PDA

View Full Version : 5 problems never stop showing. could be false



general manson
2006-09-17, 21:16
Screenshot is attached to explain.

md usa spybot fan
2006-09-17, 21:51
Please post a log of the actual detections you are getting. To do that:
Run another scan.
When the scan completes, right click on the results list, select "Copy results to clipboard".
Then paste those results to a new post in this thread.
In addition to the detections it provides the version of Spybot you are running, update level, etc.

Thanks

general manson
2006-09-17, 22:44
Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0

Windows Security Center.AntiVirusOverride: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0

Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Windows.ActiveDesktop: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-117609710-1958367476-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper!=W=1

Windows.Security.InternetExplorer: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-117609710-1958367476-725345543-1003\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-09-11 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-09-15 Includes\Cookies.sbi (*)
2006-09-15 Includes\Dialer.sbi (*)
2006-09-15 Includes\Hijackers.sbi (*)
2006-09-15 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-09-15 Includes\Malware.sbi (*)
2006-09-15 Includes\PUPS.sbi (*)
2006-09-15 Includes\Revision.sbi (*)
2006-09-15 Includes\Security.sbi (*)
2006-09-15 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-09-15 Includes\Trojans.sbi (*)


Neat.

md usa spybot fan
2006-09-18, 06:10
general manson:

None of the detections that you are getting are false positives. They all indicate unusual settings within the Windows OS that may or may not be a problem depending if you intentionally altered default settings or chose to allow certain security products to alter those settings.

The following detection:


Windows Security Center.AntiVirusOverride: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0
Indicates that the ability of Windows Security Center to monitor the status of your anti-virus has been turned off. Windows Security Center can monitor the status of the most widely used AntiVirus products (such as Ahnlab, ComputerAssociates, Kaspersky, McAfeeAnti, Panda, Sophos, Symantec, Trend, etc.). With this indicator disabled Windows Security Center will not monitor if your AntiVirus has been disabled or is out of date. If you go into Start > Control Panel > Security Center > look at the right hand side of the window and check the settings under "Virus Protection" (expand if necessary). I believe that you have overridden the protections and that you will find a button labeled "Recommendations". If you click on the "Recommendations" button I believe that you will get a window that indicates something like:I have an antivirus program that I'll monitor myself.
Note: Windows won't monitor your virus protection status and won't send you alerts if it is off or out of date.

These detections:


Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0

Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0
Go into Start > Control Panel > Security Center > Resources (on the left hand side of the window – expand if necessary) > click "Change the way Security Center alerts me". This brings up an "Alert Setting" window.

There are three possible alerts:
Firewall
Alert me if my computer might be at risk because of my firewall settings
Automatic Updates
Alert me if my computer might be at risk because of my Automatic Updates settings
Virus Protection
Alert me if my computer might be at risk because of my virus protection software settingsI believe that you will find the first and third alerts turned off. Note: Certain security products (notably McAfee and Norton) will turn off these alerts if you optionally set them to this alert function of the Windows Security Center.

This detection:


Windows.ActiveDesktop: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-117609710-1958367476-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper!=W=1
Indicates that you are allowing HTML coded wall paper on your system.

The items under ActiveDesktop are supposed to be a dword:
0 = no restriction
1 = enable restriction
NoHTMLWallPaper = only allow bitmaps (BMP) as wallpaper

See the following article for a more complete description of ActiveDesktop registry entries:
Active Desktop Restrictions
http://www.winguides.com/registry/display.php/443/
If you did not intentionally set that registry value to allow HTMLWallPaper than you should fix the detection.

This detection:

Windows.Security.InternetExplorer: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-117609710-1958367476-725345543-1003\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1
See the following thread:
Scan Result
http://forums.spybot.info/showthread.php?t=6749&highlight=iexplore.exe

general manson
2006-09-18, 06:34
For the security center for the first 2 parts you put on or lost I have this problem. As for the others I'll ignore. (I think but not sure)


The security center is currently unavailable because the security center service has not started or was stopped. Please close this window and restart the computer (or start the security center service) and then open the security center again.

