Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
October 11, 2008, 02:15:00 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
199128
Posts
22884
Topics
54923
Members
Latest Member:
sgtshagnasty
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Desktop Security Products
Comodo Firewall
Help for v3
CounterSpy and Defense+
« previous
next »
Pages:
[
1
]
Author
Topic: CounterSpy and Defense+ (Read 373 times)
Geko
Comodo Member
Offline
Posts: 46
CounterSpy and Defense+
«
on:
December 14, 2007, 04:43:19 PM »
Windows XP Prof
Comodo 3.0.14.276
Each time CounterSpy is loaded Defense+ detects a file. The file is
sbapifs.sys
.
Pending files says that this file is in
C:\windows\system32\drivers
but it does not show. I've already enabled hidden files and folders and its not there. This file is loaded by SBCSSvc.exe. I have SBCSSvc.exe as trusted application.
Now, I wanted to submit this file but I can't because I don't have it.
I suspect that Defense+ is interfering with CounterSpy.
What should I do? How can CounterSpy load this file?
I have the same problem with a-squred.
Please help
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 665
Re: CounterSpy and Defense+
«
Reply #1 on:
December 14, 2007, 06:32:20 PM »
Hi geko - your .sys file may be created on demand and deleted after use. I saw a bunch of files that were temp files that I could never actually get a look at whenever my system ran - and they were randomly named and were .dll's and .exe's. Turns out that my video card uses the .net framework files which pulls tricks like that. One problem that you will be having with the setup you describe is that even trusted files do not have rights to launch other programs unless you try it in Training Mode. You will always get an Ask pop-up until you either try setting Defense+ to Training Mode for a bit or edit the Access Rights of the program that uses sbapifs.sys. For Training Mode, click Defense+>Advanced>Defense+ Settings> and move the slider to Training Mode and then click Apply. Then run SBCSSvc.exe. You should get a small "Learning..." balloon, and if that works, then it should now have the necessary permissions. Change the Defense+ Mode back to where it was and all should be well.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
Geko
Comodo Member
Offline
Posts: 46
Re: CounterSpy and Defense+
«
Reply #2 on:
December 14, 2007, 07:22:00 PM »
I've explained myself not very well, sorry.
I don't have pop-ups. The only thing that happens is CounterSpy loads
sbapifs.sys
for its active protection. Yes, it might be a temp file. Maybe CounterSpy doesn't need it that much... Don't know how it works (I only see its used when activating realtime protection)
The thing is, it gets on My Pending Files, everytime it activates. Shouldn't this file be on Comodo's Database, so this doesn't happen? If its a safety file this shouldn't happen right?
Please, an explanation.
Logged
AnotherOne
Computer Security Testing Group
Comodo's Hero
Offline
Posts: 665
Re: CounterSpy and Defense+
«
Reply #3 on:
December 14, 2007, 07:43:11 PM »
If you see sbapifs.sys on the Pending list, and it shows up on the Purge list (click the Purge button and a list of the files on the Pending Files list that are no longer on the HD is offered and you have the choice to remove then from the Pending list), then I would assume that it is a file that is created on the fly and vanishes when not in use. You could try to locate it in the directory you mentioned while SBCSSvc.exe is running, but I expect that it will be locked while in use. You may be able to copy it? In any event, it is quite difficult for Comodo users to submit such files, and therefore it is not easy to add to the Safe files database. You could try this: Start SBCSSvc.exe and then open Comodo's interface. Click Defense+>Common Tasks>My Own Safe Files. On that screen, click Add and select Browse Files and navigate to the folder C:\Windows\System32\Drivers and locate sbapifs.svs and select it and click the right arrow to put the file on the Selected files window. Click Apply and (Apply again?) and Close the Safe files window.
Logged
What do you mean, my shoes are on the wrong feet??? These are the only feet I've got!
Geko
Comodo Member
Offline
Posts: 46
Re: CounterSpy and Defense+
«
Reply #4 on:
December 15, 2007, 02:36:57 AM »
Yes, I'm starting to think a rootkit is involved. I don't know much about how rootkits works.
I uninstalled Comodo and CounterSpy. Installed CounterSpy without Comodo. sbapifs.sys is not in the folder again.
And a blank line has been added to msconfig (see the image):
What does this blank line mean?
What can I do now?
Logged
Ron_75
Comodo's Hero
Offline
Posts: 322
Re: CounterSpy and Defense+
«
Reply #5 on:
December 15, 2007, 03:00:55 AM »
Hi Geko,
I came across this post pertaining to the same thing your discussing about
http://forums.comodo.com/general_security_questions_and_comments_not_product_related/sbapifssys-t10687.0.html
Quote
sbapifs.sys
Sbapifs.sys is related to SBAPIFS Active Protection Driver.
Manufacturer: Sunbelt Software
http://www.sunbelt-software.com/
I don't know what counterspy is and have not ever used it so i can't say with any certainty if that file is 100% safe or not, but should be if its located here --> C:\Windows\System32\driver
the file must be getting deleted and creating a new sbapifs.sys eachtime. don't worry about that, I have two files one a .dll by Ms for UPnp for shareaza that keeps doing that so each reboot it ends up in my pending files and i have to put it in my safe file list, reason for that one would be cause I don't use Upnp and have Upnp fully disabled on my system.
the other file is a everest.sys file it ends up in my documet settings temp folder and i always delete stuff there, so eachtime a new everest.sys file is created for the software i got called Everest Ultimate Edition it ends up in my pending file list and i have to re-add it to my safe file list.
hope that helps to let you know thats normal and ain't anything to worry about if its a safe file and not a malicious file or part of a malicious software
regards
Ron
P.S one more thing i did a little bit of googling about that file of yours, its normal for it not to show itself in the C:\Windows\System32\driver folder must just be how counterspy uses that file
Logged
Ron_75
Comodo's Hero
Offline
Posts: 322
Re: CounterSpy and Defense+
«
Reply #6 on:
December 15, 2007, 03:05:59 AM »
just 1 more thing even if the file is in comodo's whitelist of safe files it will keep on re-appearing in your pendling list to be re-added to your safe file list. that .dll Upnp file i have is recognised as safe when i do a lookup so its in comodo's whitelist, but because it keeps automtically being deleted and recreated it still ends up in the pending list on each reboot.
just so you know. would be interesting for a way for comdo to just automatically re-add these files especially when it recognises them as safe files from its whitelist database.
I think we'll have to wait for them to make that happen
if you want to try and find the file though then just load up that dos box and from teh root directory C:\ type dir /a /s /p sbapifs.sys if that file is currently on your hardrive then it will list from Dos. well should do anyway, no harm trying it and see
«
Last Edit: December 15, 2007, 03:13:15 AM by Ron_75
»
Logged
Geko
Comodo Member
Offline
Posts: 46
Re: CounterSpy and Defense+
«
Reply #7 on:
December 15, 2007, 03:07:53 AM »
Oh well... Thanks Ron_75.
The blank line that I talked before is a bug that CounterSpy has on some Windows. The solution to that is deleting the key in regedit.
Logged
lurkingatu2
Comodo Family Member
Offline
Posts: 69
Re: CounterSpy and Defense+
«
Reply #8 on:
December 15, 2007, 03:14:32 AM »
if you need to know if that file (sbapifs.sys) is part of sunbelt counterspy
you can ask here
http://beta.sunbelt-software.com/index.php?sid=12a43d4fcc628bc6bd89db28f0dfc6ca
it's there beta testing fourm it's where i beta tested for counterspy
sorry i can't help more but i doin't have counterspy installed right now
Logged
avira antivir pe classic winpatrol counterspy v2.5 superantispyware pro sandboxie spywareblaster zonedout for ie-spyad hostman with mvp hp host file 1.30ghz amd 256 mem xp pro sp2
Ron_75
Comodo's Hero
Offline
Posts: 322
Re: CounterSpy and Defense+
«
Reply #9 on:
December 15, 2007, 03:18:21 AM »
no prob
your welcome.
some entries for startup exetubales or hidden background launch process are hidden processes, its why some entries for launch process of some vendors software exec files are hidden due to being termed running in background processes, same for some startup entries, so its better to see if you can somehow find out how to check that blank entry instead of just deleting it first, just to make sure what entry it is for.
I know i have 1 or 2 blank entries for a couple of startup processes too but they are all safe and part of some software that just hides showing what file it is and only shows the registry key it belongs too
P.S just read you said that blank line is a bug, i guess no harm in deleting it then. probably best to just untick it and reboot and see if you have no probs and with counterspy then you know its safe to delete that blank line
«
Last Edit: December 15, 2007, 03:21:00 AM by Ron_75
»
Logged
Geko
Comodo Member
Offline
Posts: 46
Re: CounterSpy and Defense+
«
Reply #10 on:
December 15, 2007, 03:33:56 AM »
It's Ok. I've known it's a bug from CounterSpy Forum. The Tech Support says its safe to delete it.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
** New to the Comodo Forum? Start Here! **
-----------------------------
=> New Member Information
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Leak Testing/Attacks/Vulnerability Research
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
===> Virus/Malware Removal Assistance
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Instant Malware Analysis - Online (CIMA)
=> Comodo DiskShield
=> Comodo Disk Encryption
=> Comodo Secure Email (CSE) Product
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo SafeSurf and (Comodo's own toolbar)
=> Backup
===> FAQ for Comodo Backup
===> Help
=> Verification Engine (allows you to verify what you see on the Internet)
=> Comodo Vulnerability Analyzer
=> AntiSpam
=> i-Vault
=> Launch Pad
=> Trusttoolbar
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo Registry Cleaner
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> User Anywhere (Remote Access product)
=> Comodo Meet (Web Conferencing Product)
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Infrastructure Products
-----------------------------
=> ZTL
=> Trustix Enterprise Firewall
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
Page created in 0.201 seconds with 20 queries.
Powered by SMF 1.1.5
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com