I Need Some Keylogger Help

Stg-Flame

Diamond Member
Mar 10, 2007
3,623
553
126
First off, seeing all of the posts about the new forums I am not sure if this is the right place to post about this type of stuff anymore. If it isn't, someone please redirect me to the correct forum.

Now to the problem. My brother was searching some sites about Diablo 2 LoD and clicked a link from Google about a Dupe Method. When he clicked the link to "Enter the Site" McAffe (sp?) brang up a Trojan entering his computer called: "keylog-perfec.dr". Since I put Avast Anti-virus on his computer so he wouldn't have to pay for McAffe anymore (He is letting McAffe service run out) it has caught more than McAffe has. However, with this Trojan he was unable to Delete, Quarantine, or Clean the File. It left him with little options left and without myself being present, he went ahead and ignored the warnings.



This is what I found in his My Computer which was never there before. I had him run KL-Detector which found nothing, yet those two files were never there before. Not only were they never there before, but their names worry me.

When I asked him what he did specifically before McAffe brought his attention to the Trojan, this is what he said:

Flame ???? says:
I Don't think so. Just try to remember everything about it

Hamster of Chaos says:
When I entered the site. it was all black except for one thing on it that said either "Here" or "Enter Site" I cannot remember because I dont pay that much attention to that stuff.
Hamster of Chaos says:
I hit it, a thing poped up said File blablabla, Open, Save, Cancel. I hit cancel and McAfee popped up with the virus

With all that being said, if anyone has any information about this it would be greatly appreciated as he needs his computer for work. I have searched around but to no avail, I have not found a solution.

EDIT: I found the website in question: www.klandiablo2lod.konin.lm.pl/ Do not click the "Here" button.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: Chaoticpenguin666
First off, seeing all of the posts about the new forums I am not sure if this is the right place to post about this type of stuff anymore. If it isn't, someone please redirect me to the correct forum.

Now to the problem. My brother was searching some sites about Diablo 2 LoD and clicked a link from Google about a Dupe Method. When he clicked the link to "Enter the Site" McAffe (sp?) brang up a Trojan entering his computer called: "keylog-perfec.dr". Since I put Avast Anti-virus on his computer so he wouldn't have to pay for McAffe anymore (He is letting McAffe service run out) it has caught more than McAffe has. However, with this Trojan he was unable to Delete, Quarantine, or Clean the File. It left him with little options left and without myself being present, he went ahead and ignored the warnings.



This is what I found in his My Computer which was never there before. I had him run KL-Detector which found nothing, yet those two files were never there before. Not only were they never there before, but their names worry me.

When I asked him what he did specifically before McAffe brought his attention to the Trojan, this is what he said:

Flame ???? says:
I Don't think so. Just try to remember everything about it

Hamster of Chaos says:
When I entered the site. it was all black except for one thing on it that said either "Here" or "Enter Site" I cannot remember because I dont pay that much attention to that stuff.
Hamster of Chaos says:
I hit it, a thing poped up said File blablabla, Open, Save, Cancel. I hit cancel and McAfee popped up with the virus

With all that being said, if anyone has any information about this it would be greatly appreciated as he needs his computer for work. I have searched around but to no avail, I have not found a solution.

EDIT: I found the website in question: www.klandiablo2lod.konin.lm.pl/ Do not click the "Here" button.
I'll check into the site and see what the malware seems to be. In the meantime, if he's logged into anything that his stuff could get stolen from it, such as his WoW account, PayPal, eBay, bank, credit card, etc, or email accounts that could contain password-reset emails for sites like those, then he should (1) log onto a known clean computer, and (2) reset the passwords for all of those resources as a precaution.

Back in ~10 minutes with whatever info I can get on the bad site and the malware...

 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
k, I checked it out, and ran the Trojan Horse on a Win2000 installation in a virtual machine. Then I fired up AOL Kaspersky and had it scan for the malware. It removed it OK. I think maybe your bro should ditch the Avast and switch to Kaspersky. Make sure he fully configures it, including maxing out all the sliders to HIGH detection, and schedules a nightly re-scan.

For good measure, also have him run this every month: Secunia's checkup thingie. And he should make sure his Automatic Updates (in Control Panel) are set to full automatic, and if he happens to have Office software, he should hit Office Update repeatedly until he's got all the service packs and patches, and then visit again monthly.

Also, if he doesn't have any other firewall software, then get his Windows Firewall turned on.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |