PDA

View Full Version : How many problems are findable / blockable on my system?



bfd49
2005-12-03, 12:34
How many problems are findable / blockable on my system?

I installed Spybot 1.3 a couple of weeks ago. I'm using Win 95 and
MSIE 5.5, so I can't run Spybot 1.4. I've updated Spybot 1.3 with the
latest additions (Dec. 2, 2005). I've been through the Tutorial, and
through Tom Coyote's Spybot Help. I've run Spybot scans several times,
and it has found "no immediate problems" on my system each time.
I have "Immunized" several times, and that software function seems to
work. I have read the past month's posts on this Forum about
"incomplete Immunize," etc. I get the same "incomplete Immunize"
behavior as described in several of the posts, and the work-arounds
described in the replies seem to work.

But my system still seems to be infected with adware/spyware which is
generating ads inside browser windows on commercial Web sites, some of
which are allegedly "secure" sites (with https://.....). I am NOT
getting pop-up windows with ads.

My questions are,
1. "How many "bad products" are blockable on my system?"
On each start-up of Spybot, my first attempt to "Immunize" with the
red icon on the Spybot left panel gets me the message "1851 bad
products already blocked, 184 additional protection possible. Please
immunize," similar to the other users in the posts. A subsequent
use of the green "+ Immunize" button on the upper right panel OR an
"UNDO" and green "+ Immunize" gets me the message "2035 bad products
are now blocked." But I notice from several of the other posts on
this topic on this Forum that the numbers are different, sometimes
as high as 7,000 plus. So am I getting the right number of "bad
products blocked," or am I missing some? If I'm missing some, how
do I get those blocked too?

2. "How many problems are findable on my system?"
During the Spybot scans, the counter in the lower left corner of the
Spybot window counts up to about 28,200 over about 8 minutes, then
skips immediately to 32,247, the maximum. Is this the correct
behavior, or am I missing some? How are the 28,200+ "problems"
scanned for related to the 2,000 - 7,000+ "bad products" blocked?

3. "Is my system 'immunized' until I 'undo' it, or must I 'immunize' every
time I start the computer and/or the browser? Must Spybot be
up and running as an iconized task on the Windows lower bar to be
effective, or does Spybot start with the computer and run in the
background?

I'm very new at this stuff. Thank you in advance for your reply.
bfd49

md usa spybot fan
2005-12-03, 15:32
When you “Immunize”, entries are added to the system Registry. This blocks cookies from some sites (see note #1), places other sites in the restricted zone and blocks the download/execution of selected ActiveX scripts.

Some of these registry entries are added to multiple registry hives depending on the operation system (OS). This accounts for the difference in the immunization counts among the various OSs.

For additional information, see:
How Spybot-S&D protects against the installation of Spyware/Malware
http://forums.spybot.info/showthread.php?t=281

Note #1 - Windows 95 does not support Internet Explorer 6 (IE 6). Cookie blocking prior to IE 6 was not possible so Windows 95 gets the following message:
Warning
1851 bad products already blocked, 184 additional protections possible. Please immunize.
OK


The count jump during scanning has been noted before. See the following thread at net-integration:
Scan Jumps From About 22,950 To 26,469, faster than 'lightning' Options
http://net-integration.us/forums/index.php?showtopic=32419


The entries remain in the system registry until removed so it is not necessary to re-immunize until Spybot is updated.

md usa spybot fan
2005-12-06, 22:11
More about question #2 in bfd49 (http://forums.spybot.info/member.php?u=1306)’s post above.

During the running of a Spybot scan ("Check for problems") the status bar shows the following:
"Running bot-check(xxxxx/yyyyy:zzzzzz)" where:
xxxxx = Current check count
yyyyy = Total check count
zzzzz = Malware being checked for
It has been noted on various occasions that the xxxxx value in the status appears to skip approximately 4000 checks.

