PDA

View Full Version : After immunizing Trojan.Win32.Dialer.hc



mimetux
2005-11-12, 18:50
:) Hello all ,i use etrust Pestpatrol scanner 's too,after update immunize data base whit spybot the PestPatrol scan result is :

Trojan.Win32.Dialer.hc in this key :

hkey_curent_user\sofware\microsoft\windows\currentversion\internet settings\zonemap\domains\sgrunt.biz :rolleyes:

so why the others zonemaps are not detected for Trojans too ?

sorry for my english i'm french user :D

thank 's

md usa spybot fan
2005-11-12, 19:58
During the immunization process Spybot adds the following entry to the system registry to place sgrunt.biz in Internet Explorer's restricted zone.


[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sgrunt.biz]
*=dword:00000004
If that is the entry (*=dword:00000004) being detected by Pestpatrol it is a false positive while checking for Trojan.Win32.Dialer.hc.

The problem has been noted by other people. For example:
HELP i have Trojan.win32.dialer hc
http://www.wilderssecurity.com/showthread.php?p=604238

mimetux
2005-11-13, 05:26
:) ok thank 's for this answer