Discover Habbo's history
Treat yourself with a Secret Santa gift.... of a random Wiki page for you to start exploring Habbo's history!
Happy holidays!
Celebrate with us at Habbox on the hotel, on our Forum and right here!
Join Habbox!
One of us! One of us! Click here to see the roles you could take as part of the Habbox community!


Page 1 of 2 12 LastLast
Results 1 to 10 of 13
  1. #1
    Join Date
    Mar 2006
    Location
    Cheshire
    Posts
    1,945
    Tokens
    188

    Latest Awards:

    Default Ardamax Keylogger

    Just found out i've had a bloody keylogger on my system =/

    annoyingly easy to check (i pressed shift ctrl alt and h and up popped a box asking for a password)

    So yeah, ive searched through everything i can think of, and cant find a way to remove it. any help?

  2. #2
    Join Date
    Apr 2007
    Location
    Playboy Mansion
    Posts
    335
    Tokens
    0

    Default

    www.**********
    ask who keylogged u
    they produce the keylogger dl

  3. #3
    Join Date
    Jul 2008
    Location
    Gloucester
    Posts
    976
    Tokens
    0

    Default

    Locate the directory it's running from (process manager, note the process that's running and search for it). Download Unlocker Assistant and remove it along with other suspect and similarly named files. Make sure to look through and find these entries:

    Code:
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallArdamaxKeylogger
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsAppPathsakl.exe
    HKEY_CURRENT_USERSoftwareArdamaxKeyloggerLite
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunNSK
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionUninstallArdamax Keylogger
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunArdamaxKeylogger
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsApp Pathsakl.exe 
    HKEY_CURRENT_USER SoftwareArdamax Keylogger Lite 
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunNSK 
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunArdamax Keylogger
    A few searches found me that these are the active processes the Ardamax keylogger uses:
    Code:
    nsk.exe
    akv.exe
    akl.exe
    akv.exe
    nsk.exeakl.exe
    Next you need to unregister the .dlls it uses
    Copy and post the following into Run (Windows Key + R)

    Code:
    exact directory path + "regsvr32 /u" + kh.dll
    Code:
    exact directory path + "regsvr32 /u" + il.dll
    I hope that helps

    Edit: The following is a complete list of the files that you should be looking for (as far as I know this is all of them)

    Code:
    settings.ini
    akv.ini
    kh.dll
    il.dll
    nsk.exe
    akv.exe
    akl.exe
    akv.exe
    nsk.exe
    il.dll
    kh.dll
    akv.ini
    settings.iniakl.exe
    Last edited by DrLacero; 15-08-2008 at 12:56 AM.





  4. #4
    Join Date
    Dec 2006
    Location
    Nottingham
    Posts
    7,752
    Tokens
    756
    Habbo
    katie.pricejorda

    Latest Awards:

    Default

    Quote Originally Posted by DrLacero View Post
    Locate the directory it's running from (process manager, note the process that's running and search for it). Download Unlocker Assistant and remove it along with other suspect and similarly named files. Make sure to look through and find these entries:

    Code:
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallArdamaxKeylogger
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsAppPathsakl.exe
    HKEY_CURRENT_USERSoftwareArdamaxKeyloggerLite
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunNSK
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionUninstallArdamax Keylogger
    HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunArdamaxKeylogger
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindowsApp Pathsakl.exe 
    HKEY_CURRENT_USER SoftwareArdamax Keylogger Lite 
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunNSK 
    HKEY_LOCAL_MACHINE SOFTWAREMicrosoftWindows CurrentVersionRunArdamax Keylogger
    A few searches found me that these are the active processes the Ardamax keylogger uses:
    Code:
    nsk.exe
    akv.exe
    akl.exe
    akv.exe
    nsk.exeakl.exe
    Next you need to unregister the .dlls it uses
    Copy and post the following into Run (Windows Key + R)

    Code:
    exact directory path + "regsvr32 /u" + kh.dll
    Code:
    exact directory path + "regsvr32 /u" + il.dll
    I hope that helps

    Edit: The following is a complete list of the files that you should be looking for (as far as I know this is all of them)

    Code:
    settings.ini
    akv.ini
    kh.dll
    il.dll
    nsk.exe
    akv.exe
    akl.exe
    akv.exe
    nsk.exe
    il.dll
    kh.dll
    akv.ini
    settings.iniakl.exe
    That looks very useful, would it not be advisable to pull out the ethernet cable and disconnect from the internet as well and change your online passwords and emails preferably. Recap what you've done on your computer and take nothing for granted.

    Try think how you got it too, I would rep you Dr but I can't

  5. #5
    Join Date
    Aug 2008
    Location
    North London
    Posts
    132
    Tokens
    0

    Default

    I had one too, just then I resotred a couple days back and changed some pws on laptop

  6. #6
    Join Date
    Aug 2008
    Location
    North London
    Posts
    132
    Tokens
    0

    Default

    Quote Originally Posted by ClassicLegend View Post
    I had one too, just then I resotred a couple days back and changed some pws on laptop
    So will it be fixed now?

  7. #7
    Join Date
    Jul 2008
    Location
    Gloucester
    Posts
    976
    Tokens
    0

    Default

    Quote Originally Posted by ClassicLegend View Post
    So will it be fixed now?
    I very much doubt it.





  8. #8
    Join Date
    Aug 2008
    Location
    North London
    Posts
    132
    Tokens
    0

    Default

    Quote Originally Posted by DrLacero View Post
    I very much doubt it.
    Hmm, cheers for help but getting it fixed, my dads doing it we cleaning it out and scanning big and such

  9. #9
    Join Date
    Nov 2007
    Location
    London
    Posts
    1,577
    Tokens
    36

    Latest Awards:

    Default

    In future, simply download the ardamax keylogger removal tool off the ardamax website...

    http://www.ardamax.com/downloads/aklremover.exe
    Kind Regards,

    Guy
    __________________

    Since 2007. Unbelievable Uptime. Web hosting, resellers, master resellers, linux VPS, windows VPS, shoutcasts, at the lowest prices on the net.
    Tech-Hosts.co.uk.


  10. #10
    Join Date
    Aug 2008
    Location
    North London
    Posts
    132
    Tokens
    0

    Default

    That does remove the trojan itsrlf only if you downloaded the keylogger to keylog some one else, doesnt it..

Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •