PDA

View Full Version : Spybot Questions



clw2613
2009-01-17, 16:51
A couple of SPYBOT questions please. Being new here, if the questions/answers have already been posted, kindly direct me to their locations.

I am using version 1.6.0.26 of SPYBOT on a Windows XP machine. When running, the SPYBOT status bar currently indicates that there are 369882 individual scans to be run. This process currently takes 30 minutes or more to complete and uses 96%+ of CPU time, making other applications either unusable or very slow as long as the SPYBOT scans are running.

The questions:

1. Toward the end of the scans, the status bar indicates that it is scanning "download directories" even though I have not specified any download directories to scan. Based on the status bar information, there are in excess of 25,000 scans being run on the unspecified "download directories". Can this scan process be streamlined to reduce the time SPYBOT takes to complete?

2. According to the status bar, by far, the majority of the scans SPYBOT runs are related to Virtumonde and during much of that, the individual scans complete at a much slower rate than do other named threats. No doubt Virtumonde is a particularly bad actor to merit so much attention, but wondering if anything can be safely done to reduce the amount of time spent on these scans.

Many thanks in advance for assistance offered.

C.

drragostea
2009-01-17, 19:03
Try the latest version of Spybot-Search&Destroy (1.6.0.30):
http://www.safer-networking.org/en/mirrors/index.html
-
There shouldn't be anything in the Directories unless the user specifically put a folder there to scan.

To get there: Spybot>Advanced Mode>Settings>Directories.

clw2613
2009-01-17, 20:39
Try the latest version of Spybot-Search&Destroy (1.6.0.30):
http://www.safer-networking.org/en/mirrors/index.html
-
There shouldn't be anything in the Directories unless the user specifically put a folder there to scan.

To get there: Spybot>Advanced Mode>Settings>Directories.

Thx for the response! I downloaded and installed version 1.6.0.30 as you suggested, then rescanned; 36 minutes to complete a full scan.

The "download directory" scan is still there. According to the status bar it is comprised of 26000+ individual scans. There are NO download directories specified in Spybot>Advanced Mode>Settings>Directories.

Any ideas why it would be doing these "download directory" scans since there are no "download directories" specified?

The scans for the virtumonde threat still comprises ~ 2/3 of the total scans indicated by the status bar. Is there any way to streamline this process?

The issue of CPU usage preventing other applications from running concurrently seems to be better now. Previously my Outlook e-mail client could not be opened while Spybot was running. Now it opens with no problems.

Thx,
C.

drragostea
2009-01-18, 02:10
It is normal for Spybot to use CPU, well at most 50%, during a full scan because just like any other anti-virus/spyware scan, the PC will be slower during the process of scanning. I'm confident that Spybot-SD 1.6.0 will improve your situation.

The Virtumonde trojan constantly multiplies and more variants of it are created everyday :yuck:, so that may explain a portion of the scan focusing on Virtumonde/Vundo.

As for the Download Directory, I'm not so sure how the scanning works in there. It could be normal that Spybot is scanning there, even though nothing is placed there. Think of it like... Spybot will take a brief look at that directory to see if anything is there.

Thing is, the scan could be the same if you did or did not put anything in the Downloads Directory because variables like how many folders or how big each folder is can add to the overall scanning time.