Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 13th, 2002, 06:43 AM
john2g's Avatar
john2g john2g is offline
Frequent Poster
 
Join Date: Feb 2002
Location: UK
Posts: 207
Default SpyBot S&D update 07/13/03

4 additions
__________________
All electrons used in the creation of this message were recycled. No electrons were harmed or mistreated in any manner.
  #2  
Old July 13th, 2002, 07:21 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re:SpyBot S&D update 07/13/03

Updated, ran it, and it detected what it said was a keylogger file

Slient Guard, in C:\Windows\System\Code_msg.hlp and in HKLM\Software\Microsoft\CurrentVersion\SharedDlls\C:\Windows\System\Code_msg.hlp

Hmmm; strange name for a shared dll...

I wonder where that came from, and whether it is in fact something that's capable of doing any harm at all.

Somehow I doubt it...

__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #3  
Old July 13th, 2002, 07:25 AM
spy1's Avatar
spy1 spy1 is offline
Massive Poster
 
Join Date: Dec 2002
Location: Clover, SC
Posts: 3,138
Default Re:SpyBot S&D update 07/13/03

And, of course, you sent in a 'Bug Report' , questioning the finding? Pete
__________________
"When fascism comes to America it will come wrapped in the flag and carrying a cross." Sinclair Lewis
  #4  
Old July 13th, 2002, 07:32 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re:SpyBot S&D update 07/13/03

No, I didn't, to tell you the truth.

I could post at the Spybot forum, though.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #5  
Old July 13th, 2002, 07:37 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re:SpyBot S&D update 07/13/03

I did some research, and I believe it may pertain to the Pervasive Software Btrieve Database Manager, in which case it probably belongs to my Exact Accounting software.

Now that I think of it, a Btrieve file has been known for wanting to dial out once, and I denied it access.

He may have a point, although I don't think it's a serious issue.

I don't think I'll report it as a 'bug' for the time being.

I'll keep my backups, and see how my accounting software will behave.



__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #6  
Old July 13th, 2002, 08:35 AM
MyNethingyman
 
Posts: n/a
Default Re:SpyBot S&D update 07/13/03

ISCOUT32.EXE, would have been my first guess Tony.

http://www.pervasive.co.jp/support/Embedded/psql75/wizard/nojava.html




But Spybot may think it is looking at this...


http://www.adavi.com/overview.cfm#sg
  #7  
Old July 13th, 2002, 09:16 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re:SpyBot S&D update 07/13/03

That's certainly what it thinks it is.

Thanks for the first link.

Incidentally, reading that, I think the file that tried to phone out some time ago was probably W3DBSMGR.EXE.

Anyway, I think I'll restore the file and will tell Spybot to put it on the ignore list.
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #8  
Old July 13th, 2002, 09:20 AM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re:SpyBot S&D update 07/13/03

I just started up Exact, and was greeted by a LnS notification.

Would you believe that....

What do you think: is it up to no good?

[year-old attachment deleted by admin]
__________________
Tony < > CLSID List - A Collection of Autostart Locations
  #9  
Old July 13th, 2002, 02:34 PM
MyNethingyman
 
Posts: n/a
Default Re:SpyBot S&D update 07/13/03

Tony,
Put that thing away before you hurt yourself.
Be Well,
John

Pervasive.SQL USER,S GUIDE ON LINE.

http://old.sw.com.sg/products/psql20...e/3smartc7.htm



_______________________________________________

4.- Check the Registry (Btrieve 7.x)


It is possible that if at least one workstation has a corrupted registry can cause problems for all other workstations.


Btrieve version 7.x stores its settings in the Registry of the local computer. Sometimes the settings for Btrieve get corrupted and that can cause problems trying to run Adapt.


To check if the registry for Btrieve v7.x is corrupted, run the program W3DBSMGR.EXE (normally located in the \Windows\System\ directory on each workstation). Once you execute this file, If you see the "Pervasive Database" icon in the system try, the registry is OK; but, if you see an error message, part of the registry that contains the setting for Btrieve is corrupted.


Two files containing the exported settings for the workstation can be bound in the Adapt CD under \Tools\Btriv70\Registry

BTRIEVE.REG contains the exported Btrieve settings for an environment on which Btrieve is running on the server.
BTR&REQ.REG contains the exported Btrieve settings for an environment on which Btrieve is not running on the server.


By double clicking on either one of these files, you will setup the current machine with those settings overwriting the current Btrieve registry.


The easiest way is to look at the version of the W3ODBCCI.DLL, W3ODBCEI.DLL, W3DBSMGR.EXE, or W3DADBV2.DLL. The versions break down like this:
7.50 - Original release of Pervasive.SQL 2000
7.51 - Service Pack 1
7.82 - Service Pack 2a
7.90 - Service Pack 3
7.94 - Service Pack 4




  #10  
Old July 13th, 2002, 02:42 PM
TonyKlein's Avatar
TonyKlein TonyKlein is offline
Security Expert
 
Join Date: Feb 2002
Location: The Netherlands
Posts: 3,956
Default Re:SpyBot S&D update 07/13/03

Thanks John,

I remember I actually read that article when researching a W3DBSMGR.EXE invalid page fault that occurred just after quitting my accounting program.

Btrieve always sort of lingers behind in the system tray, and shuts down a little later.

However, it's part and parcel of my accounting software, of which I did a fresh install a couple of weeks ago, so there's not much more that I can do.

And anyway, I'm not bothered, just curious..

Thanks again!

Cheers,
__________________
Tony < > CLSID List - A Collection of Autostart Locations
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:22 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums