Search : in
By :

Lsas.Blaster.Keyloger

Last answer on Oct 21, 2009 4:37:24 am BST W12, on Aug 5, 2008 11:57:39 am BST 
 Report this message to moderators

Hello,
Hope you can help me ....somone with limited computer knowledge. I recently got a message from saying my internet explorer is infected with Lsas.Blaster.Keyloger and is trying send my credit card and banking details to a remote host. This happens everytime I open a web page. I have AVG free edition set up (i think!) but this did ot alert me. I did not even realise I had win anti vir2008 enabled on my pc.
Am I at risk and how can I remove it?

Configuration: Windows XP
Internet Explorer 7.0

Best answers for « Lsas.Blaster.Keyloger » in :
Victim of Scam “Lsas.Blaster.Keylogger”? Show Victim of Scam “Lsas.Blaster.Keylogger”? Issue Solution Issue Lsas.Blaster.Keylogger is a scam, a false Windows alert which is a Trojan, part of a rogue application. It will annoy you with lots of pop ups alerting you to purchase...
Rogues Infection ShowRogues Infection What is Rogue? Preliminary procedure to execute if you're running Vista What is Rogue? A rogue is a fake security software that warns that your computer is infected which is totally false. Never buy this software...
Blaster and Sasser: Causing continuous restart ShowBlaster and Sasser: Causing continuous restart When your computer is infected by the viruses Sasser or Blaster, Windows displays the following error message: Generic Host Process for Win32 Services encountered a problem and needs to...
Autoexec.nt - Subsystem 16-bit Windows ShowAutoexec.nt - Subsystem 16-bit Windows Solution 2 Solution 3 When trying to install a 16-bit windows on your PC, the following error message appears on your screen c:\windows\system32\autoexec.NT. The system file is not suitable for...
Download Spyware Blaster ShowSpywareBlaster can help keep your system spyware-free and secure. It does not have to remain running in the background. Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted...
Download MRU-Blaster ShowBecause of carelessness, the users of your computer can have access to reach your sensitive data without your knowledge. To avoid that, it would be better to use to use MRU Blaster. MRU Blaster is a program which helps you to protect your private...
Download Free Sound Recorder ShowFree Sound Recorder makes exactly that his name says. He allows to record all sounds which take out sound from your card free. Files can be directly exported in format MP3, WAV or WMA. Free Sound Recorder is the ideal tool to record your own voice...
The Sasser worm ShowIntroduction to the Sasser virus Appearing in May 2004, the Sasser virus (also known as the W32/Sasser.worm, W32.Sasser.Worm, Worm.Win32.Sasser.a, Worm.Win32.Sasser.b or Win32.Sasser) is a virus which exploits a security hole in the LSASS (Local...
The LovSan/Blaster virus ShowIntroduction to the LovSan virus Appearing in the summer of 2003, LovSan (also known as W32/Lovsan.worm, W32/Lovsan.worm.b, W32.Blaster.Worm, W32/Blaster-B, WORM_MSBLAST.A, MSBLASTER, Win32.Poza, Win32.Posa.Worm, and Win32.Poza.B) is the first...
Sound card ShowIntroduction to sound cards The sound card (also called an audio card) is the part of a computer which manages its audio input and ouput. It is usually a controller which can be inserted into an ISA slot (or PCI for more recent ones), but...

1

danzen, on Aug 5, 2008 2:36:12 pm BST
  • +3

Hello!
I have the same problem and cannot find a solution for removal anywhere on the net.......can someone make a suggestion? Mine showed up with Power Anti-virus 2009 2.6 software accomanying it......I never have downloaded that software nor have I purchased it. I assume that this worm is designed to force you to buy that software's solution and also may truly utilize your credit info and send it to an outside host.... though I am not certain of this.
Luckily, I do not have any CC info on the com....however all the alert windows, etc are driving me nuts and making my com basically unusable.......Please help!!! Thanks, y'all

Reply to danzen

2

danzen, on Aug 5, 2008 2:49:28 pm BST
  • +2

Also, my Macafee Suite says that the file tht is trying to access my credit info is as follows: C:\Documents & Settings\Owner.YOUR-588B4A13EA\Local Settings\Temporary Internet Files\Content.1ES\YY0B0326\setupxv[1].exe.
I have tried avast! virus removal tool to no avail. also I have tried the Symantec W32 Blaster Worm removal tool to no avail.

Reply to danzen

110

Mkmoon, on Jun 7, 2009 9:17:50 pm BST
Reply to Mkmoon

121

egof, on Jul 28, 2009 12:50:52 pm BST

I had this pc infected message and could not do anything--but this fix worked:
Deleted cookies and history, and all *.tmp files on drive c:
Restart computer in Safe Mode (tap F8 key when rebooting computer to get to safe mode)
Choose start in Safe Mode
Go to Restore System...and choose date before the problem
Rebooted and problem was cleared
Deleted *.tmp on drive c: to make sure the files were gone
Installed AVG free basic virus system--problem fixed!

Good Luck!

Reply to egof

69

w90wen, on Jan 6, 2009 12:33:44 am GMT
  • +1

I have the same problem. have read all the posts and did find a stategy. Firstly my norton security has not flagged any problems but the continuous pop ups and not being able to delete icon is annoying.

have done the history deletes and the ctrl alt delete clicked processes and there was only one option that was numbered. it was diffrent to what I have read here but its deletion did remove the icon and stop the pop ups. however when restarting the PC I have to do it all again. my PC is due its annual health check so hopefully. I can get the matter fully resolved but at least with what I have done coutesy of this forum i can surf and work without the annoying pop-ups.

