PeanutsPo,
Just curious...can you tell us how you arrived at the conclusion that a Keylogger is installed on the system by the name
image2872?
:info: Please start the computer, and tap the
F8 key before the Windows logo appears.
When you get the
Advanced Boot Options screen, use the arrow keys to highlight
Safe Mode with Networking, and then press:
Enter
:info: Next, please use
RKill.exe to terminate malware processes:
http://download.bleepingcomputer.com/grinler/rkill.exe
Save to the Desktop.
If
RKill.exe does not run, then download and try to run
RKill.com:
http://download.bleepingcomputer.com/grinler/rkill.com
You only need to get one of the versions of RKill to run.
There are additional versions:
RKill.scr:
http://download.bleepingcomputer.com/grinler/rkill.scr
Also, RKill, renamed, can be downloaded from the following links:
iExplore.exe:
http://download.bleepingcomputer.com...r/iExplore.exe
uSeRiNiT.exe:
http://download.bleepingcomputer.com...r/uSeRiNiT.exe
WiNlOgOn.exe:
http://download.bleepingcomputer.com...r/WiNlOgOn.exe
If your AntiVirus warns you about this tool, ignore the warning, or temporarily disable your AntiVirus.
Right-click on the downloaded
RKill file and select:
Run as Administrator
A black DOS box briefly flashes and then disappear. This is normal and indicates the tool ran successfully.
After running the tool,
do not reboot.
When the scan is done Notepad opens with the RKill report.
Please post the
RKill report in your reply.
:info:
Without a reboot, please
Download RogueKiller (Official website)
Select the x64 version download.
Save to the Desktop.
Close all windows and browsers.
Right-click and select:
Run as Administrator
At the program console, wait for the prescan to finish. (Under Status, it says: Prescan finished.)
Press:
SCAN
When done, a report opens on the Desktop:
RKreport.txt
Please provide the
RKreport.txt (Mode: Scan) in your reply.