Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Points Site Spy New Posts Donate Unanswered Posts Search Forum Rules


Reply
 
LinkBack Thread Tools
  #1  
Old 31st Jul 2007, 11:21 PM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Exclamation Perfect keylogger

HELPHELPHELP anyone please, i was running spybot (search and destroy) which discovered that i have perfect keylogger installed. i have looked online for a solution and even programs to unistall it but its still there. i followed instructions online to delete registry strings but it keeps coming back!!!

please anyone with any knowledge on this matter your help will be very much appreciated.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #2  
Old 31st Jul 2007, 11:53 PM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

This is a commercial keylogger and hard to remove. Have you downloaded anything lately like a p2p program? Limewire for example.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #3  
Old 1st Aug 2007, 12:22 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

Also
Download HijackThis . http://www.trendsecure.com/portal/en...hijackthis.php
Once you have it downloaded install/save it to it's own folder.
For example C:\program files\hijackthis
Once installed open the program and select Do a system scan and save logfile.
Save the log as a .txt file.
In the next post click Go Advanced.
Scroll down to manage attachments and add the log as an attachment.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #4  
Old 1st Aug 2007, 12:42 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

i hope that i have done everything right, the file should be attached. i did download from a p2p site i downloaded Nero Smartsuite from mininova.

many thx
Attached Files
File Type: txt hijackthis.txt (6.9 KB, 14 views)
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #5  
Old 1st Aug 2007, 01:05 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

You got the log OK but didn't install HijackThis to it's own folder. If you run it from the desktop it will not create the proper backups when doing repairs. Please do this and run a new scan.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #6  
Old 1st Aug 2007, 01:13 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

I have made a folder in C:\program files called hijackthis and then downloaded the program again to this folder and run it. attached is the log file that it created.

thx
Attached Files
File Type: txt hijackthis.txt (5.0 KB, 8 views)
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #7  
Old 1st Aug 2007, 02:02 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

I dont know if it helps but when i was looking online for a way to deleted or unistall this there where instruction on deleting registry strings and ending processes but none of the mentioned process or registry strings existed. spybot found other registry strings and two files in C:\windows\system32, one called bpk.dat and the other pk.bin i have deleted these files but the keep reappearing.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #8  
Old 1st Aug 2007, 02:03 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

Your log is fairly clean. You can remove the online scanners if you choose.
And this entry. O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

Like I stated earlier this is a particularly hard keylogger to remove.
I will assume your copy of Nero is legit.
If not then whatever warez/keygen you used is now turned on you.

You can try this as it may remove the problem.
http://free.grisoft.com/doc/download.../frt/0?prd=asf

Let us know and I will look for more information.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #9  
Old 1st Aug 2007, 02:34 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

Since you removed registry entries and files already you may have removed the un-installer.
Check your add/remove programs to make sure it isn't there. You may have to look for BPK to identify it.
The sorce file is C:\WINDOWS\system32\bpk.exe make sure this is deleted also.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #10  
Old 1st Aug 2007, 02:34 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

i currently scanning the system with the avg antispyware i will post a report for you to look at when it is finished
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #11  
Old 1st Aug 2007, 02:37 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

no the file C:\windows\system32\bpk.exe does not exist i only have two files in the sytem32 folder that spybot picks up and says are to do with perfect keylogger and they are bpk.dat and pk.bin
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #12  
Old 1st Aug 2007, 02:51 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

OK, lets try this. Go to this link and download the FREE lite version.
Perfect Keylogger Lite

http://www.blazingtools.com/downloads.html#bpklite
This will install the un-installer. Then locate the un-installer in add/remove. It may have to be found in the program files.

Let us know how it works.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #13  
Old 1st Aug 2007, 03:41 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

ok i have downloaded this and installed it. the avg spyware would not allow me to open it at first so i shut it down. do i now uninstall? there is a uninstaller in C:\program files\perfect keylogger lite\unistall.exe
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #14  
Old 1st Aug 2007, 03:45 AM
evilfantasy's Avatar
Moderator Group
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: 15th Jul 2007
Last Online: Today 06:46 PM
Posts: 5,338
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default Perfect keylogger

Thats what you need to do is open that.
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote
  #15  
Old 1st Aug 2007, 03:47 AM
No Avatar
Hemul14  United Kingdom
Member Group
 
Hemul14 is offline
 
Join Date: 31st Jul 2007
Last Online: 31st Jan 2008 02:30 AM
Posts: 13
iTrader: (0)
Hemul14 is on a distinguished road
Default Perfect keylogger

nothing happens when i double click the unistall.exe
Digg this postDel.icio.us this postReddit this post Stumble this postFacebook this post
Reply With Quote

Please support this forum, donate towards our running costs.
Reply

Thread Tools
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Keylogger! johnaast Virus, Spyware & Security 1 5th Jan 2008 05:44 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.