Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


my keyboard is possesed

  • Please log in to reply
3 replies to this topic

#1 attak sekwence

attak sekwence

  • Members
  • 64 posts
  • Gender:Male
  • Location:phoenix, AZ
  • Local time:03:20 AM

Posted 21 September 2012 - 12:53 AM

ok my keyboard has been inserting extra characters when certain keys are typed. to my understanding this could be a virus, hardware error, or driver error. When i plug in a USB keyboard I have no issues but this limits the functionality of a laptop obviously. I'm not really sure how to go about diagnosing this.

I posted initially in Am I Infected and we have ruled out Malware.
I also went into device manager and attempted to update my drivers but they are up to date and I have no option to roll them back. So I'm stuck.

I did have a side thought though on my desktop I use a razer lycosa keyboard and with the fancy shmancy razer software I could reprogram my keys to do certain things kind of like mapping for a game or something. Is there another background program or something I could use to make my still problematic keyboard emulate a working one if worse comes to worse.<--- does that make sense?

I have a hp dv7 laptop
AMD A-6 processor
6gb ram
windows 7 home premium

below is the listing of affected keys this is the output i get when pressing:
e=e(but lowers screen brightness)
o=o (lowers volume)
\=\(also moves up one line like up arrow key)
up arrow=\ and proper movement up
left arrow= I think its hitting tab?
numpad 5= enter
numpad enter= 5
numpad - =9
lower brightness= lowers brightness and adds e
f5(without hitting FN key)=w
lower volume= lowers volume and adds o

BC AdBot (Login to Remove)


#2 noknojon


  • Banned
  • 10,871 posts
  • Gender:Not Telling
  • Local time:09:20 PM

Posted 21 September 2012 - 05:01 AM

Hi -
Just one last small item thar may have been missed in Am I Infected, that may find any other small items -
This is just to finish the last part - Then we can look at other things .........

Download Adware Cleaner from Xplode to the problem computer - Right click and Run as ...Admin -
Click the SEARCH button only, allow it to run and post the log it creates back here.
AdWare Cleaner

Also check that your NumLock key is working correctly -

Thank You -

#3 Baltboy


    Bleepin' Flame Head

  • Members
  • 1,432 posts
  • Gender:Male
  • Location:Pennsylvania
  • Local time:07:20 AM

Posted 21 September 2012 - 11:00 AM

I would suspect the keyboard is failing. I have had similar issues were it was like ctrl was stuck on or the computer would randomly start up in safe mode. "sticky" keys are almost always a sign of keyboard failure.
Get your facts first, then you can distort them as you please.
Mark Twain

#4 attak sekwence

attak sekwence
  • Topic Starter

  • Members
  • 64 posts
  • Gender:Male
  • Location:phoenix, AZ
  • Local time:03:20 AM

Posted 21 September 2012 - 11:47 AM

# AdwCleaner v2.002 - Logfile created 09/21/2012 at 09:46:12
# Updated 16/09/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : t - MIKE
# Boot Mode : Normal
# Running from : C:\Users\t\Downloads\adwcleaner.exe
# Option [Search]

***** [Services] *****

***** [Files / Folders] *****

File Found : C:\Program Files (x86)\Mozilla Firefox\searchplugins\avg-secure-search.xml
Folder Found : C:\Program Files (x86)\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Conduit
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\Users\t\AppData\Local\AVG Secure Search
Folder Found : C:\Users\t\AppData\Local\Conduit
Folder Found : C:\Users\t\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\t\AppData\LocalLow\Conduit
Folder Found : C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\hcc68y9g.default\CT3072253
Folder Found : C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\hcc68y9g.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
Folder Found : C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\hcc68y9g.default\Smartbar

***** [Registry] *****

Key Found : HKCU\Software\AppDataLow\Software\Conduit
Key Found : HKCU\Software\AppDataLow\Software\Freecause
Key Found : HKCU\Software\AppDataLow\Software\SmartBar
Key Found : HKCU\Software\Ask&Record
Key Found : HKCU\Software\AVG Secure Search
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F3FEE66E-E034-436A-86E4-9690573BEE8A}
Key Found : HKCU\Software\Softonic
Key Found : HKCU\Software\Zugo
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\Software\AVG Secure Search
Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Found : HKLM\SOFTWARE\Classes\S
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT3072253
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Found : HKLM\Software\Conduit
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=,application/x-avg-sitesafety-plugin
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKU\S-1-5-21-2937148489-2211503562-1396153921-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKU\S-1-5-21-2937148489-2211503562-1396153921-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v12.0 (en-US)

Profile name : default
File : C:\Users\t\AppData\Roaming\Mozilla\Firefox\Profiles\hcc68y9g.default\prefs.js

Found : user_pref("CT3072253.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3072253.FirstTime", "true");
Found : user_pref("CT3072253.FirstTimeFF3", "true");
Found : user_pref("CT3072253.UserID", "UN70278882933696254");
Found : user_pref("CT3072253.addressBarTakeOverEnabledInHidden", "true");
Found : user_pref("CT3072253.autoDisableScopes", -1);
Found : user_pref("CT3072253.defaultSearch", "FALSE");
Found : user_pref("CT3072253.embeddedsData", "[{\"appId\":\"129571859753931591\",\"apiPermissions\":{\"cross[...]
Found : user_pref("CT3072253.enableAlerts", "always");
Found : user_pref("CT3072253.enableSearchFromAddressBar", "FALSE");
Found : user_pref("CT3072253.firstTimeDialogOpened", "true");
Found : user_pref("CT3072253.fixPageNotFoundError", "true");
Found : user_pref("CT3072253.fixPageNotFoundErrorInHidden", "true");
Found : user_pref("CT3072253.fixUrls", true);
Found : user_pref("CT3072253.installId", "fftE34.tmp.exe");
Found : user_pref("CT3072253.installType", "XPE");
Found : user_pref("CT3072253.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3072253.isNewTabEnabled", true);
Found : user_pref("CT3072253.isPerformedSmartBarTransition", "true");
Found : user_pref("CT3072253.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"false\"}");
Found : user_pref("CT3072253.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.xvideos.com%[...]
Found : user_pref("CT3072253.openThankYouPage", "true");
Found : user_pref("CT3072253.openUninstallPage", "FALSE");
Found : user_pref("CT3072253.searchInNewTabEnabledInHidden", "true");
Found : user_pref("CT3072253.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Found : user_pref("CT3072253.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"d[...]
Found : user_pref("CT3072253.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\[...]
Found : user_pref("CT3072253.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"d[...]
Found : user_pref("CT3072253.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"strin[...]
Found : user_pref("CT3072253.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"strin[...]
Found : user_pref("CT3072253.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data[...]
Found : user_pref("CT3072253.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1348038568613");
Found : user_pref("CT3072253.serviceLayer_services_appsMetadata_lastUpdate", "1348038568512");
Found : user_pref("CT3072253.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1348038568528");
Found : user_pref("CT3072253.serviceLayer_services_login_10.10.27.6_lastUpdate", "1348162382336");
Found : user_pref("CT3072253.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1348038569380");
Found : user_pref("CT3072253.serviceLayer_services_searchAPI_lastUpdate", "1348038567594");
Found : user_pref("CT3072253.serviceLayer_services_serviceMap_lastUpdate", "1348162381968");
Found : user_pref("CT3072253.serviceLayer_services_toolbarContextMenu_lastUpdate", "1348038568459");
Found : user_pref("CT3072253.serviceLayer_services_toolbarSettings_lastUpdate", "1348162382310");
Found : user_pref("CT3072253.serviceLayer_services_translation_lastUpdate", "1348162382444");
Found : user_pref("CT3072253.settingsINI", true);
Found : user_pref("CT3072253.shouldFirstTimeDialog", "false");
Found : user_pref("CT3072253.smartbar.CTID", "CT3072253");
Found : user_pref("CT3072253.smartbar.Uninstall", "0");
Found : user_pref("CT3072253.smartbar.toolbarName", "uTorrentControl2 ");
Found : user_pref("CT3072253.toolbarBornServerTime", "19-9-2012");
Found : user_pref("CT3072253.toolbarCurrentServerTime", "20-9-2012");

-\\ Google Chrome v21.0.1180.89

File : C:\Users\t\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.


AdwCleaner[R1].txt - [10513 octets] - [21/09/2012 09:46:12]

########## EOF - C:\AdwCleaner[R1].txt - [10574 octets] ##########

numlock is working correctly and the keys are not physically sticky or anything if that's what you mean.

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users