Well I might have accidently clicked on it, extracted it, and launched it.
Well it disappeared on my desktop and it most likely might be running or not. But I still want to know for sure if I have a keylogger and if I do, how to delete it.
While I was reading earlier posts, I came across a couple of people who have the same issue as me: http://www.geekstogo...er-t171303.html
http://www.geekstogo...-D-t171375.html
Here's my log:
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\McAfee\MPS\mpsevh.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\program files\mcafee\msc\mcshell.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...h...TB&M=ML3109
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.c...h...TB&M=ML3109
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.c...h...TB&M=ML3109
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.c...h...TB&M=ML3109
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [BigFix] c:\program files\Bigfix\bigfix.exe /atstartup
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: McAfee Application Installer Cleanup (0058961190237529) (0058961190237529mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP�5896~1.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
I did the AVG Scan Result, and here's the log:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:19:25 PM 9/19/2007
+ Scan result:
:mozilla.72:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.86:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.87:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.88:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.89:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.90:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.70:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.82:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.16:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.15:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.24:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.25:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.26:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.27:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.28:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.79:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.17:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.36:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.37:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.38:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.39:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.40:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.41:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.42:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.43:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.44:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.144:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.80:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.81:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.91:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.7:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.83:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.84:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.85:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.64:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.65:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.66:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.67:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.68:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.69:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.100:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.96:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.97:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.98:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.99:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.123:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.95:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.29:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.30:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.31:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.32:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.33:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.34:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.35:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.56:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.57:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.58:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.59:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.60:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.61:C:\Users\Stephanie\AppData\Roaming\Mozilla\Firefox\Profiles\d7twbcep.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
::Report end
Edited by xLunax, 20 September 2007 - 05:29 AM.