a family member installed refog keylogger in my pc.
its installation process creates a folder C:\WINDOWS\system32\MPK.
i tried to uninstall it but it asked for a password.
then i deleted all the contents of the folder MPK .
then i downloaded refog setup and installed it.
when i opened it , it asked for the password...not the new..but the old one set by that family member.
now i think all my activities are monitored by this refog.
and i wish to completely uninstall it..
i dont know what to do ?
kindly help..![]()
Last edited by ashaypal; 04-12-2009 at 11:10 PM.
The files will be disguised under different names. At least thats how it is with Pandora. If you don't know the pass, can't find a way to either brute force it or a dictionary attack you'll have to find and delete the files manually.
You said that you deleted the installer. Does that mean you attempted to uninstall it or that you deletted the application that installed it? If it is the latter you may be able to find the process with something like hijackthis, and then uninstall it with something like Revo in hunter mode.
Also, If you are not the one who installed it, whoever did more than likely created an application rule in your internet security program (if you have one), to get your IS to trust the program. I would attempt to find and remove that rule.
If you dont have a good IS program, just download a trial of KIS and use that.
waiting for ur help
it was not installed thu internet...manually installed at my pc
Last edited by ashaypal; 04-10-2009 at 02:09 PM. Reason: Automerged Doublepost
i hope someone can help me. I installed refog keylogger and accidentally set it to hide. Now I couldn't find it so i can launch and use it. I tried their online support but they only opened a ticket and after 12 hours it's still unassiged. Does anyone know how I can launch the program. I read there is a secret key combination but I have no idea what it is. Please help. Thanks
Try using antispyware or antivirus software, they should be able to detect the keylogger software and remove it. I'll try to check on "refog keylogger" and see if they can be manually terminated and removed.
your reference : Analysis Report for refog_setup_kl_533.exe
Anubis
"Semper Fidelis."
It's not so easy to manually delete the keylogger because it can be passworded so the uninstaller won't work, and most importantly it is running in stealth, there are no process to terminate.
Anyway I've figured out a simple hack on how to uninstall the keylogger. Need to do more test. Stay tuned.
Last edited by ashaypal; 09-08-2009 at 05:23 PM.
Well I saw your post Ray and it's a good hack...
It took me an hour to study refog keylogger schemes and I though the only to get rid of it is by manual brute force
Last edited by Ceyfer √; 09-08-2009 at 07:36 PM.