Scarecrow Man Posted August 15, 2005 Report Share Posted August 15, 2005 Latest Installment:Since the HijackThis log entry now has been published elsewhere, including on Sunbelt's web site, I will go ahead and reveal it. Download HijackThis, and scan the computer. If the following entry is present in the results, then the computer is infected with this spyware and the user(s) of that computer might be victims of identity theft:O4 - HKLM\..\Run: [load32] C:\WINDOWS\System32\winldra.exeSunbelt has created a free tool to remove this trojan safely. If that entry is found on any computer that you are examining or fixing, visit this page. Download the program linked there, then unplug that computer's modem from the internet. Leave it unplugged until after the trojan has been removed. I've submitted the keylogger to several antispyware and antivirus vendors, so they should be detecting it shortly, if they don't already.Sunbelt has named this trojan Srv.SSA-KeyLogger.If you think you are infected, please post a Hijack This log for one of the specialists to analyze. Do not attempt to remove anything with HijackThis without knowing what your doing.They also provide a removal tool on this page.Make sure you update you Anti-Virus ASAP. :) Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.