He's scared to remove any of these in case he breaks anything (but he's just reloaded to factory settings because of an especially bad spyware infection). Spybot's pulled the following up:
Xer0x:
- "settings" in HKEY_LOCAL_MACHINE/software/xerox
DSO Exploit:
- "Data source exploit object" in HKEY_USERS/.DEFAULTS/Software/Microsoft/Windows/Current Version/Internet Setting
Alexa Related:
- "What's related link" in C/Windows/Web/Related.htm
NewsUpdate:
- "Interface (_DCTMarqEvents)" in HKEY_LOCAL_MACHINE/software/Classes/Interface/{8614A943-FF72-11D0-9BA1-00AA00464A16}
- "Ad settings" in HKEY_LOCAL_MACHINE/software/Creative Tech/Software Installed/News
- "Autorun Settings" in HKEY_LOCAL_MACHINE/software/Microsoft/Windows/CurrentVersion/NewsUpd
- "Class ID" in HKEY_CLASSES_ROOT/CLSID/{8614A944-FF72-11D0-9BA1-00AA00464A16}
- "Interface (_DCTMarq)" in HKEY_LOCAL_MACHINE/software/Classes/Interface/{8614A942-FF72-11D0-9BA1-00AA00464A16}
- "Program Directory" - in C/Program Files/Creative/News
(x2)
- "Root Class" in HKEY_CLASSES_ROOT/CTMARQ.CTMarqCtrl.1
...and he's wondering how dangerous these are. I'm tempted to tell him to vape the lot, but...

My friend's wondering about something with Spybot
Started by
Sanity or Madness
, Jul 09 2004 10:55 PM
1 reply to this topic