Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
4 Pages V  « < 2 3 4  
Reply to this topicStart new topic
SpyBot 1.4 -- possibly something bad attached?, Wanted to add weird site to "safe list"
bloomcounty
post Jun 15 2005, 12:00 PM
Post #46


Member
**
Posts: 93
OS: Windows XP SP2 (laptop)



QUOTE(Metallica @ Jun 15 2005, 10:46 AM)
Hard to tell. If it connects automatically, it could be pre-fetching mail.
Or it could be rearranging files, because your drive is heavily fragmented.


It's not connecting automatically. My dial-up connection box to connect doesn't come up until I actually click "send/receive". I also did that netstat check and it shows that no ports are "listening" (as far as I can tell).

-- bloomcounty
Go to the top of the page
 
+Quote Post
bloomcounty
post Jun 20 2005, 01:36 PM
Post #47


Member
**
Posts: 93
OS: Windows XP SP2 (laptop)



Metallica,

I now have installed AVG and ZoneAlarm (as well as reinstalled SpyBot 1.4, and have Ad-Aware 6 SE too).

I did not run the AVG scan in safe mode (just did the initial scan, which was right after it installed). Here is the log:

Partition table (MBR) ok Quick checked
Boot sector of disk C: ok Quick checked
System registry Software\Microsoft\Windows NT\CurrentVersion\Windows\Load Scanned
System registry Software\Microsoft\Windows NT\CurrentVersion\Windows\Run Scanned
System registry Software\Microsoft\Windows\CurrentVersion\Run Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunOnce Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunOnceEx Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunServices Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunServicesOnce Scanned
System registry Software\Microsoft\Windows\CurrentVersion\Run Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunOnce Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunOnceEx Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunServices Scanned
System registry Software\Microsoft\Windows\CurrentVersion\RunServicesOnce Scanned
System registry Software\Microsoft\Windows\CurrentVersion\Winlogon\Userinit Scanned
System registry SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell Scanned
System registry exefile\shell\open\command Scanned
System registry scrfile\shell\open\command Scanned
System registry scrfile\shell\config\command Scanned
System registry batfile\shell\open\command Scanned
System registry cmdfile\shell\open\command Scanned
System registry comfile\shell\open\command Scanned
System registry piffile\shell\open\command Scanned
System registry giffile\shell\open\command Scanned
System registry htmlfile\shell\open\command Scanned
System registry htafile\shell\open\command Scanned
System registry jpegfile\shell\open\command Scanned
System registry txtfile\shell\open\command Scanned
System registry regfile\shell\open\command Scanned
System registry cplfile\shell\cplopen\command Scanned
System registry Word.Document.8\shell\open\command Scanned
System registry WordPad.Document.1\shell\open\command Scanned
C:\PROGRA~1\ACCESS~1\WORDPAD.EXE ok Quick checked
C:\PROGRA~1\GRISOFT\AVGFRE~1\avgamsvr.exe ok Quick checked
C:\PROGRA~1\GRISOFT\AVGFRE~1\avgcc.exe ok Quick checked
C:\PROGRA~1\GRISOFT\AVGFRE~1\avgemc.exe ok Quick checked
C:\PROGRA~1\GRISOFT\AVGFRE~1\avgw.exe ok Quick checked
C:\PROGRA~1\INTERN~1\IEXPLORE.EXE ok Quick checked
C:\Program Files\Microsoft Office\Office\WINWORD.EXE ok Quick checked
C:\WINDOWS\NOTEPAD.EXE ok Quick checked
C:\WINDOWS\REGEDIT.EXE ok Quick checked
C:\WINDOWS\RUNDLL32.EXE ok Quick checked
C:\WINDOWS\SCANREGW.EXE ok Quick checked
C:\WINDOWS\SYSTEM\MSHTA.EXE ok Quick checked
C:\WINDOWS\SYSTEM\SHELL32.DLL ok Quick checked
C:\WINDOWS\SYSTEM\SYSTRAY.EXE ok Quick checked
C:\WINDOWS\TASKMON.EXE ok Quick checked
C:\WINDOWS\SYSTEM\kernel32.dll ok Quick checked
C:\WINDOWS\SYSTEM\wsock32.dll ok Quick checked
C:\WINDOWS\SYSTEM\user32.dll ok Quick checked
C:\WINDOWS\SYSTEM\shell32.dll ok Quick checked


...looks like everything's clear, right? So do I need to rerun it in SAFE MODE? If so, how do I do that?

Also, what should all my settings be in AVG?

As for ZoneAlarm, for the general settings, I have it set to:
- Check for updates: automatically
- Load ZondAlarm at startup

...but do I check "protect ZoneAlarm client" -- what is that?

What should my settings be for the Contact with Zone Labs section?

In the Firewall Section, I have it set as:
Main - with both Internet zone security and trusted zone security set for HIGH
Zones - Trusted Zone has only one thing -- it lists a PPP Adapter. Originally, this was all zeros for the IP/Site Address column (0.0.0.0/0.0.0.0 or something like that). But *now* it actually has an IP Address / Site address listed. What is this? Should that be there?

I have the Program Control set to Medium (so it asks me each time), with the AVG Email scanner and update downloader, firefox and outlook express all set with a checkmark for trusted. Is that right?

Email protection is sest to off (since AVG is doing that).

I finally had it stop showing me the blocked intrustions since there's been 166 of them since yesterday (and I've only been on-line maybe a total of an hour at most!) -- there were like 10 in the first two minutes! And I only have dial-up! Is that normal or is it a sign that something weird's going on? (They were all listed as "medium" except for two listings that were "high".)

Any reason to post that log? If so, how can I?

And what should the rest of the setting, if any, be set to?


So should my computer be safe now? Can I be secure in knowing that there's nothing bad on there?

Thanks for the help! smile.gif

-- bloomcounty
Go to the top of the page
 
+Quote Post
Bazzrr
post Jul 20 2005, 06:35 AM
Post #48


Member
**
Posts: 13
From: Southland - New Zealand
OS: XP



Not sure if you have taken this further, but have just seen the same thing
Here is a link to Microsoft:
http://support.microsoft.com/?kbid=902956

I found the Microsoft link at this site:
http://malektips.com/spybot_search_and_destroy_0041.html

It would appear that Spybot is attempting to block 139mm.com by adding to the restricted sites zone.
But Microsoft Anti-Spyware has a problem with Spybot doing this, (and possibly for other sites)

To quote the Microsoft site:
"The real-time monitoring does not distinguish between additions to the restricted sites zone and additions to the trusted sites zone."

So you should click "allow" when Microsoft prompts you, and Spybot is then able to do the block.

Hope this makes it clear.
Go to the top of the page
 
+Quote Post
bloomcounty
post Jul 26 2005, 10:08 AM
Post #49


Member
**
Posts: 93
OS: Windows XP SP2 (laptop)



QUOTE(Bazzrr @ Jul 20 2005, 05:35 AM)
Not sure if you have taken this further, but have just seen the same thing
Here is a link to Microsoft:
http://support.microsoft.com/?kbid=902956

I found the Microsoft link at this site:
http://malektips.com/spybot_search_and_destroy_0041.html

It would appear that Spybot is attempting to block 139mm.com by adding to the restricted sites zone.
But Microsoft Anti-Spyware has a problem with Spybot doing this, (and possibly for other sites)

To quote the Microsoft site:
"The real-time monitoring does not distinguish between additions to the restricted sites zone and additions to the trusted sites zone."

So you should click "allow" when Microsoft prompts you, and Spybot is then able to do the block.

Hope this makes it clear.
[snapback]239243[/snapback]



Yeah, that makes sense -- thanks! I actually decided not to use SpyBot on the machine at work (we've got Ad-Aware and eTrust and our computer-guys said that should be enough). And at home I've got Windows 98, so I can't use MS Anti-spyware, so I use Ad-Aware and Spybot (and AVG and that free firewall program whose name escapes me at the moment).

-- bloomcounty
Go to the top of the page
 
+Quote Post

4 Pages V  « < 2 3 4
Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts 9 / 1,184 7th April 2008 - 12:17 PM
Winterblast started - last by Essexboy
No new   34 / 1,266 24th May 2009 - 04:42 PM
kwisj started - last by Rorschach112
No New Posts   2 / 155 13th August 2009 - 05:14 PM
rawbery79 started - last by emeraldnzl
No new   14 / 218 23rd August 2009 - 01:33 PM
bustermoves started - last by Transience

RSS Time is now: 21st November 2009 - 06:38 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising