PDA

View Full Version : Can Malware exploit Spybot and send files through the internet?



imajum
2006-10-25, 03:03
Lately, I have been having a problem with Spybot S&D. in that it has been running extremely slow when I try to immunize. I have Mcafee Security Center loaded on my software and from time to time it provides the following message via a pop-up box. Is this an indication of a malware or a trojan? I would really appreciate your guidance on this.


McAfee has allowed a change to your computer.

Details
SystemGuard Name: Internet Explorer Security Zones
Change: Registry Created

More Info
SystemGuard Description: Internet Explorer has four predefined security zones: Internet, Local intranet, Trusted sites, and Restricted sites. Each security zone has its own security setting, which is predefined or customized. Security Zones are a target of some spyware or other potentially unwanted programs because lowering the security level allows these programs to bypass security alerts and act undetected.

Process: C:\Program Files\SpyBot S&D\Spybot - Search & Destroy\SpybotSD.exe
Process Name: Spybot - Search & Destroy
Process Publisher: Safer Networking Limited
Affected Items: HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ac66.cn\

md usa spybot fan
2006-10-28, 06:52
Spybot adds the following entries to the registry during immunization:


[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ac66.cn]
*=dword:00000004

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ac66.cn\www]
*=dword:00000004
Those entries add "*.ac66.cn" and "www.ac66.cn" to Internet Explorer's restricted zone.

Evidently McAfee is misinterpreting the addition of one or both of those entries as being suspicious.