Lsas.blaster.keyloger

Solved/Closed
-
 Sambhavam -
i keep receiving a pop out message from Winweb Security saying that my pc is infected with 38 viruses. but i have done a thorough scan of which no infection was detected.

What is wrong here and how do i go about resolving this infection issue?

thank u

33 replies

I have the same thing with system sercurity and the lsas.blaster.keyloger popup and cant get rid of it i need help please . It says I too have 38 things wrong and my nortons 360 says there is nothing wrong with it.How do i get rid of it. Thankyou very much.
i have the same problem i scan my computer i have no virus how do i get this pop up off my computer.
would like to thank you for this fix roger.25@tiscali.co.uk
Duuuude thank you soooo much man worked like a charm!!!!!
Here's the cheap fix:

Boot into safe mode (Holding down F8).

Look in c:\Documents and Settings\All Users\Application Data

There is a file there that is all numbers such as: 85331323 or 46937130

Delete the sucker.

Reboot and all is well.

This is exactly what needed to be done! After 24hours of pulling my hair out and grinding my teeth in anger I came across this lovely persons idea.. At first my computer didn't start in safe mode, but tried again and when hitting f8 I hit enter too and it started the computer in safe mode. Relieved!!!

Literally, if your fortunate enough to remember the date you got the virus, go straight into restore and re-boot from that date.

I'm so happy, it doesn't even seem that it ever happened at all and so feel my gratitude should be shared! I hope you guys can solve this problem too. Good luck!

Cheeri-o
> Carey's now my best friend
This worked!!
c:\Documents and Settings\All Users\Application Data

Do you know where this is in vista windows???? I have done the cntrl-alt-delete, and downloaded spybot search and destroy, deleted my temp files. when I reboot the little darn thing came back. I tried to find the documents and settings but I don't know where to look in vista.

thanks,
> kem
I just typed the path because did not see it either.

And after reboot I made another restore point.

help me pls I cant figure out how to do this. Pretty computer savvy I am in safe mode and searching the for Look in c:\Documents and Settings\All Users\Application Data but I cannot find the number file and I dont think I am doing it right. can you please guide me? I am going into Search on the start menu.
Posts
2
Registration date
Friday December 5, 2008
Status
Member
Last seen
December 6, 2008
5
You are infected with WinWeb security a bogus antivirus software which produces false reports and attempts to have you purchase WinWeb security. You need to remove it. Instructions can be found here https://www.bleepingcomputer.com/virus-removal/remove-winweb-security
I tried this, no luck, used full and quick scans
I have the same problem. It kept telling me to scan and then would pop up to purchase. At one point, it wouldn't even allow me to get onto any internet programs. I can't open the internet, my email, my space (kids). How can I fix this if I can't get on to the internet?
as i understand it this virus has been renamed system security 4.5. i tried all of the suggested solutions to no avail, including pulling up the task window and deleting. For me it did not work. i tried to down load mc affee and it kept logging off aol and internet explorer ( i tried downloading on both systems) eventually i found windows live one care through the microsoft site, so that i knew it was genuine and had no problem downloading. it worked ,i was left with a small square blue and white icon whichi put into the recycle bin. as a bonus i have th windows one care on three months trial and do not have to pay anything until the three months expire. i supposew i could decide not to go ahead with the purchase but this system seems to be so good it would be daft not to. note you do need to remove any external spyware and the like before you download. the srcurity settting that come with your system do not need to be removed or settings change. to be sure that all is ok go to control panel and click on security and it will give the status of the three settings firewall antivirus etc. hope this is useful
I had this problem and finally got rid of it by going into safe mode (restart computer; before it loads hit F8; when safe mode screen appears, hit enter) In Safe Mode, I then updated my Adaware program and ran it. Adaware got rid of the spyware and my antivirus program and all other programs functioned again. I then got out of safe mode and ran my Adaware program three more times and scan with my Trend Micro Antivirus program two more times. Everything is working fine again.
thanks to whoever figured out that booting in SAfe-mode was the way to go.
I couldn't do much else from there, but at least was able to do a System Restore, got rid of the lsas.keyblogger, then upgraded to the latest Norton and feel safe once again.
That was horrible, and I was really really frustrated, thought I'd have to reinstall the entire OS to get rid of the sucker. thank you thank you again! - pb
Hey. I cannot start in safemode. I have tried f8, f7, going to run... then typing msconfig and nothing will come up. I am not the best with computers... Any ideas?
thank you very much for the safe mode and system restore idea..It worked like a champ and you are my hero...
Please help i tried Careys ideaa and when i try to delete it says access denied
Posts
47366
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,364
Hello,

Please download Malwarebyte to your desktop:

https://ccm.net/download/download-105-malwarebytes

Once on your desktop, rename it explorer.exe

Install Malwarebyte and update it.