Not sure when this started but is there a fix for this? Might have deleted something from the registry that could have caused this but cant remember like WSVC or soemthing like that.

md usa spybot fan
2006-09-18, 06:57
To start Windows Security Center: Go to Start > Run > type: services.msc > OK.
In the right pane, scroll down until you see Security Center.
Right click on Security Center and choose Properties.
Change the Startup type from Disabled to Automatic.
Click Apply.
Under Services Status click on the Start button.
Close Services.

general manson
2006-09-18, 23:24
I have a problem. I dont see Security center listed. The only thing closet to that, that I see is Security Accounts.

md usa spybot fan
2006-09-19, 05:05
Are you running Windows XP SP2?

Go into Windows Explorer > Help > About Windows. What does the line after Microsoft © Windows read?
Version x.x (Build …………..)

general manson
2006-09-19, 05:10
Are you running Windows XP SP2?

Go into Windows Explorer > Help > About Windows. What does the line after Microsoft © Windows read?
Version x.x (Build …………..)


Windows Explorer meaning?

md usa spybot fan
2006-09-19, 06:04
Windows Explorer meaning?
Windows Explorer!!!

From Microsoft Help and Support:
To open Windows Explorer, click Start, point to All Programs, point to Accessories, and then click Windows Explorer.

general manson
2006-09-19, 06:10
Ok didnt find it that way but i have xp.

5.1.2600 Service Pack 2 Build 2600

md usa spybot fan
2006-09-19, 14:46
If the problem is just due to missing registry entries for Security Center in Services and not other components of Windows Security Center, you could try to download and execute the wscsvc.reg file from the following Web page:
How to restore the missing "Security Center" service in Windows XP SP2?
http://www.winhelponline.com/articles/33/1/How-to-restore-the-missing-quotSecurity-Centerquot-service-in-Windows-XP-SP2.html
Note: The "Start" dword in that registry fix is "dword:00000003" which is "Manual", so you will still have to following the instructions above for going into Services.msc > Security Center and altering the settings.

general manson
2006-09-19, 23:57
ok im gonna try it and restart when done. I'll repost if it didnt work.

general manson
2006-09-20, 00:15
It works. Thank you very much. You deserve a promotion. All the windows guys I asked didnt come up with this solution. :bigthumb: :crowned: :D:

general manson
2006-09-20, 02:45
Windows Security Center.AntiVirusDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify!=dword:0

Windows Security Center.AntiVirusOverride: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusOverride!=dword:0

Windows Security Center.FirewallDisableNotify: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify!=dword:0

Windows.ActiveDesktop: User settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-117609710-1958367476-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoHTMLWallPaper!=W=1

Windows.Security.InternetExplorer: Settings (Registry change, nothing done)
HKEY_USERS\S-1-5-21-117609710-1958367476-725345543-1003\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-09-11 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-09-15 Includes\Cookies.sbi (*)
2006-09-15 Includes\Dialer.sbi (*)
2006-09-15 Includes\Hijackers.sbi (*)
2006-09-15 Includes\Keyloggers.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2006-09-15 Includes\Malware.sbi (*)
2006-09-15 Includes\PUPS.sbi (*)
2006-09-15 Includes\Revision.sbi (*)
2006-09-15 Includes\Security.sbi (*)
2006-09-15 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-09-15 Includes\Trojans.sbi (*)

What should I fix now?

md usa spybot fan
2006-09-20, 05:36
See:
http://forums.spybot.info/showpost.php?p=42964&postcount=4

general manson
2006-09-20, 05:59
I think i'll just go ahead and ignore those. I know they will come back even though nothing is actually wrong. Yall can close topic now its bookmarked. :). You do deserve a promotion in my opinion I'm so happy.

md usa spybot fan
2006-09-20, 06:18
Personally I think you should fix the problems.

general manson
2006-09-20, 22:40
WEll i say that b/c when i did this last time it messed up my firewall and disabled a bunch of things and just caused things to get worse. I'll leave them there. I'm sastified anyways.