This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Removal preparations (Keylogger)

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Today I had to print files from a public PC, and just as expected got a keylogger. Suspected so, and confirmed, by running "dir /w /o /a /p", and noticing "uhoxajc.cmd" and "autorun.inf" on the pen drive's folder ; those didn't show up in the file explorer, even with 'Hide system files disabled'. I did this on computer at my home, which is not currently connected to my network, nor the internet. I'd like to know what steps I can take without having to move files from there, because doing so would involve either connecting a USB drive to one of the other computers, or connecting it to the network, more then likely infecting those, a problem I don't want to have now. Another option would be a fail-safe way to not allow files to be written from said infected drive, but I don't think said option exists. I was told I could use a small Linux installation to clean the drive, but was given no further details on how to do that. Kaspersky Rescue Disk was also suggested, but I'd like to have as many options as possible. Am open to other suggestions.
Hi Watcher741,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.


That combination of files is typically associated with a password stealing trojan (rather than a keylogger) that specifically targets games from Gammima such as Maple Story, Counter Strike… and some others. Typically the way you get it is from downloading an "addon" or "cheat" to one of these games.


I suggest that you proceed as follows:

First, reformat the thumb drive that you believe to be infected… preferably from a "clean" computer.

Please download Flash Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives. Please do so and allow the
    utility to clean up those drives as well. Hold down the Shift key when inserting the drive until Windows detects it to keep autorun.inf from executing if it is present.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive that is plugged in when you ran it. This is a "good" version, rather than the one you currently have. Don't delete this folder…it will help protect your drives from future infection.

Now, download the following program to the flash drive and transfer it to your infected computer to run.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Once I see the results from Malwarebytes', I'll have more instructions for you.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI