See previous post about the new version 1.6 of Spybot SD and its issues. I've updated my Bart plugin (tested with XP SP2 code base, Bart Builder 3.1.3) to address these, and offer it here, along with .REG for control in Windows.
To use the plugin, do this:
- Navigate into your Bart Builder plugin folder
- Create new folder called SpybotSD and enter it
- Copy this post's plugin files to this location
- Create a subfolder Files within this location and enter it
- Copy the installed Spybot 1.6 subtree contents into here
The plugin is written with these assumptions and dependencies:
- Standard Bart PE Builder with nu2menu as shell
- Cmdow utility in Bart included Bin folder (not essential)
- Paraglider's RunScanner plugin in plugin\RunScanner
Cmdow hides windows for processors, and I use it to hide the .CMD launcher; it's purely cosmetic, so if missing, the plugin will still work. Because Cmdow can be dropped on systems and used maliciously, many scanners will detect it as a "potentially unwanted program", and fair enough!
RunScanner allows registry-aware tools to run relative to an inactive set of hives, rather than those of the booted OS. Spybot has native awareness of this situation, so theoretically doesn't need RunScanner, but I find I get better detections if I use it anyway. If RunScanner isn't present, you'd have to revise the .INF and .XML for it else it won't work.
This determines how Spybot 1.6 is integrated into the Bart CDR at build time.
; PE Builder v3 plug-in INF file for Spybot - Search & Destroy by Safer Networking Ltd.
; Created by Patrick M. Kolla, Jochen Tösmann and modified by cquirke for Spybot 1.6
Signature= "$Windows NT$"
Name="Spybot - Search & Destroy"
0x4, "Safer Networking Limited\Tweaks", "DisableTempFolderCleaning", 0x1
0x1, "Paraglider\RunScanner\SpybotSD.exe", "HKLM", "Software\Safer Networking Limited\Tweaks"
Ensure that when you copy and paste these files, that they are free of HTML tags and formatting junk, and that long lines (e.g. the two lines in the last section) are not broken. The above differs from Safer Networking's plugin for 1.5, in that:
- It includes new code file sqlite3.dll
- It suppresses automatic temp file clearance
- It persists the above setting through RunScanner
The last is useful, so you don't have to use non-zero /t parameters in an attempt to delay registry redirection until Spybot has checked for the "disable temp clearance" setting.
This integrates Spybot 1.6 into the Bart menu system, and is referenced from the .INF during build time.
<!-- Nu2Menu entry for SpybotSD -->
<MITEM TYPE="ITEM" DISABLED="@Not(@FileExists(@GetProgramDir()\..\SpybotSD\SpybotSD.exe))" CMD="RUN" FUNC="@GetProgramDir()\..\SpybotSD\SpybotSD.exe">Spybot 1.5.2</MITEM>
You may change this to strip references to RunScanner, relocate it to a different menu flyout etc. or if you're fed up with disordered menus, you may simply leave out this file (; comment it out in the .INF) and add your reference directly to plugin\nu2menu\nu2menu.xml - once again, watch out for long lines; there is in fact only one line between the MENU ID and /MENU tags.
This launches Spybot 1.6 from the nu2menu entry at runtime.
Set Opt=/t 0
If Not Defined Debug (
Cmdow @ /HID
%~dp0..\..\Bin\Cmdow @ /HID
) Else (
Echo ProgDir %~dp0
Echo Prog %Prog%
Echo Launch %Launch%
Echo Opt %Opt%
If Exist "%~dp0Files\%Prog%" Set ProgDir=%~dp0Files\
If Exist "%~dp0%Prog%" Set ProgDir=%~dp0
If Defined ProgDir (
If "%SystemDrive%"=="%~d0" (
Start %Launch% %Opt% %ProgDir%%Prog%
) Else (
) Else (
Title Error - target executable not found!
Echo "%Prog%" not found in %~dp0 or %~dp0Files\ - abort!
Exit /b 1
If Defined Debug (
Exit /b 0
You can edit this to strip out the "debug" part (define the Debug variable to enable it), as well as references to Cmdow and RunScanner. By changing the variables, you can use this for other "easy" tool plugins (e.g. HiJackThis).
The logic goes as follows; if boot drive is same as where we are, then we're Bart-booted and need to apply RunScanner redirection, else we're not, and can run the tool directly. This logic will also not use RunScanner if run from a WinPE 2.0 boot disk, which is OK with me as I don't know how safe RunScanner is for Vista hives.
An extra bit of logic is applied to deriving the path to the tool, so that the .CMD will work when run from the pre-build subtree. This is also why the .XML uses relative "GetProgramDir()\..\" paths, rather than the more commonly used "GetProgramDrive()\Programs\" paths that break in the pre-build or pre-iso environments.
You can also control some of Spybot's potentially unwanted behaviours via .REG in Windows, similar to the Software.AddReg section in the .INF above:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Safer Networking Limited\Tweaks]
"HKLM"="Software\\Safer Networking Limited\\Tweaks"
The second part of the above will pre-load appropriate settings for a Bart session using RunScanner, in case the RunScanner's parameters cause it to read its settings from the hard drive's hives.
Some settings can be changed interactively, e.g. disabling the intrusive Tea Timer feature, while others have to be excluded at the time of installation. One of the latter, is the right-click context menu action to scan using Spybot, which annoyed these folks who offer this fix:
Windows Registry Editor Version 5.00
The * association is applied to all things, hence all things can be right-clicked and scanned. There's an Undo .REG in the same post in that thread.