PDA

View Full Version : [Solved] A new bug probably



dj.turkmaster
2007-07-28, 01:28
I dont know if this is a problem with the program or with me but i wanted to report it anyway. i have allowed a new registry change and i clicked on the remember my decision button but now i wanted to deny it so i opened the settings section from the teatimer icon in the system tray and i clicked on the "x" symbol of the registry changes which i wanted to deny and then i also unticked the use whitelists button but when i start using the application with the registry keys i mentioned it says registry change allowed based on your whitelist.
these are the keys: 7/28/2007 01:01:43 Allowed (based on user whitelist) value "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" (new data: "") added in Internet Explorer searches!
7/28/2007 01:01:44 Allowed (based on user whitelist) value "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (new data: "") deleted in Internet Explorer searches!
7/28/2007 01:03:38 Allowed (based on user whitelist) value "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (new data: "") added in Internet Explorer searches!
7/28/2007 01:03:38 Allowed (based on user whitelist) value "{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}" (new data: "") deleted in Internet Explorer searches!

PepiMK
2007-07-29, 19:49
Please check "C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Excludes\RegWhite.sbs"

The whitelist option in the popup menu of the tray icon is only about an integrated whitelist for other security apps, and does NOT affect the user whitelists. You need to remove those entries from the user whitelist :)

dj.turkmaster
2007-07-30, 00:24
Please check "C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Excludes\RegWhite.sbs"

The whitelist option in the popup menu of the tray icon is only about an integrated whitelist for other security apps, and does NOT affect the user whitelists. You need to remove those entries from the user whitelist :)

i clicked on the file you said and spybot main menu opened :) what shall i do with it:oops: by the way as i said i have removed those entries from the user whitlis. i mean i clicked on the settings menu from the tray icon and then the black & white list opened and the i clicked on the "x" icon of those two registry keys i mean i removed them from the allowed registry changes menu. but when i open internet explorer it allows those registry keys itself. it doesn't ask me :)

dj.turkmaster
2007-07-30, 15:17
I help people about their problems with spybot in a turkish security forum doctus.net and a user has experienced a problem like this too. this is what he said:

There is a malicious program which starts in user startup GETPLUSd.INF. i close teatimer and do a system scan with ccleaner and remove the malicious program from startup but when i activate teatimer again it says user blacklisted and the program cannot be removed from startup.
i told him to open the settings from the system tray and remove the registry key from the blocked registry changes by clicking on the "x" icon.
than he told me that he did what i said but he gets the blacklisted message again and when he looks at the settings menu spybot has added the registry key again to the blocked registry changes section.

are we doing something wrong or is there a bug?

dj.turkmaster
2007-07-31, 23:58
hello? can anybody help me pls? :)

dj.turkmaster
2007-08-03, 17:11
team spybot can you post an advice or sth pls? maybe it can be a bug or i may be doing sth wrong. either way i need your help. cmon

tashi
2007-08-03, 21:05
Hello dj.turkmaster, I will make a note for the team. Sorry for the delay, but people are a little busy at the moment.

Someone will get back to you when they can. :)

tashi
2007-08-03, 21:17
Also, is the path for GETPLUSd.INF "C:\WINDOWS\inf\GETPLUSd.INF"?

If you can find the files/s for GETPLUSd.INF, please zip and send to: detections(AT)spybot.info (Replace AT with @)

Thanks.

dj.turkmaster
2007-08-04, 00:45
Also, is the path for GETPLUSd.INF "C:\WINDOWS\inf\GETPLUSd.INF"?

If you can find the files/s for GETPLUSd.INF, please zip and send to: detections(AT)spybot.info (Replace AT with @)

Thanks.

thank you for your reply but there is no file named like that. i've looked in the hidden directories also

dj.turkmaster
2007-08-08, 12:17
hello.
the problem still continues. any helps, comments?

PepiMK
2007-08-08, 18:04
i clicked on the file you said and spybot main menu opened :) what shall i do with it:oops:

While TeaTimer is closed, try to delete RegWhite.sbs, RegBlack.sbs and if you want, also ProcWhite.sbs and ProcBlack.sbs. Then restart TeaTimer and see what happens.

Or even better, check the access rights to these files. Are they maybe writable only by specific users? When Spybot-S&D is run on an admin account, it makes this folder writable to all users, but if you install and use it as a power user only, other users might have problems (until you run it as an admin once).

Buster
2007-08-08, 19:16
Please open the RegKeyWhite.sbe (usually located at systemdrive\documents and settings\all users\application data\spybot - search & destroy\excludes) with notepad or any other editor after you have deleted the entry from the black and white list. Does the sbe still contain the entry you tried to delete via the black and white list. If so, please make sure you hit the right button, because on the settings page the "cancel / ok" buttons are "accidentally" switched.

dj.turkmaster
2007-08-09, 00:47
hello the problem has resolved by itself :) i did the same things again removed the entries fromthe allow list and this time it asked me if it should allow or deny. interesting because i was doing the same thing every time and this time it worked. i am so happy :)