PDA

View Full Version : SD Resident - Browser Hijacker Desktop / Registry Change



ziggy
2007-04-30, 20:13
:sad:
Hi

After running SuperAntiSpyware, there were a number of infected files. After quarantining them and re-booting back into normal mode, SD Resident Teatimer popped up with the usual "detected an important registry change etc etc etc.

Having quarantined the the infected files - should I Allow or Deny the registry change ??

As you can see from the Teatimer log, I allowed some and denied others until I realized that I had no idea what was the correct process.

More often than not when rebooting or starting up the computer, resident opens up these "important...detected" dialogue boxes - and if I can recall, they generally relate to a change in the google search and I think the other one is about the Start up Entry..

I have to admit that these so called registry changes Allow or Deny have got me fairly confused - I generally Allow them and I'm now thinking that this may well be the cause of the warning box upon each reboot.


My apologies if I have provided way too much info (screen shots!) but I think more is better than less !!!

Until I hear back from you, I will leave my computer as it is, and hopefully this and your response will help to solve all this.

Many thanks
:bigthumb:

2007/04/30 04:53:16 PM Denied value "swg" (new data: "") deleted in System Startup user entry!
2007/04/30 04:53:41 PM Allowed value "!AVG Anti-Spyware" (new data: "") deleted in System Startup global entry!
2007/04/30 04:53:45 PM Allowed value "" (new data: "") deleted in System Startup global entry!
2007/04/30 05:52:21 PM Denied value "{BFB5F154-9212-46F3-B547-AC6106030A54}" (new data: "") deleted in Global browser toolbar!
2007/04/30 05:52:25 PM Denied value "{BFB5F154-9212-46F3-B547-AC6106030A54}" (new data: "") deleted in Global browser toolbar!
2007/04/30 05:52:27 PM Denied value "{BFB5F154-9212-46F3-B547-AC6106030A54}" (new data: "") deleted in Global browser toolbar!
2007/04/30 05:52:29 PM Denied value "{BFB5F154-9212-46F3-B547-AC6106030A54}" (new data: "") deleted in Global browser toolbar!
2007/04/30 05:52:32 PM Denied value "{BFB5F154-9212-46F3-B547-AC6106030A54}" (new data: "") deleted in Global browser toolbar!
2007/04/30 06:31:16 PM Allowed value "!AVG Anti-Spyware" (new data: "") deleted in System Startup global entry!
2007/04/30 06:31:26 PM Denied value "" (new data: "") deleted in System Startup global entry!

Brief copy of SuperAntiSpyware Report:

http://i158.photobucket.com/albums/t96/nct35/SuperantiSSD.jpg

Brief copy of the resident log:

http://i158.photobucket.com/albums/t96/nct35/supssd.jpg

spybotsandra
2007-05-02, 15:23
Hello,

Please read this information about TeaTimer:
http://www.safer-networking.org/en/faq/33.html
and http://www.safer-networking.org/en/faq/34.html
If you surf the web and without any user interaction the teatimer pops up and warns about a registry change it is better to "deny", but if you install something by yourself it is OK to "allow" the change.

Best regards
Sandra
Team Spybot