Page 1 of 2 12 LastLast
Results 1 to 10 of 12

Thread: Attempted Registery Change

  1. #1
    Senior Member
    Join Date
    Oct 2005
    Location
    Potomac MD USA
    Posts
    119

    Default Attempted Registery Change

    Hi:
    Is there a way to determine the source of an attempted registery change?
    I blocked this attempt because I was not doing any program changes or updates at the time that it occured.

    2/17/2006 9:00:11 AM Denied value "{EFA24E62-B078-11D0-89E4-00C04FC9E26E}" (new data: "") added in User-specific browser toolbar!

    My browsers are I.E. and Firefox.

    Thanks
    Frank C

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    You can not tell specifically what "the source of an attempted registry change" is but from the message you can derive what the change is.

    According to this message a toolbar (GUID "{EFA24E62-B078-11D0-89E4-00C04FC9E26E}") was being removed (new data: "") and the change was denied:
    • 2/17/2006 9:00:11 AM Denied value "{EFA24E62-B078-11D0-89E4-00C04FC9E26E}" (new data: "") added in User-specific browser toolbar!

    According to Castlecops that is a legitimate Toolbar:

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Senior Member
    Join Date
    Oct 2005
    Location
    Potomac MD USA
    Posts
    119

    Default Deep Dive

    Thanks for the reply:

    According to f-secure
    Deep Dive is Malware
    http://www.f-secure.com/sw-desc/toolbar_deep_dive.shtml

    Frank C also from MD

  4. #4
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,959

    Default

    Hello Frank C.
    Could we see a log please.
    • Open SpyBot, check for and get any updates available.
    • Close all browsers, check for problems and fix everything found in red
    • Then on the toolbar menu select mode and switch to advanced mode, on the left lower down select tools, and view report, ensure all the options are selected near the bottom except
    • Uncheck[ ] do not report disabled or known legitimate Items.
    • uncheck[ ] Include a list of services in report.
    • Uncheck[ ] Include uninstall list in report.
    • Now select (near the top) view report.
    • Press export in the save in box choose a place such as your my documents folder, then in your next post near the bottom select the "browse" button; navigate to and attach or post that report.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  5. #5
    Senior Member
    Join Date
    Oct 2005
    Location
    Potomac MD USA
    Posts
    119

    Default As Instructed

    Hi Tashi:
    Updated detection rules and English help
    Scan - No immediate threats were found.
    Log as specified exceeded limits
    SpybotSD.Report.txt:
    Your file of 122.7 KB bytes exceeds the forum's limit of 39.1 KB for this filetype.
    Can I cut it down ? How?
    Frank

  6. #6
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    Frank C:

    Did you?
    Quote Originally Posted by tashi
    • uncheck[ ] Include a list of services in report.
    • Uncheck[ ] Include uninstall list in report.
    This greatly reduces the size to the report.

    If the report is still too large, copy and paste it to a new post (or multiple posts if required).

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  7. #7
    Senior Member
    Join Date
    Oct 2005
    Location
    Potomac MD USA
    Posts
    119

    Default Contrite

    Sorry:
    I did not correctly uncheck items as specified.
    Frank

  8. #8
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,959

    Default

    Hi there.

    I will ask Lonny to check the log as well.

    Please see:
    Have you updated Windows? Security Programs? Links and Tips.
    Post #4
    Sun Microsystems

    Cheers.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  9. #9
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    That report looks fine to me Frank C

    Do let us know if there are any other odd problems or symtoms though

  10. #10
    Senior Member
    Join Date
    Oct 2005
    Location
    Potomac MD USA
    Posts
    119

    Default Bottom Line

    Hi:
    Yes, My windows XP is at SP2
    All Security hot fixes through Februrary are current.
    Bottom line; Is Deep dive maleware?
    Thanks Frank

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •