PDA

View Full Version : MS Windows 2003 Server and SD



ruwanr
2008-02-08, 04:41
Hi,

I was using Spybot search and Destroy 1.4 on MS Windows Server 2003 machine.
After a malware signature update on 08/02/2008 it detected the following threat.

SB S&D Checks log:
07.02.2008 08:27:53 - found: CoolWWWSearch.Tapicfg Executable.

It was then 'fixed' by SpyBot Search and Destroy.

SB S&D fixes Log:
Report generated : 2008-02-07 10:33
CoolWWWSearch.Tapicfg: Executable (file,fixed)
c:\windows\system32\tapicfg.exe

But upon re-scan the same threat was detected.

Following Event was Logged.

Microsoft Event Log:
Event type: Information
Event source : Windows file protection
Event category:none
Event ID: 64002
Date: 2/7/2008
Time:10:33:42 AM
User : N/A
Description:
File replacement was attempted on the protected system file c:\windows\system32\tapicfg.exe.
This file was restored to the original version to maintain system stability.The file version of the system file is 5.2.3790.0.
For more information , see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.


SD Resident was configured in such a way to deny subsequent modifications made to the windows registry (addition of a start up item to check the integrity of windows system files - "UserFaultCheck") due to this 'Fixing'

SD Resident Log entry :
Timestamp: 02/07/2008 - 10:38:10 AM
Description: Denied value "UserFaultCheck" (new data: "%systemroot%\system32\dumprep 0 -u") added in System Startup global entry!

SD was then updated to version 1.5.2.20. and malware signatures were updated as at 02/06/2008.

But the same problem persists.

Your good advice is needed on the above issue.
An early reply is very much appreciated.

Thanks in advance.

Ruwan

Yodama
2008-02-08, 07:41
thank you for reporting this issue,

it is a false positive. If it shows up on the next scan please right click this result and set Spybot S&D to ignore it from further scans. A fix for the detection rules will be released with the next update.

ruwanr
2008-02-08, 12:34
Hi Yodama,

Thanks for the quick reply.
I will do the needful as advised by you.

What do you mean by threat descriptions in the
Poll: Do you read the threat descriptions included in Spybot?

Well your forum site is as impressive as most of the ICT forums I for which I have subscribed to. It is very user friendly and provides easy navigation. Keep up the good work.

just_Mario
2008-02-09, 20:52
thank you for reporting this issue,

it is a false positive. If it shows up on the next scan please right click this result and set Spybot S&D to ignore it from further scans. A fix for the detection rules will be released with the next update.

Hi,
I am new her and have read this post.
As it seems, Spybot threats this executable as a problem.
On many fora this application is called a Troyan among others.
When a Internet Explorer is used, it should redirect to another website or cause the system to slow down.
Currently I have not noticed this kind of events so far.
However, Spybot found the application as being a threat.
What do I do with it then, just ignore it?
What is it actually and how dangerous is it and how do we get rid of it?
Got already the latest update today.