Thanks everybody and keep the tips coming.

Please note I did not download any additional software.

Reply to w90wen

84

Mary, on Jan 29, 2009 11:02:53 pm GMT

TRY THIS,

This information will be used to create your FREE trial account
Norton Internet Security 2009 - 30 day Trial.

http://www.softpedia.com/get/Security/Firewall/Norton-Intern­et-Security.shtml

Reply to Mary

131

Ladye_Velvet, on Oct 9, 2009 3:25:47 pm BST
  • +1

Somehow my daughter downloaded this “virus” as part of an update to another program. It took me over 9.5 hours to resolve the situation. Everytime we would get close it would “revamp” and shut the system down and refused to allow me to start in safe mode. Also it “attacked” ALL .exe extensions. Yes we have this system up and running safe and sound again. Here is how we did it as that nothing with an .exe would run.

Once the computer is started, we discovered it would still let us in to the C drive. Being able to access this helped a lot. Once in I had to reverse the steps listed in another post on here:

1) Go to the c:\windows \temp file. DELETE EVERYTHING listed in the temp file. You may find a few it will not allow you to delete, rename etc. Leave this Window Open and open a new window for step 2

2) Go to the Start\Search option and do a search for *.tmp. Make sure you type it *.tmp….. Delete EVERYTHING the search finds. IF it would NIT allow me to delete it, in the opened “C” drive window follow the path to the file it would not allow me to delete.

3) EMPTY the Recycle bin. You more than likely will also have to do this from the “C” drive window as you desk top is the dreaded blue window of death

4) Now you should be able to CNTRL+ALT+DELETE. At the very top of the processes there will be a numbered process, end this.

5) Now we did have a few .tmp files that would not allow me to delete them. So I went into their properties and changed what they could access.

6) Empty the recycle bin again.

7) Now IF you do not have a spyware destroyer, GET ONE .. DO NOT restart you system…. We used Spy Bot Seek and Destroy… It worked… After downloading your chosen spyware removal tool, scan immediately, again DO NOT restart until you have done a scan. We actually did a complete system scan with Spy Bot, IOBit 360, and Iobit Care. Spy Bot asked IF we wanted it to scan on restart, we said Yes…

8) Now we restarted the system, normally, Spy Bot kicked in, scanned the system. Quarantined the issues. The system booted just fine. We updated all Security Software.. Scanned the system again.

After 9.5 hours, I managed to reclaim my daughter’s computer from this bull shit Security System. I wish all who get this the best of luck and hope my post can help just one of you….

Reply to Ladye_Velvet

3

paland, on Aug 6, 2008 5:13:13 pm BST
  • +6

I had the same thing. I cleaned out all temp files and cookies (through IE options) and then deleted it from memory (taskbar) and then delete it from your registry (HKEY_LocalMachine/Software/Microsoft/Windows/Current Version/ Run). If you do this then you wont be bothered by these messages.

I have a feeling that the Power-AntiVirus 2009 is in itself the culprit. That is how they are going to access your credit numbers, buy having you buy it.

Reply to paland

4

paland, on Aug 6, 2008 5:21:37 pm BST

Oh, and when you are done, run one of your anti-virus programs and run a full scan. I use the corporate edition of Symantec and it found nothing after I cleaned it out.

Reply to paland

23

Liz, on Dec 21, 2008 11:27:44 pm GMT
  • +7

Ok, we have the same thing - it is showing with some bogus file called Security systems - says we the lsasl.blaster.keyloger. The "security system" program also informed me I have 38 other issues, i.e. viruses, keyloggers, etc. So, my son got a bit nervous - I reviewed it and have determined that whoever it is that is attempting to get me to buy the program has developed a real good scam. Further, my Norton Symantec doesn't detect anything. So, I will try the other steps to remove it. Thanks so much!

Reply to Liz

24

j, on Dec 21, 2008 11:40:30 pm GMT

Thank You.....I have used my System Restore....Now, the Winweb Security is GONE!!!!!!

Reply to j

43

jrs, on Dec 26, 2008 1:02:58 am GMT
  • +1

How do you use the system restore???? I CANNOT get this thing to leave and Norton will not help me unless I pay $100.

Reply to jrs

48

j, on Dec 26, 2008 9:42:56 pm GMT
  • +3

You have to have system restore as part of your programs that came with your computer. I go to my START then programs, then PC help.....that is where my System Restore is located. I used my windows defender to tell me when that winweb secuirty hit my pc. Then I took it back the day before and restored my computer to that time. It workded. then I used my Windows defender to do a FULL scan. It found some hidden attacks this program thought it acheived. I had windows defender delete all applications. So far, it is working now.

Reply to j

31

James, on Dec 22, 2008 7:07:55 pm GMT
  • +6

Hi,

I seem to be having the same issue as you are describing. Somehow, something called System Security has got onto my laptop. It opens up a window when I first switch on my laptop, then keeps appearing when I go on the net. When the window opens up it appears to do a scan and notifies me that there are 38 infections (rogues, worms, trojans, etc). When you click on the fix/remove icon it then asks you for you credit card details - I guess this is where the scam is.
This System Security virus has a icon which is a black and yellow stripped shield and has positioned itself on my taskbar, bottom right of the screen. I cannot remove this at all. Does anybody have any info on how I can get rid of this, its driving me mad?

Reply to James

81

caveguy, on Jan 27, 2009 12:11:23 am GMT

I got the same issue you have described here and after a couple of days dealing with the pop up my computer has crash and it won't respon to almost any command and if it does takes for ever to even write an email, do not what to do maybe i need the back up disk and erase all contents an downloads, i hope to find another way to fix it. if someone knows please let me know, thanks a lot.

Reply to caveguy

85

virus buster, on Feb 8, 2009 12:16:37 am GMT
  • +28

Press ctrl+alt+delete, for task manager. then go to process and find file with a long number/etc.1100456ex, then press remove or delete. the pop ups stop and the sheild dissapers after 1min. that annoying security settings shit should now be off your pc. p.s[the number1100456ex] is an example, it will be a long number which normally ends with, ex. let me know how you got on.

Reply to virus buster

90

roeroe, on Feb 26, 2009 12:38:18 am GMT
  • +1

Virusbuster...thanks ever so much....followed your instructions for getting rid of that stupid system security warning....it worked beautifully just as you said...thank you again.

Reply to roeroe

91

gordhawk, on Mar 2, 2009 3:26:19 am GMT

I tried what you said to do but it didn't get rid of this darn thing. Do you have any other ideas as this is about to drive me nuts.
Thanks

Reply to gordhawk

97

cadbary, on Apr 2, 2009 3:20:53 pm BST
  • +5

They were right in saying to CNTRL+ALT+DELETE, then stopping the process with the numbers in it.
Then go to the c:\windows \temp file. DElete EVERYTHING listed in the temp file. THEN, empty your recycle bin.
Then go to the Start\Search option and do a search for : *.tmp. Delete EVERYTHING the search finds.
Empty the recycle bin again.
Go online and download a program called Malwarebytes at:http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8­022_4-10804572.html
Make sure you DO NOT download it from ANYWHERE that lists it on an internet or GOOGLE search, EXCEPT for a trusted site such as CNET.COM. There are MANY imitators out there LOADED with viruses with spoofed names, so do not fall for it.
Download the program, install it, and let it run fully with a FULL scan, NOT a partial scan. Make sure the version you download is from the month you are downloading the file, it is updated at least on a monthly basis, if not even more often than that. Tell the software to delete everything it finds, even if it is a familiar sounding program, as that is houw the virus got in ther in the first place, by installing itself in place of windows security center and other programs.
Empty the recycle bin again, then reboot your PC. You now should have a clean PC.
Go online, and download a current version of Norton Internet Security 2009, from: http://download.cnet.com/...
DO NOT download from anywhere but the Cnet site that shows the Editors choice stars next to it in the middle of the page!!!! There are MANY spoofs out there, even listed on the CNET advertisment sponsored sites, or better yet, go to Best Buy and buy a legitimate copy that you know is clean and new.

Your PC should now be completely clean and protected. Do not go for the spoofed sites on the internet and take the easy way out, as you amy either download a spoofed copy of the software titles, or your efforts may not remove the infection from the System Restore files on your drives backup of your operating system, which will re-infect youur PC with the virus. Most virus detection programs will NOT detect the infection, as the infected files load during the boot-up BEFORE the anti-virus software does, using legitimate names.

Good Luck

Reply to cadbary

106

delibalik, on Jun 3, 2009 11:27:15 am BST

Malwarebytes cleaned all of viruses...thanks a lot....

Reply to delibalik

94

SweetT, on Mar 3, 2009 12:47:51 am GMT

Thank you so much!!!! your instructions have worked for me. The pop ups were driving me crazy so I didnt use my laptop for days. Thanks again....

Reply to SweetT

98

A.V., on May 17, 2009 1:20:44 pm BST
  • +3

Hello.
The same thing has happened to my computer, and well I'm pretty much stuck because I can't open a single thing, I tried opening my task manager and nothing, I tried opening the add or remove programs and nothing, I'm really stuck here and I would like the help so I can get this stupid Security shield off my computer because I can't open anything not even to restore my computer. I really would appreciate it. thanks.

Reply to A.V.

103

Joanne, on May 17, 2009 10:36:52 pm BST

Did you ever get rid of yours, Im going crazy here, it wont let me do anything.

Reply to Joanne

114

voice, on Jun 19, 2009 2:33:56 am BST

I finally got my computer fixed. I followed the sugestion of doing a system retore. Use your pc help system, it will tell you how to restore your system. Coose a date prior to the time you first began having the problem.

I followed up by downloading the malwarbytes program and so fthe system has still found som einfected files.

Reply to voice

102

Joanne, on May 17, 2009 10:35:14 pm BST

I cant do the control, alt, delete thing. It says Im infected. I cant download anything to get rid of this. Can ANYONE please help me?? Im been at this damn thing all day.

Reply to Joanne

104

Teri, on May 17, 2009 11:14:39 pm BST
  • +5

I cannot even get the task manager to appear. When I do alt control delete it appears very quickly then disappears. Any ideas of what to do next.

Thanks because I am extremely frustrated.

Reply to Teri

105

JW, on May 22, 2009 2:11:27 pm BST

Bring up task manager (ctrl+alt+del) as soon as your PC has run through it's start up process. The long number appears a few seconds before it takes control of your PC, so you have a short opportunity to end process.

It comes back as soon as you restart, so you need to do something else for a permanent fix.

Reply to JW

107

justin, on Jun 7, 2009 2:05:33 am BST
  • +2

I tried task manager but this system security virus that started the whole thingis preventing me from starting most of my progams.

Reply to justin

113

voice, on Jun 19, 2009 2:30:28 am BST
  • +1

I finally fixed the problem. Te bet solution is to go into your computer and do a system restore and choose a date that before the problems started. I just did it after being frustrated for almost two weeks. it worked.

Your comoputer help screen should get give you a restore option.

