Results 1 to 3 of 3

Thread: Am I infected?

  1. #1
    Junior Member
    Join Date
    Jan 2011
    Posts
    3

    Default Am I infected?

    SpyBot report shows the following entries:

    --- Search result list ---
    Microsoft.Windows.Explorer: [SBI $F1AA2176] User settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-1454471165-1957994488-1629655555-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff

    Microsoft.WindowsSecurityCenter.AntiVirusOverride: [SBI $3604910C] Settings (Registry change, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride

    Microsoft.WindowsSecurityCenter.FirewallOverride: [SBI $0C94D702] Settings (Registry change, nothing done)
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride

    Microsoft.WindowsSecurityCenter_disabled: [SBI $2E20C9A9] Settings (Registry change, nothing done)
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc\Start

    Microsoft.Windows.System: [SBI $268E3020] Settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-1454471165-1957994488-1629655555-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind

    Microsoft.Windows.System: [SBI $CA5FA75C] Settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-1454471165-1957994488-1629655555-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoShellSearchButton

    Microsoft.Windows.System: [SBI $83581ED4] Settings (Registry change, nothing done)
    HKEY_USERS\S-1-5-21-1454471165-1957994488-1629655555-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolBarsOnTaskBar

    I am not familiar enough with the Registry to tell whether these entries mean anything or not. The ones about the Security Center being disabled I understand (and have turned off because it didn't play nice with ZoneAlarm AntiVirus/Firewall), but not the rest. The only other item SpyBot found was a tracking cookie from RightMedia - ad.yieldmanager.com, which I removed. Any help will be appreciated.

  2. #2
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default




    Please read Before You Post
    While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

    Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.

    Cant really see if your infected until we see a log


    Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.com
    • DDS.scr
    • DDS.pif
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
    • Notepad will open with the results, click no to the Optional_Scan
    • Follow the instructions that pop up for posting the results.
    • Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

    Information on A/V control Here
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  3. #3
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Due to inactivity, this thread will now be closed.

    If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a new DDS log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •