Results 1 to 10 of 10

Thread: Possible Microsoft.Windows.IEFirewallBypass False Positive

  1. #1
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default Possible Microsoft.Windows.IEFirewallBypass False Positive

    It appears that there may be a defect in the coding of the signature(s) for Microsoft.Windows_IEFirewallBypass. The problem was first reported by Barry in the following thread:

    The following registry entry were Internet Explorer is added to the Windows Firewall exception list but is disabled:

    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer"
    Results in the following detection:

    Code:
    --- Report generated: 2007-10-28 02:00 ---
    
    Microsoft.Windows.IEFirewallBypass: [SBI $FFF24D3C] Settings (Registry value, nothing done)
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Program Files\Internet Explorer\IEXPLORE.EXE
    
    
    --- Spybot - Search & Destroy version: 1.5  (build: 20070924) ---
    That detection is the same as if Internet Explorer is added to the Windows Firewall exception list and is enabled as follows:

    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"

    Code:
    --- Report generated: 2007-10-28 02:03 ---
    
    Microsoft.Windows.IEFirewallBypass: [SBI $FFF24D3C] Settings (Registry value, nothing done)
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Program Files\Internet Explorer\IEXPLORE.EXE
    
    
    --- Spybot - Search & Destroy version: 1.5  (build: 20070924) ---

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Thank you md usa spybot fan, I made a note for the team.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    thanks for reporting,

    this will be taken out of detection with the next update scheduled for the middle of this week.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  4. #4
    Junior Member
    Join Date
    May 2007
    Location
    Oklahoma City
    Posts
    9

    Default

    Thanks for posting this - I had the same problem on two home pc's. At least I am getting smart enough not to "fix" an item until I am SURE that it needs fixing. Appreciate the info.

  5. #5
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    JohnBurns:

    I have not re-tested the false positive. Did the 2007-10-31 or 2007-11-07 update fix the problem?

    Regards,
    md usa spybot fan
    Last edited by md usa spybot fan; 2007-11-07 at 16:30.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  6. #6
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    Yodama:

    Would you please check the Microsoft.Windows.IEFirewallBypass signatures again.

    I retested the Microsoft.Windows.IEFirewallBypass detection as I had originally. It how appears that neither the Enabled nor the Disabled entries are detected.

    In other words the false positive for the following registry entry (Disabled) has been corrected:

    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Disabled:Internet Explorer"
    However, it now appears that there is a false negative (no detection) for following registry entry (Enabled):

    Code:
    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  7. #7
    Junior Member
    Join Date
    May 2007
    Location
    Oklahoma City
    Posts
    9

    Default

    Quote Originally Posted by md usa spybot fan View Post
    JohnBurns:

    I have not re-tested the false positive. Did the 2007-10-31 or 2007-11-07 update fix the problem?

    Regards,
    md usa spybot fan
    Sorry for delay in reply - in answer to your question - no, the 2007-11-07 still has the problem.

  8. #8
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    @md usa spybot fan

    yes we currently deactivated the detection on this.
    It will most likely be reactivated along the updates after the next main release.

    @JohnBurns

    could you post the date of the security.sbi on the computers still showing this issue?

    you can find the date of the securityc.sbi and security.sbi after a scan in advanced mode - tools - view report - view report.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  9. #9
    Junior Member
    Join Date
    May 2007
    Location
    Oklahoma City
    Posts
    9

    Default

    Quote Originally Posted by Yodama View Post
    @md usa spybot fan


    @JohnBurns

    could you post the date of the security.sbi on the computers still showing this issue?

    you can find the date of the securityc.sbi and security.sbi after a scan in advanced mode - tools - view report - view report.
    Not sure exactly what you need. Here is what I can find:

    Spybot - Search & Destroy 1.5.1.17
    Latest Detection 11/7/2007

    eSupport.FFBiosExt: [SBI $12D696B9] System file (File, nothing done)
    C:\WINDOWS\SYSTEM32\drivers\TVICHW32.SYS


    --- Spybot - Search & Destroy version: 1.5 (build: 20071005)

    Hope this helps.

  10. #10
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    JohnBurns:

    Quote Originally Posted by JohnBurns View Post

    eSupport.FFBiosExt: [SBI $12D696B9] System file (File, nothing done)
    C:\WINDOWS\SYSTEM32\drivers\TVICHW32.SYS
    That detection looks more like the one in the following thread rather than the detection being discussed here in this thread:

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz IntelŪ PentiumŪ 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •