PDA

View Full Version : Probem after d/l'ing updates today



firebrddriver
2008-04-09, 23:14
After I d/l'ed the updates today,(4/9) just before the scan is finished it stops and the following warning box appears,,

"There were problems in the include file C:/program files/spybot.search_destroy/includes/trojansC.sbi" See "includes errors.log" for details.

If I close the box the scan will finish. I tried to find the "error log" without any sucess. I had no problems until todays update.

Also,,using windows XP,,S&D version 1.4,,and ran a virus scan just to be sure

I just remembered something else,,the other day I installed "spy sweeper",,however I don't start it unless I want to scan the computer,,could this possibly be the cause,,I can un-install it if thats the case

md usa spybot fan
2008-04-09, 23:31
firebrddriver:

If you post the "... includes errors.log ...", it may help resolve the problem.

The "Include errors.log" can be found in one of the following folders:
Windows 95 or 98:
C:\Windows\Application Data\Spybot - Search & Destroy\Logs
Windows ME:
C:\Windows\All Users\Application Data\Spybot - Search & Destroy\Logs
Windows NT, 2000 or XP:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Logs
Windows Vista:
C:\ProgramData\Spybot - Search & Destroy\Logs
To post the "Include errors.log": Using Windows Explorer, navigate to the "Include errors.log". Double click on it and it should open with Notepad. To copy to the Clipboard > Right click and select Select All > Right click again and select Copy. Then paste (Ctrl+V) those results to a new post in this thread. Do the same thing with the "Include errors.log" file.

firebrddriver
2008-04-09, 23:38
This is what was in the includes errors,,

C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>

I acually scanned twice maybe thats why the entry is there two times,,is this the info you need??

firebrddriver
2008-04-10, 00:10
I don't mean to get ahead of you in anyway whatsoever,,but in doing a search of this problem I see this advice as part of the fix,,

Step # 1: Disable Teatimer

Spybot S&D's tea timer normally provides real-time protection from spyware, however it may interfere with what we need to do. We will disable it until the machine is clean when it can be re-enabled.

This is a two step process.
First step:
Right-click the Spybot Icon in the System Tray (looks like a blue/white calendar with a padlock symbol)


Now like I said I'm not trying to get ahead in any way,,matter of fact I'm not very good with computers and this is why I'm even posting this part,,but,,for the life of me I can't find the "spybot icon in the system tray",,as a matter of fact,,whats the system tray?,,I know I must sound like an idiot. I just don't want to bother you with that problem when the time comes for that part of the fix,,,,,thanks for understanding.

firebrddriver
2008-04-10, 20:45
Hi all,,I'm waiting to hear from an advisor for this problem,,but just wondering,,can anyone tell me what this will try to do to my computer til it gets removed? Would I be safe in going to any sites where I have to give sensitive info,,thanks,,Heres what I have,

Zlob.DNSChanger.rtk

Like I said I've already posted this problem on the forum in this thread and I'm not trying to get any faster help,,just don't want to do something to expose info.

"Probem after d/l'ing updates today"

md usa spybot fan
2008-04-10, 22:41
firebrddriver:


Hi all,,I'm waiting to hear from an advisor for this problem,,but just wondering,,can anyone tell me what this will try to do to my computer til it gets removed? ...
According to (Post #21 (http://forums.spybot.info/showpost.php?p=180875&postcount=21) and Post #22 (http://forums.spybot.info/showpost.php?p=181054&postcount=22)) in the following thread, if you upgrade to Spybot 1.5.2 the problem is resolved:
TrojansC.Sbi
http://forums.spybot.info/showthread.php?t=14869

firebrddriver
2008-04-10, 23:39
Thank you,,I have to go out but will try your suggestion later and let you know the outcome,,but was still wondering if its safe to do anything online that involves banking or the like til this is taken care of,,also,,I can just d/l the newer version without un-installing the older version,,correct ?

md usa spybot fan
2008-04-11, 06:47
firebrddriver:

The error in the scan should not affect your use of the internet.

I suggest that you uninstall the prior version before installing the new one or else you most likely will end up with two (2) add/remove entries (one for the old version and one for the new).

firebrddriver
2008-04-11, 07:44
Thanks,,other than un-installing from the control panel is there any other entries I should look for to delete,,or will a plain old uninstall be fine.

md usa spybot fan
2008-04-11, 09:27
firebrddriver:

Actually this is what I do and recommend:

To completely uninstall Spybot-S&D including any system registry entries or files that may have been altered while using various features of Spybot:
Go into Spybot > Immunize.
Click "Undo" button (at the top of the right pane).
Go into Spybot > Mode > Advanced Mode > Tools > Resident.
Uncheck (if checked) the following:
Resident "SDHelper" (Internet Explorer bad download blocker) active.
Resident "TeaTimer" (Protection of over-all system settings) active.

Go into Spybot > Mode > Advanced Mode > Tools > IE Tweaks.
Uncheck (if checked) any of the following "Miscellaneous locks":
Lock Hosts file read-only as protection against hijackers.
Lock IE start page setting against user changes (current user).
Lock IE control panel against opening from within IE (current user).

Go into Spybot > Mode > Advanced Mode > Tools > Hosts file
Click the "Remove Spybot S&D hosts list" button (at the top)
Exit Spybot-S&D
Make sure that TeaTimer is not running by checking for the TeaTimer System Tray Icon. If the icon is there:
Right click Spybot's TeaTimer System Tray Icon > click Exit Spybot-S&D Resident. TeaTimer should close.

Go to Windows > Control panel > Add or Remove Programs > Locate "Spybot – Search & Destroy 1.4" > Remove.
Using Windows explorer, verified that the following folder has been delete. If not, delete it:C:\Program Files\Spybot - Search & Destroy
Note: If you were running "SDHelper" you will have to exit all Internet Explorer sessions and may have to restart your system in order to delete the program folder.
If you want to make sure that all the registry entries that Spybot-S&D added during installation are removed, there is a .reg file available on the safer-networking.org WEB site that can do that (I recommend that you do this since some registry entries that were used in Soybot 1.4 are no longer used in Spybot 1.5). See the following article:
FAQ - Frequently Asked Questions
How to uninstall?
http://www.safer-networking.org/index.php?page=howto&detail=uninstall
The direct download link is:
this very small fix (http://www.safer-networking.org/files/remove-spybotsd-settings.reg)
--- or ---
remove-spybotsd-settings.reg (http://www.safer-networking.org/files/remove-spybotsd-settings.reg)
Download the file.
Double click on it
Answer Yes then OK

spybotsandra
2008-04-11, 12:02
Hello,

You seem to be using a dated version of Spybot-S&D.
Please download our current version Spybot - Search & Destroy 1.5.2. That should fix it.
You will find links to several download locations for this new version on our web site:
http://www.safer-networking.org/en/mirrors/index.html
Please search for new updates after installing Spybot-S&D 1.5.2.

Best regards
Sandra
Team Spybot

firebrddriver
2008-04-11, 19:23
Followed all instructions and everything seems to be working great,,thank you for all your help and for understanding that I'm not very technically savy as far as computers go,,I notice all your instructions to people are easy to follow and to understand,,again thank you. One further question if I may ask,,,and I looked in the help section of S&D and read the turtorial on this subject but I'm just a little confused but,,what does "immunizing" do in lay terms,,,thanks for all your help and hope I don't have to bother you any time soon.

Bill

md usa spybot fan
2008-04-11, 22:14
Bill:


... what does "immunizing" do in lay terms...
Breafly:

Immunization in Spybot 1.5.

The immunization process adds entries to the system registry and/or files to either restrict certain things that a site (domain) you are accessing through your browser is allowed to do or blocks access to the that site (domain) entirely.

