PDA

View Full Version : spybots quits



200spy
2007-04-30, 17:02
The program always worked on this machine but since the last update it does not if I uninstall and reinstall and update without the new advcheck.dll it works.

The problem is it just quits in the middle of a scan.
If I update advcheck.dll it quits in the malware.sbi ( DyFUCA)
If I exclude malware.sbi It will finish.

I tried safe mode and many other spyware programs hijackthis etc.
Virus programs ( kaspersky, Avira etc.)

I cant find anything

Any ideas ?

xp sp2 all the updates, Kaspersky Internet


:spider:

200spy
2007-04-30, 17:32
I must also add:


it does sometimes , like stated in one of the others thread, automatically user aborts.
:sad:

Argus
2007-05-01, 06:15
No ideas, but it sounds similar to what I get (http://forums.spybot.info/showthread.php?t=13342).
The first time I thought it was related to DEP, as I found that message saying that windows had shut down spybot "to protect my computer", but putting spybot in the DEP ignore list and rebooting has made no difference.

I have yet to try in safe mode, as suggested by Spybotsandra, but will do so soon.

I have never had this, or the user abort thing happen before, when I scanned last week spybot worked just fine. :sad:

200spy
2007-05-05, 23:00
FYI

Problem fixed !


Used sysinternal filemon to monitor file SpybotSD.exe actvity.
Found that the last file is the one causing the crash is qfecheck.exe
witch is an M$ xp sp1 file ( Q 282784) to verify the installed fixes.
Renaming that file stops the problem ( removed file ext.).

16:47:18 SpybotSD.exe:1520 SET INFORMATION C:\WINDOWS\system32\drivers\fidbox.dat SUCCESS Position: 3262844
16:47:18 SpybotSD.exe:1520 CLOSE C:\WINDOWS\ SUCCESS
16:47:18 SpybotSD.exe:1520 OPEN C:\WINDOWS\qfecheck.exe SUCCESS Options: Open Access: All
16:47:18 SpybotSD.exe:1520 QUERY INFORMATION C:\WINDOWS\qfecheck.exe SUCCESS Length: 48944
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\qfecheck.exe SUCCESS Offset: 0 Length: 2
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\qfecheck.exe SUCCESS Offset: 60 Length: 4
16:47:18 SpybotSD.exe:1520 QUERY INFORMATION C:\WINDOWS\qfecheck.exe SUCCESS Length: 48944
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\qfecheck.exe SUCCESS Offset: 200 Length: 4
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\qfecheck.exe SUCCESS Offset: 352 Length: 4
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\qfecheck.exe SUCCESS Offset: 356 Length: 4
16:47:18 SpybotSD.exe:1520 QUERY INFORMATION C:\WINDOWS\qfecheck.exe SUCCESS Length: 48944
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\qfecheck.exe SUCCESS Offset: 42256 Length: 6688
16:47:18 SpybotSD.exe:1520 READ C:\WINDOWS\system32\ntdll.dll SUCCESS Offset: 316416 Length: 4096
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03 SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\Program Files\Spybot - Search & Destroy\ SUCCESS
16:47:19 SpybotSD.exe:1520 OPEN C:\Program Files\Spybot - Search & Destroy SUCCESS Options: Open Access: 00000000
16:47:19 SpybotSD.exe:1520 SET INFORMATION C:\WINDOWS\system32\drivers\fidbox.dat SUCCESS Position: 3905332
16:47:19 SpybotSD.exe:1520 CLOSE C:\Program Files\Spybot - Search & Destroy SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\system32\EXE2BIN.EXE SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\system32\NLSFUNC.EXE SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\TWUNK_16.EXE SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\Documents and Settings\TRIUMPH\Local Settings\Temporary Internet Files\Content.IE5\index.dat SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\Documents and Settings\TRIUMPH\Cookies\index.dat SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\Documents and Settings\TRIUMPH\Local Settings\History\History.IE5\index.dat SUCCESS
16:47:19 SpybotSD.exe:1520 CLOSE C:\WINDOWS\qfecheck.exe SUCCESS


:bigthumb: :D:

chi-va
2007-05-06, 01:30
Hello,

Good work!:bigthumb:

With your help our detectives should be able to fix this very soon.

Peter Pan
2007-05-06, 13:00
Hi,

I encoutered the same issue: since its last update, SpyBot S&D quit near the end of a scan, in ZQest.K8L search. After reading the prost of 200spy, I Proceeded by trial and error and so I identified that search of several types of products caused the unrelevant ending: dialers.sbi, malware.sbi, malwareC.sbi, spybots.sbi, spybotsC.sbi.

Differently from 200spy, unselecting only malware.sbi and/or renaming qfecheck.exe (located in \windows\system32 rather than \windows on my PC) didn't solve the problem. But replacing new version of advcheck.dll by the pevious one did!

