Magekíd’s guide: How to CLEAN your PC from keyloggers.
Hi all, this guide will help you on how to clean your pc from keyloggers.
Please take a look.
Screenshots have now been added!!!
English is not my mother tongue, so some things are hard for me to explain, but I think i’m doing a good job, in general ^^
First of all, a note: Hijackthis is a tool, used for finding infections in your computer. Please note: THIS IS NOT A SCANNER. It shows both malicous rules, but also LEGIT rules. Do not fix rules in Hijackthis yourself!
You can find a list of forums that are qualified to look at your Hijackthis log here: ASAP
In addition, here’s a list of forums where you can post your hijackthis logfile. – If you know any others, please let me know in a comment/reply!
Recommended
Jame’s Technical Support Forum <– I can take a look at your log there 🙂
Dutch/Belgium:
http://www.hijackthis.nl/forum
http://www.minatica.be/forum.php
http://www.antispywareoffensief.nl/forum/
English:
http://www.spywareinfoforum.com/
http://forums.techguy.org/
http://www.techsupportforum.com/
Before posting a Hijackthis log, please do the following steps upfront. I know this is alot of work, but that way most malware is already deleted and your logfile can be looked at faster.
Please remember: Follow ALL steps, including step 7
Note: Vista Users must run installations and the downloaded programs as Administrator. You can do this by right-clicking the program and select Run as Administrator (The screenshot shows it for Hijackthis, You must use this for every program we use here)
1. Download ATF Cleaner here: http://www.atribune.org/ccount/click.php?id=1 – and save it somewhere (Desktop for example)
– Start ATF Cleaner and check everything except “Prefetch” at the tab “Main“. Then press “Empty Selected”
– If you use Firefox as your browser, go to the Firefox tab and check everything except “Firefox Saved passwords”. Then press “Empty Selected”
– If you use Opera as your browser, go to the Opera tab and check everything except “Saved Passwords“. Then press Empty Selected.
2. Download Ad-aware 2008 Free here – and install it. If you get an license note during the installation, press Use Free After the installation, start Ad-Aware and press Update.
When Ad-Aware is finished updating, press Scan and do a Full system scan
When the scanning is completed, You’ll see two tabs with infected objects. The first tab contains Critical Objects and the second tab Privacy Objects Check everything at both tabs and press Remove At the top of both tabs you see a number which says the amount of infections found. Please wait until both numbers say “0” and then press Complete.
Close Ad-Aware
3. Download Spybot Search & Destroy here: http://www.safer-networking.org/en/mirrors/index.html – and install it. During the installation, uncheck “Use Internet Explorer protection (SDHelper)” and “Use system settings Protection (TeaTimer)”
When the installation is completed, start Spybot S&D and press OK at the notice you get about Ad-Aware. It may also notify you about deleting temporary files. Just select yes Follow the Wizard, and when the wizard is done press Update in Spybot. Search for updates, check all available updates and install the updates. After that press the Immunize tab and Immunize your system. When the Immunization is done, press the Search & Destroy tab and start scanning your computer.
When Spybot S&D is done scanning. Check all found objects and press Fix Selected Problems.
If Spybot S&D cannot delete all found objects, it will ask if it can scan at the next reboot to fix the problems. Press Yes.
Now close Spybot S&D.
4. Download MBAM (MalwareBytes’ Anti-Malware) here: http://www.besttechie.net/tools/mbam-setup.exe – and install it. Make sure that at the end of the installation, Update MalwareBytes’ Anti-Malware and Start MalwareBytes’ Anti-Malware is checked.
When MBAM is started. Go to the Scanner tab and do a Full scan
Once MBAM is done scanning, press Show Results and make sure all found objects are selected. After that press Remove Selected
When MBAM is done deleting objects a logfile will open. You can close this logfile.
The Logfile will automatically be saved at the Logs tab in MBAM.
If MBAM found objects that can’t be deleted, it will ask to reboot your computer. Allow this and restart your computer.
4. If you didn’t restart your computer after running MBAM, restart it now anyway.
5. Do a full system scan with your virusscanner and remove all found infections.
If you do not have a virusscanner, you can scan online with one of these scanners. (Use Internet Explorer to scan)
BitDefender: http://www.bitdefender.com/scan8/ie.html
Panda: http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Kaspersky: http://www.kaspersky.nl/scanner
Remove all infections found.
6. Restart your computer.
7. Download Hijackthis here: http://download.bleepingcomputer.com/hijackthis/HJTInstall.exe – and install it. After the installation Hijackthis will open. Press Do a systemscan and save a logfile.
A notepad file will open. In the Notepad file, press CTRL + A to select everything, CTRL + C to Copy everything. Then press CTRL + V in a new topic at the forum you want to post the log.
Also paste the MBAM log on the forum you place the Hijackthis logfile.
Many thanks for reading, if you have questions or problems, please ask 🙂
Also: Please note: Doing this all, is NOT A GUARANTEE your computer is not infected. There is no scanner that has a 100% detection rate.
– Magekid
Image too bigThe spybot screenshot is too big so it messes up the page’s display.
Size it down please :p
Firefox problemsI followed your guide but now i cant go to a bunch of sites in firefox or they bot load properly. I reinstalled firefox and still the same problem. Can u give me some sugestions.
Nice improvementsNice improvements 🙂
Updated with screenshotsThe guide has now been updated with screenshots 🙂
Enjoy!
– Magekíd
ThanksHi all,
Thanks for the replies.
– Combofix: This is a very powerful program. Generally, it’s not advised unless a Hijackthis-Logfile reader asks it. (Because it can harm your system if not used properly)
– CCleaner: ATF cleaner does pretty much the same, but ATF Cleaner is much smaller 🙂
CCleaner/ATF cleaner does help though: Alot of keyloggers(or.. malware in general)save themselfs in the temporary folders. CCleaner/ATF cleaner empties these folders 🙂
– Magekíd
Yeah CCleaner really is aYeah CCleaner really is a nice program, altough I don’t really think that it has the capability to help against keyloggers that much 😛 Oh and I never analyze before i run it, analyze takes more time than the actual cleaning, and I don’t really see why you should analyze.
-Because I can, the only reason I need
Nice guideI see you have put effort on this guide. There’s few things you could add to this guide:
Combofix
Download Combofix.
Doubleclick Combofix.exe and follow instructions.
When program is ready it produces a log. Post this to forums
PS. Dont click combofix.exe window while it’s scanning your computer. It may cause freeze.
CCleaner
Download and install CCleaner. It’s useful little program wich removes trash from your computer.
Select Cleaner tab and then “Analyze”.
When it’s done select “Run Cleaner”
Also you can do same for Registry, just remember to backup your registry before doing so!!
Also I don’t take any responsibility if your computer goes crazy (wich of course shouldn’t happen)
That’s all for now I think..
Keep it up mate. 🙂
Quite useful, for anyoneQuite useful, for anyone playing wow, or more generally for anyone using a PC 🙂
Thanks.