{"id":415,"date":"2008-05-25T16:45:02","date_gmt":"2008-05-25T21:45:02","guid":{"rendered":"http:\/\/alsplace.aldenbaker.com\/alsplace\/opsys\/os-xp\/415\/xp-sp3-triggers-false-positives-in-security-apps\/"},"modified":"2008-05-25T16:55:24","modified_gmt":"2008-05-25T21:55:24","slug":"xp-sp3-triggers-false-positives-in-security-apps","status":"publish","type":"post","link":"http:\/\/alsplace.info\/?p=415","title":{"rendered":"XP SP3 triggers false positives in security apps"},"content":{"rendered":"\n<!-- ALL ADSENSE ADS DISABLED -->\n<p align=\"justify\"> <\/p>\n<div align=\"justify\">\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"0\" width=\"100%\" summary=\"Top Story summary\" bgcolor=\"#ffffff\">\n<tr>\n<td width=\"110\" align=\"left\" valign=\"top\"><img decoding=\"async\" loading=\"lazy\" src=\"http:\/\/WindowsSecrets.com\/images\/wsn\/Scott-Dunn-2.jpg\" border=\"0\" alt=\"Scott Dunn\" title=\"Scott Dunn\" width=\"110\" height=\"100\" align=\"left\" \/><\/td>\n<td width=\"510\" align=\"left\" valign=\"top\">By Scott Dunn<\/p>\n<p> <strong>Installing Windows XP Service Pack 3 can cause your anti-malware programs to report the presence of Trojans and keyloggers that aren&#39;t there.<\/strong><\/p>\n<p> The false positives have blocked important system files in some cases, and in others they have misled users into reinstalling XP. <\/td>\n<\/tr>\n<\/table><\/div>\n<p align=\"justify\"> <strong>SP3 causes some malware scanners to cry &quot;wolf&quot; <\/strong><\/p>\n<p> <a href=\"http:\/\/WindowsSecrets.com\/links\/casamqr63t9zd\/6bafe3h\/?url=www.pctools.com%2Fforum%2Fshowthread.php%3Ft%3D51766%26page%3D3%26highlight%3DTrojan-spyware.Pophot.WX\" title=\"http:\/\/windowssecrets.com\/links\/casamqr63t9zd\/6bafe3h\/?url=www.pctools.com%2Fforum%2Fshowthread.php%3Ft%3D51766%26page%3D3%26highlight%3DTrojan-spyware.Pophot.WX\">Comments<\/a> on a PC Tools forum confirm customer reports that the company&#39;s Spyware Doctor program generates a false positive on systems with Windows XP SP3.<\/p>\n<p> Similarly, at least one site claims that Symantec&#39;s Norton Internet Security software identifies a common system file as a keylogger.<\/p>\n<p> ReviewSaurus <a href=\"http:\/\/WindowsSecrets.com\/links\/casamqr63t9zd\/ea29d8h\/?url=www.reviewsaurus.com%2Ftips-tricks%2Fwindows-xp-sp3-service-pack-3-install-problems%2F\" title=\"http:\/\/windowssecrets.com\/links\/casamqr63t9zd\/ea29d8h\/?url=www.reviewsaurus.com%2Ftips-tricks%2Fwindows-xp-sp3-service-pack-3-install-problems%2F\">reports<\/a> that XP SP3 causes Norton Internet Security to identify <strong>ctfmon.exe<\/strong> as a keylogger (a kind of malware that records your keystrokes to capture passwords and other important data).<\/p>\n<p> In reality, the <strong>ctfmon.exe<\/strong> file in your Windows\\System32 folder is a Microsoft system file that enables alternative input methods such as speech, tablet, or on-screen keyboard.<\/p>\n<p> A spokesperson for Symantec was not immediately available for comment.<\/p>\n<p> In the case of Spyware Doctor, the popular antispyware tool from PC Tools detects <strong>Trojan-Spy.Pophot.WX<\/strong> in <strong>RunDLL32.exe<\/strong> even if the system is uninfected. <strong>RunDLL32.exe<\/strong> is a system file that Windows uses to run code in dynamic link library (DLL) files.<\/p>\n<p> The scan may also implicate other related system files, according to a <a href=\"http:\/\/WindowsSecrets.com\/links\/casamqr63t9zd\/27921bh\/?url=fearbotulism.blogspot.com%2F2008%2F05%2Fentirely-unacceptable.html\" title=\"http:\/\/windowssecrets.com\/links\/casamqr63t9zd\/27921bh\/?url=fearbotulism.blogspot.com%2F2008%2F05%2Fentirely-unacceptable.html\">report<\/a> on the blog A Healthy Fear of Botulism.<\/p>\n<p> By default, Spyware Doctor prevents any files it identifies as infected from running. If an important system file such as <strong>RunDLL32.exe<\/strong> is flagged incorrectly, the result can be disastrous for your PC. For example, users may be blocked from opening Windows Control Panel or using System Restore, among other operations.<\/p>\n<p> One user who contacted us noted that blocking <strong>RunDLL32.exe<\/strong> created &quot;an endless loop of scanning to remove the file, rebooting, finding the file again.&quot;<\/p>\n<p> &quot;I&#39;ve lost more than two days trying to fix something that was never broken,&quot; he adds. &quot;As far as mistakes go, this is pretty major.&quot;<\/p>\n<p> Other Spyware Doctor customers just gave up: &quot;I had the same problem today,&quot; <a href=\"http:\/\/WindowsSecrets.com\/links\/casamqr63t9zd\/97d7fch\/?url=forums.computing.co.uk%2Fthread.jspa%3FmessageID%3D1066398\" title=\"http:\/\/windowssecrets.com\/links\/casamqr63t9zd\/97d7fch\/?url=forums.computing.co.uk%2Fthread.jspa%3FmessageID%3D1066398\">reported<\/a> Dave (screen name doz3r). &quot;I got tired of fighting with it and just reinstalled the OS.&quot;<\/p>\n<p> For its part, PC Tools claims that a patch is in the works. &quot;We are implementing a fix immediately,&quot; <a href=\"http:\/\/WindowsSecrets.com\/links\/casamqr63t9zd\/1f80ech\/?url=www.pctools.com%2Fforum%2Fshowpost.php%3Fp%3D184523%26postcount%3D27\" title=\"http:\/\/windowssecrets.com\/links\/casamqr63t9zd\/1f80ech\/?url=www.pctools.com%2Fforum%2Fshowpost.php%3Fp%3D184523%26postcount%3D27\">wrote<\/a> Super Moderator Anthony Chen on the PC Tools forum.<\/p>\n<p> As of Wednesday evening, PC Tools has yet to make a fix available through the company&#39;s Smart Update feature.<\/p>\n<p> <strong>Until there&#39;s a fix, there&#39;s a workaround <\/strong><\/p>\n<p> In the case of the Norton Internet Security, ReviewSaurus advises users to ignore the false warning about <strong>ctfmon.exe<\/strong>.<\/p>\n<p> Until a fix is available from PC Tools, Chen advises customers to add <strong>RunDLL32.exe<\/strong> to the global action list manually. The workaround consists of the following steps:<\/p>\n<p> <strong>Step 1.<\/strong> In the Spyware Doctor window, click the Settings button on the left.<\/p>\n<p> <strong>Step 2.<\/strong> Click Global Action List to the right of that.<\/p>\n<p> <strong>Step 3.<\/strong> At the bottom of the window, click Add.<\/p>\n<p> <strong>Step 4.<\/strong> In the New Rule dialog box, choose &quot;File on disk&quot; from the &quot;Select data type&quot; drop-down list.<\/p>\n<p> <strong>Step 5.<\/strong> To the right of the text box below, click the &#8230; button to browse for a file. Locate and select <strong>RunDLL32.exe<\/strong> in the Windows\\System32 folder.<\/p>\n<p> <strong>Step 6.<\/strong> Make sure &quot;Always allow&quot; is selected in the drop-down list at the bottom and click the Add button.<\/p>\n<p> <strong>Other XP SP3 compatibility problems may yet loom <\/strong><\/p>\n<p> This is not the first problem created by Microsoft&#39;s latest (and last) service pack for Windows XP. Earlier this month, some HP PCs with an AMD processor experienced endless reboots after SP3 was installed.<\/p>\n<p> These and other issues are documented by Windows Secrets columnist Susan Bradley&#39;s <a href=\"http:\/\/WindowsSecrets.com\/links\/casamqr63t9zd\/cde76fh\/?url=atch0\" title=\"http:\/\/windowssecrets.com\/links\/casamqr63t9zd\/cde76fh\/?url=atch0\">Patch Watch<\/a> column in the paid section of this week&#39;s newsletter, as well as in her <a href=\"http:\/\/www.windowssecrets.com\/2008\/05\/15\/07-XP-Service-Pack-3-crashes-HPs-AMD-based-PCs#\" title=\"http:\/\/www.windowssecrets.com\/2008\/05\/15\/07-XP-Service-Pack-3-crashes-HPs-AMD-based-PCs#\">May 15<\/a> column. Bradley also <a href=\"http:\/\/www.neighborhoodrealtyonline.com\/\">where to buy viagra without a prescription<\/a>  provides advice on preparing for SP3 in the paid section of the <a href=\"http:\/\/www.windowssecrets.com\/2008\/05\/01\/08-What-you-need-to-know-before-you-install-XP-SP3\" title=\"http:\/\/www.windowssecrets.com\/2008\/05\/01\/08-What-you-need-to-know-before-you-install-XP-SP3\">May 1<\/a> issue.<\/p>\n<p> If you are concerned about the effect the collection of patches that comprise XP SP3 will have on your PCs, wait a while before downloading and installing the service pack.<\/p>\n<p> Check the support sites of the vendors of your most important products for news of compatibility issues with SP3. As the problems experienced by users of these anti-malware programs show, a collection of patches as large as SP3 may require some patches of its own. <\/p>\n<hr \/>\n<p>After the release of <strong>Windows XP SP3<\/strong> there are thousands of people who are facing various problems. <strong>The problems are from installation of SP 3<\/strong>, to post installation problems. All these problems occur because people really don&rsquo;t follow the correct way of installing the service pack :<\/p>\n<p><strong>In order to ensure that you don&rsquo;t face such a problem please follow these steps<\/strong> &#8211;<\/p>\n<p>1. Download the <a href=\"http:\/\/www.microsoft.com\/downloads\/info.aspx?na=90&amp;p=&amp;SrcDisplayLang=en&amp;SrcCategoryId=&amp;SrcFamilyId=5b33b5a8-5e76-401f-be08-1e1555d4f3d4&amp;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2fd%2f3%2f0%2fd30e32d8-418a-469d-b600-f32ce3edf42d%2fWindowsXP-KB936929-SP3-x86-ENU.exe\" target=\"_blank\">service pack 3 from here (official microsoft download)<\/a> (direct link).<br \/> 2. Restart the computer and boot the computer in safe mode.<br \/> 3. Install the SP 3 from there.<\/p>\n<p><strong>Note<\/strong> : If you don&rsquo;t know how to boot in safe mode, then simply exit all the third party software and especially antivirus, firewall, anti-spyware etc.<\/p>\n<p><strong>Please note<\/strong> : Some people who are using Norton internet security are reporting that it&rsquo;s giving false positives after they install SP3. It&rsquo;s telling ctfmon.exe as a keylogger. It&rsquo;s just a false positive and you should ignore that alert from Norton internet security.<\/p>\n<!-- Social Bookmarks BEGIN -->\n<div class=\"social_bookmark\">\n<a title=\"Click me to see the sites.\" href=\"#\" onclick=\"$$('div.d415').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;\"><strong><em>Bookmark to:<\/em><\/strong><\/a>\n<br \/>\n<div class=\"d415\" style=\"overflow:hidden\">\n<br \/>\n<br \/>\n<a style=\"font-size:90%;text-align: right; \" title=\"Click me to hide the sites.\" href=\"#\" onclick=\"$$('div.d415').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;\">Hide Sites<\/a>\n<\/div>\n<\/div>\n<!-- Social Bookmarks END -->\n<script type=\"text\/javascript\">$$('div.d415').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); <\/script>","protected":false},"excerpt":{"rendered":"<p>By Scott Dunn Installing Windows XP Service Pack 3 can cause your anti-malware programs to report the presence of Trojans and keyloggers that aren&#39;t there. The false positives have blocked important system files in some cases, and in others they have misled users into reinstalling XP. SP3 causes some malware scanners to cry &quot;wolf&quot; Comments [&hellip;]<\/p>\n<!-- Social Bookmarks BEGIN -->\n<div class=\"social_bookmark\">\n<a title=\"Click me to see the sites.\" href=\"#\" onclick=\"$$('div.d415').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;\"><strong><em>Bookmark to:<\/em><\/strong><\/a>\n<br \/>\n<div class=\"d415\" style=\"overflow:hidden\">\n<br \/>\n<br \/>\n<a style=\"font-size:90%;text-align: right; \" title=\"Click me to hide the sites.\" href=\"#\" onclick=\"$$('div.d415').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;\">Hide Sites<\/a>\n<\/div>\n<\/div>\n<!-- Social Bookmarks END -->\n<script type=\"text\/javascript\">$$('div.d415').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); <\/script>","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[9],"tags":[],"_links":{"self":[{"href":"http:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/posts\/415"}],"collection":[{"href":"http:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=415"}],"version-history":[{"count":0,"href":"http:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/posts\/415\/revisions"}],"wp:attachment":[{"href":"http:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=415"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}