View Full Version : Immunization problems - help of affected users desired

2007-12-21, 16:45
Ok, Yodama tried to ask for some information, I'll try to rewrite this in an understandable manner. If instructions are still unclear, please let me know and I'll update this :)

We're looking for help in trying to determine the exact source of this problem, and since it is not reproducable on any of our tests system, nor with reproducing all security software configurations named so far (assuming one of the later would block anything), we're asking for your help:
Make a screenshot of the incomplete immunization (press Alt + PrtScr (PrintScreen) key while the Spybot-S&D immunization window is shown).
Open Paint, paste the screenshot (Edit menu), and save it as immunization-bug-061.png or similar.
Start regedit (from your Start menu, choose Run, type in regedit.exe, then press OK).
In the left part of regedit, you'll see a tree-like structure. Look up the incomplete parts only (see your screenshot) in the attached table, and navigate to the key path named there (the [key]\[key] in that list represents a separation in tree layers).
Once you found the last tree leaf from this key path, right-click it, and select Export.
Click here (http://www.safer-networking.org/images/screenshots/bug061-export.png) for a screenshot if you are unsure about steps 4 and 5.
Save this under a name that represents the actual name (e.g. ie-3264-default-ips.reg).
Send the screenshot image and these .reg files by email to http://forums.spybot.info/misc.php?do=email_dev&email=ZGV0ZWN0aW9uc0BzcHlib3QuaW5mbw==, using the subject "Bug 061".
.And now, the table referred to above:

Internet Explorer (32 bit)
Software (Plugins)
Please export this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\ Internet Explorer (32 bit) on a 64 bit OS
\Software (Cookies)
Please export this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History
\Software (Domains)
Please export this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
\Software (IPs)
Please export this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges
\Software (Plugin)
Please export this key:
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility Internet Explorer (32 bit/64 bit)
.Default (Cookies)
Please export this key:
KEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\
.Default (Domains)
Please export this key:
KEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zonemap\Domains
.Default (IPs)
Please export this key:
KEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\
UserName/Usernumber (Cookies)
Please export this key:
KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History
UserName/Usernumber (Domains)
Please export this key:
KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zonemap\Domains
UserName/Usernumber (IPs)
Please export this key:
KEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\

2007-12-21, 16:53
the guide seems good and understandable, by me at least :)

2007-12-21, 21:10
is when your host file is locked by zonealarm or spybot itself through advanced settings in spybot, spybot cannot immunize the host file so it shows unprotected on some numbers there. However, and easy fix is to temporary unlock your host file with those programs, immunize, and then relock it. Other then that, i have not experienced any immunization probs.

2007-12-24, 13:03
The only issue I have had is that after Norton 360 completes a scan, I have to re-immunize. Appears that Norton has picked a certain host file (or version of host file) to protect / restore.

Once I click the immunize button, the file is fixed until the next scan by Norton 360. This is most likely being done by the Network Address Security Scan as Norton 360 results state that it fixed the Windows Host File...


Regards and Happy Holidays from Texas,


2007-12-27, 17:31
Issue 061 has been fixed, Yodama tracked it down to an "incompatibility" with another security software... one that removes immunization for a bunch of products :fear:
Yes, that's right, a legit anti-spyware application actively removes immunization for WhenU, UCmore, HotBar and New.Net. Ok, some of these are on the border between good and bad, but just silently removing immunization against them is a bit too "efficient" maybe :fear: