| GreenBean | 06-15-2013 07:46 PM | When I have had issues with 'computers' that are not APPLE, my brother gave this advice.
Let's assume it's a keylooger so all steps to 'clean up' can be done.
Other methods would include getting hold of wireshark and monitoring your outbound traffic for packets being sent to ad companies or rogue websites. You could then block these on your router. You can also use TCPView within windows to monitor these. See if anything looks suspicious.
Grab a firewall and lock it down. Set it for everything to ask for permission. That way you'll be able to narrow down the process or executable that's trying to upload logged data. View all hidden and system files on your PC, do a wildcard search for all files that have changed in the last few hours of PC use. One may look suspicious, this may be the root log that's recording keystrokes before being sent. It might be an idea to use your laptop offline in the first instance while running network checks and see if anything is still trying to 'send' data out despite no connectivity.
Malwarebytes is meant to be good for detecting this kind of stuff, although I've not really used it much. You could try creating another account that makes use of a high level UAC as well and logging in as that user, see if any spurious programs require elevated privileges, although if it's already created an entry in the HKLM-Run I'm guessing it just needed the one time elevation that's already been provided.
It will take a while to dig through all this and if you suspect a keylogger you're not going to be able to use your laptop for anything private until you confirm (facebook, banking, email etc.), which leads us into - just flatten and rebuild. |