Results 1 to 2 of 2

Thread: Norton/Symantec reports Spybot innoculations as "Adware.SystemProcess"

  1. #1
    Junior Member
    Join Date
    Apr 2006
    Location
    NYC
    Posts
    4

    Default Norton/Symantec reports Spybot innoculations as "Adware.SystemProcess"

    I SWEAR this is related! I know this isn't a Symantec board but hear me out! This is ON TOPIC!

    About a day or two ago, computers on my network start reporting that Symantec AntiVirus (Corporate edition 10.1) found and deleted "Adware.SystemProcess". Symantec runs a quickscan on bootup, so that's fine that it cought that. But then it started happening at every boot up on more and more PC's.

    When I looked at the logs in Symantec AV, it said that "Adware.SystemProcess" was baisicly just a bunch of registry entries (keys most likely). All the users under HKEY_USERS had the following entries under Software\microsoft\Windows\Current Version\Internet Settings\P3P\History\:

    • bfast.com
    • commission-junction.com
    • fastclick.com
    • fastclick.net
    • linksynergy.com ... and sometimes
    • qksrv.net


    Neither Symantec nor Spybot detected anything else except maybe some cookies.

    Then after some googling I find this:

    http://answers.yahoo.com/question/in...0224557AAh1WXb

    Basically, someone pointed out in question form that Symantec is reporting these particular innoculations as false positives for adware, and an answerer elaborated perfectly, but neither had a resolution.

    And then I start finding other forums refering back to this URL when I google Adware.SystemProcess Symantec and either Spybot or Spywareblaster.

    So do I sit and wait for Symantec to fix their mistake and send an update that stops the reporting of innoculations as adware? Or do I wait for the anti-malware apps to send an update that makes changes in how those particular innoculations are made?

    Or does everyone who has Spybot, Spywareblaster, AND Symantec have to, from now on, add specific "ignore" entries whenever this problem arises? If so, should we/they put the ingores in the anti-malware or in the anti-virus software?

    Thanks for your time everyone.

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hi,

    this appears a false positive on Symantec's part.

    HKEY_CURRTENT_USER\Software\microsoft\Windows\Current Version\Internet Settings\P3P\History\<domain>

    Stores the behavior for the IE towards the domains listed under the keypath shown above. A data of '5' means that cookies from that site are blocked while a data of '1' would allow all cookies.

    With Spybot S&D's cookie Immunization the data for the sites listed above is set to '5' --> blocked.

    It appears that Symantec detects those ad/tracking sites entered but does not check the data and thus producing the false positives.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •