marie2x:
It would appear that the following registry entry changed from:
Code:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit"="C:\WINDOWS\system32\Icpywinp.exe,C:\\WINDOWS\\system32\\userinit.exe,"
To:
Code:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit"="C:\\WINDOWS\\system32\\userinit.exe,"
I can't find any information on Icpywinp.exe (the program removed from the entry).
My corresponding registry entry reads:
Code:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UserInit"="C:\\WINDOWS\\system32\\userinit.exe,"
If you were fixing things with Spybot when the message was receive, my first inclination would be to allow the change.
Perhaps the Fixes.yymmdd-hhmm.log produced by Spybot at that time might contain a clue to what stimulated the change. If you like to post the Fixes.yymmdd-hhmm.log from the running of Spybot when you received the message, we could take a look at that.
There are two methods to copy and post that information:
- Method 1:
- Go into Spybot > Mode > Advanced mode > Tools > View Reports > View Previous reports. Look for the Fixes.yymmdd-hhmm.log file that was produced when you found and fixed the detection you are questioning. Open it. To copy it to the Clipboard, right click on the listing and select Select All > Right click again and select Copy. Paste (Ctrl+V) the contents of the Clipboard into a new post in this thread.
- Method 2
- The Fixes.yymmdd-hhmm.log files are stored in the following folders:
- Windows 95 or 98:
C:\Windows\Application Data\Spybot - Search & Destroy\Logs - Windows ME:
C:\Windows\All Users\Application Data\Spybot - Search & Destroy\Logs - Windows NT, 2000 or XP:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs - Windows Vista:
C:\ProgramData\Spybot - Search & Destroy
- Using Windows Explorer, navigate to the correct Fixes.yymmdd-hhmm.log. Double click on it and it should open with Notepad. To copy it to the Clipboard, right click on the listing and select Select All > Right click again and select Copy. Paste (Ctrl+V) the contents of the Clipboard into a new post in this thread.
Note: By default here are two Checks.yymmdd-hhmm.log files produced during a scan. The second Checks.yymmdd-hhmm.log has the details of what the scan found. A Fixes.yymmdd-hhmm.log is produced if you fix or attempt to fix something.