PDA

View Full Version : Disable TeaTimer Firewall



hitman72
2011-02-19, 10:39
hi, after the last update (?), now TeaTimer (that I use in "paranoid mode") has an internal firewall. how can I disable it? for my needs, the internal firewall of windows is sufficient. thank you and sorry for my poor english

tashi
2011-02-19, 17:03
Hello hitman72,

hi, after the last update (?), now TeaTimer (that I use in "paranoid mode") has an internal firewall. how can I disable it? for my needs, the internal firewall of windows is sufficient. thank you and sorry for my poor english
Internal firewall? Could you give more details please. :)

Best regards.

Joergenr
2011-02-19, 18:51
Hi
I cannot be sure but I think hitman 72 is referring to the same thing I am experiencing.
Today when I started my computer the TeaTimer went crazy. Several windows showed up wanting me to accept changes. As you can see from the log I accepted the first ones, but got paranoid and denied the rest. The same thing happened again later today after a SS&D search. After that I accepted the rest. The entries in the log looks like exceptions in my Windows Firewall.
Here is a part of the log:

Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger") added in Firewall Authorized Applications!
19-02-2011 11:28:15 Allowed (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!
19-02-2011 11:28:34 Allowed (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashAvast.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus") added in Firewall Authorized Applications!
19-02-2011 11:29:24 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe:*:Enabled:ashWebSv") added in Firewall Authorized Applications!
19-02-2011 11:29:26 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe" (new data: "C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe:*:Enabled:aswRegSvr") added in Firewall Authorized Applications!
19-02-2011 11:29:45 Allowed (based on user decision) value "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe" (new data: "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe:*:Enabled:SaxoTrader 2") added in Firewall Authorized Applications!
19-02-2011 11:30:05 Denied (based on user decision) value "C:\WINDOWS\system32\sessmgr.exe" (new data: "C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
19-02-2011 11:30:07 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:07 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:08 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:09 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" (new data: "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" (new data: "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:12 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashServ.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashServ.exe:*:Enabled:ashServ") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "%windir%\system32\sessmgr.exe" (new data: "%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\Synovel Spicebird\spicebird.exe" (new data: "C:\Program Files\Synovel Spicebird\spicebird.exe:*:Enabled:Synovel Spicebird") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\OpenOffice.org 3\program\soffice.exe" (new data: "C:\Program Files\OpenOffice.org 3\program\soffice.exe:*:Enabled:OpenOffice.org") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\Secunia\PSI\psi.exe" (new data: "C:\Program Files\Secunia\PSI\psi.exe:*:Enabled:Secunia PSI") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\Mozilla Firefox\firefox.exe" (new data: "C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\Opera\opera.exe" (new data: "C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser") added in Firewall Authorized Applications!
19-02-2011 11:30:13 Denied (based on user decision) value "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" (new data: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger") added in Firewall Authorized Applications!
19-02-2011 11:31:58 Denied (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!
19-02-2011 11:32:00 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashAvast.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus") added in Firewall Authorized Applications!
19-02-2011 11:32:01 Denied (based on user decision) value "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe" (new data: "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe:*:Enabled:SaxoTrader 2") added in Firewall Authorized Applications!
19-02-2011 11:36:12 Allowed (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!
19-02-2011 11:36:25 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashAvast.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus") added in Firewall Authorized Applications!
19-02-2011 11:36:29 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe:*:Enabled:ashWebSv") added in Firewall Authorized Applications!
19-02-2011 11:36:37 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe" (new data: "C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe:*:Enabled:aswRegSvr") added in Firewall Authorized Applications!
19-02-2011 11:36:39 Allowed (based on user decision) value "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe" (new data: "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe:*:Enabled:SaxoTrader 2") added in Firewall Authorized Applications!
19-02-2011 11:36:44 Allowed (based on user decision) value "C:\WINDOWS\system32\sessmgr.exe" (new data: "C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
19-02-2011 11:36:49 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe") added in Firewall Authorized Applications!
19-02-2011 11:36:54 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe") added in Firewall Authorized Applications!
19-02-2011 11:36:56 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe") added in Firewall Authorized Applications!
19-02-2011 11:36:59 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:00 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:02 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:03 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:05 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:07 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:13 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:18 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" (new data: "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:22 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" (new data: "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:24 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:25 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe") added in Firewall Authorized Applications!
19-02-2011 11:37:31 Denied (based on user decision) value "C:\Program Files\Alwil Software\Avast4\ashServ.exe" (new data: "C:\Program Files\Alwil Software\Avast4\ashServ.exe:*:Enabled:ashServ") added in Firewall Authorized Applications!
19-02-2011 11:37:34 Allowed (based on user decision) value "%windir%\system32\sessmgr.exe" (new data: "%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
19-02-2011 11:37:43 Allowed (based on user decision) value "C:\Program Files\Synovel Spicebird\spicebird.exe" (new data: "C:\Program Files\Synovel Spicebird\spicebird.exe:*:Enabled:Synovel Spicebird") added in Firewall Authorized Applications!
19-02-2011 11:37:49 Allowed (based on user decision) value "C:\Program Files\OpenOffice.org 3\program\soffice.exe" (new data: "C:\Program Files\OpenOffice.org 3\program\soffice.exe:*:Enabled:OpenOffice.org") added in Firewall Authorized Applications!
19-02-2011 11:37:51 Allowed (based on user decision) value "C:\Program Files\Secunia\PSI\psi.exe" (new data: "C:\Program Files\Secunia\PSI\psi.exe:*:Enabled:Secunia PSI") added in Firewall Authorized Applications!
19-02-2011 11:37:56 Allowed (based on user decision) value "C:\Program Files\Mozilla Firefox\firefox.exe" (new data: "C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox") added in Firewall Authorized Applications!
19-02-2011 11:37:58 Allowed (based on user decision) value "C:\Program Files\Opera\opera.exe" (new data: "C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser") added in Firewall Authorized Applications!
19-02-2011 11:38:05 Allowed (based on user decision) value "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" (new data: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger") added in Firewall Authorized Applications!
19-02-2011 18:18:31 Allowed (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!
19-02-2011 18:18:35 Allowed (based on user decision) value "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe" (new data: "C:\Program Files\Saxo Bank\SaxoTrader 2\IitClientStation2.exe:*:Enabled:SaxoTrader 2") added in Firewall Authorized Applications!
19-02-2011 18:18:36 Allowed (based on user decision) value "C:\WINDOWS\system32\sessmgr.exe" (new data: "C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
19-02-2011 18:18:37 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:38 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:38 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:39 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:39 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:39 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:40 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:40 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:41 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:41 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:41 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" (new data: "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:42 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" (new data: "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:42 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:42 Allowed (based on user decision) value "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe" (new data: "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe") added in Firewall Authorized Applications!
19-02-2011 18:18:43 Allowed (based on user decision) value "%windir%\system32\sessmgr.exe" (new data: "%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
19-02-2011 18:18:43 Allowed (based on user decision) value "C:\Program Files\Synovel Spicebird\spicebird.exe" (new data: "C:\Program Files\Synovel Spicebird\spicebird.exe:*:Enabled:Synovel Spicebird") added in Firewall Authorized Applications!
19-02-2011 18:18:44 Allowed (based on user decision) value "C:\Program Files\OpenOffice.org 3\program\soffice.exe" (new data: "C:\Program Files\OpenOffice.org 3\program\soffice.exe:*:Enabled:OpenOffice.org") added in Firewall Authorized Applications!
19-02-2011 18:18:45 Allowed (based on user decision) value "C:\Program Files\Secunia\PSI\psi.exe" (new data: "C:\Program Files\Secunia\PSI\psi.exe:*:Enabled:Secunia PSI") added in Firewall Authorized Applications!
19-02-2011 18:18:45 Allowed (based on user decision) value "C:\Program Files\Mozilla Firefox\firefox.exe" (new data: "C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox") added in Firewall Authorized Applications!
19-02-2011 18:18:46 Allowed (based on user decision) value "C:\Program Files\Opera\opera.exe" (new data: "C:\Program Files\Opera\opera.exe:*:Enabled:Opera Internet Browser") added in Firewall Authorized Applications!
19-02-2011 18:18:47 Allowed (based on user decision) value "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" (new data: "C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger") added in Firewall Authorized Applications!