I believe that I have figured out why Spybot skips these checks. It appears that these skipped checks are only used when a directory is added to the "Advanced mode > Settings > Directories" feature. If you go into Spybot > Mode > Advanced mode > Settings > Directories and add a directory, Spybot no longer appears to skip these checks. Instead it appears to rapidly process (possibly load) those checks and then spends a considerable amount of extra time before the zzzzz portion of the status changes from "ZWax" (during full scans) to these checks: "Internet Explorer – various - Tracking Cookie" followed by "Internet Explorer – username - Bookmark".

Caution: Don't go adding items to the Directories feature just to make Spybot process those checks. It must be noted that the "Directories" feature is an "Advanced mode" feature and has a specific purpose. Before considering adding items to the "Directories" feature make sure that you understand what the feature is used for. Read the notes on the "Directories" facility screen, the help facility comments about the feature as well as the following so that you understand the purpose and the pitfalls:
FAQ - Frequently Asked Questions
Why does Spybot-S&D find so many Spyware installers / how is that Download directories setting used?
http://www.safer-networking.org/en/faq/15.html

The Download directories setting should be set only to your download folders, where you can easily identify the files you downloaded. Files in other places will be searched for automatically, there is no need to enter them in the setting. In fact, adding your whole hard disk to this setting will most likely result in false positives.
If files like wbemtest.exe in your Windows/System folder are detected as a spyware installer, that is such a false positive.

bfd49
2006-01-02, 05:40
Thank you for your two reply posts to my original post. I read them
at the time and determined that Spybot seems to be working properly.
I also read the information in the other links you referenced. This
was also helpful. I've just re-read all of that stuff.

I have a further clarification question on your Note #1 (quoted below).
When you said that "Note #1 - Windows 95 does not support Internet
Explorer 6 (IE 6). Cookie blocking prior to IE 6 was not possible...,"
did you mean not possible for Spybot or for Win95/IE? In MSIE 5.5,
I am allegedly able to block stored and unstored cookies separately,
so are you saying that this doesn't actually work, or that Spybot
could not block cookies with MSIE 5.5? Thank you again in advance.

bfd49



When you “Immunize”, entries are added to the system Registry. This blocks cookies from some sites (see note #1), places other sites in the restricted zone and blocks the download/execution of selected ActiveX scripts.

Some of these registry entries are added to multiple registry hives depending on the operation system (OS). This accounts for the difference in the immunization counts among the various OSs.

For additional information, see:
How Spybot-S&D protects against the installation of Spyware/Malware
http://forums.spybot.info/showthread.php?t=281

Note #1 - Windows 95 does not support Internet Explorer 6 (IE 6). Cookie blocking prior to IE 6 was not possible so Windows 95 gets the following message:
Warning
1851 bad products already blocked, 184 additional protections possible. Please immunize.
OK


The count jump during scanning has been noted before. See the following thread at net-integration:
Scan Jumps From About 22,950 To 26,469, faster than 'lightning' Options
http://net-integration.us/forums/index.php?showtopic=32419


The entries remain in the system registry until removed so it is not necessary to re-immunize until Spybot is updated.

md usa spybot fan
2006-01-02, 07:40
Spybot-S&D and other products such as SpywareBlaster add registry entries to block the storing of cookies. This type of blocking only became available with Internet Explorer 6.

Microsoft Knowledge Base Article – 182569
Description of Internet Explorer security zones registry entries
http://support.microsoft.com/default.aspx?kbid=182569


Privacy in Internet Explorer 6

Internet Explorer 6 added a Privacy tab to give users more control over cookies. There are different levels of privacy on the Internet zone, and they are stored in the registry at the same location as the security zones.

You can also add a site to allow or to block cookies based on the site, regardless of the privacy policy on the Web site. Those registry keys are stored in the following registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History

Listed under this key are domains that have been added as a managed site. These domains can carry either of the following DWORD values:

0x00000005 - Always Block
0x00000001 - Always Allow