Author Topic: Keylogger  (Read 1770 times)

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Keylogger
« Reply #20 on: May 26, 2007, 05:41:10 PM »
We removed Netbus Pro folder, some programs just refuse to go away the uninstall method

Let's remove it from add/remove programs list

Open Hijackthis>>Open Misc tools section>>Open Uninstall Manager
Hightlight NetBus Pro and then select "Delete this entry"
Ok the prompt

How are things running?
« Last Edit: May 26, 2007, 05:41:45 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
Keylogger
« Reply #21 on: May 26, 2007, 05:43:11 PM »
ok its gone we can run some final steps as u said
« Last Edit: May 26, 2007, 05:44:30 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Keylogger
« Reply #22 on: May 26, 2007, 06:00:41 PM »
By the way, AVG looks like it quarantined the related uninstaller .dll
That's probably the main reason it won't uninstall, it is probably safer removing manually as we did
Some programs don't like to wholely remove anyways

Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Find and delete these files/ folders
FILES
c:\findlop.txt <-file
C:\ComboFix-quarantined-files.txt
C:\ComboFix2.txt
C:\NoLop.txt
Dr.Webcureit.exe on desktop
Combofix.exe on desktop

Folders:
C:\_OTMoveIt
C:\Documents and Settings\Ahmed\DoctorWeb
C:\Combofix
C:\Qoobox
C:\NoLopBackups

Reset Windows to Hide hidden files and folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Do Not Show hidden files and folders.
    * Check the Hide protected operating system files (recommended) option.
    * Click OK.

If everything is running better
Go to START>>All Programs>>Accessories>>System Tools>>System Restore
Create a New restore point
Give it a name and click Create
When that's done

Go to START>>RUN>>type the following
cleanmgr
Hit OK
Let if finish calculating

Select the More Options tab
and click Cleanup.. under 'System Restore'
This will clear all later restore points except for the one you just made

Ok the prompts, it may take a few seconds to remove old restore points
Ok again after it's ready and let it finish cleaning

You should give your computer a bit more protection
Install
SpywareBlaster 3.5.1 by JavaCool  
    *Will block bad ActiveX Controls
    *Block Malevolent cookies in Internet Explorer and Firefox
    *Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates
After updating, select "Protection" on the Left
Then select "Enable all Protection"
"Check for updates every couple of weeks"
after every update just simply click the "enable protection on all unprotected items"

 Spybot 1.4, this is a free spyware scanner, I suggest that you install it and keep it
You can download it from
HERE

Install with default settings that are selected
After installation--Click the UPDATE button on the left
SEARCH FOR UPDATES on the right
RIGHT CLICK in the download results and click Select All
OR
Individually Check, and then download all updates
Ensure all updates are successful, a GREEN check will indicate this
If you have an error updating, search for updates again and retry the download until all updates are successfully installed
After update is complete

Click the "Search & Destroy" button on the left
"Check for Problems"---When the Scan is complete
FIX all selected promblems in RED

RESTART the computer to finish any cleaning process
In addition, utilize the Immunization feature
After every update
Click the "Immunize" button>>OK the prompt>>Immunize again at the top green cross

If there are other user profiles on the computer, have them login and enable all protections with Spywareblaster
and Immunize with Spybot after every update

Be very careful what you download, before you open a file, right click on it and scan it with your Virus scanner

I hope that helps
« Last Edit: May 26, 2007, 06:01:42 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
Keylogger
« Reply #23 on: May 26, 2007, 06:26:26 PM »
i tryed for along time to download spyware blaster from most of the links and it dosnt work
« Last Edit: May 26, 2007, 06:30:17 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Keylogger
« Reply #24 on: May 26, 2007, 06:30:41 PM »
« Last Edit: May 26, 2007, 06:31:55 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
Keylogger
« Reply #25 on: May 26, 2007, 07:12:49 PM »
ok i done everything finally is my comp safe now?
« Last Edit: May 26, 2007, 07:48:39 PM by guestolo »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Keylogger
« Reply #26 on: May 26, 2007, 07:49:22 PM »
[quote name=\'Moe C\' post=\'331268\' date=\'May 26 2007, 05:12 PM\']ok i done everything finally is my comp safe now?[/quote]

Should be, but I asked this question 3 or 4 times and you never gave me a reply
HOW IS EVERYTHING RUNNING NOW>>????

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Moe C

  • Hero Member
  • *****
  • Posts: 1280
  • Karma: +0/-0
    • View Profile
    • http://
Keylogger
« Reply #27 on: May 26, 2007, 07:51:59 PM »
sry yea i noticed that

it was slow when i downlaoded all the stuff u told me but now its ok

THX ALOT U R BEST


all done in 1 day
« Last Edit: May 26, 2007, 07:55:52 PM by Moe C »
I'm a scammer right? Ban me



OK


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Keylogger
« Reply #28 on: May 26, 2007, 07:56:20 PM »
Good work
Remember, be careful on what you download

Keep AVG updated and occasionally let it scan your computer

I'll lock this topic as your problems appear to be resolved
Take care Moe C

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here