Results 1 to 9 of 9
  1. #1
    Verified Member
    Overall activity: 0%

    Join Date
    Apr 2009
    Location
    Dehra Dun, India, India
    Posts
    32
    Liked
    0 times
    Points
    3,823

    Confused refog keylogger uninstall

    a family member installed refog keylogger in my pc.
    its installation process creates a folder C:\WINDOWS\system32\MPK.
    i tried to uninstall it but it asked for a password.
    then i deleted all the contents of the folder MPK .
    then i downloaded refog setup and installed it.
    when i opened it , it asked for the password...not the new..but the old one set by that family member.
    now i think all my activities are monitored by this refog.
    and i wish to completely uninstall it..
    i dont know what to do ?
    kindly help..
    Last edited by ashaypal; 04-12-2009 at 11:10 PM.

  2. #2
    Senior Techie
    Overall activity: 0%

    Join Date
    Jan 2009
    Location
    Wv, USA
    Posts
    245
    Liked
    0 times
    Points
    3,303
    The files will be disguised under different names. At least thats how it is with Pandora. If you don't know the pass, can't find a way to either brute force it or a dictionary attack you'll have to find and delete the files manually.
    You said that you deleted the installer. Does that mean you attempted to uninstall it or that you deletted the application that installed it? If it is the latter you may be able to find the process with something like hijackthis, and then uninstall it with something like Revo in hunter mode.
    Also, If you are not the one who installed it, whoever did more than likely created an application rule in your internet security program (if you have one), to get your IS to trust the program. I would attempt to find and remove that rule.
    If you dont have a good IS program, just download a trial of KIS and use that.

  3. #3
    Verified Member
    Overall activity: 0%

    Join Date
    Apr 2009
    Location
    Dehra Dun, India, India
    Posts
    32
    Liked
    0 times
    Points
    3,823
    waiting for ur help

    it was not installed thu internet...manually installed at my pc
    Last edited by ashaypal; 04-10-2009 at 02:09 PM. Reason: Automerged Doublepost

  4. #4
    Newbie
    Overall activity: 0%

    Join Date
    Sep 2009
    Posts
    1
    Liked
    0 times
    Points
    1,884
    i hope someone can help me. I installed refog keylogger and accidentally set it to hide. Now I couldn't find it so i can launch and use it. I tried their online support but they only opened a ticket and after 12 hours it's still unassiged. Does anyone know how I can launch the program. I read there is a secret key combination but I have no idea what it is. Please help. Thanks

  5. #5
    Administrator
    Overall activity: 0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,879
    Liked
    1723 times
    Points
    52,283
    Try using antispyware or antivirus software, they should be able to detect the keylogger software and remove it. I'll try to check on "refog keylogger" and see if they can be manually terminated and removed.

  6. #6
    Guest
    Overall activity: 6.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,088
    Liked
    792 times
    Points
    50,236
    your reference : Analysis Report for refog_setup_kl_533.exe

    Anubis
    "Semper Fidelis."


  7. #7
    Administrator
    Overall activity: 0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,879
    Liked
    1723 times
    Points
    52,283
    It's not so easy to manually delete the keylogger because it can be passworded so the uninstaller won't work, and most importantly it is running in stealth, there are no process to terminate.

    Anyway I've figured out a simple hack on how to uninstall the keylogger. Need to do more test. Stay tuned.

  8. #8
    Verified Member
    Overall activity: 0%

    Join Date
    Apr 2009
    Location
    Dehra Dun, India, India
    Posts
    32
    Liked
    0 times
    Points
    3,823
    Quote Originally Posted by ashaypal View Post
    a family member installed refog keylogger in my pc.
    its installation process creates a folder C:\WINDOWS\system32\MPK.
    i tried to uninstall it but it asked for a password.
    then i deleted all the contents of the folder MPK .
    then i downloaded refog setup and installed it.
    when i opened it , it asked for the password...not the new..but the old one set by that family member.
    now i think all my activities are monitored by this refog.
    and i wish to completely uninstall it..
    i dont know what to do ?
    kindly help..
    finally i got the solution (http://www.raymond.cc/blog/archives/2009/09/08/how-to-uninstall-refog-keylogger-without-knowing-master-password/ ).. after such a long time. by the way i formatted my pc to get rid of the problem
    Last edited by ashaypal; 09-08-2009 at 05:23 PM.

  9. #9
    Guest
    Overall activity: 6.0%

    Join Date
    May 2007
    Location
    Philippines
    Posts
    4,088
    Liked
    792 times
    Points
    50,236
    Well I saw your post Ray and it's a good hack...

    It took me an hour to study refog keylogger schemes and I though the only to get rid of it is by manual brute force
    Last edited by Ceyfer √; 09-08-2009 at 07:36 PM.

 

 

Similar Threads

  1. How to find installation Date & Time of Refog Keylogger?
    By techbeam in forum Spyware/Viruses
    Replies: 2
  2. HELP how to delete refog keylogger from my pc?
    By llovely555 in forum Software
    Replies: 5

Tags for this Thread

All times are GMT +8. The time now is 04:30 PM.