Really need your expertise here. I can only type correctly using my notepad.

On any other application whatever I type would be totally different. Example my letter Y would appear as F.

I have scanned using AdAWARe, xOFTSPY, our virus s/w and Spybot.

I have checked the regional and keyboard settings but all looked okay. I did not make any changes. In fact everything was working just over 2 hours ago.

I tried doing a Detect and Repair of my office Still the same All my MS applications have this issue.Attached from Hijack This

Logfile of HijackThis v1.99.1
Scan saved at 4:07:40 PM, on 6/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\S24EvMon.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Symantec\Ghost\ngctw32.exe
C:\oracle\ora92\bin\omtsreco.exe
C:\Program Files\PurgeIE\PurgeIE_Service.exe
C:\WINNT\System32\RegSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZCfgSvc.exe
C:\WINNT\System32\1XConfig.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\NotifyPhoneBook.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINNT\system32\notepad.exe
C:\Program Files\XoftSpy\XoftSpy.exe
C:\Program Files\GlobeCom\TOra\tora.exe
C:\WINNT\system32\telnet.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Administrator\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NGClient] C:\Program Files\Symantec\Ghost\ngctw32.exe
O4 - HKLM\..\Run: [XoftSpy] C:\Program Files\XoftSpy\XoftSpy.exe -s
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [QNPlus] C:\Program Files\Conceptworld\QNPlus\QNPlus.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: hp psc 1000 series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
O4 - Global Startup: hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Download with FreeDAccelerator! - C:\Program Files\Free Download Accelerator 2\FreeDAccelerator.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) -
O16 - DPF: {37E64B05-0435-4F48-A8A8-DDC412A701F4} (PCV.ctlPCV) -
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) -
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon.dll
O20 - Winlogon Notify: Sebring - C:\WINNT\System32\LgNotify.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec Ghost Client Agent (NGClient) - Symantec Corporation - C:\Program Files\Symantec\Ghost\ngctw32.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oracle\ora92\bin\omtsreco.exe
O23 - Service: OracleOraHome92ClientCache - Unknown owner - C:\oracle\ora92\BIN\ONRSD.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: PurgeIE XP Service (PurgeIEservice) - Assistance & Resources for Computing, Inc. - C:\Program Files\PurgeIE\PurgeIE_Service.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINNT\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINNT\System32\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Program Files\RealVNC\VNC4\WinVNC4.exe" -service (file missing)

Dani AI

Generated

This looks like a classic case where the keyboard is being remapped at the software/desktop level rather than by the physical keyboard or its basic driver. Notepad uses a very simple edit control and often bypasses the Text Services / input-hooking layers that Office and other rich-text apps use. That explains why typing can be “correct” in Notepad but garbled elsewhere. already had a detection with Kaspersky and ’s idea to re-install the keyboard driver is a sensible quick test — but also run the isolation checks below because a resident hook/IME/rootkit can reintroduce the problem.

Try these steps in order (work cautiously; back up the registry before edits):

  1. Unplug network (to prevent reinfection) and reboot into Safe Mode (F8). If problem disappears, a third‑party service/driver is likely.
  2. Create a new Windows user account and test—if the new account is clean, the issue is per‑profile.
  3. Kill ctfmon.exe (Task Manager) and disable advanced text/input services temporarily (Regional/Languages -> Text Services). Test Office apps again.
  4. Use msconfig (selective startup) to disable non‑Microsoft services and startup items; reboot and re-enable items one at a time to find the culprit.
  5. Inspect startup/Winlogon/BHO entries with Autoruns (Sysinternals) and examine injected DLLs for Office processes with Process Explorer (lower pane -> DLLs). Look for unknown Winlogon notify DLLs, remote‑control agents (VNC), or unfamiliar BHOs.
  6. Run an offline rescue/rootkit scan (bootable AV rescue disk and a rootkit scanner). If a keylogger/rootkit is found, clean offline or image/restore from known good backup.

Notes and cautions: don’t delete registry/Winlogon entries until you export them. If the mapping recurs after cleaning, assume persistent rootkit or credential theft — change critical passwords from a clean machine and consider a rebuild. Replacing the physical keyboard or uninstalling/reinstalling the device (as suggested) is harmless to try, but if the problem returns it confirms a software hook rather than hardware failure.

Try going to the Device Manager (right-click My Computer, hit Manage, Device Manager will be listed as a clickable item in the console that will appear), uninstalling the keyboard, then re-installing. When you have the Device Manager up, expand the keyboard section, right-click the keyboard icon, hit Uninstall. Then, when finished, go to the computer icon at the top there and right-click and say "Scan for hardware changes". It should install your keyboard automatically. If it complains about a driver not available, you will need the CD or you can probably find the driver .inf or setup.exe file on the web.

Dude no do. This is a virus. I solved it by downloading kaspersky virus detector. this is cool have a look at it. Thanks again mate.

First one for me, seeing a virus that takes out your keyboard! Sorry I wasn't more help, and that I was more skeptical, but at least you got your keyboard working. Assumed that since you said you had already done a virus scan that it wasn't a virus. Glad Kaspersky worked out.

There's also Sophos, at least a version of it anyway, that is ran off of a DOS prompt that I've used at work in Command Prompt Safe Mode (hold F8 at Windows Logo to get the option to use this) off a CD we use that is really good, will detect stuff that Symantec/Norton don't, like this virus apparently, when we find out we've been hit by a virus the our AV missed. But Kaspersky is probably just as good, obviously, so at least you've got a couple of alternatives now to whatever you normally use. Personally, I've gotten more false positives with Norton/Symantec and McAfee than they actually find real infected files, and they won't find others that other AVs I've used (like Sophos, PC-cillin, Avert) DO find... makes ya wonder how safe we all really are...

Guess wat mate, the damned thing just appeared out of nowhere again!! Just when i thought it was allover , the insurgents of k/b virus appeared. this time i scanned it again but kaspersky found nuthiing so i will try to uninstall the damned k/b n let u know dude. be strong for me ;P

Sorry you're back into it again. We'll watch for ya when ya post up again after the uninstall/re-install of the keyboard. Might want to do the virus scan again since it worked before, then the uninstall/re-install while off the internet (taking out your Ethernet or phone cord), and a reboot. Might even give HijackThis! a try for something like this, since it's one of those recurring things after you think you've fixed it. Could be you're downloading something to replace what you're getting rid of, and that usually signifies spyware.

Microsoft's own Anti-Spyware utility

I might be completely off the mark, but with stuff like this, I don't take chances. Only when I've used every tool I can think of, and registry hacking, do I throw in the towel and re-install the system. Hopefully you're up to the tools.

Tom

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.