PDA

View Full Version : SB's less than explicit scan results



urrguru
2010-02-09, 06:45
A fresh install of and scan using SB S&D results in an entry that is pretty concerning and yet SB's 'added info' panel merely says something like 'internet explorer is subject to security changes. Check security settings'.

So I checked my ESET AV's settings and even the Windows Security Center, and found nothing indicating any issues.

However somewhat disturbingly, my next SB scan hit on nothing at all, even though I only unticked the initial SB scan's hit for the internet explorer settings 'issue'.

What with some recent serious issues (apparently caused from regretfully trying to run Lavasoft's free Ad-Aware on top of SB), ie; I'm surmizing something corrupted my master boot record, and despite my repairing it and even restoring the system to the point where I'd installed Ad-Aware, things seem pretty much out of hand

Starting to think I've got a virus and should be formatting.

Suggestions about the supposed internet explorer settings security issue would be appreciated, has anyone else run into SB's rather unhelpful hit's 'added info' tab's unhelpful details about an IE settings security issue?

spybotsandra
2010-02-09, 11:42
Hello,

Do you mean Windows.Security.InternetExplorer?

I suggest you "Fix selected problems" on those detections unless you experienced an issue such as the one described in the following article and intentionally changed those registry entries from their default setting:

AutoShapes that were added to an HTML or an MHTML file in a Microsoft Office program do not appear when you open the file in Internet Explorer after you install Windows XP SP2 (http://support.microsoft.com/?scid=kb%3Ben-us%3B883969&x=12&y=12)

The key "HKEY_CURRENT_USER,"\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN" (standard value is 1 with SP2) determines the ability to perform certain actions for local websites, i.e. websites saved on harddisk.

The value is set to 0 (zero) by some malicious applications in order to deminish the security settings for the zone "local computer". (see here (http://msdn.microsoft.com/security/productinfo/XPSP2/securebrowsing/locallockdown.aspx) for details).

There are several threads on the subject:

Windows.Security.Internet Explorer (http://forums.spybot.info/showthread.php?t=6560)
Scan Result (http://forums.spybot.info/showthread.php?t=6749)

If you want you can also tell Spybot-S&D to exclude those detections from further scans.

You can exclude a product from the search as follows:
First of all procede a scan with Spybot - Search & Destroy. Now, mark the item, you want to exclude from the search, with a left-click.
It is marked blue now. Then right-click this entry and select "exclude this product from further searches".

It is also possible to exclude it before the search. Please run Spybot - Search & Destroy in "Advanced Mode" and go to "Settings" -> "Ignore products". There you can tick the checkbox in front of the product you want to exclude from the search.

Best regards
Sandra
Team Spybot