Request a FULL system scan

Please, I would appreciate your feedback

Regards
I have the same problem too I am running spyware doctor and still get the pop up
I got the sam one but the only thing I found to remove it was to reinstall windows if you have you software than cool
I recently had this worm. After attempting all the suggested remadies, to no avail, all I did was click the decline or the X. I did this for about 2 or 3 weeks then it didn't appear anymore. This worm is just a scam for people to purchase useless software in the amount of $45.00.

Just be patient. Don't fall for this scam.
The correct way to get rid of this pesty pop up and to get ur computer back to the way it was before. shut down computer. Restart, hit f8 before load up. This will take you to safe mode and don`t freak out cause everything will appear large. This will enbale you to get to restore of your computer. Restore computer to earlier date, before this sucker attacked ur computer. This should fix it.
Thanks for the heads up but, what if you don't have a restore point??
Please lmk asap............Thanks!!!

Signed,
Irritated!!!!
> runemova
just trying to offer some help here, since I got some myself - :-)

When you go to System Restore, the default restore point dates are today and yesterday, but theres a checkbox where you can request earlier dates. Go back as far as you can to when you first think you got the trojan, and restore to the day or week or whatever before then, and restore.
That got rid of it for me, then I updated my Norton, all clean now, thank goodness! good luck -pb
I can't use system restore. It says that I have to go to domain adminstrator to turn it on. Any suggestions. I can't get into any screens except safe mode
Thank you so much Carey, boxcar84our and pb!!!!! You are life savers! Our little laptop was the second of our computers to get this thing and I was very close to tears and totally frustrated until I tried your suggestions. Our main computer has now been away with the computer fix-it guy for three weeks. He said that he had to completely wipe the hard drive (luckily I saved all our important files elsewhere) and I'm really scared about how much he's going to charge us now. Well I'm feeling rather chuffed now. Thank you friends!!!!
Thanks sooo much.. I work online and got it from FB thats it not using that anymore.. I was about try cry then I couldnt find where to restore in vista safe mode, as kept saying was open already kept going in and out of safe mode then it opened restored to day before and it works worm free, could not of done it without you all thanks so much
I agree, Carey is my new best friend! I rebooted in Safe Mode, and did the restore thing and all seems well! Thanks to everyone!

g
try Restore point or formate windows
you cam F disk and remove all partitions and do a reinstall. if you any files that you need try putting them on a disc or external hard drive or memory stick. Than run the F disk( https://support.microsoft.com/en-us/windows/create-and-format-a-hard-disk-partition-bbb8e185-1bda-ecd1-3465-c9728f7d7d2e ) than run a reinstall ... this works for very bad infections. hope this helps =)
Thats the last option to do, good2know
I tried following the instructions at https://www.bleepingcomputer.com/virus-removal/remove-security-tool but Security Tool would not let me run mbam OR rkill. It also prevented me from killing the processes through task manager. Here's how I fixed it:

1. Start in safe mode by holding F8 while starting up
2. Press windows key + r to open a run dialog
3. Type msconfig
4. Click on the startup tab
5. Select the item that is all numbers. Its "Command" should be "C:\ProgramData\##########\#########.exe" where the #s are random numbers
6. Click OK and reboot in normal mode

Security Tool should now be temporarily disabled so you can run mbam as explained in the link above.

Good luck!
And by "select," I mean uncheck that entry in the startup tab. That'll keep Security Tool from starting the next time you start your computer.
Thank you so much... I copped this virus yesterday and after running numerous scans, nothing seemed to pic up the virus. I ran with the above help and the computer seems to be back to its normal self. Thank you so much! Melissa
My son's laptop got this virus today and I managed to remove it using Carey's instructions, now I'm SuperMum! Thanks Carey!
Hi

I used Ambuscias' method and it worked very well indeed. Why do I need to rename the malware tool explorer?

But many thanks

Murmurings
Posts
47366
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,364
Hello,

It is just in case we had not identified the virus correctly and that we were dealing with a rogue.

Regards
it worked thanks to all
All i did was to reboot in safe mode(restart and repeatedly press f8, then select safe mode)reload my norton and restart pc, thern scan..chiching
It seems as though no matter what I do, it always says access denied or some other command that will not allow me entrance to anything I ask. Safe mode or not. It is a rediculous joke to play for sure.
Posts
47366
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 1, 2021
11,364
Hello Pixie,

I sympathize with you, but please be more specific, explain "no matter what I do", "other command", "anything I ask".

Thank you