Windows XP sp. 3

JR

hitman72
2011-02-20, 11:18
yes perfect, I have the same problem of Joergenr! Only on a pc, on other 2 computers (same with xp sp3) I have no problem... Any idea?

Peadar
2011-02-20, 18:12
Same here, gentlemen, on a 4-years-old TOSHIBA & XP laptop having just had a reinstall. It may not be an issue with TeaTimer, only made obvious by it. In my case, the notification area crashes, too, either completely or leaving just one or two icons available; I need to restart TeaTimer.exe in order to restore Spybot's icon and explorer.exe for all other icons.

hitman72
2011-02-23, 13:20
I do not read any solution yet (strange. ..). so I reinstalled spybot. is the first serious bug that I find with this program, and I use spybot from first version. ciao :-)

tashi
2011-02-23, 16:53
Hi hitman72,

I reinstalled spybot.
Did re-installing fix the issue you reported?

Best regards.

k_kolev1985
2011-02-28, 20:24
I had the same problem - after the last update of "Spybot - Search and Destroy", on every Windows startup the resident protection "TeaTimer" started given me alerts about changes related to the Windows Firewall exceptions (changes). I made a clean install of "Spybot - Search and Destroy" and after it thankfully the problem is gone :).

MisterW
2011-03-01, 11:52
Hello,
since the last update the entries that belong to Windows firewall get monitored in order to protect the system against malware that tries to bypass the firewall.
Normally there should be only a warning of the TeaTimer if
- you use it in paranoid mode
- you use an old version of TeaTimer (in that case you may should update :grandpa:)
- it is really a malicious software that tries to bypass the firewall

Best regards,
Markus
Team Spybot

PeteMoon
2011-03-01, 12:35
I am getting a similar problem since 17 Feb. At most boot-ups (not every time) I get the following (copied from Resident LOG):

17/02/2011 14:00:24 Denied (based on user decision) value "%windir%\system32\sessmgr.exe" (new data: "%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
17/02/2011 14:00:29 Denied (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!

I can't find any reference to "paranoid mode" in the setup, or Tools - Resident.
The version I'm running is 1.6.2.46, last update 24/2
How do i know if I'm using the most up-to-date version of teatimer?
Thanks, Pete

PeteMoon
2011-03-01, 12:53
ps I have Windows Firewall turned OFF (running another firewall).
Pete

ELECTRO
2011-03-02, 00:33
Ich habe gleiches Problem auf 3 Windows XP Rechnern genau nach diesem Windows-Update:

Update für Windows XP (KB971029) Installieren Sie dieses Update, um AutoRun-Einträge im Dialogfeld der automatischen Wiedergabe auf CD- und DVD-Laufwerke zu beschränken.

Habe dabei jeweils 3x erlauben (ob mit oder ohne Haken "Merke diese Entscheidung") für das gleiche Programm.

jeweils hier:

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

Der Teatimer findet aber nicht alle 3 auf einmal, sondern jeweils einen oder zwei, dann nach Neustart nochmal.

Bei 35 Programmen die in der Windows-Firewall eingetragen sind, sind das dann 105 mal "Erlauben" klicken und 105 mal "Merke die Entscheidung" klicken.

In der Log-Datei kommen die dann logischerweise bei jedem Start.

Bei einem Freund von mir war noch nichts, da er dieses Update von Microsoft noch nicht hatte, daher denke ich da besteht der Zusammenhang.

Gruß ELECTRO

hitman72
2011-03-02, 09:22
hi, from yesterday I have this PROBLEM again (I have reinstalled spybot few days ago). It is very BORING! if the problem can not be resolved I will have to use other programs similar to SpyBot. nice day to all

spybotsandra
2011-03-02, 09:53
Hello,

The best way for you is probably to disable the "Paranoid Mode" of the resident TeaTimer.
Therfore right click on the TeaTimer icon (named Spybot SD Resident) in the system tray (lower right of your pc).
Now untick "Paranoid Mode (as on any unknown)".

