Keylogger installed? How to remove it?

desertman

New Member
Messages
7
Hello Forum,

A friend of mine had recently her green card stolen. Some weeks later she started to apply for a replacment card by filling out a PDF form on her computer with Windows 8.1. She then decided otherwise and stopped filling out the form. Not even 15 minutes later she got a phone call from a woman who pretended to be from the USCIS (the US immigration agency), asking her why she stopped filling out the form and offering her to help her to get a replacement green card. My friend was confused, kind of believing that the woman was indeed from USCIS, but luckily did not give her any information in that phone call. Since then my friend got apparently some emails, allegedly from this woman, and now another phone call in which this woman again tried to get some information out of my friend.

It seems to me that my friend has some malware on her computer that keeps track of what she is doing or typing and then sends this information somewhere - and that without the installed (and paid for) Norton security software giving any alarm.

What can I do to help my friend to find out what is going on on her computer, and how can she get rid of a possibly installed malware?

Thanks for your help!

desertman
 

My Computer

System One

  • OS
    Windows 8.1
Try these steps:
Launch System Configuration (msconfig)

Services tab:
picture.php
Hide all Microsoft services
Press the [ Disable all ] button​

Startup tab:
Press the [ Disable all ] button
Enable/select your Antivirus real time application if it is present in the list (not all are)
Enable/select your Touchpad is you have any customized keys or functions​
press [ Ok ]

Restart your system.
Restart your machine in case there are any system operations pending

Click here to download Old Timer-TFC.
>> save the application to your Desktop.
:info: Old Timer-TFC is a standalone application, there is no install.

:warn:Save your work and close all open windows.
TFC will close ALL open programs including your browser!

Right click, run as administrator TFC

Click the Start button to begin the cleaning up temporary files and folders.
:warn: Do not work on other things while TFC is running - most applications use some sort of temporary files. Just let TFC run by itself on the machine until it completes.

:busted: Restart your machine immediately after TFC completes.
AdwCleaner by Xplode:
Run the following steps in the General Changelog Team tutorial:

Malware is often difficult to eradicate - it is even more difficult if more than one path is taken on different sites.

As you have posted the issue here on SevenForums, also post any logs here on SevenForums - not on the General Changelog Team (GCT) site. SevenForums members might ask you to launch other on-demand scanners that are not familiar to GCT.

When your system is clean of malware, launch AdwCleaner a final time and click the Uninstall button.
Follow this tutorial:
Scan for Malware using Malwarebytes Anti-Malware Free

Please be sure to post the logs from AdwCleaner and Malwarebytes.

Depending on what those two utilities find and clean, there might be additional scanners recommended.
 

My Computer

System One

  • OS
    Win8.1 Pro | Win10TP Pro - boot to VHD
    Computer type
    Laptop
    System Manufacturer/Model
    HP Pavilion dv6-c610us
    CPU
    AMD VISION A6-3420M Quad-Core (2.4GHz/1.5GHz)
    Motherboard
    HP
    Memory
    6GB DDR3 SDRAM (2 DIMM)
    Graphics Card(s)
    AMD Radeon HD 6520G Discrete-Class Graphics
    Monitor(s) Displays
    HP 2072a (20" LED)
    Screen Resolution
    1600 x 900
    Hard Drives
    Hitachi 640GB (5400 RPM)
    Seagate 2 TB external
    WD 500 GB external
    Keyboard
    Logitech K520 (wireless bundle)
    Mouse
    Logitech M310 (wireless bundle)
    Browser
    IE 11 (default) & Pale Moon
    Other Info
    HP product specs:

    http://support.hp.com/us-en/product/HP-Pavilion-dv6-6c00-Entertainment-Notebook-PC-series/5191856/model/5218495/document/c03138553/
@Bart - For others interested, per info on TFC, it does not support Win 8 ? Is there a similar program for Win 8 ?
 

My Computer

System One

  • OS
    Win 8.1 64bit
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba
    CPU
    Intel i3, 2348
    Memory
    4GB
    Graphics Card(s)
    Intel HD3000

My Computer

System One

  • OS
    Linux Mint 17.2
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba Satellite C850D-st3nx1
    CPU
    AMD E1-1200 APU with Radeon (tm) HD Graphics 1.40 GHZ
    Memory
    12GB
    Graphics Card(s)
    AMD Radeon™ HD 7310 Graphics
    Sound Card
    Realtek HD
    Monitor(s) Displays
    LCD
    Screen Resolution
    1366 x 768
    Hard Drives
    Crucial M500 240GB SSD
    Mouse
    Logitech M525
    Internet Speed
    45/6 - ATT U-Verse
    Browser
    Google Chrome
    Antivirus
    None needed. It is Linux.
    Other Info
    Arris NVG589 Gateway; Router - Cisco RV320; Switch - Netgear GS108 8-Port Switch & Trendnet TEG-S50g 5-Port Switch; Access Points - Engenius ECB350, Trendnet TEW-638APB; NAS - Lenovo ix2-4; Printer - Brother HL-2280DW; Air Print Server - Lantronix XPrintServer

    A/V UPS - Tripp-Lite Smart 1500LCD 1500 Va/900 W.
@Bart - For others interested, per info on TFC, it does not support Win 8 ? Is there a similar program for Win 8 ?
Hmmm, I run TFC on Win8 and Win10TP without issue.

