PDA

View Full Version : Spybot Program Files Folder Opens on Every Startup



roger2
2007-06-13, 11:57
Hi Forum, I had a look to see if anyone had posted this q before but could not see one (your search is a bit rubbish though).

However, when I start my machine up it always opens the spybot program files folder, any ideas why or how to resolve this?

Best regards

Roger

Zenobia
2007-06-14, 00:51
I see two other people here had this happen,but can't find one where it was fixed.You could post your system startup list,I guess,and see if there's anything in there.To do that,you'd open Spybot,select mode up top,then Advanced Mode,then over to the left,select Tools,then System Startup.Then click Export,save the startup report somewheres,then copy and paste it here.

roger2
2007-06-14, 11:15
Awesome thanks zanobia, here it is:


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2007-02-03 TeaTimer.exe (1.4.0.2)
2007-02-02 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-06-06 Includes\Cookies.sbi
2007-05-30 Includes\Dialer.sbi
2007-06-06 Includes\DialerC.sbi
2007-05-30 Includes\Hijackers.sbi
2007-06-06 Includes\HijackersC.sbi
2006-10-27 Includes\Keyloggers.sbi
2007-06-06 Includes\KeyloggersC.sbi
2007-05-30 Includes\Malware.sbi
2007-06-06 Includes\MalwareC.sbi
2007-03-21 Includes\PUPS.sbi
2007-06-06 Includes\PUPSC.sbi
2007-06-06 Includes\Revision.sbi
2007-05-30 Includes\Security.sbi
2007-06-06 Includes\SecurityC.sbi
2007-06-06 Includes\Spybots.sbi
2007-06-06 Includes\SpybotsC.sbi
2005-02-17 Includes\Tracks.uti
2007-05-16 Includes\Trojans.sbi
2007-06-06 Includes\TrojansC.sbi

Located: HK_LM:Run, AVG7_CC
command: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
file: C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
size: 416256
MD5: 2200c98c049de1a7638ea0edba1c8882

Located: HK_LM:Run, EPSON Stylus CX3200
command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
size: 74752
MD5: 7984d2a1b7a3a691889c53708fe450bf

Located: HK_LM:Run, Google Desktop Search
command: "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
file: C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
size: 1831936
MD5: 5c4f5211e54c0c7d6af5591b69209f1d

Located: HK_LM:Run, ICQ Lite
command: "C:\Program Files\ICQLite\ICQLite.exe" -minimize
file: C:\Program Files\ICQLite\ICQLite.exe
size: 3144800
MD5: 7b2cb5259ced4485ce0d6b06a45ff561

Located: HK_LM:Run, LogMeIn GUI
command: "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
file: C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
size: 63048
MD5: 234051c0d242a6f4a79ae5212c1323d4

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 282624
MD5: d195e74b712dd105402b90e6cb28263f

Located: HK_LM:Run, Sony Ericsson PC Suite
command: "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
file: C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
size: 159744
MD5: f0b9213ad99e77fc481c24c9023aa9c6

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
file: C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
size: 83608
MD5: 9c1c80bbf8e6044980890e2d2d91091c

Located: HK_LM:Run, WinVNC
command: "C:\Program Files\ORL\VNC\WinVNC.exe" -servicehelper
file: C:\Program Files\ORL\VNC\WinVNC.exe
size: 208896
MD5: f4910e28a285a13e642cdfe302e4ad91

Located: HK_LM:Run, ZoneAlarm Client
command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
size: 919280
MD5: 3e1731c55f77d150791d4c7e87ad4e5c

Located: HK_LM:Run, NvCplDaemon (DISABLED)
command: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, NvMediaCenter (DISABLED)
command: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, nwiz (DISABLED)
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1519616
MD5: 66db459386d7bf62852b1bfa029fb887

Located: HK_LM:Run, OLP-Tray (DISABLED)
command: C:\Program Files\Royal Mail\SmartStamp\BINARY\STRAY.EXE
file: C:\Program Files\Royal Mail\SmartStamp\BINARY\STRAY.EXE
size: 40960
MD5: a1fe8ca62338ffeb5bbd9e1dfa0f33f6

Located: HK_LM:Run, Picasa Media Detector (DISABLED)
command: C:\Program Files\Picasa2\PicasaMediaDetector.exe
file: C:\Program Files\Picasa2\PicasaMediaDetector.exe
size: 366400
MD5: 5345770beec2f434e005c579e5518b4c

Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 282624
MD5: d195e74b712dd105402b90e6cb28263f

Located: HK_LM:Run, RTHDCPL (DISABLED)
command: RTHDCPL.EXE
file: C:\WINDOWS\RTHDCPL.EXE
size: 16261632
MD5: 10b0722c7203181b0c50c6cb974d2f2a

Located: HK_LM:Run, SkyTel (DISABLED)
command: SkyTel.EXE
file: C:\WINDOWS\SkyTel.EXE
size: 2879488
MD5: c74b86642f131d76c0ede673fdf137b2

Located: HK_LM:Run, SPAMfighter Agent (DISABLED)
command: "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
file: C:\Program Files\SPAMfighter\SFAgent.exe
size: 473600
MD5: 66852164c1860d0c853022a927de6e1f

Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8

Located: HK_CU:Run, MsnMsgr
command: "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
file: C:\Program Files\MSN Messenger\MsnMsgr.Exe
size: 5674352
MD5: c4281ad865739e71fd1e4dac19a68d60

Located: HK_CU:Run, Skype
command: "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
file: C:\Program Files\Skype\Phone\Skype.exe
size: 23395880
MD5: 727f5581a387b32b7e7259ab11b65768

Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy 1.4\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy 1.4\TeaTimer.exe
size: 1415824
MD5: bf7e563f3c28799e612acbfc2fd089c5

Located: HK_CU:Run, swg
command: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
file: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
size: 68856
MD5: e616a6a6e91b0a86f2f6217cde835ffe

Located: HK_CU:Run, WMPNSCFG
command: C:\Program Files\Windows Media Player\WMPNSCFG.exe
file: C:\Program Files\Windows Media Player\WMPNSCFG.exe
size: 204288
MD5: 7eaed08ccca4ddde61a388c82598cfa9

Located: HK_CU:RunOnce, ICQ Lite
command: C:\Program Files\ICQLite\ICQLite.exe -trayboot
file:

Located: HK_CU:Run, MSMSGS (DISABLED)
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74e6e96c6f0e2eca4edbb7f7a468f259

Located: HK_CU:Run, RoboForm (DISABLED)
command: "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
file: C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
size: 160832
MD5: 0ffcdc4dc3aa2fde9dcbd0c72d2feda0

Located: HK_CU:Run, Skype (DISABLED)
command: "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
file: C:\Program Files\Skype\Phone\Skype.exe
size: 23395880
MD5: 727f5581a387b32b7e7259ab11b65768

Located: HK_CU:Run, SkypeClient (DISABLED)
command: "C:\Program Files\PDT\VoIPVoiceIntegration\VoIPVoice Integration.exe"
file: C:\Program Files\PDT\VoIPVoiceIntegration\VoIPVoice Integration.exe
size: 57344
MD5: 3539cd0a73d3d8b80b0291d42923a28d

Located: HK_CU:Run, swg (DISABLED)
command: C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
file:

Located: Startup (common), Acrobat Assistant.lnk
command: C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
file: C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
size: 82026
MD5: 21189b8f2d747b6981a54d5c5d554c8e

Located: Startup (common), PGPtray.exe.lnk
command: C:\WINDOWS\Installer\{9BD98248-C709-47B9-9B0A-8BD1BE53850E}\Icon6560581611.exe
file: C:\WINDOWS\Installer\{9BD98248-C709-47B9-9B0A-8BD1BE53850E}\Icon6560581611.exe
size: 55296
MD5: b67ff8b9127d74083b9500bdf91bcd6b

Located: System.ini, crypt32chain
command: crypt32.dll
file: crypt32.dll

Located: System.ini, cryptnet
command: cryptnet.dll
file: cryptnet.dll

Located: System.ini, cscdll
command: cscdll.dll
file: cscdll.dll

Located: System.ini, LMIinit
command: LMIinit.dll
file: LMIinit.dll

Located: System.ini, ScCertProp
command: wlnotify.dll
file: wlnotify.dll

Located: System.ini, Schedule
command: wlnotify.dll
file: wlnotify.dll

Located: System.ini, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll

Located: System.ini, SensLogn
command: WlNotify.dll
file: WlNotify.dll

Located: System.ini, termsrv
command: wlnotify.dll
file: wlnotify.dll

Located: System.ini, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll

Located: System.ini, wlballoon
command: wlnotify.dll
file: wlnotify.dll

Zenobia
2007-06-14, 22:36
I don't see anything related to Spybot,other than Teatimer,and that shouldn't make the Spybot programs file folder run on startup.brb.

