Jump to content

Srv.SSA-KeyLogger


Scarecrow Man
 Share

Recommended Posts

Latest Installment:

Since the HijackThis log entry now has been published elsewhere, including on Sunbelt's web site, I will go ahead and reveal it. Download HijackThis, and scan the computer. If the following entry is present in the results, then the computer is infected with this spyware and the user(s) of that computer might be victims of identity theft:

O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\winldra.exe

Sunbelt has created a free tool to remove this trojan safely. If that entry is found on any computer that you are examining or fixing, visit this page. Download the program linked there, then unplug that computer's modem from the internet. Leave it unplugged until after the trojan has been removed. I've submitted the keylogger to several antispyware and antivirus vendors, so they should be detecting it shortly, if they don't already.

Sunbelt has named this trojan Srv.SSA-KeyLogger.

If you think you are infected, please post a Hijack This log for one of the specialists to analyze. Do not attempt to remove anything with HijackThis without knowing what your doing.

They also provide a removal tool on this page.

Make sure you update you Anti-Virus ASAP. :)

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy