Spybot cannot delete this alexa related exploit. I have run S&D numerous times and selected fix. Spybot says it is fixed but when I rerun S&D the exploit is still there. When I look for the related strings in regedit they are there but they are incomplete (e.g. HK_USERS\S-1-5-18\Software
\Microsoft
\Windows\C
urrentVers
ion\Intern
et Settings\Zones\0\1004!=W=3
as it appears in Spybot. When I find the string in REGEDIT it is identical except for the end of 1004!=W=3). When I ran Hijackthis the exploit strings do not show up.
My question: Is it safe to delete the strings useing regedit?
There are five strings in HK_USERS one each in S-1-5-18, s-1-5-21-436374069-8429252
46-1060284
298-1004, s-1-5-19, s-1-5-20, and default
I have included my hijack this log. It follows:
Logfile of HijackThis v1.98.2
Scan saved at 4:56:17 PM, on 8/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\msiexe
c.exe
C:\Hijackthis\HijackThis.e
xe
N3 - Netscape 7: user_pref("browser.startup
.homepage"
, "
http://www.adelphiapowerpage.com/")
; (C:\Documents and Settings\Ron Humann\Application Data\Mozilla\Profiles\defa
ult\hcfcjf
ky.slt\pre
fs.js)
N3 - Netscape 7: user_pref("browser.search.
defaulteng
ine", "engine://C%3A%5CPROGRAM%2
0FILES%5CN
ETSCAPE%5C
NETSCAPE%5
Csearchplu
gins%5CSBW
eb_01.src"
); (C:\Documents and Settings\Ron Humann\Application Data\Mozilla\Profiles\defa
ult\hcfcjf
ky.slt\pre
fs.js)
O2 - BHO: Yahoo! Companion BHO - {02478D28-C3F9-4efb-9B51-7
695ECA0567
0} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCO
MP5_0_2_6.
DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\ACROBAT\ACTIVEX\ACROIE
HELPER.OCX
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D
4657B8C449
A} - C:\PROGRAM FILES\ZERO KNOWLEDGE\FREEDOM\PKR.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-0
0E02927A30
4} - C:\PROGRAM FILES\ZERO KNOWLEDGE\FREEDOM\FREEBHOR
.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radi
o - {8E718888-423F-11D2-876E-0
0A0C908246
7} - C:\WINDOWS\System32\msdxm.
ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Ad-aware] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-aware.exe" +c
O4 - HKCU\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\
migrate.dl
l,ProcessW
in9xNetwor
kPrinters
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O16 - DPF: Win32 Classes -
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-6
35E46C2288
D} (Toontown Installer ActiveX Control) -
http://download.toontown.com/sv1.0.13.21.1/ttinst.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cabStart Free Trial