Now Spybot S&B seems to work fine with previous version of advcheck.dll

Thanks again :)

200spy
2007-05-06, 15:04
Hi,

I encoutered the same issue: since its last update, SpyBot S&D quit near the end of a scan, in ZQest.K8L search. After reading the prost of 200spy, I Proceeded by trial and error and so I identified that search of several types of products caused the unrelevant ending: dialers.sbi, malware.sbi, malwareC.sbi, spybots.sbi, spybotsC.sbi.

Differently from 200spy, unselecting only malware.sbi and/or renaming qfecheck.exe (located in \windows\system32 rather than \windows on my PC) didn't solve the problem. But replacing new version of advcheck.dll by the pevious one did!

Now Spybot S&B seems to work fine with previous version of advcheck.dll

Thanks again :)

:fear:

Removing qfecheck.exe still works for me but may not be the solution for
you.

I would suggest you try filemon.exe if you have the problem again
http://www.microsoft.com/technet/sysinternals/fileanddiskutilities.mspx

It's a simple program all you have to do is use the filter
include SpybotSD.exe for the search and let it run and then start SpybotSD.exe , when it stops you will have a log of the activity and could find out where it gets stuck.

I am not too sure that going back to a previous version of advcheck.dll
is any good . That's why I have investigated further.

I don't know how SpybotSD.exe works but it could be detecting a file related to qfecheck.exe on my computer

:cool:

200spy
2007-05-06, 15:27
Be carefull.
I removed the exe part of qfecheck.exe. If you simply rename it, let say abc.exe
spybot may pick it up again as an executable file and block you again
:laugh:

Peter Pan
2007-05-27, 05:01
Hi,

for 200spy, I did rename the file by deleting its exe extension but this workaround didn't solve the problem for me.

Till today, I was running previous version of advcheck.dll and it seemed to work fine. I just checked by replacing the DLL with its current version (1.5.2) and the issue appeared again!
So I go back to version 1.5.1 as it works.

Hey support team, any comment or solution?

Best regards

chi-va
2007-05-29, 11:50
Which Windows version do you use?

Please take a look here:
http://forums.spybot.info/showthread.php?t=14007

Try the suggestion from md usa spybot fan and replace your advcheck.dll.

Argus
2007-05-29, 15:26
using the advcheck.dll in teh beta "advanced detection updates", as suggested in the thread you linked to hasn't helped for me :sad:

chi-va
2007-05-29, 19:05
@Argus

I'm sorry!:sad: This was a suggestion for Peter Pan. Your problem is different. Please use filemon and poste your report in our forum.
www.microsoft.com/technet/sysinternals/FileAndDisk/Filemon.mspx

Apart from that, please add a screen shot of the error message or tell us the exact error message.

Argus
2007-05-30, 03:13
Hi, I don't get any error messages, but spybot just disappears just before completion of a scan. it gets up tyo about 63,889, and then vanishes.
Nothing appears in event viewer, or anywhere that I can find.
I haven't been able to complete a scan with spybot for quite some time now.

I originally posted about this here (http://forums.spybot.info/showthread.php?t=13342), but the issue was confused by numerous FP's which it seems were caused by corruption of spybots' / spyware blasters' immunizations.

The FP's are all gone, but I'm left with a disappearing spybot.

Ok, I'm, now scanning with spybot, with filemon running, will post results.

Argus
2007-05-30, 03:34
Hi, I can't attach the full log, even zipped it comes out as over 2 mb, the forum won't accept it. I put the last 10 or so lines in the attachment, if you pm me with an email address, I can send teh whole thing if you need it.
the last file scanned

497235 11:18:36 AM SpybotSD.exe:864 CLOSE C:\My Documents\Downloads\Setups\dxwebsetup.exe SUCCESS

which is where spybot vanished.

Normally it doesn't make it that far thru the scan, as I mentioned before, it usually crashes at 63,889 (video access activex object), this time it made it thru to at least 65,000. I don't know for sure, I was watching filemon.

chi-va
2007-05-30, 14:12
We are getting closer. It seems that you have added folders in "Settings->Directories". Is this correct?

If yes, please try this:

1. Deactivate the file set "Trojans.sbi" in "Settings->File set" and try to scan.

2. Activate the file set again, remove the download folders and try to scan again.

3. Now a scan test without "Trojan.sbi" and without the added download folders.

Please poste us the results.

Argus
2007-05-31, 01:56
Hi Chi-Va, and thanks :-)

Yes, I did have several directories in settings -> directories

results:
1) crashes as usual

2) scan completed!!! :bigthumb:

3) didn;'t do, as 2) worked. I can do if you feel there's any need to, or it would help at all.

Many thanks, argus

Peter Pan
2007-06-01, 08:01
Which Windows version do you use?

Please take a look here:
http://forums.spybot.info/showthread.php?t=14007

Try the suggestion from md usa spybot fan and replace your advcheck.dll.

I'm running WXP SP2.

As I mentioned in reply to "md usa spybot fan", replacing to DLL solved the problem. Please note after download of the beta version, Spybot SD didn't terminate and restart by itselft. I had to quit and restart the program by myself (but I didn't care!)

Thanks a lot for your help and efficiency.

Best regards