PDA

View Full Version : Feeling hopeless



EyeKandyDesigns
2014-02-01, 16:56
I recently had a tracking virus that got into my desktop and my laptop so I wiped both clean and am now running spybot on both machine on Windows 8

Both are giving me slightly different results, and I choose fix problem, it checks them all, and when I run spybot again they come back. Are they anything to worry about? Can I fix the issues so they don't keep coming back (if they aren't threats)? Thanks in advance for any help.

Here are the ones from my desktop:

Search results from Spybot - Search & Destroy

2/1/2014 9:44:52 AM
Scan took 00:27:04.
9 items found.

Microsoft.Windows.ActiveDesktop: [SBI $377029D9] User settings (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper

Microsoft.Windows.ActiveDesktop: [SBI $377029D9] User settings (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-3513414735-2105950253-21738575-1001\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper

Microsoft.Windows.ActiveDesktop: [SBI $377029D9] User settings (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

MS Media Player: [SBI $5C51E349] Client ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-3513414735-2105950253-21738575-1001\Software\Microsoft\MediaPlayer\Player\Settings\Client ID

MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name

Cache: [SBI $49804B54] Browser: Cache (1) (Browser: Cache, nothing done)


History: [SBI $49804B54] Browser: History (33) (Browser: History, nothing done)



--- Spybot - Search & Destroy version: 2.1.18.131 DLL (build: 20130516) ---

Zenobia
2014-02-01, 22:01
Microsoft.Windows.ActiveDesktop: [SBI $377029D9] User settings (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper

Microsoft.Windows.ActiveDesktop: [SBI $377029D9] User settings (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-3513414735-2105950253-21738575-1001\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper

Microsoft.Windows.ActiveDesktop: [SBI $377029D9] User settings (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper
For these ones,please see here:
http://forums.spybot.info/showthread.php?67414-Are-these-false-positives
If you(or somebody you trust) set them yourself,you shouldn't fix them.
If you didn't set things up that way,then try running Spybot as administrator before scanning,then fixing them,so they hopefully don't come back in a scan again:
http://www.safer-networking.org/faq/how-can-i-get-administrator-rights-under-windows-vista7/


Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

Internet Explorer: [SBI $0BC7B918] User agent (Registry Change, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent

MS Media Player: [SBI $5C51E349] Client ID (Registry Change, nothing done)
HKEY_USERS\S-1-5-21-3513414735-2105950253-21738575-1001\Software\Microsoft\MediaPlayer\Player\Settings\Client ID

MS DirectDraw: [SBI $EB49D5AF] Most recent application (Registry Change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name

Cache: [SBI $49804B54] Browser: Cache (1) (Browser: Cache, nothing done)


History: [SBI $49804B54] Browser: History (33) (Browser: History, nothing done)
These ones are just tracks:
http://www.safer-networking.org/faq/usage-tracks/
Running Spybot as administrator is a good idea to be sure they are being fixed.However,after you fix those,some or all of them will reappear in a Spybot scan after you've used your computer for a bit,so there's really no need to worry about them. :)

EyeKandyDesigns
2014-02-02, 00:05
Sorry if this sounds stupid, but I just reset up these computers and I am the only person I set up....so how would I run as an administrator? I thought I was the admin :(

Zenobia
2014-02-02, 03:37
Doesn't sound stupid at all. :)
Yes,your account is (most likely) an administrator account,but in Windows Vista and above,user account control is used,mainly to help stop (malicious or otherwise) programs,etc. from making unwanted changes to your computer without the user knowing about it,so if warranted,sometimes you see a prompt from uac to bring your attention to the change about to be made,and asks you whether you allow it or not.
Here is the wiki about it:
http://en.wikipedia.org/wiki/User_Account_Control
These are some of the times you might see a UAC prompt:
http://en.wikipedia.org/wiki/User_Account_Control#Tasks_that_trigger_a_UAC_prompt

In Spybot's case,running the system scan as administrator gives it a little more oomph to get things done.
This is a tutorial on how to run a program as administrator in windows 8 and 8.1.The easiest to follow is probably option 1 or option 2.
http://www.eightforums.com/tutorials/9564-run-administrator-windows-8-a.html

EyeKandyDesigns
2014-02-02, 15:35
Wow, that was super easy and well I feel a little dumb for not knowing that lol....ok gonna try it out now. Thank you so much for your help!
-RJ

Zenobia
2014-02-02, 20:17
You're welcome. :)