Reply to voice

129

chip, on Oct 7, 2009 6:54:27 pm BST

I am still trying to remove the lss.blaster.keyloger..... control altdeleteis not working... help !! by the time i type anything in, that stupid security tool warning pops up.

Reply to chip

130

Eric stacy, on Oct 7, 2009 11:04:21 pm BST
  • +3

Once again I will post this. It works permanently. And it is simple with limited ability.

lsas.blaster.keylogger is a combination worm,trojan and virus.
This is the way to get rid of the problem completely.
Go to the internet and look for and download a file called
combofix.exe at http://combofix.org/download.php
Keylogger will ussually not block internet. Save the file to your desk top.
Rename the file combofix.com so that it will work at the dos level on your computer.
Reboot your computer. While it is starting hit the f8 key until a number of start
up options apear. You will have no mouse so use your arrow keys and click on Safe Mode or
safe mode with support. Bottom line, get to safe mode.
Your computer will boot to a simple desk top without all the extra programs. Click on
the combofix.com file and follow the instructions. It will clean your system completely
free of the logger virus. Let the program do the work. Don't rush. It will take about
15-20 minutes, but no data will be lost. Just the virus.

Good Luck,

Eric stacy

Reply to Eric stacy

134

la bella cee, on Oct 17, 2009 9:36:49 pm BST

Eric stacy you are a life saver. the combofix program will wipe it out completely
thank soo much

Reply to la bella cee

135

 KZ, on Oct 21, 2009 4:37:24 am BST

We just got hit with this virus and got very nervous at what might be lost or taken! I have followed your instructions and so far so good. I am running scans now and might do the system restore as well but so far no pop ups.

Reply to KZ

86

virus buster, on Feb 8, 2009 12:16:37 am GMT
  • +1

Press ctrl+alt+delete, for task manager. then go to process and find file with a long number/etc.1100456ex, then press remove or delete. the pop ups stop and the sheild dissapers after 1min. that annoying security settings shit should now be off your pc. p.s[the number1100456ex] is an example, it will be a long number which normally ends with, ex. let me know how you got on.

Reply to virus buster

92

gordhawk, on Mar 2, 2009 1:37:23 pm GMT

I must be doing something wrong because I have followed your instructions and I still have that gold and black shield down by the clock. Let me tell you exactly what I'm doing and see if I'm doing everything right. After I read your message about how to get rid of this problem I press ctrl,alt. Then when the task manager comes up I go to processes and highlight the long number that is there and then press the delete button. Is this the correct way to do this?

Reply to gordhawk

93

tarryboots, on Mar 2, 2009 7:03:39 pm GMT

Thank you very much Virus Buster for helping us get rid of the System Security Pop Ups. Did not get any joy from Tiscali or Dell help. You were extremely helpful and did exactly as your name suggests!

Reply to tarryboots

37

brit09, on Dec 24, 2008 1:57:39 pm GMT
  • +1

Hi liz can you plz tell me how you got rid of that program called "system security" it is infected my computer too

Reply to brit09

40

tazz, on Dec 24, 2008 11:06:36 pm GMT

Hello, i have the same problem security systems warning etc, anti virus is green and my computer is fine.
to uninstall it just use system restore or maunally find and delete it.
if this doesnt work reinstall windows.

Reply to tazz

44

dane, on Dec 26, 2008 1:19:59 am GMT
  • +1

Have you an answer to stop this from appearing all the time

Reply to dane

100

Joanne, on May 17, 2009 6:19:50 pm BST
  • +1

My IE Browser was taken away. I cant even do the control, alt, delete. Any other suggestions?

Reply to Joanne

108

r, on Jun 7, 2009 8:25:51 pm BST
  • +2

For whoever is having this issue and cannot open absolutely ANYTHING, I know how you feel. I read solutions like open task manager, delete temp files & cookies..I read it all. I know it's even frustrating to read since you can't do anything about it without something popping up at the bottom saying it's infected. What I did to open task manager (and try doing this as soon as you log on your computer so you're not flooded with pop ups) was press Alt Ctrl Delete, but HOLD it and do not let go or else you'll have no chance & it'll just say it's infected. You'll have to hold all 3 buttons and ending system security off your task manager at the same time. It's a challenge, but it worked for me. The System Security icon at the bottom right hand of your screen should then disappear. Along with what I just said, go to tools, click delete browsing history and then delete temp files and cookies. After I tried opening an application such as MSN that hadn't worked before due to Lsas.Blaster.Keylogger, but it opened no problem. You should be fine after.

Reply to r

54

ear, on Dec 29, 2008 7:40:10 am GMT

Will this help with the Mozilla Firefox?

Reply to ear

5

W12, on Aug 6, 2008 10:34:10 pm BST
  • +1

Paland
Thanks for your help. Please excuse my ignorance but how do I delete from memory and also from registry.
Can you give me step by step instructions?

Reply to W12

8

willy, on Nov 23, 2008 9:17:55 pm GMT

I have used your instructions on how to get rid of lsas.blaster.keyloger and have not been able to do so. I'm receiving a program intitled winweb security that brings up the keyloger. I have an icon for winweb at the bottom right of my computer. It pops up the keyloger and wants me to buy their security program. Scam! I have gone through my programs and it is not their. Probably because I didn't buy it. I think if I could delete winweb security the keyloger would also delete. Any suggestions? Thanks.

Reply to willy

10

winweb security scam, on Dec 9, 2008 4:05:26 am GMT
  • +4

WARNING: Winweb Security is a SCAM!
DO NOT continue with winweb as it will steal critical/personal information!
It reports that Lsas.Blaster.Keyloger is the culprit, but that is not the case,
as Lsas.Blaster.Keyloger is either a part of Winweb, or does not exist.
Fortunately, it seems that the payment is corrupt on the website, in that
it will not let you buy the program, and therefore should not leak any information.

