SP2
|
| Hid

There are anti virus News Groups specifically for this type of discussion.

microsoft.public.scripting.virus.discussion
microsoft.public.security.virus
alt.comp.virus
alt.comp.anti-virus

First try the following....

Dump the contents of the IE Temporary Internet Folder cache (TIF)
Start --> Settings --> Control Panel --> Internet Options --> Delete Files

Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear

Reboot your PC into Safe Mode and shutdown as many applications as possible.
It would also help for you to read - "How to perform a clean boot in Windows XP"
http://support.microsoft.com/kb/310353

Using your NAV software, perform a Full Scan of your platform and clean/delete any infectors
found

If that doesn't work please perform the following...

Download CLEAN.EXE from the URL --
http://www.ik-cs.com/programs/virtools/clean.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter
{ http://kixtart.org Kixtart is CareWare } three batch files, two Kixtart scripts, two Link
(.lnk) files and a PDF instruction file.

GETFILES.BAT -- For downloading (FTP) the files needed to run the McAfee Command Line
Scanner. If you are using Windows XP, you may have to disable the Windows XP FireWall to
allow the FTP utility to download the needed files

CLEAN.BAT -- For running within Windows after running c:\mcafee\GetFiles.BAT. If you choose
to scan again at a future date, run this batch file. It will automatically check the date
of the McAfee DAT files and if it is a couple of days old, it will download (FTP) the latest
signature files and install them before performing the scan.

DOSCLEAN.BAT -- For use on a Win9x/ME PC or on a Win2K/WinXP PC that is using FAT32 after
you have booted from an Emergency Boot Disk or DOS disk and have already executed;
c:\mcafee\GetFiles.BAT from within Windows. DOS disk boot images can be obtained from;
http://www.bootdisk.com/bootdisk.htm

I need you to perform the following...

Execute; CLEAN.EXE
Choose; Unzip
Choose; Close

Execute; c:\mcafee\GetFiles.BAT
{ or Double-click on 'GetFiles Link' in c:\mcafee }

Reboot the PC into Safe Mode [F8 key during boot]

Shutdown as many applications as possible !
It would also help for you to read - "How to perform a clean boot in Windows XP"
http://support.microsoft.com/kb/310353

Execute; c:\mcafee\CLEAN.BAT
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\ScanReport.HTML will be generated. At the
end of the scan, it will be displayed in your browser (Opera, FireFox or Internet Explorer).
It is suggested that you move the report out of c:\mcafee before performing another scan.
It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.

* * * Please report back your results * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: Nothing on screen?
    ... hour trying to boot in safe mode. ... As a last resort I was going to try to do the repair installation of windows ... Go into the System BIOS - can you get around in the System BIOS? ... Exit System BIOS and boot the System in Safe Mode again. ...
    (microsoft.public.windowsxp.general)
  • Re: HP 1310n (AMD ATHON Processor and SP3 UPDATE
    ... Continual reboots or can only boot into Safe Mode after installing WinXP SP3? ... into normal (Windows) mode. ... Creating a backup copy of the registry for MicrosoftWindows XP: ...
    (microsoft.public.windowsupdate)
  • Re: HP 1310n (AMD ATHON Processor and SP3 UPDATE
    ... Boot into Safe Mode and rename INTELPMM.SYS to INTELPMM.OLD. ... MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002 ... Creating a backup copy of the registry for MicrosoftWindows XP: ...
    (microsoft.public.windowsupdate)
  • Re: HP 1310n (AMD ATHON Processor and SP3 UPDATE
    ... This is for only being able to boot in the safe mode after installing SP3. ... MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002 ... Creating a backup copy of the registry for MicrosoftWindows XP: ...
    (microsoft.public.windowsupdate)
  • Re: XP will not load; how to back up data?
    ... When you boot in safe mode, what is the last driver loaded before it hangs? ... Failing that, get a Windows XP setup CD, boot on it. ... > A coworker suggested that I try to get to a command prompt and then copy ...
    (microsoft.public.windows.mediacenter)