C
* * Chas
I'm running Spybot 1.4 on a Win98SE system. It started reporting
Smitfraud-C the other day.
Here's the Spybot message:
Smitfraud-C.: Settings (Registry change)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\E
xplorer\NoActiveDesktopChanges!=dword:0
Aside from this Registry entry, there are no other symptoms or changes.
AdAware 1.06, NOD32 and F-Prot didn't find anything. I'm running MS
TweakUI 1.33 and Active Desktop disabled. I think that it's a false
positive.
Here a description of Smitfraud.c
Trojan-Spy.HTML.Smitfraud.c Other versions: .a
Aliases
Trojan-Spy.HTML.Smitfraud.c (Kaspersky Lab) is also known as:
Phish-BankFraud.eml.a (McAfee), Trojan Horse (Symantec),
Trojan.Bankfraud (Doctor Web), HTML.Phishing.Bank-1 (ClamAV),
Trj/Citifraud.A (Panda), HTML/Smithfraud.gen (Eset)
Smitfraud-C the other day.
Here's the Spybot message:
Smitfraud-C.: Settings (Registry change)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\E
xplorer\NoActiveDesktopChanges!=dword:0
Aside from this Registry entry, there are no other symptoms or changes.
AdAware 1.06, NOD32 and F-Prot didn't find anything. I'm running MS
TweakUI 1.33 and Active Desktop disabled. I think that it's a false
positive.
Here a description of Smitfraud.c
Trojan-Spy.HTML.Smitfraud.c Other versions: .a
Aliases
Trojan-Spy.HTML.Smitfraud.c (Kaspersky Lab) is also known as:
Phish-BankFraud.eml.a (McAfee), Trojan Horse (Symantec),
Trojan.Bankfraud (Doctor Web), HTML.Phishing.Bank-1 (ClamAV),
Trj/Citifraud.A (Panda), HTML/Smithfraud.gen (Eset)