PDA

View Full Version : Registry Change Attempted but Denied



Harry Letterman
2007-09-16, 22:06
With Spybot 1.5 this morning I noticed a registry entry change warning from Spybot. A toolbar was trying to install. I clicked the "Deny change" button and ticked "Remember this decision". I have a screenshot of the Spybot registry change warning window.

About a week ago I had a bad encounter with h**p:/mamaha.info/drugs/CalCet.htm. Details of that incident can be read at this Spyware Warrior thread (http://www.spywarewarrior.com/viewtopic.php?t=26227). "Dawg" at Wilders Security Forum says that the host of the malware is h**p://www.sex2person.info/xxxxxx/ (link to Dawg's post (http://www.wilderssecurity.com/showpost.php?p=1076615&postcount=10)).

I scanned with Spybot 1.4 and it fixed 3 registry changes. A couple days later I updated to Spybot 1.5 and a scan showed no problems. However, I have noticed a couple of times where IE 6 windows would "cascade open" uncontrollably. I have a HijackThis thread at Spyware Warrior but there are no takers so far. I am also doing a trial evaluation of SpywareTerminator and did a "Fast Spyware Scan" and it found 2 items (the links are to descriptions only):
AnalogX PacketMon ( http://www.analogx.com/contents/download/network/pmon.htm)
BrainNames (http://www.sophos.com/security/analyses/brainnames.html?_log_from=rss) (Sophos link)

I just performed a new scan with Spybot 1.5 and it says that no problems were found. I do have the Logs from v1.4 where Mamaha was involved. Should I post a HJT log here? I'm primarily concerned about that attempted registry change (BHO toolbar). I DID deny the change.

Thanks for reading!

tashi
2007-09-17, 19:22
Hello.

Should I post a HJT log here?

Please do NOT post hjt logs in the Spybot forum (http://forums.spybot.info/showthread.php?t=1266)


I have a HijackThis thread at Spyware Warrior but there are no takers so far.
If you posted in our Malware removal forum requesting assistance, you would need to inform SWW.

Regards. :)

Harry Letterman
2007-09-17, 23:31
Hi Tashi,

Thanks for the reply and advice. I adctually did know not to post an HJT log in this particular forum. I should have been more clear in my question.

I just had another incident where IE 6 windows would "cascade open" uncontrollably. I rebooted and, for now, things are fine.

I will have Suzi (Admin at Spyware Warrior) delete my HJT post as there are still no replies.


I don't know if this helps but here is Spybot registry change warning window screenshot -

http://s237.photobucket.com/albums/ff138/Bresson34/?action=view&current=SpybotKeyDeny01.jpg

tashi
2007-09-18, 07:25
Hello.


I will have Suzi (Admin at Spyware Warrior) delete my HJT post as there are still no replies.

You could follow the procedure in the following link, which includes running a Spybot-S&D scan in safe mode, and an on-line anti virus scan:
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) posting only the logs requested.

Best regards. :)