Suspecting a keylogger, please advise...

Darkshadw

Honorable
Jan 6, 2013
2
0
10,510
Hello all,

So I was searching through my registry to fix a game's settings that I have been messing with and I saw the following key: "HKEY_USERS\S-1-5-21-1428292790-3725576381-3897953999-1000\Software\358a16345d3d971d0a3993e532e3803c\[kl]" And in there it shows me stuff like this:

XML:
15/01/01 regedit Registry Editor
blade kittin[Back][Back]en[ENTER]

15/01/01 regedit Registry Editor

15/01/01 regedit Registry Editor
[ENTER]

I do have most of my accounts secured with a password and a text verification. But this is still freaking me out. What do you guys think that is going on? This is a freshly installed Windows 7 Home Premium (Installed it about a week ago).

Thanks,

Sapphire ~
 
Solution
G
It doesn't appear to be something very malicious. McAfee describes it as a PUP (potentially unwanted program). I don't know what the [kl] stands for, but I don't thing it refers to a keylogger:

http://home.mcafee.com/virusinfo/virusprofile.aspx?key=9360947#none

The following registry elements have been created:

HKEY_CURRENT_USER\SOFTWARE\358A16345D3D971D0A3993E532E3803C\


The following registry elements have been changed:


HKEY_CURRENT_USER\DI = 33

HKEY_CURRENT_USER\ENVIRONMENT\SEE_MASK_NOZONECHECKS = 49

HKEY_CURRENT_USER\SOFTWARE\358A16345D3D971D0A3993E532E3803C\[KL]

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\CONHOST = %WINDIR%\conhost.exe...
G

Guest

Guest
It doesn't appear to be something very malicious. McAfee describes it as a PUP (potentially unwanted program). I don't know what the [kl] stands for, but I don't thing it refers to a keylogger:

http://home.mcafee.com/virusinfo/virusprofile.aspx?key=9360947#none

The following registry elements have been created:

HKEY_CURRENT_USER\SOFTWARE\358A16345D3D971D0A3993E532E3803C\


The following registry elements have been changed:


HKEY_CURRENT_USER\DI = 33

HKEY_CURRENT_USER\ENVIRONMENT\SEE_MASK_NOZONECHECKS = 49

HKEY_CURRENT_USER\SOFTWARE\358A16345D3D971D0A3993E532E3803C\[KL]

HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\CONHOST = %WINDIR%\conhost.exe

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\CONTROL\SESSION MANAGER\MEMORY MANAGEMENT\CLEARPAGEFILEATSHUTDOWN = 0

Blade Kitten is a video game:

http://www.bladekitten.com/


Please download AdwCleaner.


  • Double-click the adwcleaner.exe to run the tool.
    Click Scan.
    When the scan is finished, click Clean.
    When the cleaning process is over, click Report and a Notepad window will be opened.
    Please post the contents here in your topic.
 
Solution