Are you basing your statement on the OSes listed, or did I miss an explicit ... won't run on Windows higher than ....

Thanks torre.
 

My Computer

System One

  • OS
    Win8.1 Pro | Win10TP Pro - boot to VHD
    Computer type
    Laptop
    System Manufacturer/Model
    HP Pavilion dv6-c610us
    CPU
    AMD VISION A6-3420M Quad-Core (2.4GHz/1.5GHz)
    Motherboard
    HP
    Memory
    6GB DDR3 SDRAM (2 DIMM)
    Graphics Card(s)
    AMD Radeon HD 6520G Discrete-Class Graphics
    Monitor(s) Displays
    HP 2072a (20" LED)
    Screen Resolution
    1600 x 900
    Hard Drives
    Hitachi 640GB (5400 RPM)
    Seagate 2 TB external
    WD 500 GB external
    Keyboard
    Logitech K520 (wireless bundle)
    Mouse
    Logitech M310 (wireless bundle)
    Browser
    IE 11 (default) & Pale Moon
    Other Info
    HP product specs:

    http://support.hp.com/us-en/product/HP-Pavilion-dv6-6c00-Entertainment-Notebook-PC-series/5191856/model/5218495/document/c03138553/
@Bart - For others interested, per info on TFC, it does not support Win 8 ? Is there a similar program for Win 8 ?
Hmmm, I run TFC on Win8 and Win10TP without issue.

Are you basing your statement on the OSes listed, or did I miss an explicit ... won't run on Windows higher than ....

Thanks torre.

Just basing the question on the specs from the link: (OS listed)



Operating System:Windows XP/Vista/7
32-bit program. Can run on both a 32-bit and 64-bit OS

TFC Download
 

My Computer

System One

  • OS
    Win 8.1 64bit
    Computer type
    Laptop
    System Manufacturer/Model
    Toshiba
    CPU
    Intel i3, 2348
    Memory
    4GB
    Graphics Card(s)
    Intel HD3000
Thanks for all your answers. As it turns out my friend did not download a PDF and filled that out but rather went onto a commercial (and fraudulent) website to apply for a replacement green card. No wonder that they called her (trying to get her credit card numbers) - she herself gave them her phone number. At the moment she does not even know whether she actually gave them the numbers and whether they charged anything - she seems to be not completely on top of this.

No malware, just another case of someone who fell for an Internet scam.
 

My Computer

System One

  • OS
    Windows 8.1
Ask your friend to sort through this carefully:

USCIS pages:


These USCIS documents are identification papers for immigrant persons. They provide the means to employment and credit. It is important that your friend notifies the organization of her loss and completes the application for a replacement.

She can block the eMails, but phone calls are more difficult to block.

If you can tell me what eMail client she uses, I can provide the 'block eMail from this bad user' information. I recommend deleting it from the server - never mind saving it to look at - just get rid of it. If the scammers catch on that their eMail isn't getting through they might switch sender ids, but if the email does not come from a .gov account, it probably isn't worth investigating - too tempting to click 'n see - ooops.
 

My Computer

System One

  • OS
    Win8.1 Pro | Win10TP Pro - boot to VHD
    Computer type
    Laptop
    System Manufacturer/Model
    HP Pavilion dv6-c610us
    CPU
    AMD VISION A6-3420M Quad-Core (2.4GHz/1.5GHz)
    Motherboard
    HP
    Memory
    6GB DDR3 SDRAM (2 DIMM)
    Graphics Card(s)
    AMD Radeon HD 6520G Discrete-Class Graphics
    Monitor(s) Displays
    HP 2072a (20" LED)
    Screen Resolution
    1600 x 900
    Hard Drives
    Hitachi 640GB (5400 RPM)
    Seagate 2 TB external
    WD 500 GB external
    Keyboard
    Logitech K520 (wireless bundle)
    Mouse
    Logitech M310 (wireless bundle)
    Browser
    IE 11 (default) & Pale Moon
    Other Info
    HP product specs:

    http://support.hp.com/us-en/product/HP-Pavilion-dv6-6c00-Entertainment-Notebook-PC-series/5191856/model/5218495/document/c03138553/
Back
Top