Secure Most Provide you most reliable security utilities!
Home Articles File Center Privacy Contact us Links
Now Position: Home>Tech Articles>Adware/Spyware Removal>123Keylogger
How to Remove 123Keylogger Spyware?
123Keylogger Description:                   Free Download Registry Booster

123Keylogger is a spyware program that logs user activity on the compromised computer, including Web sites visited and programs run. 123Keylogger can be configured to send the collected information to an unsolicited third party and run in stealth mode in order to prevent its detection. 123Keylogger is a severe violation of your security and privacy and advised to be removed with no delay.

Remove the Spyware Using Spyware Doctor!

Free download SpyNoMore

Sponsored Links:

Free Download Now:



123Keylogger Removal:

To remove 123Keylogger, please follow the instruction:

  1. Terminate the processes in Task Manager:
    Viewer.exe
    UnloadES.exe
    bbbb.exe.exe
     
  2. Click Start > Run. Type REGSVR32 -u %Dll_name%. Then click OK. Replace %Dll_name% with following:
    HookEngine.dll
     
  3. Click Start > Run. Type REGEDIT. Then click OK. Navigate to the subkeys and delete the values:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"ES Current Services" = "C:\WINDOWS\System32\Winservc\[FILE NAME].exe" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\123Keylogger
    \"DisplayName" = "123Keylogger Software v1.0 (build 20)" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\123Keylogger
    \"UninstallString" = ""C:\WINDOWS\System32\Winservc\Uninst.exe"" HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\"ES Current Services" = "C:\WINDOWS\System32\Winservc\[FILE NAME].exe" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SYMANTEC_CORE_LC\0000\Control\"ActiveService" = "Symantec Core LC" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\Control\*NewlyCreated" = "0" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\Control\"ActiveService" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"Service" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"Legacy" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"ConfigFlags" = "0" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"Class" = "LegacyDriver" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS
    \0000\"DeviceDesc"= "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_INVISSYS\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Enum\"0" = "Root\LEGACY_INVISSYS\0000" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Enum\"Count" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Enum\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\Security\"Security" = "01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"Type" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"Start" = "3" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"ErrorControl" = "1" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"ImagePath" = "\??\C:\WINDOWS\System32\Winservc\invis.sys" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\InvisSys\"DisplayName" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SYMANTEC_CORE_LC
    \0000\Control\"ActiveService" = "Symantec Core LC" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\Control\*NewlyCreated" = "0" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\Control\"ActiveService" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"Service" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"Legacy" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"ConfigFlags" = "0" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"Class" = "LegacyDriver" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"ClassGUID" = "{8ECC055D-047F-11D1-A537-0000F8753ED1}" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\0000\"DeviceDesc" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_INVISSYS\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Enum\"0" = "Root\LEGACY_INVISSYS\0000" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Enum\"Count" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Enum\"NextInstance" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\Security\"Security" = "01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"Type" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"Start" = "3" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"ErrorControl" = "1" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"ImagePath" = "\??\C:\WINDOWS\System32\Winservc\invis.sys" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InvisSys\"DisplayName" = "InvisSys" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Screenshots" = "0" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_ScreenShotTime" = "0x00007530" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_JpegQuality" = "32" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_ScreenShotFolder" = "C:\WINDOWS\System32\Winservc/Screenshots" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Keyboard" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Activated" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Executed" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Clipboard" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Web_Page" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Web_address" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Location" = "C:\WINDOWS\System32\Winservc" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_KeylogerFilename" = "[FILE NAME].exe" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_Unload" = "1" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_LogFolder" = "C:\WINDOWS\System32\Winservc" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_LogName" = "CatchLog" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_tmpFirst" = "0" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_tmpSession_Type" = "76" HKEY_LOCAL_MACHINE\SYSTEM\SelectServ\"3EA6524740FF4f9691CF201751FFC58A_tmpProcName" = "regshot.exe"
    Registry management is too hard? Download Registry Mechanic, and you will find it too easy!
     

  4. Remove the files mentioned above and following directory in Explorer if exist:
    %SystemRoot%\system32\Winservc

Spyware Doctor can automatically remove the Spyware. Even if you remove it manually, we recommend you should use Spyware Doctor to make sure it's completely removed from your system and will not be reinstalled by itself.

Free download SpyNoMore

More Removal Instructions for Emerging Adware & Spyware
More Removal Instructions for More Adware/Spyware Programs
Sign up for free up-to-date messages about your PC's security & privacy:
              Email
Confirm email
     Your Name    
 Anti-Keylogger  Password Pecovery
 Anti-Spam  PC Monitoring
 Anti-Spyware  Personal Firewall
 Anti-Virus  System Tools
 Online Privacy    
PQ DVD to iPod Video Suite
PQ DVD to iPod Video Suite (PQ DVD to iPod + iPod Video Converter) is a One-Click, All-In-One solution to convert DVD, Tivo, DivX, MPEG, WMV, AVI, RealMedia and many more to iPod Video ...
Kaspersky Internet Security
Internet Security processes all incoming and outgoing data on your computer, including email, Internet traffic and network interaction, without the need for additional security applications ...
Cucusoft MPEG/AVI to DVD/VCD/SVCD Converter Pro
It enables you to convert and burn any video file directly to VCD, DVD, SVCD, MPEG1 and MPEG2 format. Pro version included all the features of the lite version ...
FREE Spyware Scan! SpyNoMore
SpyNoMore scans, cleans and blocks spyware as well as any other good anti-spyware product, but with one big advantage, Custom Fix (patent pending). Spyware programs are growing more sophisticated by the day ...
Copyright ©2003-2009 SecureMost.com. All other trademarks are the sole property of their respective owners.