md usa spybot fan
2007-05-09, 17:06
I am running ZoneAlarm firewall and received the following detections using the 2007-05-09 Includes\Beta.sbi.
__________________
Checks.070509-0923.log
--- Report generated: 2007-05-09 09:23 ---
Microsoft.WindowsSecurityCenter.FirewallDisabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall!=dword:1
Microsoft.WindowsSecurityCenter.FirewallDisabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall!=dword:1
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2006-05-01 TeaTimer.exe (1.4.0.2)
2006-01-16 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-04-18 advcheck.dll (1.5.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-05-09 Includes\Beta.sbi (*)
2005-02-16 Includes\Beta.uti
2007-05-09 Includes\Cookies.sbi
2006-12-08 Includes\Dialer.sbi
2007-05-09 Includes\DialerC.sbi
2007-04-04 Includes\Hijackers.sbi
2007-05-09 Includes\HijackersC.sbi
2006-10-27 Includes\Keyloggers.sbi
2007-05-09 Includes\KeyloggersC.sbi
2007-03-21 Includes\Malware.sbi
2007-05-09 Includes\MalwareC.sbi
2007-03-21 Includes\PUPS.sbi
2007-05-09 Includes\PUPSC.sbi
2007-05-09 Includes\Revision.sbi
2006-12-08 Includes\Security.sbi
2007-05-09 Includes\SecurityC.sbi
2007-03-21 Includes\Spybots.sbi
2007-05-09 Includes\SpybotsC.sbi
2005-02-17 Includes\Tracks.uti
2007-05-02 Includes\Trojans.sbi
2007-05-09 Includes\TrojansC.sbi
__________________
Registry entries:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000000
__________________
Checks.070509-0923.log
--- Report generated: 2007-05-09 09:23 ---
Microsoft.WindowsSecurityCenter.FirewallDisabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall!=dword:1
Microsoft.WindowsSecurityCenter.FirewallDisabled: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall!=dword:1
--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2006-05-01 TeaTimer.exe (1.4.0.2)
2006-01-16 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-04-18 advcheck.dll (1.5.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-05-09 Includes\Beta.sbi (*)
2005-02-16 Includes\Beta.uti
2007-05-09 Includes\Cookies.sbi
2006-12-08 Includes\Dialer.sbi
2007-05-09 Includes\DialerC.sbi
2007-04-04 Includes\Hijackers.sbi
2007-05-09 Includes\HijackersC.sbi
2006-10-27 Includes\Keyloggers.sbi
2007-05-09 Includes\KeyloggersC.sbi
2007-03-21 Includes\Malware.sbi
2007-05-09 Includes\MalwareC.sbi
2007-03-21 Includes\PUPS.sbi
2007-05-09 Includes\PUPSC.sbi
2007-05-09 Includes\Revision.sbi
2006-12-08 Includes\Security.sbi
2007-05-09 Includes\SecurityC.sbi
2007-03-21 Includes\Spybots.sbi
2007-05-09 Includes\SpybotsC.sbi
2005-02-17 Includes\Tracks.uti
2007-05-02 Includes\Trojans.sbi
2007-05-09 Includes\TrojansC.sbi
__________________
Registry entries:
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=dword:00000000