Zenobia
2007-06-14, 23:07
Well,I was going to suggest Autoruns since it would show a lot more startup entries,but the logfile is really,really huge,even if you take out the Microsoft entries,so guess that won`t be a good idea.

:scratch:

If you`re willing,you could try uninstalling,then reinstalling Spybot to see if the problem will go away.Though be forewarned,the problem may not go away,since if there`s a hidden startup entry somewhere,the Very Small Fix may not get rid of it.But,it might be worth a shot.
http://www.safer-networking.org/en/howto/uninstall.html

md usa spybot fan
2007-06-14, 23:35
roger2:

Did you by chance rename the default installation folder of:
C:\Program Files\Spybot - Search & Destroy
To:
C:\Program Files\Spybot - Search & Destroy 1.4
Or vice versa after the installation of Spybot-S&D 1.4?

In what folder is TeaTimer.exe actually located?

Zenobia
2007-06-14, 23:49
Missed that.Ty,md.

md usa spybot fan
2007-06-15, 00:14
Zenobia:

I specially looked for something like that (and actually missed it at first glance) because I thought I remembered (from way back when) that someone else had a problem with a Windows Explorer session opening when they tried to start SpybotSD.exe (from a shortcut icon if I remember correctly). It involved the renaming of the "C:\Program Files\Spybot - Search & Destroy" folder because in their case the name was too long to suit them or some other such nonsense.

The bottom line is, if I remember correctly, that there is a possibility that if an entry points to an incorrect folder or non-existing folder that Windows Explorer opens. Note: I didn't attempt to replicate the problem, so I am just going by my some times on and some times off memory of old problems.

Zenobia
2007-06-15, 00:24
Yes,that was in one of the posts I found,but then I missed it,lol. :blink:
http://forums.spybot.info/showthread.php?t=1294

roger2
2007-06-16, 17:39
ah yes i changed the folder name on installation so i could keep up with which version was on this machine, i will try re-installing and let it use the default folder name.
thanks
rog

md usa spybot fan
2007-06-16, 18:33
Since it appears that there is a mix up between the program folders of the new an old version and the system registy, I suggest that you completely uninstall Spybot-S&D before reinstalling:
Go into Spybot > Immunize
Click "Undo" button (at the top)
Uncheck (if checked) the following:
"Enable permanent blocking of bad addresses in Internet Explorer"

Go into Spybot > Mode > Advanced Mode > Tools > Resident
Uncheck (if checked) the following:
Resident "TeaTimer" (Protection of over-all system settings) Active.

Go into Spybot > Mode > Advanced Mode > Tools > IE Tweaks.
Uncheck (if checked) any of the following "Miscellaneous locks":
Lock Hosts file read-only as protection against hijackers
Lock IE start page setting against user changes (current user)
Lock IE control panel against opening from within IE (current user)


Go into Spybot > Mode > Advanced Mode > Tools > Hosts file
Click the "Remove Spybot S&D hosts list" button (at the top)

Exit Spybot-S&D
Make sure that TeaTimer is not running by checking for the TeaTimer System Tray Icon. If the icon is there:
Right click Spybot's TeaTimer System Tray Icon > click Exit Spybot-S&D Resident. TeaTimer should close.

Go to Windows > Control panel > Add or Remove Programs > Locate "Spybot – Search & Destroy 1.4" > Remove. If "Spybot – Search & Destroy 1.4" is listed, also remove that.
Using Windows explorer, verified that the following folder(s) has been delete. If not, delete them: C:\Program Files\Spybot - Search & Destroy C:\Program Files\Spybot - Search & Destroy 1.4

Make sure that all the registry entries that Spybot-S&D added during installation are removed, there is a .reg file available (this very small fix (http://www.safer-networking.org/files/remove-spybotsd-settings.reg))on the safer-networking.org WEB site that can do that. See the following article:
FAQ - Frequently Asked Questions
How to uninstall?
http://www.safer-networking.org/index.php?page=howto&detail=uninstall
Download the file.
Double click on it
Answer Yes then OK
Reinstall Spybot 1.4 (spybotsd14.exe).

roger2
2007-06-17, 12:56
that has resolved the issue. I had tried reinstalling before but of course i used my same 'strategy' of naming the program files folder with the version so ended up with the same condition.
Thanks for your help
All the best
Rog