nrshapiro
2007-06-18, 23:43
This could be a false positive, or else Spybot doesn't work well across user accounts. I had some spyware on our family shared machine, which I've cleaned using various utilities and my own knowledge of windows. Adaware and avg antivirus and antispyware report the machine clean.
Spybot reports it clean under my user account, or after a safe mode boot either on the default admin account or my admin account.
But when I look under my son's account, whos a limited user under Windows XP home SP2, spybot SD keeps coming back and reporting
--- Search result list ---
Smitfraud-C.Toolbar888: Settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-1416163055-3445941883-4294521060-1013\Software\Microsoft\aldd
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
I have seen the registry key it's reporting in place; and perhaps something keeps putting it back there. But why isn't this caught when I scan from my admin account? Do you have to run from each account, or will spybot check all the hives and user data each time?
And how does this key alone, in the absence of finding any other files or infections related to smitfraud, mean I am infected? Where is the key coming from?
Spybot reports it clean under my user account, or after a safe mode boot either on the default admin account or my admin account.
But when I look under my son's account, whos a limited user under Windows XP home SP2, spybot SD keeps coming back and reporting
--- Search result list ---
Smitfraud-C.Toolbar888: Settings (Registry key, fixed)
HKEY_USERS\S-1-5-21-1416163055-3445941883-4294521060-1013\Software\Microsoft\aldd
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
I have seen the registry key it's reporting in place; and perhaps something keeps putting it back there. But why isn't this caught when I scan from my admin account? Do you have to run from each account, or will spybot check all the hives and user data each time?
And how does this key alone, in the absence of finding any other files or infections related to smitfraud, mean I am infected? Where is the key coming from?