However, it seems there is a way to erase the program/virus.
It doesn't go by Winweb Security as the filename,
instead, you want to look for:

1806188250.exe
and
1806188250.EXE-18E9FE96.pf

The only way that I can think of to delete these files is to
boot up under Safe Mode, and search for these files and
manually delete them.

I repeat, stay away from this program.
DO NOT USE, DOWNLOAD, OR BUY THIS PROGRAM!!

Reply to winweb security scam

17

j, on Dec 17, 2008 12:31:08 am GMT

Can someone please help me get this stupid winweb securtiy off my computer without having to buy software to do so.

Reply to j

18

karasusynth, on Dec 17, 2008 5:18:12 am GMT

To get winweb off your computer, you need to start up your computer in safe mode.
then go to the start menu and click on search (alternately, open any folder and click on search)
make sure you're looking in hidden files and folders, and search for:

1806188250.exe

one the result comes up, you should be able to manually delete it.
(to bypass sending it to recyle bin, click on the file and press Shift+Delete)

Reply to karasusynth

56

gazgaz, on Dec 29, 2008 7:40:21 pm GMT

How do i start up computer in safe mode and i cant fing system restore

Reply to gazgaz

66

ljlemi, on Jan 3, 2009 8:59:48 pm GMT

To start up in safe mode: restart pc..while restarting tap F8 key until safe mode appears

Reply to ljlemi

68

w90wen, on Jan 6, 2009 12:32:14 am GMT
  • +1

I have the same problem. have read all the posts and did find a stategy. Firstly my norton security has not flagged any problems but the continuous pop ups and not being able to delete icon is annoying.

have done the history deletes and the ctrl alt delete clicked processes and there was only one option that was numbered. it was diffrent to what I have read here but its deletion did remove the icon and stop the pop ups. however when restarting the PC I have to do it all again. my PC is due its annual health check so hopefully. I can get the matter fully resolved but at least with what I have done coutesy of this forum i can surf and work without the annoying pop-ups.

Thanks everybody and keep the tips coming.

Please note I did not download any additional software.

O

Reply to w90wen

73

oaktown, on Jan 9, 2009 5:32:10 pm GMT
  • +1

Hey, i have the same problem turn up on my laptop. i did a system restore, and problem gone. the thing with system restore is that you most computers are not set up with system checkpoints. so if you go to try to restore alot of the times there is no check point. a check point is a time when the computer takes a snapshot of all you info., files, etc. usually if you set it up, you can do a check point 4 times a month, so if you have a problem one week, you can go back one week and not lose that much info. if you bought the computer at a store and didnt build it yourself, then it might have been set up. my laptop was set up. my desktop was not. i lost everything. i reinstalled windows and made a check point.....got a virus or corrupt file.....last week....was able to go back to december and recover without reinstalling window all over again. you can try deleting files, folders, but you are not going to get rid of the system security spam. if you want to try to, then you have to delete these in Safe Mode. when you power up your laptop computer, as soon as you see something, anything on the screen, hold the F8 button... on a desktop computer usually you will see the some numbers like the size of memory in your computer..etc...this is when you hold the F8 button.. some computers can be tricky...my laptop didn't want to go into Safe Mode...so i turned it off or restarted it with the button or switch...not with the start button. This made the computer go into Safe Mode...because i turned it off manually.

once it goes into safe mode you have to wait...do not hit any keys on your keypad.
it will eventually show you a black screen with safe mode on the top corners and i think the bottom corners.
you still have to wait. it will start windows with very large letters. sign in as adminstrator. most computers don't have a password. if yours does type it in. if you dont know it, then try to sign in under your other profile, if there is one there.
once you get past this screen, it gets easy. your computer or laptop might ask you if you want to continue in safe mode to try and fix the problem.. read the instructions...it should say something about going into system restore. this is where you want to go. once you are there, then look for the tab that say restore to an earlier point. click next. then look for a date that is highlighted, this will be a check point, you can go back a month or two...hopefully you have a check point. if you dont, then this wont work. go back and exit, you will have to turn off computer, and reboot in to safe mode again and reinstall windows...
If you do have a check point click on it, and then hit next....this will take a few minutes, depending on how much memory you have, and how much memory is taken up on your computer. it will turn off and resart on its own...
After this problem should be gone.

Reply to oaktown

19

yada, on Dec 18, 2008 12:07:02 am GMT

I can not delete the regestry it wont allow me too

Reply to yada

20

j, on Dec 19, 2008 3:38:42 am GMT

Thank You.....But, I believe I took care of the problems using System Restore!

Reply to j

6

paland, on Aug 7, 2008 4:55:22 pm BST
  • +1

To delete from memory, just Cntr-Alt-Del and then Task Manager. Then go to the 'processes' tab. You will see the program Power Anti-virus running there. Just remove it.

