using Kaspersky Pure 2011 (updated per defaults) and one of my family visited a website with a jscript that tried to download. It looks like Kaspersky caught it:
12/6/2011 6:43:02 PM Web Anti-Virus Detected: Trojan-Downloader.JS.JScript.k Firefox http://www.kryptonsite.com/jqueryslidemenu.js
But I did not see that notice but had issues the following morning using firefox to browse. After several attempts to correct, I rebooted my PC and then saw the keylogger entry in Kaspersky:
12/7/2011 5:35:50 AM Proactive Defense Detected: PDM.Keylogger Absent Keylogger activity kernel mode memory patch
I immediately took the PC off line and then selectively put it back online to get virus definition updates and to try various scanning tools. I have since run Kaspersky full scan (twice), Symantec's malware scanner and also have done manual checks for items in registry, startup areas and specific windows files.
Update: gmer log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-11 22:14:38
Windows 6.0.6002 Service Pack 2
Running: cyto126b.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0011f6058553
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0011f6058553@0007e0c855f6 0x83 0x05 0x1D 0xF2 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0011f6058553 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0011f6058553@0007e0c855f6 0x83 0x05 0x1D 0xF2 ...
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0011f6058553 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\0011f6058553@0007e0c855f6 0x83 0x05 0x1D 0xF2 ...
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0011f6058553 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\BTHPORT\Parameters\Keys\0011f6058553@0007e0c855f6 0x83 0x05 0x1D 0xF2 ...
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0011f6058553 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet005\Services\BTHPORT\Parameters\Keys\0011f6058553@0007e0c855f6 0x83 0x05 0x1D 0xF2 ...
Reg HKLM\SYSTEM\ControlSet039\Services\BTHPORT\Parameters\Keys\0011f6058553 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet039\Services\BTHPORT\Parameters\Keys\0011f6058553@0007e0c855f6 0x83 0x05 0x1D 0xF2 ...
---- EOF - GMER 1.0.15 ----
I could not get ddr to run successfully, it prompted for permission to run and then it popped a quick DOS screen and then went away without any other windows or prompts. I could not find it in the running processes or services.
I am not confident that I have eradicated the threat.
Suggestions on how to ensure that the PC is clean?
Thank you
Charlie
Attached File(s)
-
gmer_log_12112011.log (1.55K)
Number of downloads: 0
This post has been edited by cbarendt: 11 December 2011 - 10:22 PM

Help
This topic is locked

Back to top









