Log in

View Full Version : SpyBot Scan Display


mitchsc
Jun 19, 2009, 11:58 AM
I thought I had a virus on my PC based on a SpyBot scan.

So I called Tech Support (in India) for my Security Software (CA) and spoke to a very knowledgeable rep.

He linked to my PC and ran a bunch of diagnostics and said it was clean. No viruses or malware of any kind.

I told him I was perplexed because SpyBot was "hanging up" (hovering) for like 20 minutes on 2 trojans on every scan (Vurtumonde and Zlob). It still was scanning, but those 2 trojan names remained in the SpyBot window.

He was familiar with both trojans and could see my point. He did more testing on my PC. Even looked through the registry manually, but everything was clean.

I ran SpyBot on my wife's PC and my laptop, and it hung up on the same 2 trojans on those computers as well.

Then he got an idea that seemed to explain everything. Does this make sense?

When SpyBot is scanning, there is a bar at the bottom of the SpyBot window that shows the total files to be scanned, the number of files scanned so far, and the name of each "file" that it is scanning at the moment (I thought). That is where I got the names of these 2 trojans.

I assumed that the "file name" listed on the SpyBot bar was the name of a file on my PC. The tech suggested that maybe it is the name of the spyware detection rules that has been downloaded into SpyBot to LOOK FOR, not necessarily what is on my PC. So he thinks that these two trojans may have just been added to SpyBot's detection list during a recent download of new pests to LOOK FOR.

This theory explains everything and makes sense.

Does anyone know if that is how SpyBot works? That is displays what it is "looking for", and not the file names on the PC?

Thanks...

Perito
Jun 19, 2009, 12:15 PM
If it's displaying file names, then it's a file name, not a malware class or type. I believe your tech was telling you the truth.

I ran SpybotS&D on my system and I could see (on the status bar at the bottom) Spybot looking for various bots (Running bot-check (name of bot)). It took longer on some classes of bots than others. I also noticed that it took a long time on my system looking for "Virtumonde.dll". I didn't wait around for Zlob. I suspect that there are a lot of Virtumonde and Zlob types of trojans. I think it's likely that you have no infections that SpybotS&D finds.

If you want a second opinion, run MalwareBytes. I prefer that to SpybotS&D. I think it's more reliable in finding malware:

Malwarebytes.org (http://malwarebytes.org/)

mitchsc
Jun 19, 2009, 01:35 PM
Thank you Perito for confirming that about spybot.

I've heard from others also that MalwareBytes is very good.

The CA tech told me that MalwareBytes runs in the background all the time. So does my CA anti-spyware. I believe that Spybot does not.

If I download MalwareBytes, will it create a conflict with my CA? And/or will it slow down my PC?

Thanks...

Perito
Jun 19, 2009, 02:04 PM
The free version of MalwareBytes doesn't run in the background at all. You have to pay for the "protection" which does that.

I do not believe you'll have a problem with it at all.

mitchsc
Jun 19, 2009, 03:08 PM
Great! Thanks...