IPB

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> Keylogger?
Jarronn
post 27.03.2009 15:30
Post #1


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




I didn't get anything like this suspected keylogger warning before. Now I get it rather regularly. I'm wondering if it has anything to do with the fact that I use a Microsoft ergonomic keyboard with my PC.

I would enter the exact keylogger address in my computer, but I don't know how to find it now. I hope you can help. Thanks
Go to the top of the page
 
+Quote Post
Sjoeii
post 27.03.2009 17:27
Post #2


Professional
**************

Group: Gold beta testers
Posts: 7308
Joined: 17.01.2006
From: Amsterdam




Could you post a screenshot please= That way it is easier to see what is happening


--------------------
* Download latest products * Kaspersky Removal Tool * GetSystemInfo* Virus watch 3 * Dutch Support Forum

If you want to discuss non technical kaspersky issue please come and visit the KL Labs FanClub Forum (RU|INT)
Go to the top of the page
 
+Quote Post
Jarronn
post 27.03.2009 20:46
Post #3


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




QUOTE(Sjoeii @ 27.03.2009 04:27) *
Could you post a screenshot please= That way it is easier to see what is happening

I don't know how to create a screenshot and I can only see that window when it informs me that keylogger activity is suspected. I don't know how to bring that window up until it says that. What I can do is copy and past the message the next time it happens. It usually happens about once a day or two.

Go to the top of the page
 
+Quote Post
Jarronn
post 27.03.2009 22:17
Post #4


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




I forgot to mention that it started happening after I used the Kaspersky tool to uninstall the old program and put in the 2009 version of Kaspersky
Go to the top of the page
 
+Quote Post
Jarronn
post 27.03.2009 22:18
Post #5


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




Internet security
Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 00:29
Post #6


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




ALRIGHT! GOT IT FOR YA!

And I wasn't even using the keyboard at the time it happened.

It's a Microsoft ergonomics keyboard. I'll never do without one again, if I can help it!Has done wonders for my wrists.

Client Server Runtime Process (events: 1)
Client Server Runtime Process (events: 1)
3/27/2009 11:26:13 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\ELKBD.SYS Not terminated: Keylogger
3/27/2009 11:26:13 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\ELKBD.SYS Detected: Keylogger
3/27/2009 11:26:13 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\ELKBD.SYS Detected: Keylogger
3/27/2009 11:26:13 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\MHK.SYS Not terminated: Keylogger
3/27/2009 11:26:13 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\MHK.SYS Detected: Keylogger
3/27/2009 11:26:13 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\MHK.SYS Detected: Keylogger
3/27/2009 10:25:19 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\ELKBD.SYS Not terminated: Keylogger
3/27/2009 10:25:19 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\ELKBD.SYS Detected: Keylogger
3/27/2009 10:25:19 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\ELKBD.SYS Detected: Keylogger
3/27/2009 10:25:19 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\MHK.SYS Not terminated: Keylogger
3/27/2009 10:25:19 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\MHK.SYS Detected: Keylogger
3/27/2009 10:25:19 AM Keylogger activity C:\WINDOWS\SYSTEM32\DRIVERS\MHK.SYS Detected: Keylogger

edit: del chunk of very lengthy pasted log.

This post has been edited by richbuff: 28.03.2009 03:24
Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 00:31
Post #7


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




Hey, it happens every around the hour (and on the half-hour) I used the computer. Obviously, it happens whether I am typing or not

This post has been edited by Jarronn: 28.03.2009 00:33
Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 03:01
Post #8


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




QUOTE(Jarronn @ 27.03.2009 11:31) *
Hey, it happens every around the hour (and on the half-hour) I used the computer. Obviously, it happens whether I am typing or not

I sure hope someone here can help me
Go to the top of the page
 
+Quote Post
richbuff
post 28.03.2009 03:27
Post #9


True legend
***************

Group: Moderators
Posts: 18847
Joined: 14.06.2007




Did you try right click entry and select Add to exclusions?


--------------------
Please see the Important topics, located at the top of this section, and at the top of other sections of this forum.
Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 06:56
Post #10


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




QUOTE(richbuff @ 27.03.2009 14:27) *
Did you try right click entry and select Add to exclusions?

Why should I do that?

I just ran a full scan if there was truly a keylogger that should not be in my computer shouldn't the 2009 Kaspersky Internet security program have caught it? It says everything is fine with my computer.

Go to the top of the page
 
+Quote Post
richbuff
post 28.03.2009 07:28
Post #11


True legend
***************

Group: Moderators
Posts: 18847
Joined: 14.06.2007




Because they are not malware, they are legitimate items that exhibit keylogger behavior. ELKBD.SYS is part of Intel Quick Resume Technology and MHK.SYS is part of Jetico BestCrypt Encryption System.


