CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Smitfraud leftovers according to Spybot

 
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Hijackedmatt

Cadet
Cadet


Joined: Dec 10, 2005
Posts: 2
Location: USA

PostPosted: Mon Dec 12, 2005 1:03 am    Post subject: Smitfraud leftovers according to Spybot
Reply with quote

I was hit by the SpyAxe malware and, while it took a lot of work, it was removed using the various directions posted to do so. The problem is when I run Spybot. It is stating that the Smitfruad-C. is still found. When I click on it to be fixed, Spybot says it cannot due to the fact the item is still running or in memory. The path below is the item. Can this be manually deleted or am I missing something. I am scared to death of messing with the regestry without prior knowledge. Can someone help me?

Smitfraud-C.: User settings (Registry change, fixing failed)
HKEY_USERS\S-1-5-21-2427726106-2774426341-1010874584-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\free-spy-cam.net\*!=W=4

If you need Hijackthis postings or anything else, let me know. I hate this stuff! I want a virgin computer again.

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Dec 12, 2005 1:33 am    Post subject:
Reply with quote

That registry key refers to an entry in one of the IE Security Zones. Since the value is not shown it is impossible to tell for sure which zone it is in. I suggest that you open IE and go to Tools > Internet Options and click on the Security tab. Highlight the zones in turn and click on Sites. This will show all the sites in that particular zone. Look for free-spy-cam.net and determine which zone it is in. If it is in the restricted zone this is quite safe and provides protection should you inadvertently visit that site.


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Hijackedmatt

Cadet
Cadet


Joined: Dec 10, 2005
Posts: 2
Location: USA

PostPosted: Mon Dec 12, 2005 6:00 am    Post subject:
Reply with quote

Thanks for the info. It is nice to know that it may not be a problem. Is there a way to let Spybot S&D know that this is not a problem? And why would this show up after the SpyAxe attack? I have been using Spybot prior to the attack and this had never shown up before. Any ideas?

Back to top
View users profile Send private message
Oldfrog

Special Response Team


Joined: Jun 27, 2004
Posts: 8576
Location: Deep in the Heart of Texas
Moderators MVP Premium SRT

PostPosted: Mon Dec 12, 2005 2:51 pm    Post subject:
Reply with quote

Like I said earlier, I can't tell from the information provided which zone that key places the URL in. If it is placed in your trusted zone then I would consider it a problem. If it occurs in any zone other than Restricted I would simply remove it using the IE applet. If it is in the Restricted zone then you can mark it as safe in Spybot by selecting that detection then right clicking it and selecting "Exclude this product from further searches".


_________________
image MS MVP Security 2006-2008
Back to top
View users profile Send private message Send email Visit posters website MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Rogue Anti-Spyware All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer