The detections indicate that, if you were using the Windows firewall instead of the McAfee Firewall, Windows Internet Explorer (iexplore.exe) would be authorized to receive unsolicited incoming traffic which would be a potential security problem.You have disabled your firewall ..
the normal default setting of the Windows firewall does include authorizing Windows Internet Explorer to receive unsolicited incoming traffic. Since the detection indicates an abnormal setting for the Windows firewall that may have been introduced by malware at some point in time, I suggest that you fix the detections with Spybot
However, the normal default setting of the Windows firewall does not include authorizing Windows Internet Explorer to receive unsolicited incoming traffic.
Alan D:
All communication is two way (request > response). Windows Internet Explorer must be able accept inbound traffic, but it should only be in response to an outbound request. The two detections (Microsoft.Windows.AppFirewallBypass and Microsoft.Windows.IEFirewallBypass) that Spybot added are looking for Windows Firewall registry entries that allow programs to accept unsolicited incoming traffic. In other words, registry entries that could allow a program to respond to an incoming request.
However, most firewalls only allow an inbound response to an outbound request. Is there also an indication within your AVG firewall if Internet Explorer is/isn't allowed to act as a Server in addition to the one "Allow" you cited?
The detections were just added so those settings could have been there for a while. No one seems to have discovered the cause of the setting being there.First, reading this thread I got the feeling something had happened to make the firewall notices appear. Is this so, and how do I find out?
Others may have different opinions, but personally I would only run Spybot in safe mode if I were have problems removing something while running in normal mode.In general, I have read of people running scans in Safe Mode. As far as Spy Bot is concerned, when should I run it in Safe Mode? Is Safe Mode only for when it needs to fix something, or fix something that didn't go away in normal mode?