Welcome Guest, to the Spybot Forums! It's 2025, and we just upgraded our forum software.
Today is Safer Internet Day, and with our new forum, you can finally use passkeys to login. That was about time!
Of course, you could ask if a forum is still useful, with so many social media networks out there where you might already have an account, and met a lot of users. You can now use your login from some of those networks to log in here. And by posting here, your question and data is stored on our servers and not automatically shared with a whole social media network.
We'll also start using the forum for small bits of information, announcements and more again.
- First put hijackthis into a permanent folder.
- Do this first - go to C: and create a new permanent folder.
Example C:\AntiSpyWare or C:\hijackthis- This is necessary to ensure you have backups should anything go wrong.
- Then put (or download - choose "save" not "run") the hijackthis.exe file in this folder.
If you downloaded a zipped HJT file unzip it to the permanent folder so you have C:\hijackthis\hijackthis.exe.- Example of the wrong way:
C:\DOCUME~1\Name\LOCALS~1\Temp\Temporary Directory for hijackthis.zip\HijackThis.exe
- Double click HijackThis.exe.
- Hit None Of The Above, just start the program.
- Hit Scan.
- When the scan is finished, the "Scan" button will change into a "Save Log" button.
- Click that, save the log somewhere, and copy/paste the HJT log into your own new topic.
How to copy and paste
- Most of what hjt lists will be harmless or even required, so do not fix anything yet.
- Downloads:
- http://www.downloads.subratam.org/hijackthis.zip
- If you are unfamiliar with zip programs get HijackThis.exe here:
- http://www.merijn.org/files/HijackThis.exe
tashi said:Hi there.
Can you copy/paste the HJT log we discussed into this topic please and a helper will take a look as soon as able.![]()
Before you post a log, and who will advise you.
LonnyRJones said:Hi
It doesnt appear to be still running , It would have looked like this in a HJT log
C:\WINDOWS\IDDE\kmonitor.exe
C:\WINDOWS\SYSTEM\svchost.exe
O23 - Service: MS Software Generic Host Process for Win32 Services (svchost) - Unknown owner - C:\WINDOWS\SYSTEM\svchost.exe
Are you saying it is still present after your PCguard and ad-aware fix it ?
in addition:royakai said:yes it is... it's name is 'Apartment' and enclosed in HKEY_CLASSES_ROOT: CLSID\... under ServerImpro32 folder;
by the way - I'm not sure that the keylog in report is the same that the one I'm writting about
LonnyRJones said:These are what it created for me, Are you comfortable working in the registry ?
HKEY_CLASSES_ROOT\CLSID\{DEE6806C-FB33-D04C-E1C6-8DA9B2204850}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IDDE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
thanks,
yes, mostly I know how to "surf' throughout registry, but what do you mean under letter 'B', the second file on list? There are only 'Default' (icmui.dll), and 'ThreadingModel' (Apartment)
abou IDDE - it doesn't exist any longer; I saw it in report of 5th March;
I don't see svchost in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
c:\WINDOWS\IDDE < folder
c:\WINDOWS\system\MSIDLLSI.DAT
c:\WINDOWS\system\setup.log
c:\WINDOWS\system\svchost.exe
c:\WINDOWS\system32\TMLib.dll
c:\WINDOWS\system32\TMUtils.dll
c:\WINDOWS\ddemal.bin
c:\WINDOWS\tm-log.log
LonnyRJones said:These are what it created for me, Are you comfortable working in the registry ?
HKEY_CLASSES_ROOT\CLSID\{DEE6806C-FB33-D04C-E1C6-8DA9B2204850}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IDDE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
thanks,
yes, mostly I know how to "surf' throughout registry, but what do you mean under letter 'B', the second file on list? There are only 'Default' (icmui.dll), and 'ThreadingModel' (Apartment)
abou IDDE - it doesn't exist any longer; I saw it in report of 5th March;
I don't see svchost in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
c:\WINDOWS\IDDE < folder
c:\WINDOWS\system\MSIDLLSI.DAT
c:\WINDOWS\system\setup.log
c:\WINDOWS\system\svchost.exe
c:\WINDOWS\system32\TMLib.dll
c:\WINDOWS\system32\TMUtils.dll
c:\WINDOWS\ddemal.bin
c:\WINDOWS\tm-log.log
royakai said:There are no files showed above in my computer even I use mode that shows hidden files...
I cannot to simply delete this:
HKEY_CLASSES_ROOT\CLSID\{DEE6806C-FB33-D04C-E1C6-8DA9B2204850} - ThreadingModel (Apartment)
'unable to delete all specified values'...
joke?
royakai said:which process should I kill, because that is what blocks to delete it, I think?
Run check.bat and post back with the text that will open(Echo %DATE% %TIME%
sc query svchost
sc query svchostQuarantine
reg query HKEY_CLASSES_ROOT\CLSID\{DEE6806C-FB33-D04C-E1C6-8DA9B2204850}
reg query HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IDDE
reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
)>logit.txt 2>&1
start notepad logit.txt
LonnyRJones said:These are what it created for me, Are you comfortable working in the registry ?
HKEY_CLASSES_ROOT\CLSID\{DEE6806C-FB33-D04C-E1C6-8DA9B2204850}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IDDE
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\svchost
c:\WINDOWS\IDDE < folder
c:\WINDOWS\system\MSIDLLSI.DAT
c:\WINDOWS\system\setup.log
c:\WINDOWS\system\svchost.exe
c:\WINDOWS\system32\TMLib.dll
c:\WINDOWS\system32\TMUtils.dll
c:\WINDOWS\ddemal.bin
c:\WINDOWS\tm-log.log
LonnyRJones said:What process do you suspect ?
Copy the contents of the quote box (not including the word quote) below into a new notepad document (not wordpad).
Click file> save as...> call it check.bat > file types *all files*> and save it to desktop.
Run check.bat and post back with the text that will open
LonnyRJones said:What process do you suspect ?
alg.exe - it was installed during the same time when I started to see the first informations that 'advanced KEYLOGGER' want to go through...
It's Microsoft's one...
LonnyRJones said:What process do you suspect ?
Copy the contents of the quote box (not including the word quote) below into a new notepad document (not wordpad).
Click file> save as...> call it check.bat > file types *all files*> and save it to desktop.
Run check.bat and post back with the text that will open
royakai said:wow!
probably I've done it!!!
I denied system control over ThreadingModel (Apartment), and Default (imcui.dll), and allowed Administrator and user to set control over it, and...
I deleted it from registry!!!
I'm going to check it by PCGuard and AdAware to see the results...
By the way - what do you think about it?
Could you explain how advanced keyloggers work?
LonnyRJones said:Sounds as if the registry keys permisions were messed up, You solved it by changing them, then was able to delete the key.
You understand ? , it was not some process keeping it there.