PDA

View Full Version : Don't know how to analyze a deny or allow entry



shorty45
2008-05-24, 21:15
This is my first post, please excuse if not in the correct forum.

On start up I am getting messages from TeaTime to allow or deny a couple of changes. Since it has been coming at a time that I'm not actively surfing the net or have added any new programs, I am denying the changes. But, every start up I get the same messages. I have not checked the box to remember this entry as I wasn't sure if I was doing the correct thing or not.

My only background information is that my son was surfing the web when spybot notified him to deny or accept a start page change. I told him to deny the change.

A day or two later on windows start up, we recieved the black screen concerning a problem and started with the best known configuration. From that point on at every start up we receive a message to deny or accept a BootExecute in Session Manger. We always deny and then get another message concering ExcludeFromKnownDlls. We deny that also.

I will print a portion of the log immediately before and then a few afterwards to see if I am making any sense.

5/16/2008 6:28:52 PM Denied (based on user decision) value "First Home Page" (new data: "http://go.microsoft.com/fwlink/?LinkId=54843") added in Browser page!
5/17/2008 3:36:22 PM Allowed (based on user decision) value "{DE625294-70E6-45ED-B895-CFFA13AEB044}" (new data: "") added in ActiveX Distribution Unit!
5/18/2008 1:17:22 PM Denied (based on user decision) value "BootExecute" (new data: "") deleted in Session manager!
5/18/2008 1:23:28 PM Denied (based on user decision) value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
5/18/2008 1:35:16 PM Denied (based on user decision) value "BootExecute" (new data: "") deleted in Session manager!
5/18/2008 1:41:06 PM Denied (based on user decision) value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
5/18/2008 1:50:21 PM Denied (based on user decision) value "BootExecute" (new data: "") deleted in Session manager!
5/18/2008 1:50:44 PM Denied (based on user decision) value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!

Can you help?

Thank you.

spybotsandra
2008-05-26, 18:49
Hello,

Please read this information about TeaTimer:
http://www.safer-networking.org/en/faq/33.html
and http://www.safer-networking.org/en/faq/34.html
If you surf the web and without any user interaction the teatimer pops up and warns about a registry change it is better to "deny", but if you install something by yourself it is OK to "allow" the change.
The tutorial (point 8) on our homepage should also help explaining:
http://www.safer-networking.org/en/tutorial/index.html

Best regards
Sandra
Team Spybot