Hello, A few friends have told me today they've gotten emails apparently from me, but with strange links. Clearly someone has raided my address book. Interestingly, one friend received an email with a link to a thai website that, as I found through a Google search, relates to someone calling himself Mr KeyBoard Hacker.
Anyway, I have run a few clean up tools and have started changing important passwords, but I would like to be sure I have removed whatever software might be tracking my keyboard activity, so that I can be sure I won't need to change all the passwords again so soon.
I'll post the logs for the scans I've already run. Could someone tell me if I need to do more? Thanks very much in advance.
To start with, hear is the AdwCleaner log:
# AdwCleaner v5.019 - Logfile created 11/11/2015 at 18:31:43
# Updated 08/11/2015 by Xplode
# Database : 2015-11-09.1 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : Teresa - TERESA-HP
# Running from : C:\Users\Teresa\Downloads\adwcleaner_5.019.exe
# Option : Cleaning
# Support :
http://toolslib.net/forum***** [ Services ] *****
***** [ Folders ] *****
[-] Folder Deleted : C:\Program Files (x86)\Probit Software
[-] Folder Deleted : C:\Program Files (x86)\myfree codec
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodecC
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Probit Software
[-] Folder Deleted : C:\Users\Clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaamhiihn
[!] Folder Not Deleted : C:\Users\Clara\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaamhiihn
[-] Folder Deleted : C:\Users\Clara\AppData\LocalLow\CodecC
[-] Folder Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\Extensions\staged\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
[!] Folder Not Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\Extensions\staged\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
[-] Folder Deleted : C:\Users\Marius\AppData\LocalLow\CodecC
[-] Folder Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\Extensions\staged\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
[!] Folder Not Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\Extensions\staged\{a2bff6ba-8d18-488c-853c-ad9bc29f2482}
[-] Folder Deleted : C:\Users\Teresa\AppData\Roaming\DigitalSites
***** [ Files ] *****
[-] File Deleted : C:\Users\Clara\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ekdjfcdinekpfcedakhpngcnaamhiihn_0.localstorage
[-] File Deleted : C:\Users\Clara\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ekdjfcdinekpfcedakhpngcnaamhiihn_0.localstorage-journal
[-] File Deleted : C:\Users\Clara\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ekdjfcdinekpfcedakhpngcnaamhiihn_0.localstorage
[-] File Deleted : C:\Users\Clara\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ekdjfcdinekpfcedakhpngcnaamhiihn_0.localstorage-journal
[-] File Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\user.js
[-] File Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\user.js
[-] File Deleted : C:\Users\Clara\AppData\Roaming\Mozilla\Firefox\Profiles\h69ubxaw.default\user.js
[-] File Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\user.js
[-] File Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\user.js
[-] File Deleted : C:\Users\Marius\AppData\Roaming\Mozilla\Firefox\Profiles\fa889zg6.default\user.js
[-] File Deleted : C:\Users\Teresa\AppData\Local\Google\Chrome\User Data\Default\local storage\hxxp_www.lyricsmode.com_0.localstorage-journal
[-] File Deleted : C:\Users\Teresa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_embed.movshare.net_0.localstorage-journal
[-] File Deleted : C:\Users\Teresa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_kwiclick.en.softonic.com_0.localstorage-journal
[-] File Deleted : C:\Users\Teresa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.bearshare.net_0.localstorage-journal
[-] File Deleted : C:\Users\Teresa\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.movshare.net_0.localstorage-journal
[-] File Deleted : C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\8qywzvdz.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\8qywzvdz.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\8qywzvdz.default\searchplugins\Vosteran.xml
[-] File Deleted : C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\8qywzvdz.default\user.js
[-] File Deleted : C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\8qywzvdz.default\user.js
[-] File Deleted : C:\Users\Teresa\AppData\Roaming\Mozilla\Firefox\Profiles\8qywzvdz.default\user.js
[-] File Deleted : C:\Windows\Downloaded Program Files\popcaploader.inf
[-] File Deleted : C:\Windows\SysNative\ImhxxpComm.dll
***** [ DLLs ] *****
***** [ Shortcuts ] *****