Results 1 to 4 of 4

Thread: Is this a FP?

  1. #1
    Junior Member
    Join Date
    Dec 2006
    Posts
    2

    Default Is this a FP?

    I have SpyBot 1.4 with the latest updates 2006-12-01

    I just did a span and found the following which SpyBot identified as Smitfraud-C

    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Shared\Access\Parameters\FirewallPolicy\StandardProfile\Authorized\Applications\List\C:\Windows\scvhost.exe

    Is this a FP? I'm asking because no other software seems to spot it
    (CounterSpy, AVG, Kaspersky)

    Thanks.

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hello ,

    it is not a false positive, your computer is infected.

    the correct path and name for the legit file is c:\windows\system32\svchost.exe

    observe the letters carefully , this is often done to make the trjoans look like legit files.

    this infection enables Smitfraud-C. to pass your Windowsfirewall
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Junior Member
    Join Date
    Dec 2006
    Posts
    2

    Thumbs up Thanks!

    You guys are the greatest!

  4. #4
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    If you would like someone to take a look at logs and assist you in the removal of any malware that might be present on the System, please follow the procedure in this link:
    "BEFORE you POST" -Preliminary Steps and scanning with SPYBOT-S&D

    Then start your own thread in the Malware Removal Forum

    Cheers.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •