PDA

View Full Version : Confused - help please!! :-)



Spybotuserr
2009-09-09, 18:28
Dear Forum,

Could somebody please clarify for me if:
- the below result is serious? (ie. Malware related)
- or just a 'warning' related to an Internet Explorer setting

I have searched the forum and read conflicting statements. My lack of experience with computers also is reducing my understanding of the problem.

Thank you in advance and I look forward to the answer.

Best wishes,

Spybotuserr

-----------------------------------------------------------------
My system:
Window$ XP Pro SP3
Firefox 3.5.2
Internet Explorer 8.0.6001.18702
Avast Pro (resident)
ZA Pro (resident)
MBAM (resident)
Spybot 1.6.2.46 (not resident) (latest update 09-09-2009)

--- Search result list ---
Microsoft.Windows.Security.InternetExplorer: [SBI $A3433CBF] Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-3267268965-3008618058-2928108558-1005\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-01-31 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-09-07 advcheck.dll (1.6.4.18)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-09-08 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-05-19 Includes\Dialer.sbi (*)
2009-09-08 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-09-08 Includes\HijackersC.sbi (*)
2009-06-23 Includes\Keyloggers.sbi (*)
2009-09-08 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-08-19 Includes\Malware.sbi (*)
2009-09-08 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-09-08 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-09-08 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-09-08 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti (*)
2009-08-25 Includes\Trojans.sbi (*)
2009-09-08 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Zenobia
2009-09-10, 08:06
Could somebody please clarify for me if:
- the below result is serious? (ie. Malware related)
- or just a 'warning' related to an Internet Explorer setting

It is a warning about an Internet Explorer setting,because sometimes malware will change the security settings in Internet Explorer.Letting Spybot fix it should set it back to the recommended registry setting.

However,there is also the chance you might have made that setting yourself,so in that case,you would ignore the detection.

For an example,in this thread Rosenfeld set this himself:
http://forums.spybot.info/showthread.php?t=6560

OK, I found the answer

The data for iexplore.exe is set to 0 by checking Internet options, advanced tab, security section: 'allow active content to run in files on my computer'

As I set that deliberately, I'll exclude the item from Spybot scans.

Hope that is clearer than mud. ;)

Other ways this could have been set by someone themselves are,they might have checkmarked Allow active content from CDs to run on My Computer in Internet Explorer -> Tools -> Internet Options -> Advanced tab -> Security .

Or,they may have edited the registry themselves,to fix a problem,such as the one described in the workaround in this Microsoft article:
http://support.microsoft.com/kb/883969

Also,if you highlight Microsoft.Windows.Security.InternetExplorer with your mouse after a Spybot scan,and then click the bar with the two blue arrows on it to the right,there should be a description of the detection from Spybot.It mentions the setting can sometimes be changed by other security software,and to check it.