Guide: How to CLEAN your PC from Keyloggers

#0 - Aug. 20, 2008, 2:50 p.m.
Blizzard Post
Logicaly’s guide: How to CLEAN your PC from keyloggers.

Hi all, this guide will help you clean up your PC. Not just keyloggers, but also other malicious software.
Last update: August 4, 2010

Screenshots have now been added!!!
Please also take a look at the Unofficial Helper's Forum (with IRC!)
> http://www.bamboobix.info < (Thanks to Anayra for running this!)


First of all, a note:
Hijackthis is a tool, used for finding infections in your computer. Please note: THIS IS NOT A SCANNER. It shows both malicious rules, but also LEGIT rules. Do not fix rules in Hijackthis yourself!
You can find a list of forums that are qualified to look at your Hijackthis log here: http://asap.maddoktor2.com
In addition, here’s a list of forums where you can post your hijackthis logfile. – If you know any others, please let me know in a comment/reply!
Dutch/Belgium:
www.hijackthis.nl/forum
www.minatica.be/forum.php
http://www.antispywareoffensief.nl/forum/

English:
http://www.spywareinfoforum.com/
http://forums.techguy.org/
http://www.techsupportforum.com/

You are also permitted to post your logfile in this thread. Please not that whatever you choose to do, please post your logfile at only one place. Posting it on multiple places is a waste of time for the helpers.


Before posting a Hijackthis log, please do the following steps upfront. I know this is a lot of work, but that way most malware is already deleted and your logfile can be looked at faster.
Please remember: Follow ALL steps, including step 7

Note: Vista/Win. 7 users must run installations and the downloaded programs as Administrator. You can do this by right-clicking the program and select Run as Administrator (The screenshot shows it for Hijackthis, You must use this for every program we use here)
http://img408.imageshack.us/img408/6665/guide1bb5.jpg <-- Screenshot

1.
  • Download CCleaner here: http://www.piriform.com/ccleaner/download - and install it.

  • Once it’s booted, press the button to Clean up your system.
  • This can take a few minutes, depending on how much trash there is on your PC. Please read what is being removed, you might not want the program to remove your Internet History or saved passwords.
    Note: CCleaner can ask you to install Yahoo Toolbar during the installation. Uncheck this option if you do not want the toolbar!
    Screenshot: http://www.plaatjesupload.nl/bekijk/2010/02/08/1265647242-080.jpg


    2. Download SUPERAntiSpyware (http://downloads.superantispyware.com/downloads/SUPERAntiSpyware.exe )and install it.
    Afterwards, open the scanner and make sure it’s up-to-date. Press Scan Your Computer and then select Perform Complete Scan. Wait until the scan is complete. Once done, make sure everything is checked and press Next until everything is deleted/fixed. If it asks you to reboot, do so.
    Screenshot: http://www.plaatjesupload.nl/bekijk/2010/08/04/1280913154-790.jpg

    3.
  • Download Spybot Search & Destroy ( http://www.safer-networking.org/nl/mirrors/index.html ) and install it.

  • During the installation, uncheck "Use Internet Explorer protection (SDHelper)" and "Use system settings Protection (TeaTimer)"

  • After the installation, boot Spybot S & D. Search for updates first, and download them all.

  • Click on the Immunize tab afterwards, followed by clicking the Immunize button.
  • Wait until the operation has been completed.
  • Then go to the Search and Destroy tab. Click on Check All after that and wait until things are done.
  • Select all problems found, and repair the problems.
  • Close Spybot afterwards.
    Screenshot: http://www.plaatjesupload.nl/bekijk/2010/02/08/1265650645-650.jpg

    4.
  • Download MBAM (MalwareBytes' Anti-Malware) (http://www.malwarebytes.org/mbam-download.php ) - and install it. Make sure that at the end of the installation, Update MalwareBytes' Anti-Malware and Start MalwareBytes' Anti-Malware is checked.

  • Select Full Scan and start scanning. When it is done, select everything and delete the found objects.

  • A logfile will also open automatically. Save this logfile and post it together with your Hijackthis logfile.

  • The Logfile will automatically be saved at the Logs tab in MBAM.
    If MBAM found objects that can't be deleted, it will ask to reboot your computer. Allow this and restart your computer.
    Screenshot: http://www.plaatjesupload.nl/bekijk/2010/02/08/1265650977-740.jpg

    5. Do a full system scan with your virusscanner and remove all found infections.
    If you do not have a virusscanner – GET ONE ASAP!!- , you can scan online with one of these scanners. (Use Internet Explorer to scan)

    BitDefender: http://www.bitdefender.com/scan8/ie.html
    Panda: http://www.pandasoftware.com/activescan/com/activescan_principal.htm
    Kaspersky: http://www.kaspersky.nl/scanner

    Remove all infections found.

    6. Restart your computer.

    7.
  • Download Hijackthis http://go.trendmicro.com/free-tools/hijackthis/HijackThisInstaller.exe - and install it.

  • After the installation Hijackthis will open. Press Do a systemscan and save a logfile.
    A notepad file will open. In the Notepad file, press CTRL + A to select everything, CTRL + C to Copy everything. Then press CTRL + V in a new topic at the forum you want to post the log.

  • Screenshot: http://www.plaatjesupload.nl/bekijk/2010/02/08/1265651202-490.jpg

    Also paste the MBAM log on the forum you place the Hijackthis logfile.


    Many thanks for reading, if you have questions or problems, please ask :)

    Also: Please note: Doing this all, is NOT A GUARANTEE your computer is not infected. There is no scanner that has a 100% detection rate.

    - Logicaly
    PS. Logicaly is my new main. The old one was Magekíd. It’s still me :D
    PS2. To that sneaky person posting in the US forums: WTB credits-link!
    PS3. Last update: Removed Ad-Aware, added SUPERAntiSpyware, changed a few lines :)
    #2 - Aug. 20, 2008, 2:54 p.m.
    Blizzard Post
    Blue tagged as well :-)

    This should be very useful for those who were looking for attractive legs ;-)

    #430 - Oct. 16, 2009, 3:39 p.m.
    Blizzard Post
    To save a little bit of space, all of our guides were collated into this sticky:

    [Guides] Our collection of How To Guides
    http://forums.wow-europe.com/thread.html?topicId=7700700766&sid=1
    #2116 - March 20, 2010, 9:37 a.m.
    Blizzard Post
    Hello Pallidwarf. If the investigation into your account is now complete you are free to delete any characters created by the intruders.

    Keep up the good work in here guys.
    #2403 - May 3, 2010, 6:37 p.m.
    Blizzard Post
    Q u o t e:
    You're really helping people out with your work.. I would like to thank you for that.

    I’d like to second that also – this thread is an excellent resource for players, and we really appreciate its continued presence and all the hard work. <3
    #2550 - May 18, 2010, 2:51 p.m.
    Blizzard Post
    Mmmm...large logs.
    #3082 - July 16, 2010, 3:27 p.m.
    Blizzard Post
    Q u o t e:

    Just want to say thank you again to you two for taking time out to check all of these, not just for me but for everyone that comes to you with a problem. I am a total Computer noob and none of this makes the tiniest bit of sense. I really hope Blizzard takes on board all this you do and rewards you appropriately.


    We take notice, yes. We offered them free /pandahugs, but they replied; “serving the greater good of the community is all the reward that a true gentleman needs.”

    It brought a tear to my eye.