--------------------
Please see the Important topics, located at the top of this section, and at the top of other sections of this forum.
Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 08:04
Post #12


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




QUOTE(richbuff @ 27.03.2009 18:28) *
Because they are not malware, they are legitimate items that exhibit keylogger behavior. ELKBD.SYS is part of Intel Quick Resume Technology and MHK.SYS is part of Jetico BestCrypt Encryption System.

Well, that's a relief! It's not some sort of Trojan condom virus. Okay!

So, the next time it shows up I should right-click on...what exactly? and set it to exclusion?

Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 13:13
Post #13


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




I've tried right-clicking on the individual files and I'm not being given any "exclusion" option
Go to the top of the page
 
+Quote Post
richbuff
post 28.03.2009 13:19
Post #14


True legend
***************

Group: Moderators
Posts: 18847
Joined: 14.06.2007




Did you try to right click on the entry in the detection report?


--------------------
Please see the Important topics, located at the top of this section, and at the top of other sections of this forum.
Go to the top of the page
 
+Quote Post
Jarronn
post 28.03.2009 22:12
Post #15


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




QUOTE(richbuff @ 28.03.2009 00:19) *
Did you try to right click on the entry in the detection report?

It can be so frustrating dealing with you technical people. You assume too much!

What is the "entry in the detection report"? And PLEASE give me a very simple and direct response. Oh, you feel this makes me stupid? Okay, I'll openly admit it I'M STUPID. Direct me as though I am mentally retarded.


Thanks

Go to the top of the page
 
+Quote Post
rudger79
post 28.03.2009 22:38
Post #16


Kaspersky fan
**********

Group: Members
Posts: 2218
Joined: 20.10.2008
From: Kodiak USA




Hi.
Click on the big Red & Black "K" in the system tray, lower right of screen. From the screen that opens click on the detected tab, lower right of screen. If the keylogger detection is showing there, right click on it to see if you can add it to exclusions. smile.gif


--------------------
1. Vista Home Premium SP2 64-bit OS 3gb Defender Off - FF 3.5.6 - Opera 10.01 - IE 8 - KIS 9.0.0.736(a.b.) Currently Testing PURE
2.
XP Media Center Edition SP-3, 1gb ] FF 3.5.6 - KIS 9.0.0.736
(a.b.)
Go to the top of the page
 
+Quote Post
Jarronn
post 29.03.2009 10:08
Post #17


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




QUOTE(rudger79 @ 28.03.2009 09:38) *
Hi.
Click on the big Red & Black "K" in the system tray, lower right of screen. From the screen that opens click on the detected tab, lower right of screen. If the keylogger detection is showing there, right click on it to see if you can add it to exclusions. smile.gif

I clicked on the detected tab and the keylogger detected paths I have already posted were not in there.

What's next?

Thanks
Go to the top of the page
 
+Quote Post
Jarronn
post 30.03.2009 20:20
Post #18


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




Okay, I think I figured out what to do and I thought I would share it so that you can help anyone else who happens to have the same problem:

The small window that opens when I would get the suspected keylogger activity notification would not remain for long if I didn’t click on something. In the upper-right of the window there is a small arrow V. I clicked on that V and I was given the option to disable that notification. I clicked on disabling that particular notification and I hope that will solve the problem.

If that will created more problems in the future I would like to know. I mean, I don’t want ALL notifications for suspected keylogger activity to be disabled.

Thanks

Go to the top of the page
 
+Quote Post
Jarronn
post 31.03.2009 09:41
Post #19


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




Okay, I discovered another method I will share in the hopes that it will help someone else with this problem. For 2009 Kaspersky Internet Security:

At the bottom right of the computer screen double-click on the Kaspersky K that should be in the system tray

At the bottom right of the Kaspersky window that opens click on “Detected”

Towards the (((UPPER-LEFT))), under where the Detected tab is, there is a drop-down window box. Click on the arrow and from the menu click:

All Detected Malware

For me, that ((((FINALLY))))) showed the keylogger alert. Then I clicked on what I wanted to highlighted then right-clicked on the keylogger alert there and chose:

Add to exclusions

The Keylogger alert there then disappeared.

I hope this helps you help anyone else with this problem. If there is anything else I should know please clue me in. I want to be certain any different keylogger alerts are not disabled

Thanks

Go to the top of the page
 
+Quote Post
Jarronn
post 1.04.2009 16:37
Post #20


Member
**

Group: Members
Posts: 43
Joined: 21.01.2008




I want to take this opportunity to thank you all for the help you have given me. I apologize if I got frustrated by my stupidity in such matters.

I hope what I shared can help others who may be having the same problem I was having after first installing Kaspersky Internet security 2009


Thanks again!
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 9.02.2010 17:25