(Msg. 2) Posted: Mon May 26, 2008 3:16 pm
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
Massimo wrote:
> Hello,
>
> Spybot scan mentions this registry change:
>
> Microsoft Windows SecurityCenter.FirewallOverride
> (SBI $0C94D702) settings
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
> (is not) dword:0
>
> What does it mean and what would be advisable to do?
>
> Thanks,
>
> Massimo
(Msg. 3) Posted: Mon May 26, 2008 5:57 pm
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
From: "Massimo"
| Hello,
|
| Spybot scan mentions this registry change:
|
| Microsoft Windows SecurityCenter.FirewallOverride
| (SBI $0C94D702) settings
| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
| (is not) dword:0
|
| What does it mean and what would be advisable to do?
|
| Thanks,
|
| Massimo
If you are using a 3rd party FireWall application, ignore it.
(Msg. 4) Posted: Mon May 26, 2008 5:57 pm
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
David H. Lipman wrote:
> From: "Massimo"
>
> | Hello,
> |
> | Spybot scan mentions this registry change:
> |
> | Microsoft Windows SecurityCenter.FirewallOverride
> | (SBI $0C94D702) settings
> | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
> | (is not) dword:0
> |
> | What does it mean and what would be advisable to do?
> |
> | Thanks,
> |
> | Massimo
>
> If you are using a 3rd party FireWall application, ignore it.
>
If I recall, it just means that the Windows firewall manager cannot see
and control whatever firewall is in use.
Search and Destroy has the ability to exclude any detection if that is
the case.
(Msg. 5) Posted: Mon May 26, 2008 8:46 pm
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
(Msg. 6) Posted: Mon May 26, 2008 8:47 pm
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
Hello David,
On Mon, 26 May 2008 17:57:20 GMT, "David H. Lipman"
wrote:
>From: "Massimo"
>
>| Hello,
>|
>| Spybot scan mentions this registry change:
>|
>| Microsoft Windows SecurityCenter.FirewallOverride
>| (SBI $0C94D702) settings
>| HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
>| (is not) dword:0
>|
>| What does it mean and what would be advisable to do?
>|
>| Thanks,
>|
>| Massimo
>
>If you are using a 3rd party FireWall application, ignore it.
I use Comodo firewall...
Thanks for the clear answer.
(Msg. 7) Posted: Mon May 26, 2008 8:49 pm
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
Hello,
On Mon, 26 May 2008 12:34:11 -0600, Lon
wrote:
>David H. Lipman wrote:
>> From: "Massimo"
>>
>> | Hello,
>> |
>> | Spybot scan mentions this registry change:
>> |
>> | Microsoft Windows SecurityCenter.FirewallOverride
>> | (SBI $0C94D702) settings
>> | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
>> | (is not) dword:0
>> |
>> | What does it mean and what would be advisable to do?
>> |
>> | Thanks,
>> |
>> | Massimo
>>
>> If you are using a 3rd party FireWall application, ignore it.
>>
>If I recall, it just means that the Windows firewall manager cannot see
>and control whatever firewall is in use.
>
>Search and Destroy has the ability to exclude any detection if that is
>the case.
(Msg. 8) Posted: Wed Apr 01, 2009 5:15 am
Post subject: Re: Spybot scans registry change... [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
On Mon, 26 May 2008 15:16:51 +0200, Massimo
wrote:
> Hello,
>
> Spybot scan mentions this registry change:
>
> Microsoft Windows SecurityCenter.FirewallOverride
> (SBI $0C94D702) settings
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallOverride
> (is not) dword:0
>
> What does it mean and what would be advisable to do?
>
I know this post is very, very late, but I just added this group.
If you are running an AntiVirus, like Symantec (aka Norton), they turn
off various Windows features because the AntiVirus handles these. The
"FirewallOveride" is just one of them.
The upshot is, with the AntiVirus installed, having these features in
Windows disabled is normal. SpyBot sees this. To prevent future
notices from SpyBot you use the set to ignore these problems as
follows:
Change to Advanced Mode
Settings (on sidebar)
Select Ignore Products
Click the Security.sb1 tab
Now use the checkboxes to set ignore for;
...Microsoft.Windows.AppFirewassBypass
...Microsoft.WindowsSecurityCenter.FirewallBypass
Change back to Default Mode
You should also set ignore for whatever else is normal for you, such
as the WindowsSecurityCenter overrides for Automatic Updates (I have
auto-updates turned off on my home system, I run Microsoft Updates
manually each Wednesday).
--
======== Tecknomage ========
Computer Systems Specialist
IT Technician
San Diego, CA
All times are: Eastern Time (US & Canada) Goto page 1, 2
Page 1 of 2
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum