Take A Look At This.....Keylogged ETC...

Discussion in 'Archives' started by Phil, Jun 20, 2007.

Take A Look At This.....Keylogged ETC...
  1. Unread #21 - Jun 21, 2007 at 9:27 AM
  2. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Thanks for that, but how exactly do i do those things...or unregister them or whatever, if someone could make a step by step guide, i'll be really happy.

    There also may be a little money in it for someone if they can make a step by step short guide to slove the problem..

    Cheers everyone.
     
  3. Unread #22 - Jun 21, 2007 at 11:22 AM
  4. Yakov
    Joined:
    Apr 22, 2005
    Posts:
    2,233
    Referrals:
    1
    Sythe Gold:
    0

    Yakov Jewish Ex-Global Mod
    Do Not Trade

    Take A Look At This.....Keylogged ETC...

    Here you go.

    EDIT:

    Step 1: CTRL + ALT + DELETE.

    This will open up the taskmanager.

    [​IMG]

    Step 2: End the process, by either right clicking on the process and ending the process tree, or hitting the end process button

    [​IMG]


    Step 3: Deleting all the shit you don't need.

    Step 3A:Remove everything from these directories if you have them.

    Code:
    %program_files%\ckm
    %program_files%\fkg
    %programs%\ardamax keylogger
    
    
    Step 3B: Remove all these files

    Code:
    akl.exe
    akv.exe
    ardamax keylogger.lnk
    cmmd.006
    cmmd.007
    cmmd.exe
    explorer.006
    explorer.007
    explorer.ex0
    fkg.chm
    fkg.exe
    flash_player_v4.006
    flash_player_v4.007
    1661156
    2827223
    2831364
    2831365
    2831366
    2840953
    3049927
    akl.chm
    %program_files%\tnd\tnd.exe
    %program_files%\tnd\tray.gif
    %system%\nsk.exe
    %program_files%\tnd\akv.exe
    %program_files%\tnd\akv.ini
    %program_files%\tnd\menu.gif
    %program_files%\tnd\qs.html
    %program_files%\tnd\tnd.002
    %program_files%\tnd\tnd.003
    %program_files%\tnd\tnd.004
    %program_files%\tnd\tnd.006
    %program_files%\tnd\tnd.007
    %program_files%\tnd\tnd.chm
    %program_files%\nsk\akv.exe
    %program_files%\nsk\nsk.exe
    %program_files%\tnd\uninstall.exe
    %programs%\ardamax keylogger\ardamax keylogger.lnk
    %programs%\ardamax keylogger\help.lnk
    %programs%\ardamax keylogger\log viewer.lnk
    kh.dll
    license.txt
    log viewer.lnk
    menu.gif
    qs.html
    svchost.006
    svchost.007
    flash_player_v4.exe
    help.lnk
    install.exe
    svchots.exe
    sysw.006
    sysw.007
    topinstall.exe
    tray.gif
    uninstall.exe
    %program_files%\ckm\akv.exe
    %program_files%\ckm\ckm.003
    %program_files%\ckm\ckm.004
    %program_files%\ckm\ckm.006
    %program_files%\ckm\ckm.007
    %program_files%\ckm\ckm.chm
    %program_files%\ckm\ckm.exe
    %program_files%\ckm\license.txt
    %program_files%\ckm\menu.gif
    %program_files%\ckm\qs.html
    %program_files%\ckm\tray.gif
    sysw.exe
    tnd.exe
    %program_files%\ckm\uninstall.exe
    kh.dll
    install.exe
    sysw.exe
    svchots.exe
    %program_files%\nsk\akv.exe
    topinstall.exe
    %program_files%\ckm\uninstall.exe
    %program_files%\ckm\ckm.exe
    %program_files%\ckm\akv.exe
    %system%\nsk.exe
    %program_files%\tnd\akv.exe
    %program_files%\nsk\nsk.exe
    %program_files%\tnd\tnd.exe
    %program_files%\tnd\uninstall.exe
    akl.exe
    flash_player_v4.exe
    fkg.exe
    cmmd.exe
    
    Step 3C: Opening your registry.

    Do so, by going to Start -> Run and type in "regedit" and then hit ok.

    You need to delete all these directories/files.

    Code:
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run cmmd
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run fkg
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ardamax keylogger 
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ardamax keylogger displayname
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\ardamax keylogger uninstallstring
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run fkg
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run cmmd
    
    Step 4: kh.dll can probably be found by doing a search. Start -> Programs -> Search.

    Search for "all files" and type in kh.dll. Remove it when it comes up.
     
  5. Unread #23 - Jun 21, 2007 at 11:33 AM
  6. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Thanks very much Yakov....add me on MSN if you like...I'll probs be on tonight.

    Thx so much.
     
  7. Unread #24 - Jun 21, 2007 at 11:51 AM
  8. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Thanks a lot m8, i i have none of that stuff, i've looked in registry and neither the directries or the files exist.
    I've looked for at least half the files you listed and none of them are there. I've looked for the process running, and that also isn't there.

    I've looked for all of the above, and it isn't there, it's as if i'm not keylogged?

    I don't know..Is there a chance it didn't infect my PC? or..?

    Thanks very much Yakov.

    What shall i do now lol :s:(
     
  9. Unread #25 - Jun 21, 2007 at 12:57 PM
  10. Daily
    Joined:
    May 6, 2005
    Posts:
    4,425
    Referrals:
    18
    Sythe Gold:
    5

    Daily BANNED FROM MARKET
    Banned

    Take A Look At This.....Keylogged ETC...

    Have fun with that. Why would you open crap from RANDOM people? Srrsly. >_<

    Here.

    Oh try this also before you try anything else.

    http://www.scanspyware.net/info/Ardamax.htm

    Delete the following directories

    %programfilesdir%\HTV
    %programfilesdir%\NSK
    %programsdir%\ARDAMAX KEYLOGGER
    Ardamax Keylogger
    %programsdir%\ARDAMAX KEYLOGGER LITE
    %commonprogramsdir%\ARDAMAX KEYLOGGER
    ARDAMAX KEYLOGGER LITE
    %commonprogramsdir%\ARDAMAX KEYLOGGER LITE


    Delete the following files

    %programfilesdir%\HTV\HTV.exe
    %programfilesdir%\HTV\HTV.006
    %programfilesdir%\HTV\HTV.007
    %programfilesdir%\HTV\HTV.003
    %programfilesdir%\HTV\HTV.004
    %programfilesdir%\HTV\AKV.exe
    %programfilesdir%\HTV\qs.html
    %programfilesdir%\HTV\HTV.chm
    HTV.001
    %programfilesdir%\HTV\HTV.002
    HTV.005
    %programfilesdir%\HTV\akv.cfg
    HTV.009
    %programfilesdir%\NSK\AKV.EXE
    NSK.EXE
    %programfilesdir%\NSK\QS.HTML
    %programfilesdir%\NSK\NSK.CHM
    tray.gif
    %programfilesdir%\HTV\menu.gif
    %programfilesdir%\NSK\TRAY.GIF
    %programfilesdir%\NSK\MENU.GIF
    Uninstall.exe
    LICENSE.TXT
    %programfilesdir%\NSK\UNINSTALL.EXE
    %programsdir%\ARDAMAX KEYLOGGER\HELP.LNK
    %programfilesdir%\Ardamax Keylogger\kh.dll
    il.dll
    akl.exe
    %programfilesdir%\Ardamax Keylogger\AKV.exe
    qs.html
    %programfilesdir%\Ardamax Keylogger\AKL.chm
    %programfilesdir%\Ardamax Keylogger\akl.001
    %programfilesdir%\Ardamax Keylogger\akl.002
    akv.ini
    tray.gif
    menu.gif
    HELP.LNK
    %commonprogramsdir%\Ardamax Keylogger\Help.lnk
    %programsdir%\ARDAMAX KEYLOGGER\LOG VIEWER.LNK
    license.txt
    %programfilesdir%\ARDAMAX KEYLOGGER LITE\KH.DLL
    %programfilesdir%\ARDAMAX KEYLOGGER LITE\AKL.CHM
    %programfilesdir%\ARDAMAX KEYLOGGER LITE\AKL.EXE
    akl.klf
    Uninstall.exe
    %commonprogramsdir%\Ardamax Keylogger\Log Viewer.lnk
    %programsdir%\ARDAMAX KEYLOGGER\ARDAMAX KEYLOGGER.LNK
    %programfilesdir%\ARDAMAX KEYLOGGER LITE\UNINSTALL.EXE
    %programfilesdir%\ARDAMAX KEYLOGGER LITE\LICENSE_LITE.TXT
    Ardamax Keylogger.lnk
    ARDAMAX KEYLOGGER LITE.LNK


    Delete the following registry keys

    ARDAMAX KEYLOGGER LITE
    akl.exe
    ARDAMAX KEYLOGGER
    ARDAMAX KEYLOGGER LITE

    Delete the following registry values
    NSK
    fkg
    HTV Agent
     
  11. Unread #26 - Jun 21, 2007 at 1:01 PM
  12. Th3 4ccount s3ller
    Joined:
    Jan 26, 2007
    Posts:
    483
    Referrals:
    0
    Sythe Gold:
    0

    Th3 4ccount s3ller Forum Addict

    Take A Look At This.....Keylogged ETC...

    well, i never would accept a file through msn especially if i didnt know the person.. so u dont wan't to hard drive clean.. hmm. try system restore?
     
  13. Unread #27 - Jun 21, 2007 at 1:28 PM
  14. X Remedy
    Referrals:
    0

    X Remedy Guest

    Take A Look At This.....Keylogged ETC...

    Honestly, it's hard to get rid of a keylogger without reformatting, most keyloggers, such as BPK, SC, ect, make a duplicate file of certain, important internal files. What I would do if I was you, is buy a flash drive, put all the files you obsolutely NEED on there, and reformat, it would be your safest bet, but if you absolutely can't....I guess search through all the files in your computer, look for duplicates and hope you delete the right one.

    Sorry if I wasn't much help =\ lol
     
  15. Unread #28 - Jun 21, 2007 at 1:49 PM
  16. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Thanks.

    Daily, again none of the files or registries you posted exist.

    I don't know...am i keylogged?
     
  17. Unread #29 - Jun 21, 2007 at 3:36 PM
  18. rayden123
    Joined:
    Mar 18, 2007
    Posts:
    628
    Referrals:
    0
    Sythe Gold:
    0

    rayden123 Apprentice

    Take A Look At This.....Keylogged ETC...

    No you are not :S
     
  19. Unread #30 - Jun 21, 2007 at 4:16 PM
  20. Yakov
    Joined:
    Apr 22, 2005
    Posts:
    2,233
    Referrals:
    1
    Sythe Gold:
    0

    Yakov Jewish Ex-Global Mod
    Do Not Trade

    Take A Look At This.....Keylogged ETC...

    Heh, % = variable.

    So,

    %program_files%

    means it can be like

    C:\Yakov's Files\program files\my files\keylogger

    EDIT: Upon further research, I've realized that Task Manager may not pick up ARDAMAX. So try using a different task manager, which are available on the internet.

    The reason none of daily's files show up, is because he's telling you what to delete if you have ARDAMAX LITE, and you're infected with Ardamax, not the lite version of it.
     
  21. Unread #31 - Jun 21, 2007 at 5:33 PM
  22. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    I've scanned my computer with Norton, Spyware Docter, ScanSpyware and Zone Alarm, all have come up clean.

    I've used 2 complicated methods of finding and deleting spyware, and they both came up clean (I think).

    I've tried both Yakov's and Daily's methods, and they came up with nothing...

    I'm beginning to wonder whether I am keylogged.

    Yakov, if you could explain exactly where the %programfiles% things are i'd appreciate it, cos i must be an idiot..:p

    Keep tryin' guys please :) Thx
     
  23. Unread #32 - Jun 21, 2007 at 5:39 PM
  24. Yakov
    Joined:
    Apr 22, 2005
    Posts:
    2,233
    Referrals:
    1
    Sythe Gold:
    0

    Yakov Jewish Ex-Global Mod
    Do Not Trade

    Take A Look At This.....Keylogged ETC...

    Ok

    For example

    %program_files%\ckm\ckm.003

    Now my Program Files folder is in my C drive.

    C:\Program Files <-

    So I would go there ^ Look for a folder called "ckm". Then I would open it and search for the file "ckm.003" and delete it. Understand?
     
  25. Unread #33 - Jun 21, 2007 at 5:41 PM
  26. Daily
    Joined:
    May 6, 2005
    Posts:
    4,425
    Referrals:
    18
    Sythe Gold:
    5

    Daily BANNED FROM MARKET
    Banned

    Take A Look At This.....Keylogged ETC...

    You might HAVE to format.

    :\
     
  27. Unread #34 - Jun 21, 2007 at 5:46 PM
  28. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Yeah, i get it, it's what i thought.

    I've looked, NOTHING there...

    That's like 5 spyware/virus scanners, 2 hard methods, tried both dailys and yakovs, tried everything :s

    I'm going to bed now, I'll carry on tommorow.

    Thx a lot guys.
     
  29. Unread #35 - Jun 22, 2007 at 6:14 AM
  30. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Used now...

    Norton, ZoneAlarm, Scanspyware, Spyware Docter, Dr Web Scanner, HiJack This and Spysweeper.

    All get nothing.
     
  31. Unread #36 - Jun 22, 2007 at 8:39 AM
  32. Macroman
    Joined:
    Jan 21, 2007
    Posts:
    6,919
    Referrals:
    9
    Sythe Gold:
    12

    Macroman Hero
    Do Not Trade

    Take A Look At This.....Keylogged ETC...

    Spy Bot Search and Destroy,
    Delete all The Temp Files
     
  33. Unread #37 - Jun 22, 2007 at 1:54 PM
  34. Labeled
    Joined:
    Jun 22, 2007
    Posts:
    63
    Referrals:
    0
    Sythe Gold:
    0

    Labeled Member
    Banned

    Take A Look At This.....Keylogged ETC...

    Pretty sure thats right.. But just incase its not. Good luck : ]
     
  35. Unread #38 - Jun 22, 2007 at 5:07 PM
  36. The_Number_0
    Joined:
    Jun 22, 2007
    Posts:
    80
    Referrals:
    0
    Sythe Gold:
    0

    The_Number_0 Member
    Banned

    Take A Look At This.....Keylogged ETC...

    Ouch, I hope you get rid of it dude.
     
  37. Unread #39 - Jun 23, 2007 at 2:12 AM
  38. isosceles
    Joined:
    Jan 22, 2007
    Posts:
    455
    Referrals:
    0
    Sythe Gold:
    0

    isosceles Forum Addict
    $5 USD Donor

    Take A Look At This.....Keylogged ETC...

    oooo, I had ardamax awhile back. I just did a system restore, removed some remaining crap with spysweeper and spybot s&d, and finally did a manual search for any of those files. I never had any problems afterwards.
     
  39. Unread #40 - Jun 23, 2007 at 7:54 AM
  40. Phil
    Joined:
    Jan 21, 2007
    Posts:
    2,210
    Referrals:
    6
    Sythe Gold:
    5

    Phil Ex-Mod
    ♥ Will Love Govind Forever ♥

    Take A Look At This.....Keylogged ETC...

    Thanks guys, that's the problem, i've searched it with like 7 or 8 different spyware/virus scanners and got nothing.
     
< Think Im Keylogged | paypal help >

Users viewing this thread
1 guest


 
 
Adblock breaks this site