Best regards
Sandra
Team Spybot

hitman72
2011-03-02, 09:58
Yes I know (but I need "registry protection"), I use SpyBot from its early versions. but is it so hard ad a menu like "enable/disable firewall"? I am using MY firewall! it 's all so strange... ciao

spybotsandra
2011-03-02, 10:00
Hello,

You will have resident protection.
I did not say disable the resident TeaTimer.
I said disable the paranoid mode.

Best regards
Sandra
Team Spybot

hitman72
2011-03-02, 10:14
I use "Paranoid mode" mainly to prevent programs from installing on the startup (including trusted programs!). ok if it can not be solved, there are no problems ... thanks

PeteMoon
2011-03-02, 14:23
Hi

These are the latest messages I was getting:
02/03/2011 13:07:05 Allowed (based on user decision) value "%windir%\system32\sessmgr.exe" (new data: "%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
02/03/2011 13:07:08 Allowed (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!
02/03/2011 13:07:10 Allowed (based on user decision) value "%windir%\system32\sessmgr.exe" (new data: "%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019") added in Firewall Authorized Applications!
02/03/2011 13:07:11 Allowed (based on user decision) value "%windir%\Network Diagnostic\xpnetdiag.exe" (new data: "%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000") added in Firewall Authorized Applications!

I have now turned Paranoid Mode off, and it seems to have stopped the messages, but what does "Paranoid Mode" do? There's no mention of it in Spybot's help.

Thanks.

spybotsandra
2011-03-02, 14:33
Hello,

The "Paranoid Mode" alerts every registry change.
If you disable that mode only bad changes or suspicious ones will be alerted.
This thread (http://forums.spybot.info/showthread.php?t=46937) has more details on the new TeaTimer.

Best regards
Sandra
Team Spybot

PeteMoon
2011-03-02, 14:43
Thanks spybotsandra.
It seems strange though that these messages have all started for us at the same time. Before updating Spybot on Feb 17 I never got them, and I've always been on Paranoid Mode. PeteMoon
:)

spybotsandra
2011-03-02, 14:46
Did you read what Markus wrote before?


since the last update the entries that belong to Windows firewall get monitored in order to protect the system against malware that tries to bypass the firewall.

PeteMoon
2011-03-02, 14:48
Did you read what Markus wrote before?

Yes I did, but I have Windows Firewall turned off - if that makes any difference?

Buster
2011-03-02, 17:18
Hi!

Teatimer checks specific entries in the registry, like "HKEY_CURRENT_USER,"\Software\Microsoft\Windows\CurrentVersion\Run\" and other autorun sections in the registry. We do not monitor all sections but only those critical to your system security. Since our last update we have added the "Windows Firewall authorized Applications" section to Teatimer's watch list. The difference between paranoid and normal mode is quite easy to explain. If you activate paranoid mode, Teatimer will notify about every change in the registry at the specified locations. Running Teatimer with "paranoid mode" switched off will only notify the user if known malware has changed or added a registry entry.

PeteMoon
2011-03-02, 17:43
Thanks Buster
I've disabled Paranoid Mode now and no more Firewall messages appearing at start-up.
Love Spybot and wouldn't be without it.
:)

dreifels
2011-04-27, 03:48
Hi!
... Since our last update we have added the "Windows Firewall authorized Applications" section to Teatimer's watch list. The difference between paranoid and normal mode is quite easy to explain. If you activate paranoid mode, Teatimer will notify about every change in the registry at the specified locations. Running Teatimer with "paranoid mode" switched off will only notify the user if known malware has changed or added a registry entry.

well,was made after my complain
However, sometimes now TT doesn't always remember an OK if checkmarked "remember". This you need to investigate.

another issue I have new, is that after download and install successfully MS Update http://www.microsoft.com/downloads/de-de/details.aspx?FamilyID=ce925e76-cb85-48f6-8c0f-e53fa2b09be6 => NDP20SP2-KB2446704-v2-IA64.exe
the related entry does not procees, so that I always get again the notification image that a new download for security is available.
Maybe there is a conflict with WIndows Installer 4.5 => http://www.microsoft.com/downloads/de-de/details.aspx?displaylang=de&FamilyID=5a58b56f-60b6-4412-95b9-54d056d6f9f4

mike0
2011-07-31, 14:14
Conclusion:
You have added a new feature: "Checking firewall entries"
In Paranoid mode SB&D does not care about the checked "Remember this decission" so it will complain on every boot about this changes.
You found that's Ok and a wanted/required behaviour and you recommand to turn "paramoid mode" of to get rid of that tons of popups?
Did i get it?

So, pardon me, i have to ask:
1 Please tell me, why ignoring the checked "remember this" is OK?
I don't understand that.
2 As everyone wound be annoyed by the repeted, and then useless firewall-warnings, everyone would have to turn of paranoid mode, so what's the use of that mode anymore, when it must be turned off or the user will be annoyed?

I think the problem is not checking or not checking the f entries,
the problem is,
SB&D ignors the decissions(sp?) the user made!

(If i change the user, SB&D complains every times too about the change of the default user....regardless if i checked the remenber box...but that another problem)

mike0
2011-07-31, 14:20
Yes I did, but I have Windows Firewall turned off - if that makes any difference?

If you have turned the fw of, the registry is still changed.

Please consider to turn the Windows firewall on. That's good practise.

Fran_
2011-08-13, 23:27
Today I looked at the Teatimer log (for something unrelated) and found 2 entries for %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 seconds after startup. The change was allowed "based on user decision".

My Teatimer is version 1.6.6.32. The MS Firewall service is not running. I use a different firewall. There was no alert from Teatimer, so no user decision. That value was already in the registry, because the same 2 entries have appeared at startup every day since last May, so why is it considered a change anyway? The snapshot files have current dates.

What's going on?? Where could these 'changes' be coming from? Is there any way to determine what process initiated the change?

Fran

Fran_
2011-08-14, 16:53
I'm starting a new thread because nobody replied to my post in the old one.

Yesterday I looked at the Teatimer log (for something unrelated) and found 2 entries for %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 seconds after startup. The change was allowed "based on user decision".

My Teatimer is version 1.6.6.32. The MS Firewall service is not running. I use a different firewall. There was no alert from Teatimer, so no user decision. That value was already in the registry, because the same 2 entries have appeared at startup every day since last May, so why is it considered a change anyway? The snapshot files have current dates.


Additional information:

I looked at the snapshot file and it is identical to the registry entry except it has 'System' in the key where the registry has 'SYSTEM'. That hardly seems enough to cause Teatimer to think it's a change, but possible.

The actual change to the Registry was made when I installed SP 2 in 2005.

I would say it's pretty certain that Teatimer is producing false change notices for whatever reason.

It doesn't hurt anything I can see, but I don't like the log filling up with these useless entries, and it would be really annoying to anyone running in paranoid mode.

Fran

spybotsandra
2011-08-15, 16:34
Hello Fran,

Do you have anything in the black and whitelist?
Please right-click the Resident icon in the system tray "Spybot S&D resident" and select "Settings". There you will find 4 lists for remembered decisions (allowed/denied processes and registry changes).

Best regards
Sandra
Team Spybot

Fran_
2011-08-15, 18:15
Thanks for responding. I was afraid the old thread was being ignored.

I have only one blocked registry change - not related.

I'm having troube seeing the connection. It's not a question of whether a change is allowed or denied, but whether there is a change at all. There is not.

I printed the key from regedit and it showed the last write date to be in 2005.

Out of curiosity I changed 'System' to 'SYSTEM' in the snapshot file and the log showed the same two changes. (It was changed back to 'System' next time I started Teatimer.)

I think I've stopped the log entries by deleting the sessmgr registry entries from the list for both Domain and Standard profiles in Control Set 1 and 2. They were totally useless to me anyway. I'd be more comfortable if I knew why it was happening. The problem with Teatimer might affect something else that does matter.

I don't think I said I'm running XP Home SP 2 and Teatimer version 1.6.6.32. If I can help locate the problem, I'd be glad to try.

Thanks,
Fran