You really shouldn't go into the registry if you dont understand it. One wrong move and your system is toast.
But, Start / Run / Type in "regedit" (without the quotes)
That will open the registry. Then follow the path I listed above

Reply to paland

7

willy, on Nov 23, 2008 5:34:29 pm GMT

Did you ever get rid of lsas.blaster.keyloger? If so, how did you do it? I followed the instructions, but I still can't get rid of it. Thanks

Reply to willy

9

steve, on Nov 24, 2008 1:58:13 pm GMT

I used system restore to an erlier date. seemed to work ok

Reply to steve

57

gazgaz, on Dec 29, 2008 7:43:20 pm GMT

Were do i find system resore

Reply to gazgaz

11

kai, on Dec 9, 2008 5:17:40 am GMT

I was infected by this same virus tonight.
it hijacked where my broswer can can, it uses it's own search/spam engine
i tried deleting the stuff via regedit, it helped, but the problem of redirect searches still exists.
the program no longer opens up as i was able to sucesffuly delete it.
I am not able to use spybot even though i have done a fresh install. I can't use the restore function.
any help greatly appreciated

Reply to kai

12

kai, on Dec 9, 2008 5:50:54 am GMT

I have tried using Malwarebytes Anti Malware (MBAM)

i was able to install it but couldn't open it after install.
tried this in safe mode also. and still can't do sys restore

Reply to kai

13

Karasu, on Dec 9, 2008 6:41:16 am GMT

Also avoid Malwarebytes Anti Malware (MBAM) if possible.
I don't know of any threat it poses, if any, but it doesn't
offer any kind of help that I've seen.

best way to get rid of Winweb, as I have just tested out
and it works, is to restart your computer in Safe Mode,
google it if you don't know how to, just type in

safe mode <your windows operating system(e.g. ME, XP, Vista)>

Then search all files including
hidden files and folders for:

1806188250

That is the filename that Winweb goes by.
The only/best way to delete Winweb Security
is by this means. It will only let you manually delete it
under safe mode.

And so far the best anti-virus program I've come across
is Windows Defender. Free download. You can pay,
but it will scan and allow you to remove any negative
files with the free version.

Reply to Karasu

14

Karasu, on Dec 9, 2008 6:48:54 am GMT

Kai, how did you delete winweb?
I don't know too much about different virus/malware removal programs,
but some can cause more of a threat (case-in-point = Winweb Security)
and some don't always do what they say.

All I can say is to search for the winweb file (searching hidden files and folders as well) under:
1806188250
if it comes up as a result it is still on your computer,
if not, either try a system restore or download Windows Defender
and do a full system scan, you might have contracted another virus through
winweb.

Reply to Karasu

21

bear, on Dec 20, 2008 8:45:01 pm GMT

Wow what a pain this has been , shame you cant take these people round the alley and give them a kicking, still we are all a bit too pc these days . Had to read loads and even learn some stuff along the way . thanks to your site i got myself restored from an earlier date . all done , cheers again bear .

Reply to bear

32

TK_N_SF, on Dec 23, 2008 4:58:44 am GMT

Karasu/Kai/et. al.:

I encountered this problem on 12/22/2008 with one important difference. The purported 'product' was not named WinWeb, it was named System Security. Everything else (look, feel, list of alleged problem files, etc.) was the same.

When I booted the computer and System Security began its scan, I opened the Task Manager and noticed a file called 83314392.exe using a bunch of CPU resources. I searched for this file on my computer's hard drive and found a folder called 1372029626 containing the executable along with a few other files. The executable's icon matched System Security's logo and the folder's creation date was 12/22/2008. The search turned up another file as well located in file called 'PREFETCH.' I deleted both the folder (1372029626) and the other random file in PREFETCH and then rebooted. This solved the problem.

The interesting thing here is that the hacker has changed the name of the product from WinWeb to System Security and has buried the executable in a different, inconspicuous folder. It is likely the hacker will continue to change the name of the product so searching on the latest name will likely prove unhelpful. The key here is to run Task Manager whenever the rogue program is running to identify the name of the offending executable (by seeing which process is chewing up CPU resources), then search for that executable and delete the appropriate folder(s) and file(s).

Good luck everyone!

TK

Reply to TK_N_SF

38

TK_N_SF, on Dec 24, 2008 9:05:43 pm GMT

I forgot to mention that I had to re-boot in Safe Mode before I could delete the offending folder and files.

TK

Reply to TK_N_SF

132

Miki, on Oct 17, 2009 12:56:03 pm BST

I found all the files mentioned. Thing is it won't let me log into safe mode.
Is there any way I can get to safe mode without using the F8 button and msconfig?

Reply to Miki

42

Ladyblue, on Dec 25, 2008 10:41:29 pm GMT

Hi:

I encountered the problem today. My culprit was named "System Security" , also there was a listing also under "UMCSS.Exe which I had to remove. My file # were 19415226966 and 860606479/3814DD56.PF, also 75048700efif11DO. (I got the message about 38 infected virus)

I went into the registry under Keylonger and deleted everything under keylonger and UMCSS.EXE.

Finally I ran the software antivirus "McAfee"

Reply to Ladyblue

15

kai, on Dec 9, 2008 7:00:30 am GMT

I think i deleted it by going into safe mode and deleting the suscipious folder w/ the number in the windows temp folder.
i will try searching for the folder mentioned above in safe mode and report back, i have a feeling i've already tried.
i have a few problems going on

1. when i google something and click on results, it redirects me random sites
2. i can't do system restore. i get to select date, i'd click next , but can't finish the step after that to get restore going.
3. i wasn't fully able to install malwarebytes antimalware program. it hangs at like 99%
i've already tried deleting and reinstalling without luck.
4. can't open spybot for some reason, have tried reinstalling already. i am able to run ad-aware and avg w/ no problems, but they do not detect anything. (I have most up to date definitions) same thing w/ all windows xp updates, all are current.

Reply to kai

16

kaiotes, on Dec 9, 2008 7:09:38 am GMT

I have looked for the folder mentioned above, no results.
maybe i fixed the lsas blaster problem but i still have these other issues, most importantly the not being above to use system restore problem

thanks

Reply to kaiotes

22

jroc, on Dec 21, 2008 9:38:23 pm GMT

Hello,

I just experienced this so called security center pop up issue. My wife was paging around for some details on her palm phone and picked this crap up. I started with my McAfee security program 2009 and it found nothing, wondering if McAfee is worthwhile or not? Anyway, tried downloading the Malwarebytes software, once again, found nothing. Now I am getting pissed right? Next...Downloaded Windows Defender and performed the scan and guess what? It found the Winweb file. I removed it. The icon was still sitting in my tray so I rebooted my computer and whala... everything now seems to be good.

Reply to jroc

27

db, on Dec 22, 2008 8:52:04 am GMT

I got winweb and it's assorted cronies saying my laptop was infrected this morning.
May I just add, I'm no computer expert whatsoever so please be patient.
First of all I tried rebooting in safe mode (I'm using Vista) by holding down F8 then tappining on the same. Nothing happened except the computer offered up the usual user login page. So then I downloaded Windows Defender which told me I have no virus's.
The trouble is the winweb window keeps appearing still as well as another called....wait for it, it'll pop up in a moment. There it is VirusRemover2008, another infernal darn infection to sort out.
However, even though these bloody things keep popping up, Windows Defender has just come back to say I have no virus's.
Can anyone tell me what is going on and possibly guide me further.
Thanks...db

Reply to db

28

mukesh, on Dec 22, 2008 12:31:42 pm GMT

Hi
i am also facing the same problem in my pc so pls give me suggestion how to remove this virus

Reply to mukesh

29

db, on Dec 22, 2008 2:05:05 pm GMT

I'm now trying windows malicious software removal tool which has been going through fioles for the past 4 hours or so. It's not even half way through yet and I'm not the biggest saver of stuff on my laptop.

Reply to db

30

DA, on Dec 22, 2008 4:52:14 pm GMT
  • +1

Hey guys i just fixed it. WOAH!!!!! well i formatted my comp before and the guy who fixed my comp told me not to use system recovery. he said if i use it again it will not turn back on again. well i guess it's because i broke my comp by using system recovery.
SO I HOPE YOU CAN DO THIS INSTEAD TO DELETE WIN WEB SECURITY!

first go to safe mode.
then go to any document and type on the address bar this, C:\Documents and settings\all users\application data


LOOK FOR THE RANDOM NUMBERed FOLDER AND CHECK IF IT IS WIN WEB SECURITY and if it is so delete it and clear off from recycle box!


HOPE IT WORKS FOR YOU>> WELL IT SHOULD BE :]

Reply to DA

33

Alan, on Dec 23, 2008 5:26:56 pm GMT

Hey , i was having the same problems as all of you's and i think i found a solution! the scam program that got on my computer was spyware guard 2008 . i tried everything !! even the help from this page. i googled for some help to remove this scam program and i got this website
http://www.bleepingcomputer.com/malware-removal/remove-spywa­re-guard-2008
it worked for me , in less then an hour my computer was up and running again , it gives you intructions that are easy to follow as well, after doing a quickscan as it told me to , i did a full scan and it got rid of 2 more trojans ,
i can now go on my computer uninterupted and scam free :)

Reply to Alan

34

a, on Dec 24, 2008 6:22:04 am GMT

Task manager...right click and go to file location..go back one on the directory bar...then end process in task manager...then delete...worked for me

Reply to a

35

debee, on Dec 24, 2008 8:22:04 am GMT

Hello there.... I wasted 5 hours trying to get this system security virus off my computer.
I downloaded a Malware program...scanned the computer...then ran my anti virus, and then ran spybot then ran windows defender. I deleted files such as 'prefetch' and 1806188250.exe

well, nothing worked, the system page that scans your PC always kept running.

so, then I tried to go in safe mode. I clicked star, then clicked Help and Support. I clicked Performance and Maintenance, I clicked Using System Restore to undo changes and then I clicked Run the System Restore Wizard.

Low and behold...after I clicked on a date 6 days ahead of today Dec 18, 08 my computer did a scan and restarted.
Hallel flippin lujah.... my computer is back to normal... no more scanning ...saying my PC is infected .

I fixed it. working with computers since 1995 I learnt a real valuable lesson...don't waste time trying all kinds of fancy methods to find/scan the computer to heal or uninstall a bad virus/program. I came onto this site and you people gave me hope with the info you took the time to explain... I thank you.

have a Nice Holiday ....now I'm not stressed out about this crazy system security virus.
( PS: if you find my instructions hard to understand...just click start and type in the help line 'safe mode'
the step by step instructions will appear...I printed them and followed the easy steps :))))

debee

Reply to debee

76

dollface, on Jan 14, 2009 12:50:51 am GMT

Thanks Debee your too cool - all gone

Reply to dollface

36

debee, on Dec 24, 2008 8:25:31 am GMT

Sorry....on the 5th sentence of my last post... I mis-spelled the word start.... ( I typed star, )

I meant ....I clicked the Start button on the bottom left side of my computer )
the menu then showed up.

Reply to debee

39

Tw112, on Dec 24, 2008 10:30:36 pm GMT

When i got this "virus" on my pc i went to task manager, processes and saw a random number combo, with that i opened it up and saw a logo the same as the one on my toolbar, i then deleted it, i am all good now. the weird thing is that it only showed up to me to download during the week of christmas

Reply to Tw112

41

Wallace, on Dec 25, 2008 4:48:12 pm GMT
  • +1

Okay.
here is the reality of the situation:

1/ Running System Restore Wizard - results in message:"No changes made to computer. Computer cannot be restored." (I tried different back dates -nothing worked. (Poster said something about clicking on "6 days a AHEAD of today"???? Of course, this is impossible.)

2/downloading free "Windows Defender" and waiting over an hour for the scan, results in NO PROBLEMS BEING FOUND.

3/going the safe mode -search in hidden files for "1806188250.exe", results in file not being found, period. (I searched with the "search" command. I did not do a manual search in the registry.)


2 hours wasted this Christmas morning.


Cummon fellows! This has gotta be a world-wide problem.(And nothing being done to rectify??)
Certainly something can be done!

(I tried also the recommended STOPzilla, but after downloading for half an hour, I find out they want -MONEY.)

.....
How does one go about getting to "Task Manager" (on Windows XP)?


Presently Im right fed up with this whole computer thing.
I dont want to learn this SHIT.

Reply to Wallace

45

Wallace, on Dec 26, 2008 3:04:56 pm GMT

Wallace here!:

Ive been on internet for 20 minutes now and seems I have got rid of this feckin' thing finally. (But its like fixing a main water tap: you think you fixed it, but the pressure is still on and your counting the seconds fearing it will burst again.)

Anyways this must be mutating all the time coz when I did the Task Manager search, no 692527612.exe (or any of the others) was present.

However there was a 689823290.exe and I took the change and deleted this.

Also , doing a 'files & folders" check, I deleted 689823290.exe-3A9C4D6B.pf Prefetch devil and was directed to folder 1524317627 where some of these fecks are stored.

So then, having no idea whatsoever what Im doing, I deleted those three and seems to have solved the problem.


...
Nobody here answered any of my questions so far, so perhaps this one too is wasted effort:

Ive seen this shit: "lsass.exe". Sure looks suspicious.
Should I bag its ass? , or is it necessary for the system.

Reply to Wallace

46

debee, on Dec 26, 2008 6:30:17 pm GMT

HI there..... don't waste your time deleting or trying to find files... If you look above several posts...

I left step by step directions....to fix the problem.

After spending 5 hours with my computer & finally fixed the problem....

I figured I would be nice and post the info...

obviously the people who posted below me...didn't even bother to read or follow what I wrote.


oh, well, I guess everyone has to decide what they want to do to fix the problem.

Reply to debee

47

Wallace, on Dec 26, 2008 8:53:16 pm GMT

Debe:

Just tell me one thing:

In System Restore how do you "click on a date 6 days ahead of today "?

Reply to Wallace

49

j, on Dec 27, 2008 3:20:10 am GMT

There is absolutley no way to go ahead of time to do a restore, NONE! You can however, go back. Back to a time Before your trouble began.

Reply to j

52

debbee, on Dec 28, 2008 7:45:16 pm GMT

Hello.... whoever said you can't go back on the date.... is wrong..... my problem happened on Dec 22, 08 & I set my computer to Dec 18, 08 and it worked.... never had that system security scanner work since then.

the instructions. are as follows

To run System restore... in safe mode.

click your start button, then click Help and Support, Click performance and maintenance, click using system
restore to undo changes. and then click Run the system restore wizard.

( I'm reading this from the instructions that I printed from the process )

You will see a calendar show up....after these steps.... simply click onto a day... several days before the issue
happened.... I chose 5 days ahead. ( the days will be highlightened...which ones to choose)\\

try that.... it worked for me...

so, once again to whoever said this can't be done... ( choosing a date before the incident is wrong :(

Reply to debbee

65

daytona, on Jan 2, 2009 2:19:37 am GMT

Debbee


Your input is 100% correct. It worked fine for me after I tried a few other suggestions. As a matter of fact....I was working on-line when the program decided to download and open up. That was about 7:30 PM 01-01-09. Now it is 10:45 PM 01-01-09 and all is well. I actually restored my computer to 9:34 AM 01-01-09 (the last time the system did a restore back-up). So, I did not have to go a day or two.
Thanks for the input. What also helped was having my laptop next to my computer to do searched and such

Reply to daytona

50

lx, on Dec 28, 2008 11:10:30 am GMT

I have read all of the above solutions but nothing works... i found the folder bu it say need permission to delete it... so i cant delete it...

Reply to lx

51

bear, on Dec 28, 2008 1:02:12 pm GMT

I know what you mean , real pain or what . what i did was found out how to restore settings before i had this problem , so if you think it started say 2 days ago try restarting at a date 5 days ago , the anoying little icon should disappear from the bottom of the screen and i lost nothing else , good luck . you can google how to do it .

Reply to bear

53

lucy, on Dec 29, 2008 12:29:55 am GMT

I am having the same problem and did not ask for this site, how do I get rid of it very annoying pop's up all the time and won't go away no matter what I do.

Reply to lucy

55

bear, on Dec 29, 2008 9:25:52 am GMT

Hi lucy,
restore your computer start date , to a date prior to the first time you became aware of the pop up , you can find how to do this via goggle.
good luck bear.

Reply to bear

59

Hazel, on Dec 30, 2008 3:01:26 am GMT

Thank you all for the great info. I had the same problem and systems restore did the trick. My systems restore was in accessories, then in system tools. The first date I picked didn't work, so I tried another date, and it worked and the problem is gone........thank goodness. Good luck to the rest and thanks again for the info.

Reply to Hazel

60

gr, on Dec 30, 2008 7:55:19 pm GMT
  • +1

Hey bear,

I tried several system restore for the exact same problem with no success. I went into task manager and found the file #2118...... that was similar to what everyone else was finding and deleted it here. Icon in taskbar disappeared. Then I deleted desktop shortcut to recycle bin. In "all programs" I deleted it here too. Seems to have worked. Thanks everyone for the advice. What a nightmare??

Reply to gr