Firstly, I'd like to say thanks for taking such an interest. When I first posted here, I thought about linking to my other posts to give the full story, but I decided it was better just to try to ask a simple question and not take up too much of someone's time. But it's great that you made the effort to find my other posts and I appreciate it.
Although, it appears to be unlikely that this detection is a false positive, Spybot appears to have cleared it up. I'm a bit confused on why you are still worried if avast, MBAM, and Spybot have came it clean.
I'm not too worried now, just trying to tie up a few loose ends.
I was just thinking that this could be a trace of a "keylogger". After all, it is a new machine and the pre-installed software (some you do not need) may have included the optional Ask.com toolbar.
Yeah, that was my first thought too, but I would have expected to find lots of threads about the ask.com toolbar causing false positives if that was the case. However as I couldn't really find anything about it, I decided to be careful and assume that it was a real keylogger.
I found your thread on PC Advisor. If you do not mind, I was wondering what you meant by "picking up a really serious bit of malware". Were you referring to the labtop?
Yes. To be clear, there's my father's laptop on which Spybot reported the stealth keylogger and there's my pc which is a desktop and is absolutely fine. And by "serious bit of malware" I was referring to the stealth keylogger.
1. You are fine for now. It is good news that your AV and anti-malware programs are not picking up anything.
2.Possibly with the preinstalled software (since some might host the optional Ask.com toolbar).
3. Nope. McAfee is McAfee. When it is distributed, it is offered as a trial. Not crippleware or a security suite with security holes.
4. Not necessarily "infected". To me, I've always said that if a malicious registry key was in your machine, it is technically dead. It is missing it's critical components (the core of the software) such as the files and services that are installed. But that does not mean it is always the case. I mean you can always remove the key in a split second.
1.,2.,3. Ok
4. You've slightly lost me there, but I'd really just like to go back to my original question. Because Spybot did a back-up of the registry before I got rid of the keylogger, is the back-up infected? Should I do a new back-up? Or is there no problem?
How is the HJT logs going at PCA?
Ok. The thread is
here. Had my logs looked over and they're fine. Ran into some trouble in getting Combofix to work and I've left it for the moment. I'd ask for help somewhere dedicated to Combofix before trying it again.
So, it's just really that point 4 above that I could do with being cleared up. Thanks again for your help.