I have a Toshiba connect 2tb & cant get rid of Keyloggers.spectorpro.r Help

  • 7 November 2015
  • 7 replies
  • 45 views

I have no idea how i got it on there> the product was purchased at office depot & when i tried to registr it, it said not a valid S/N
I tried to quaranteen & delete but cant.  As a last ditch effort i just unplugged it & hid it under a rock,  it freaks me out because i have small children in the house>

7 replies

Userlevel 7
Badge +62
Hello ?,
 
Welcome to the Webroot Community,
 
Sorry to hear of the issue that you are having.
 
My best advice is for you to Submit a Support Ticket which is free of charge with an active Webroot subscription. They will gladly look into this for you.
 
Hope this helps?
 
 
Userlevel 7
Badge +6
Your course of action will depend wether or not you still want the data on that 3tb disk.. If not dban it ( wipe it clean ). For a 2Tb disk it may take quite a few hrs but then at least you are sure the disk is clean. 
Userlevel 7
Badge +62
Hello ?,
 
You didn't mention if you had that Keyloogger.spectprpro.r on a Mac PC. 
 
If this Toshiba is used as your back up drive (Time Machine) then please read the following by our Mac Threat Researcher ?.
 
"In some cases, Webroot will detect a threat that is located on your backup, such as Time Machine. If the file are in the backup, then they cannot hurt your system. You would have to restore the files from the backup to get them on the system, and at that point the Real Time Shield in Webroot would find and remove them. Even though Webroot cannot remove these files, as space for newer backups is needed the older backups will be deleted. This will delete the threats from the backup as well.
We recommend if Webroot continues to detect these files that you uncheck the box next to them on the removal page. This will tell Webroot to ignore the files in their current location.
If you would like to remove these files manually from the backup in Time Machine, you can use the following steps:
Note: This action is permanent, and will impact all past backups on the given Time Machine drive, even backups from the distant archives on that drive. For this reason, be absolutely certain you want to remove an item before deleting it, otherwise you may end up missing data you would have wanted to keep.
1. Open the backup manager by pulling down Time Machine menu item and selecting, “Enter into Time Machine.”
2. Navigate to the directory location of the files/folders you want to remove.
3. Right-click on the folder or file you want to remove and select “Delete all backups of [File Name].”
4. Confirm the removal.
As the process is the same whether you are deleting the backup of a file or an entire folder, please be careful to only select the items you wish to delete. You cannot recover these files.
Another option available to Time Machine users is to exclude the files and folders from being backed up by the Time Machine. You can add them to the exclusion list which will permanently block the files/folders from being backed up in the future. By doing this, the infected file will eventually be deleted from the backup over time and prevent it from ever getting re-introduced to the drive should it be installed on the computer again."
 
Again I hope this helps.
 
 
Im sorry i forgot to put the fact that it is a MAC & that the security threats webroot found is in fact only on the Toshiba backup hard drive.  I have already contacted Toshiba for support & did not get a response. When i tried to do it myself online it kicked the serial number out & said it wasnt correct. I checked it three times & it is correct. I have original box & receipt from office depot. I am currently installing a 4tb my book from WD so i can transfer everything from my windows computer & start using the mac more.

Userlevel 7
Badge +62
Hi there!
 
I was wondering if you couldn't call Office Depot and ask them about that drive you have purchased? Toshiba would be the only people that could get the registration from that drve to register online. Also you should have a warranty with that drive. Did you call Toshiba at 1-800-618-4444?  I believe they are closed on the weekend.They are usually pretty prompt and helpful.
 
Now I am not understanding what you need from Webroot?
Userlevel 7
Hello Stickman,
No need to worry, there isnt a keylogger on your device.  Thie file that we are finding is the AppleExcludeList.kext on your backup. We are finding it due to the fact that apple has put the keyloggers information in the file and we are reading that.  I suggest that you allow the file, as we cannot remove it and nor should we as it is a legit file.  After allowing it please turn off scan mounted drives and this should correct the issue that you are having.
Regards,
 
Userlevel 7
Badge +62
Thank you ?,
 
I apologize that I didn't refer to your last comment in another post of the same issue. I must be getting senial. :$

Reply