Spybot Logo
Go Back   Safer Networking Forums > Software > Spybot-S&D
Register ProjectsBlogs FAQ Search Today's Posts Mark Forums Read Home Support Download Donate

Reply
 
Thread Tools Display Modes
Old 2005-10-25, 17:28   #1
debanks
Junior Member
 
Join Date: Oct 2005
Location: Surrey UK
Posts: 1
Angry Spybot & Windows Security Centre.....warning

Spyboot keeps finding two suspicious and recuring files. Windows Security Centre Firewall\Disable Notify. There is a similar one for Firewall. These files are in Settings HKEY_LOCAL_MACHINE\Software\Microsoft\SecurutyCentre\Antivirus disable Notify!=dwordO.
I delete them but they recur. In windows security centre everything is switched on. I'm running McAfee Firewall and anti Virus plus AGV free anti virus on XP Home. My questions are : Are these files dangerous, what do they mean and how can I stop them recuring.

I did have a Bagle worm that slipped through undetected.

Derek Banks
debanks is offline   Reply With Quote
Old 2005-10-25, 17:33   #2
spybotsandra
Member of Team Spybot
 
spybotsandra's Avatar
 
Join Date: Oct 2005
Location: Germany
Posts: 3,344
Rated LASSHes: 1,408
Default

Hello,

Since the Detections Update from July 25, 2005, Spybot - Search & Destroy 1.4 has been detecting Security Risks (renamed to "Windows Security Center" on July 30) associated with Microsoft Security Center Registry changes. This is neither a false positive nor a bug. It is just an information.
Spybot-S&D only wants to bring to your attention that "someone" disabled one or more notifications in the Windows Security Center, e.g. the notifications that your virus protection is not active or not up-to-date. If you changed the settings yourself you can safely tell Spybot-S&D to exclude those detections from further scans.
In order to do so please right-click each in turn, then click "exclude this detection from future scans". That way, should any other part of security center settings change, Spybot-S&D will still detect those.
The same is true if you have another security solution installed (like McAfee Security Center or Norton Internet Security). These programs do also disable the Windows Security Center in order to take care of things themselves.
The reason why the changes are flagged by Spybot-S&D is that there are also malware programs that disable the notifications so the user doesn't take note of his security tools not being effective.

Best regards
Sandra
Team Spybot
spybotsandra is offline   Reply With Quote
Old 2005-10-25, 20:04   #3
md usa spybot fan
Spybot Advisor Team
 
md usa spybot fan's Avatar
 
Join Date: Oct 2005
Posts: 5,879
Default

debanks:

Additional clarification:

Quote:
Originally Posted by debanks
In windows security centre everything is switched on.
If you go into Start > Control Panel > Security Center > Resources (on the left hand side of the window – expand if necessary) > click "Change the way Security Center alerts me". This brings up an "Alert Setting" window.

There are three possible alerts:
  • Firewall
    Alert me if my computer might be at risk because of my firewall settings
  • Automatic Updates
    Alert me if my computer might be at risk because of my Automatic Updates settings
  • Virus Protection
    Alert me if my computer might be at risk because of my virus protection software settings
I believe that you will find that the first and third items are unchecked. This is the cause of the following Spybot detections:

Code:
Windows Security Center.FirewallDisableNotify: Settings
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Windows Security Center.AntiVirusDisableNotify: Settings
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0
When the McAfee SecurityCenter is optionally selected as the default security center, it turns off these alerts within the Windows Security Center so that the Windows Security Center will no longer notify you if your firewall and/or antivirus are disabled. As indicated by spybotsandra, this is not a threat as long as McAfee SecurityCenter is running. However, from my perspective, McAfee has done a disservice to their users by not informing them that by selecting the McAfee SecurityCenter as the default Security Center these Windows Security Center alerts will be turned off. If you were to abandon McAfee products in the future they have left the features of the Windows Security Center in a compromised condition. I personally do not have my McAfee SecurityCenter running as the default security center.
__________________

Getting an answer is one thing, learning is another.


Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

Last edited by md usa spybot fan; 2005-10-25 at 20:42.
md usa spybot fan is offline   Reply With Quote
Old 2005-10-29, 11:14   #4
loctet
Junior Member
 
Join Date: Oct 2005
Location: Hérault- FRANCE
Posts: 2
Question Hi spybotsandra,

[QUOTE=spybotsandra]Hello,

Quote:
In order to do so please right-click each in turn, then click "exclude this detection from future scans". That way, should any other part of security center settings change, Spybot-S&D will still detect those.

