I was in an online, and I think my computer had been downloading updates, when a Spybot box opened saying it had "encountered and terminated a process listed as part of a malicious software." It was offering me the option to delete the file, but I wanted to research before I decided that. I updated spybot, immunized, and started a scan, while I googled the file. But having done that, I am only more confused. It almost seems the file is a windows security update. I'm not good at this stuff, but I'm real nervous about what to do. Any help, out there?
XP Pro, , Firefox 3.6.3, SpyBot 1.6.2.46, updated just now (6/14).
The spybot box that suddenly opened said this of the file:
process ID: 3792
filename: NDP1.1sp1-KB979906-X86.exe
Found in C:\WINDOWS\SoftwareDistribution\Download\Install\NDP1.1sp1-KB979906-X86.exe!
identified as SpyArsenal.HomeKeyLogger
In the spybot logs the following is what's listed for today:
6/14/2010 1:41:19 AM Allowed (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") added in System Startup user entry!
6/14/2010 3:12:29 AM Allowed (based on user decision) value "NetFxUpdate_v1.1.4322" (new data: ""C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" 0 v1.1.4322 GAC + NI NID") added in System Startup global entry!
6/14/2010 3:12:29 AM Encountered and terminated SpyArsenal.HomeKeyLogger in C:\WINDOWS\SoftwareDistribution\Download\Install\NDP1.1sp1-KB979906-X86.exe!
6/14/2010 3:12:31 AM Allowed (based on user decision) value "NetFxUpdate_v1.1.4322" (new data: "") deleted in System Startup global entry!
XP Pro, , Firefox 3.6.3, SpyBot 1.6.2.46, updated just now (6/14).
The spybot box that suddenly opened said this of the file:
process ID: 3792
filename: NDP1.1sp1-KB979906-X86.exe
Found in C:\WINDOWS\SoftwareDistribution\Download\Install\NDP1.1sp1-KB979906-X86.exe!
identified as SpyArsenal.HomeKeyLogger
In the spybot logs the following is what's listed for today:
6/14/2010 1:41:19 AM Allowed (based on user decision) value "FlashPlayerUpdate" (new data: "C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p") added in System Startup user entry!
6/14/2010 3:12:29 AM Allowed (based on user decision) value "NetFxUpdate_v1.1.4322" (new data: ""C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" 0 v1.1.4322 GAC + NI NID") added in System Startup global entry!
6/14/2010 3:12:29 AM Encountered and terminated SpyArsenal.HomeKeyLogger in C:\WINDOWS\SoftwareDistribution\Download\Install\NDP1.1sp1-KB979906-X86.exe!
6/14/2010 3:12:31 AM Allowed (based on user decision) value "NetFxUpdate_v1.1.4322" (new data: "") deleted in System Startup global entry!