PDA

View Full Version : What to do with Manual Scan Results?



JorgeA
2010-07-13, 20:10
Hello,

I recently joined my old Windows for Workgroups 3.11 PC to my home network. Out of curiosity, I ran a manual Spybot scan on the old PC off my Windows 98 machine, via the context menu that pops up when you right-click on a drive in Windows Explorer. (Yes, I do have a lot of old hardware!)

The scan took a while to finish, but it finally did and four entries came up showing the following information:

Filename
FLAG.GLB SpywareDetector Spybot - Search & Destroy (Heuristic)
00000000.GRP WebWatcher Spybot - Search & Destroy (Heuristic)
ADMIN.GRP WebWatcher Spybot - Search & Destroy (Heuristic)
ADMINSHD.GRP WebWatcher Spybot - Search & Destroy (Heuristic)

Each of these had a little icon at left that showed half of a red circle with an "X" inside, then one quarter in red and white stripes, and one quarter clear.

At the bottom of the Scanner box, it now says, "Scan finished."

A few questions:

1) Does "Scan finished" mean that it found AND removed the suspicious items, or only that it found but did not remove them?

2) Are the items in question now removed? If not, how do I remove them?

3) What does the red half-circle with the one-quarter stripes mean?

Bottom line: What (if anything) do I now need to do to end up with a clean, uninfected machine?

Thanks very much.

--JorgeA

Alpha Quadrant
2010-07-16, 03:46
Hello,

I recently joined my old Windows for Workgroups 3.11 PC to my home network. Out of curiosity, I ran a manual Spybot scan on the old PC off my Windows 98 machine, via the context menu that pops up when you right-click on a drive in Windows Explorer. (Yes, I do have a lot of old hardware!)

The scan took a while to finish, but it finally did and four entries came up showing the following information:

Filename
FLAG.GLB SpywareDetector Spybot - Search & Destroy (Heuristic)
00000000.GRP WebWatcher Spybot - Search & Destroy (Heuristic)
ADMIN.GRP WebWatcher Spybot - Search & Destroy (Heuristic)
ADMINSHD.GRP WebWatcher Spybot - Search & Destroy (Heuristic)

Each of these had a little icon at left that showed half of a red circle with an "X" inside, then one quarter in red and white stripes, and one quarter clear.

At the bottom of the Scanner box, it now says, "Scan finished."

A few questions:

1) Does "Scan finished" mean that it found AND removed the suspicious items, or only that it found but did not remove them?

2) Are the items in question now removed? If not, how do I remove them?

3) What does the red half-circle with the one-quarter stripes mean?

Bottom line: What (if anything) do I now need to do to end up with a clean, uninfected machine?

Thanks very much.

--JorgeA

Reply 1) Scan finished means that it is done scanning. No files have been removed.

Reply 2) Based on their file extension I believe the items in question are operating system files/data files so I don't think there is anything to worry about. .GLB and .GRP extensions are old executable files used on old computer Systems, the extension is no longer used on newer computers. When I scan my computer with manual scanner it often detects program uninstallers in the Heuristics section as a "Tasker", but the same files will be "clean" in the Malware section and in the main scanner, as well as when it. Based on my experimenting with it I believe the Heuristics scanner is prone to false positives, if the malware scanner didn't find anything then you should be ok.

Reply 3) I believe the red circle with the white "X" means possible threat. On the right hand side it lists a column titled "Status". It will tell you what it detected. If nothing was detected in the file then it will say "nothing found"

The bottom line, I don't think your machine is infected with anything. I think it is just a false positive.

JorgeA
2010-07-16, 16:44
Alpha Quadrant,

I appreciate your reply, this is reassuring.

The scanner looked through thousands of files where it gave a result of "nothing found." It was only those four .GRP or .GLB files where it said anything different -- "WebWatcher" for the .GRP files, or "SpywareDetector" for the .GLB.

And if even those are O.K., then we're good to go. Thanks very much!

--JorgeA