Hello. Thanks in advance for your help. I first noticed a change in my microsoft office outlook ...then later in all of the office suite products. The physical appearance changed to one that appeared something more like "safe mode". After running the scan on my pc with Lightspeed Total Traffic Control, the virus w32.fakealert.gen-p was detected. I quarantined this and deleted it. After doing so, I uninstalled office, re-ran the scan, and then reinstalled office. The new install has the same issues. I read your recommendations and now am going to paste all of the log files to see if you can possibly help me. Thanks so much-


Hello April and welcome to daniweb. Thank you for following the steps in our Read Me sticky. You have posted two copies of the same DDS scanner log. We need to see the other log which is the one that shows Disk Partitions, Disabled Device Manager Items, System Restore Points, …

Hello April and welcome to daniweb. Thank you for following the steps in our Read Me sticky. You have posted two copies of the same DDS scanner log. We need to see the other log which is the one that shows Disk Partitions, Disabled Device Manager Items, System Restore Points, Installed Programs and Event Viewer Messages From Past Week. We do need to see that log.
I am not familiar with your security program, Lightspeed Total Traffic Control, research tells me it is a program used on a school network.
Since I am not that familiar with the program I cannot say how good it is so I won't pass judgment on it's findings. However, the symptoms you describe are not the "normal" or usual symptoms of a Fake.Alert infection, which is a family of Trojans by the way, not a virus. Fakealert spyware belongs to a family of Trojans that aid rogue anti-spyware programs in infecting the user's system. They generate a fake warning message and show false alerts to the user that the system is infected with spyware and Trojans, it fools the user into buying the software.They usually show themselves by very large, sometimes full screen covering "official looking" alerts. They DO look very real, often times showing what is a false scanner running and finding multiple supposed infections on the system. It will generally show you a very large number of supposedly infected files that it "claims" can only be removed by purchasing their program. These trojans generally stop the users ability to even run their normal security programs and if they can run they find nothing. But usually the scanning ability is totally disabled. Many times this warning screen disables your ability to even see most of the desktop. Did you receive any of these types of warning screens? It is also unusual for a regular anti virus program to be able to remove or quarantine these, they may be found but you will be told they cannot be removed by your regular program. MBA-M IS the program of choice for removal of these.

When your computer is infected by Trojan.Fakealert, you may notice slower computer performance, frequent warning alerts that your system has been infected with a virus or Trojan, new icons on your desktop, a switched homepage in the browser or you might even have a different desktop wallpaper.
However all you have said is your Office programs all look odd, like safe mode. You said you uninstalled them, reinstalled them but the problem remains. How did you reinstall these? I see no evidence in your DDS log of these programs being installed. I see your MBA-M install or update, Microsoft Visual Studio 8 but nothing about Microsoft Office.It should show in the log and it does not, anywhere.

There is also another concern to me is, IF this truly is one of these in this Trojan family, is one of the actions they can take is to steal your personal info, name, contacts, AND more importantly any financial info you have on the computer, bank account numbers, credit card numbers, Social Security numbers, those very important, personal items. I mention this because one listing in your log says,financeweb.doe.k12.ga.us. If I am reading this correctly it has or could have something to do with Finance,Dept.of Education Kindergarten-12 state of Georgia, U.S. There is nothing wrong with the listing itself, it's a perfectly legal listing one finds in logs, or listings of this type. Generally they come from an activex program which is required for banking or webpage access for particular sites. Any number of these can be found on a computer, it is just the fact that this appears to have to do with banking and if there is one of these on the computer then these items could be at great risk of being stolen or compromised.

As I said above, research tells me Lightspeed Total Traffic Control is a Security Suite of programs used on a school network. While I am not familiar with the program itself, I am familiar with school networks. I have a daughter who is a teacher and a granddaughter who is a college student. Both of them are connected to the internet via their respective school networks and because of this both have immediate assistance from their schools IT depts and must also follow their directives in cases of possible infections on their computers. My daughter is required to use the "in school security suite" on her school computer, it may be the same one you have, I don't know. She does not nor is required to use it on her home computer even though she uses her home computer for school work but it is not connected to the school network. My granddaughter was required to take her laptop to the IT dept when she arrived at school and they installed the anti-virus program they require for use by computers on their network. I am not certain what program it is though it is a "regular" commercial program that any of us can purchase and install, the students get it for free from the school. The school also installed MBA-M on her computer. Anyway, in both cases, if either gets a serious infection on the computer they have to consult the IT dept for assistance in cleaning. Do you have this option? If you do I believe this would be your best option if is actually connected at all times to your school network. Now if this is your home computer and you have only installed the Lightspeed program because it was available, that is a different situation and it may be we can attempt to work through this problem. But if it is on a network with other school computers then I believe you should contact your school IT dept for assistance. You will need to show them all you have done thus far including the logs.
Let me know and if it is a home computer I will be happy to try to assist.

Thanks for your help. It is a school computer. I am the Technology Coach at the high school for our county. Since submitting this log to you, i started to look at other machines. It seems that our network administrator switched from SOPHOS antivirus to Lightspeed in September. He said that he pushed out the antivirus using a script. However on the machines that I checked, the virus definitions had not been updated in 76 days and the antivirus has NEVER done a complete system scan. I did this manually on 9 machines yesterday and and all 9 had 2-6 viruses...many trojans, worms, etc. I immediately contacted the NA and he said it is not anything to be that alarmed about ...that all machines have viruses...and that it is the job of the antivirus to catch them and remove them. It seems that i am the only one concerned here. This morning when people turned on their machines about 75% of the machines are hung on the applying settings screen. I called him and he is working on it. Doesn't know what happened. Anyway, thanks again for your assistance. At the time of submitting my log files, I was under the impression that mine was an isolated case. Aren't you glad that you aren't the Network Administrator here this morning???

Oh yeah, as for the install of office, I uninstalled the program, shut down, restarted, then pulled the install file from our network. That very well could be an infected installation ...If i need further assistance after he gets his part done, I will contact you. Thanks again for your research and suggestions. I REALLY REALLY appreciate it!

Hello April, Of course this is absolutely none of my business, but sounds to me that your network administrator simply isn't doing his job! It frankly sounds, to me anyway, he doesn't know HOW to do his job!
With this install of this Lightspeed Total Traffic Control it appears that your administrator did not even follow the industry standard steps listed in the install instructions on every security program available for sale or for free to the most average home computer user; Install the program, Update the program, Do a Full Scan with the program and configure the program to do both of these automatically, daily, weekly or however often you wish these two items to be done. I could be wrong but I would think that professional network protection would certainly have those basic instructions also. You said "he pushed out the antivirus using a script". I am an average home user, I know absolutely nothing about writing scripts but it sounds to me like he forgot some very key lines of his script or wrote it incorrectly, automatically update, automatically scan and remove infections.

As I said, I am not familiar with this Lightspeed Total Traffic Control and it may be excellent, it seems to receive fairly high reviews. Reading through their website it truly appears to me your network administrator is not doing his job to assist this security system to correctly do the job it is designed to do or possibly hasn't set it up correctly or fully. You said that "virus definitions had not been updated in 76 days and the antivirus has NEVER done a complete system scan". I don't know when this security system was put into use and I don't know when school began in your school system but just reading a calendar tells me this goes back to mid-September. According to the Lightspeed Total Traffic Control website it says the following:

When we create a new virus signature we make sure that it blocks all the variants of the virus that we have in our virus collection.... Each time we make any change to a signature, such as changing the category, the changes are automatically sent to all of our customers as part of our automatic database update process...There are very few days where new viruses or virus variants are not found. Some days over 1,000 new virus signatures are added to our database and distributed to our customers.
That statement makes it sound as if he hasn't done his job, seeing that your databases are updated with new definitions each time they are sent to your network and that sounds at least that this occurs daily. Your 9 computers can't possibly be the only ones on the network to have gone 76 days without updates.

You said you manually did this on your own yesterday on 9 machines and all 9 had infections on them. Your NA's response, "all machines have viruses". I have to disagree, and being a Technology Coach I would have to assume that you would also disagree. All machines don't and won't have viruses if their security programs are configured and used correctly. Of course even the most secure systems can have an infection get through, but a good and correctly configured security system certainly lessens this possibility. Since you found infections on all 9 of the machines you worked on yesterday I would say something is definitely wrong here, especially taking into consideration this sentence from the Lightspeed website, "we make sure that it blocks all the variants of the virus". 9 computers updated and scanned, 9 computers infected tells me something isn't set up correctly. He was correct in saying, it is the job of the antivirus to catch them and remove them BUT the anti-virus program didn't DO anything until you told it to do it's job.

It sounds to me like the system WAS fully up to date when it was installed, which it likely would have been. But that is as far as he went, install. No scans, no updating, nothing. If offered protection for awhile but now, 76 days later the system is losing it's protection ability, your 2 to 6 infections on all the machines you worked on tells me this. Don't know how many machines are in this entire network but I would be willing to bet that your 9, hopefully, would fall somewhere in the middle with the number of infections found. Some likely will have many more and some will have less but if all 9 of yours tested "positive" I think everyone would have the same results on their computers too.

75% of the machines are hung on the applying settings screen.
Almost sounds as if a major update has been attempted at least. Possibly he decided he had better update this security system and the updates were so large that it may be too much for all of the computers to handle all at the same time. I also think you are right about the Office install coming from one of those infected machines too.

For your reading "pleasure" here is the Lightspeed Total Traffic Control website;


It's not an easy site to navigate and parts of it are a bit too technical for me but with time and patience eventually you do get to where you want to go.

This entire episode will be very interesting to follow. If you don't mind can you post back here with updates?

