PDA

View Full Version : "Windows Security center disable"



kingofdeathmatch
2007-04-03, 15:36
Hi there. i was just wondering if anyone else ran into this piece of spyware, the "Windows security center disable". S&D finds it, fixes it, but it always comes back. I know that it is in the registry, im just wondering if anyone knows a way out?? cheers for any help.

spybotsandra
2007-04-03, 16:41
Hello,

Spybot - Search & Destroy 1.4 has been detecting Security Risks (renamed to "Windows Security Center" on July 30) associated with Microsoft Security Center Registry changes. This is neither a false positive nor a bug. It is just an information.
Spybot-S&D only wants to bring to your attention that "someone" disabled one or more notifications in the Windows Security Center, e.g. the notifications that your virus protection is not active or not up-to-date. If you changed the settings yourself you can safely tell Spybot-S&D to exclude those detections from further scans.
In order to do so please right-click each in turn, then click "exclude this detection from future scans". That way, should any other part of security center settings change, Spybot-S&D will still detect those.
The same is true if you have another security solution installed (like McAfee Security Center or Norton Internet Security). These programs do also disable the Windows Security Center in order to take care of things themselves.
The reason why the changes are flagged by Spybot-S&D is that there are also malware programs that disable the notifications so the user doesn't take note of his security tools not being effective.

Some more information is also available in our forum:
http://forums.spybot.info/showthread.php?t=87

Best regards
Sandra
Team Spybot

kingofdeathmatch
2007-04-03, 19:13
cheers for that!

Tarheel72
2007-04-13, 19:25
I have a similar problem but I think it is related to a worm. Whenever I let SpyBot delete the entries, or even when I do it manually, they always come back. Even if deleted in safe mode. Whenever I try to download updates from MS, it fails. I also was not able to use the internet based scan at TrendMicro. It will scan and detects items, but then when I tell it to delete them, it fails and locks up. The machine has SP1 and I am trying to download SP2. First, I have to manually delete the registy keys. Then I set the Automatic Updates to "on". I have to keep the registry edit open or it will recreate the AU folder in both the HKLM and HKCU folders.

I let MS update check my machine and then it starts searching for updates. After about 10 minutes I get a message in the viewing screen of the webpage that it is unable to access the webpage.

SOmethign is playing around with my IE settings. I have trouble loading pages from sites that are security related, but not others. Sometimes when I hit a link on a webpage instead of opening the new page it acts like it is the only page open. It starts it up in a new window and immediately closes the old window, preventing me from navigating back to the previous page. So if something locks up I can not go back and try again, I have to close the program and start all over.

I am not running Norton or anything else, even SpyBot, to monitor for infections. I used to use SpyBot Teatimer but I turned it off to do the scans and updates. The older version of Windows security (the one they got from Giant) was on there, but it has been shut down for some time since they quit supporting it and providing updates. You say some programs would over ride the microsoft autoupdate settings. Which ones and how do you disable that permenately? thanks