The items listed under "Internet Explorer (32 bit) " and "Internet Explorer (32/64 bit) " add entries to the system registry.
Items listed as "... (Cookies)" block the storing of cookies from certain sites.
Items listed as "... (Domains)" and "... (IPs)" add sites to the restricted sites zone. "... (Domains)" are added to the restricted sites zone by domain name.
"... (IPs)" are added to the restricted sites zone by IP Address. Adding sites to the restricted zone blocks their ability to store cookies, download ActiveX processes as well as placing other restrictions on those sites depending on your settings for restricted zone sites within Internet Explorer.

Items listed as "... (Plugins)" block the download/execution of specific ActiveX processes.
The items listed under Mozilla products such as "Firefox" add entries to Mozilla's hostperm.1 file.
Items listed as "... (Cookies)" prohibit sites from storing cookies.
Items listed as "... (Images)" prohibit sites from displaying images.
Items listed as "... (Installations)" prohibit sites from initiating extensions installations.
Items listed as "... (Popups)" prohibit sites from opening popup windows.
The item listed under "System" adds entries to the system's HOSTS file.
Item listed as "Global (Hosts)" adds entries to the system HOSTS file, equating site names (domain names) to the localhost (your system), affectively blocking access to those sites.

firebrddriver
2008-04-11, 23:58
I have one final question,,with the older version of S&D I had to manually start it,,the newer version starts as I'm booting up,,if i didn't want the new version to start could I just go into msconfig and uncheck the tea timer???

md usa spybot fan
2008-04-12, 17:04
firebrddriver:


I have one final question,,with the older version of S&D I had to manually start it,,the newer version starts as I'm booting up,,if i didn't want the new version to start could I just go into msconfig and uncheck the tea timer???
Yes you could but there is facility within Spybot to do that. To disable TeaTimer:
Go into Spybot > Mode > Advanced Mode > Tools > Resident.
Uncheck the following:Resident "TeaTimer" (Protection of over-all system settings) Active.

firebrddriver
2008-04-12, 22:55
So in other words if I disable teatimer within the advanced mode,,instead of in msconfig,,S&D will not start when I boot up,,is that correct??,,but,,,if I leave the settings as they are,,with S&D running from the get go,,(boot up) do I have "real time " protection,,the same as say you have with an anti virus program? One very last question,,,how often should you immunize,,or is that a one time only thing when you install S&D,,,,,again thanks for all your help in dealing with a computer challenged person like me. Everyone on the advisory team is tops!!

firebrddriver
2008-04-12, 23:32
Boy everytime I think I've asked my last question I come up with a new one,hopefully this will be the last,,when I up-date I notice I have to check off,,,"English taget descriptions" and "English help file",,,did I forget to do something in the install process,,or is this built into S&D where you have to check it off manually,,I guess theres no way it could be d/l'ed automatically with the other up-dates,,,its no big thing,,I was just wondering if I had the chance to select that option when I did the install and didn't pick it,,,thanks.

md usa spybot fan
2008-04-13, 06:29
Firebrddriver:


So in other words if I disable teatimer within the advanced mode,,instead of in msconfig,,S&D will not start when I boot up,,is that correct?? …
That is correct.


… but,,,if I leave the settings as they are,,with S&D running from the get go,,(boot up) do I have "real time " protection,,the same as say you have with an anti virus program? …
If you leave that setting alone, TeaTimer will start when you logon. TeaTimer is not really that same as an anti-virus program, but you essentially have real time protection.


… One very last question,,,how often should you immunize,,or is that a one time only thing when you install S&D. …
You should immunize each time you update.


… when I up-date I notice I have to check off,,,"English taget descriptions" and "English help file",,,did I forget to do something in the install process,,or is this built into S&D where you have to check it off manually,,I guess theres no way it could be d/l'ed automatically with the other up-dates,,,its no big thing,,I was just wondering if I had the chance to select that option when I did the install and didn't pick it,,,thanks.
Not all updates items are checked by default and there is no option during the installation that controls that. The development team determines which update items are checked when they set up the control file for the updates.

firebrddriver
2008-04-13, 23:14
I'm finished in this thread if you want to archive it,,or whatever you do with threads that ended,,,thanks again!!!