|
123Keylogger is a spyware program that logs user activity on the compromised computer, including Web sites visited and programs run. 123Keylogger can be configured to send the collected information to an unsolicited third party and run in stealth mode in order to prevent its detection. 123Keylogger is a severe violation of your security and privacy and advised to be removed with no delay.
Remove the Spyware Using Spyware Doctor!

Sponsored Links:
Free Download Now:

123Keylogger Removal:
To remove 123Keylogger, please follow the instruction:
- Terminate the processes in Task Manager:
Viewer.exe
UnloadES.exe
bbbb.exe.exe
- Click Start > Run. Type REGSVR32 -u %Dll_name%. Then click OK. Replace %Dll_name% with following:
HookEngine.dll
- Click Start > Run. Type REGEDIT. Then click OK. Navigate to the subkeys and delete the values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"ES Current Services" = "C:\WINDOWS\System32\Winservc\[FILE NAME].exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\123Keylogger \"DisplayName" = "123Keylogger Software v1.0 (build 20)" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\123Keylogger \"UninstallString" = ""C:\WINDOWS\System32\Winservc\Uninst.exe"" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\"ES Current Services" = "C:\WINDOWS\System32\Winservc\[FILE NAME].exe" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYMANTEC_CORE_LC\0000\Control\"ActiveService" = "Symantec Core LC" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\Control\*NewlyCreated" = "0" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\Control\"ActiveService" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"Service" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"Legacy" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"ConfigFlags" = "0" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"Class" = "LegacyDriver" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS
\0000\"DeviceDesc"= "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Enum\"0" = "Root\LEGACY_INVISSYS\0000" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Enum\"Count" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Enum\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Security\"Security" = "01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"Type" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"Start" = "3" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"ErrorControl" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"ImagePath" = "\??\C:\WINDOWS\System32\Winservc\invis.sys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"DisplayName" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMANTEC_CORE_LC
\0000\Control\"ActiveService" = "Symantec Core LC" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\Control\*NewlyCreated" = "0" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\Control\"ActiveService" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"Service" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"Legacy" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"ConfigFlags" = "0" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"Class" = "LegacyDriver" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"DeviceDesc" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Enum\"0" = "Root\LEGACY_INVISSYS\0000" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Enum\"Count" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Enum\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Security\"Security" = "01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"Type" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"Start" = "3" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"ErrorControl" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"ImagePath" = "\??\C:\WINDOWS\System32\Winservc\invis.sys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"DisplayName" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Screenshots" = "0" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_ScreenShotTime" = "0x00007530" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_JpegQuality" = "32" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_ScreenShotFolder" = "C:\WINDOWS\System32\Winservc/Screenshots" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Keyboard" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Activated" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Executed" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Clipboard" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Web_Page" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Web_address" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Location" = "C:\WINDOWS\System32\Winservc" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_KeylogerFilename" = "[FILE NAME].exe" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Unload" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_LogFolder" = "C:\WINDOWS\System32\Winservc" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_LogName" = "CatchLog" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_tmpFirst" = "0" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_tmpSession_Type" = "76" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_tmpProcName" = "regshot.exe"
Registry management is too hard? Download Registry Mechanic, and you will find it too easy!
- Remove the files mentioned above and following directory in Explorer if exist:
%SystemRoot%\system32\Winservc
Spyware Doctor can automatically remove the Spyware. Even if you remove it manually, we recommend you should use Spyware Doctor to make sure it's completely removed from your system and will not be reinstalled by itself.

More
Removal Instructions for Emerging Adware & Spyware
|