pow1983
2011-07-11, 00:15
Hi There,
Whilst browsing I obviously landed on a dodgy site.
It attempted to install Fraud.InternetSecurity2011 on my computer. It crashed IE then Tea Timer came up with 3 requests which I denied (see below). AVG also popped up and got rid of a number of .exe files.
As a precaution I decided to do a full spybot scan and it found more registry entries that tea timer didnt pick up on. I just really wanted to know why.
This is what Tea Timer discovered:
10/07/2011 21:28:00 Denied (based on user decision) value "HideSCAHealth" (new data: "1") added in System Startup user entry!
10/07/2011 21:28:07 Denied (based on user decision) value "" (new data: ""C:\Users\ME\AppData\Local\mho.exe" -a "%1" %*") changed in EXE Extension handler!
10/07/2011 21:28:14 Denied (based on user decision) value "ctfmon.exe" (new data: "C:\WINDOWS\system32\ctfmon.exe") added in System Startup user entry!
The attached image is what Spybot then discovered after a full scan.
Thanks,
Whilst browsing I obviously landed on a dodgy site.
It attempted to install Fraud.InternetSecurity2011 on my computer. It crashed IE then Tea Timer came up with 3 requests which I denied (see below). AVG also popped up and got rid of a number of .exe files.
As a precaution I decided to do a full spybot scan and it found more registry entries that tea timer didnt pick up on. I just really wanted to know why.
This is what Tea Timer discovered:
10/07/2011 21:28:00 Denied (based on user decision) value "HideSCAHealth" (new data: "1") added in System Startup user entry!
10/07/2011 21:28:07 Denied (based on user decision) value "" (new data: ""C:\Users\ME\AppData\Local\mho.exe" -a "%1" %*") changed in EXE Extension handler!
10/07/2011 21:28:14 Denied (based on user decision) value "ctfmon.exe" (new data: "C:\WINDOWS\system32\ctfmon.exe") added in System Startup user entry!
The attached image is what Spybot then discovered after a full scan.
Thanks,