I have a problem, the contextual menu does not allow this modification. The line in is dimmed (not selectable).

Thanks.
Best regards

Last edited by loctet; 2005-10-29 at 11:17.
loctet is offline   Reply With Quote
Old 2005-10-29, 15:45   #5
md usa spybot fan
Spybot Advisor Team
 
md usa spybot fan's Avatar
 
Join Date: Oct 2005
Posts: 5,879
Default

If you want to exclude the item from future detections:
  • Expand the detection if necessary (+ to the left of the detection).
  • Select the item (entry) that you want to exclude by left clicking on it to highlight it.
  • Then right click on highlighted detection.
  • Select from the list of options in the menu.
In other words left click to select then right click to display options. If you don't select (highlight) the item first the options menu is for the entire detection list.
__________________

Getting an answer is one thing, learning is another.


Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.
md usa spybot fan is offline   Reply With Quote
Old 2005-10-29, 18:31   #6
nickW
Translator Team
 
nickW's Avatar
 
Join Date: Oct 2005
Location: France
Posts: 151
Default

Bonjour loctet,

Il faut être en "Mode avancé" pour pouvoir effectuer cette manip.

Voir en haut, dans le menu Mode.

Salut.
__________________
nickW, traductrice de Spybot-S&D en français
Membre de l'ASAP
Assiste.com
Forum d'Assiste.com
nickW is offline   Reply With Quote
Old 2005-10-29, 19:02   #7
md usa spybot fan
Spybot Advisor Team
 
md usa spybot fan's Avatar
 
Join Date: Oct 2005
Posts: 5,879
Default

NickW:

I do not believe that you are correct. There is a difference between:
  • "Exclude this detection from further searches"
    and
  • "Exclude this product from further searches"
spybotsandra's original suggestion was to:

Quote:
Originally Posted by spybotsandra
… exclude those detections from further scans.
In order to do so please right-click each in turn, then click "exclude this detection from future scans".
To the best of my knowledge you can only "Exclude this detection from further searches" after you "Check for problems" and the detection is listed on the problem detection screen.

You can exclude "products" (or un-exclude them) by going into Spybot > Mode > Advanced mode > Settings > Ignore products.

If you have excluded a single detection you can remove it from the ignore list by going into Spybot > Mode > Advanced mode > Settings > Ignore single entries.
__________________

Getting an answer is one thing, learning is another.


Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.
md usa spybot fan is offline   Reply With Quote
Old 2005-10-30, 23:06   #8
loctet
Junior Member
 
Join Date: Oct 2005
Location: Hérault- FRANCE
Posts: 2
Default Hi nickW

Effectivement je ne suis pas en mode avancé.
Merci de votre réponse et pour l'adresse du forum.
Salut.
loctet is offline   Reply With Quote
Old 2005-11-11, 10:46   #9
EloquentBaboon
Junior Member
 
Join Date: Nov 2005
Posts: 1
Default Help!!

I received the same notification and asked spybot to fix it along with 4 instances of RealDownloadExpress --- now i'm having issues. If my machine idles too long, it locks up. Also sometimes the screen-saver is interrupted for no apparent reason. A friend of mine says it sounds like i've inadvertently deleted some registry files. Asked S&D to recover, the RealDownloadExpress came back, but not the Windows Security Centre Firewall\Disable Notify.

Can anyone tell me/speculate on what's going on here and what i can do to fix it?

Thanks very much in advance
EQB



Quote:
Originally Posted by debanks
Spyboot keeps finding two suspicious and recuring files. Windows Security Centre Firewall\Disable Notify. There is a similar one for Firewall. These files are in Settings HKEY_LOCAL_MACHINE\Software\Microsoft\SecurutyCentre\Antivirus disable Notify!=dwordO.
I delete them but they recur. In windows security centre everything is switched on. I'm running McAfee Firewall and anti Virus plus AGV free anti virus on XP Home. My questions are : Are these files dangerous, what do they mean and how can I stop them recuring.

I did have a Bagle worm that slipped through undetected.

Derek Banks
EloquentBaboon is offline   Reply With Quote
Old 2005-11-11, 20:32   #10
Dragonphish
Junior Member
 
Join Date: Nov 2005
Location: Long Island NY USA
Posts: 1
Wink Windows Security Issues

The detections for Windows Security Virus scan and Firewall issues were easily verified and excluded per the instructions previously listed in this thread. Thanks to all who contributed.
Dragonphish is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 23:52.


Copyright © 2000-2009 Safer Networking Limited. All rights reserved.