Results 1 to 8 of 8

Thread: Windows Internet Explorer . . .

  1. #1
    Senior Member LoneLurker's Avatar
    Join Date
    Nov 2005
    Location
    Texas, USofA
    Posts
    109

    Default Windows Internet Explorer . . .

    Greetings from LeonSprings, Texas USofA,

    "Windows.Explorer" is displayed in RED and the Key in the registry file is not there. I run SBS&D v1.4 and updated about 1/2 hour ago, about everyother day, some times 2 or 3 times in one day depending on how much done on the net. Have not used IE since about October, 2005 there have not been any changes to the registry file, except for those that I made by installing software like the "GDI32 - WMF Patch" from NOD32 linked from CastleCops.

    Is this a valid problems for me? Or is this a GHOST and really is not there? As stated above the entry is not there because I clicked on it to access that key and it went to the top of the list titled (Default).

    Windows.Explorer: User settings (Registry change, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff!=W=0
    Last edited by LoneLurker; 2006-01-10 at 01:44.
    LoneLurker"LoneWanderer""Adults are obsolete children. Dr. Seuss
    Win7 Pro SP1 x64;FireFox V. current: SBS&D V. current; WinPatrol, WinPrivacy, WinAntiRansom

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    There is a thread with a similar detection being discussed here:
    Windows.Explorer FP in beta.sbi 6 January 2006?
    http://forums.spybot.info/showthread.php?t=1519

    Note: That flag does not deal with Internet Explorer. When the NoLogoff is a dword:00000001 it allegedly prevents the user from logging off of Windows NT or Windows 2000 systems. For example see:
    NoLogoff
    http://www.microsoft.com/resources/d...ntry/93519.asp

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Senior Member LoneLurker's Avatar
    Join Date
    Nov 2005
    Location
    Texas, USofA
    Posts
    109

    Default

    Quote Originally Posted by md usa spybot fan
    There is a thread with a similar detection being discussed here:
    Windows.Explorer FP in beta.sbi 6 January 2006?
    http://forums.spybot.info/showthread.php?t=1519

    Note: That flag does not deal with Internet Explorer. When the NoLogoff is a dword:00000001 it allegedly prevents the user from logging off of Windows NT or Windows 2000 systems. For example see:
    NoLogoff
    http://www.microsoft.com/resources/d...ntry/93519.asp
    "md usa spybot fan,"

    Have noted that references are for Windows 2000 and up, I'm on Win98SE v4.10.2222A and stuck there due to retired with little income for moving to later versions of WindBlows er Windows.

    After checking that entry, " HKEY_USERS\.DEFAULT. . Explorer\NoLogOff 0x00000000 (0)" (quoted from my system) there is not an exclamation point (!) in my system's entry nor 'W'. In the reported RED exploit it is shown as ". . \NoLogOff!=W=0" (also note it is set to '0' in SBS&D report not '1') for that threat. Even though I do not use IE this entry could be changed without my knowledge? Plus I am using 'RegProt' that is supposed to inform me when changes are made to that file. Is this also a flaw?
    LoneLurker"LoneWanderer""Adults are obsolete children. Dr. Seuss
    Win7 Pro SP1 x64;FireFox V. current: SBS&D V. current; WinPatrol, WinPrivacy, WinAntiRansom

  4. #4
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    I’m sorry, I should have explained: In Spybots detections the "!=" means not equal. So the detection is looking for anything other than a "dword:00000000". i.e Registry key !=W=0 is Registry key not equal to a dword:00000000.

    I can’t explain your findings that the key is a dword:00000000 and got detected.

    The only thing that I can suggest is:
    1. Ignore the detection for the time being and
    2. Keep you eye on the following thread and see if Yodama determines more regarding the detection.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  5. #5
    Senior Member LoneLurker's Avatar
    Join Date
    Nov 2005
    Location
    Texas, USofA
    Posts
    109

    Default

    Quote Originally Posted by md usa spybot fan
    I’m sorry, I should have explained: In Spybots detections the "!=" means not equal. So the detection is looking for anything other than a "dword:00000000". i.e Registry key !=W=0 is Registry key not equal to a dword:00000000.

    I can’t explain your findings that the key is a dword:00000000 and got detected.

    The only thing that I can suggest is:
    1. Ignore the detection for the time being and
    2. Keep you eye on the following thread and see if Yodama determines more regarding the detection.
    "md usa spybot fan,"

    Excuse me for not knowing this as I am not a programmer nor any of the other nerds. One other point, if I may? You are not "SORRY", you are a very GOOD person because you are here in this forum assisting US Dummies, and we need alot of HELP. Should I repost over in that other thread (?) or would you move this for me?

    TIA,
    LoneLurker"LoneWanderer""Adults are obsolete children. Dr. Seuss
    Win7 Pro SP1 x64;FireFox V. current: SBS&D V. current; WinPatrol, WinPrivacy, WinAntiRansom

  6. #6
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    Quote Originally Posted by LoneLurker
    Should I repost over in that other thread (?) or would you move this for me?
    I don't have any administrative rights in this forum so I can't move the thread. I did PM Yodama to make them aware of this thread.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  7. #7
    Senior Member LoneLurker's Avatar
    Join Date
    Nov 2005
    Location
    Texas, USofA
    Posts
    109

    Default

    Quote Originally Posted by md usa spybot fan
    I don't have any administrative rights in this forum so I can't move the thread. I did PM Yodama to make them aware of this thread.
    "md usa spybot fan,"

    Thank you for all you have done as it is more than I had really expected.
    LoneLurker"LoneWanderer""Adults are obsolete children. Dr. Seuss
    Win7 Pro SP1 x64;FireFox V. current: SBS&D V. current; WinPatrol, WinPrivacy, WinAntiRansom

  8. #8
    Junior Member
    Join Date
    Feb 2006
    Posts
    23

    Default

    I got 98SE and installed Tweak UI and get the same thing.
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoLogOff!=W=0

    It showes up as "NoLogoff"=hex:01,00,00,00

    After letting spybot fix it the logoff was back in the start menu and it was showing up as value data of 0

    I changed it to value data of 1 but it still showed the logoff in the start menu.

    Seeing how spybot keep bring this up in a scan I right clicked on it and picked "Exclude this detection from further searches"

    Is there another fix or is this ok to just "Exclude this detection from further searches"?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •