PDA

View Full Version : repeting registry changes on reload



graham
2007-12-03, 15:49
I have just installed some new memory, and immediately started getting a message about a registry change to KernelFaultCheck every reload (also 2-3 blue screens , but they have stopped now)
I allowed/remembered this change, as assumed must be to do with new mem.
After some investigation I ordered installed a registry checker (AMUST) ran this , and at one point it asked for a registry change which I again allowed.
Now every time I reload I get a message to say Kernelfaultcheck changed, then two about global toolbar value deleted.
Seems to be working OK - but why repeated messages ?
(I have run AVG and Spybot and both comeback clean)

md usa spybot fan
2007-12-03, 16:18
What version of TeaTimer are you running?

graham
2007-12-03, 16:36
my spybot version is 1.4.
I also have the problem where the warning message is covered up, and you have to try and click around the edge ?

graham
2007-12-03, 16:39
this is teatimer log since new mem installed:


30/11/2007 10:40:38 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
01/12/2007 10:58:54 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
01/12/2007 11:03:05 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
01/12/2007 12:41:51 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
02/12/2007 12:45:51 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 08:14:08 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 10:13:43 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 10:18:43 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 10:21:35 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 10:25:08 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 10:26:59 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 12:19:05 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 12:59:37 Allowed value "{BDEE1959-AB6B-4745-A29B-F492861102CC}" (new data: "") added in ActiveX Distribution Unit!
03/12/2007 12:59:48 Allowed value "RegCompact" (new data: "") added in Winlogon Notifiers!
03/12/2007 13:07:10 Allowed value "" (new data: "") deleted in Global browser toolbar!
03/12/2007 13:07:13 Allowed value "{31D1CA78-F919-4198-8DA5-AB6F44E4AB28}" (new data: "") deleted in Global browser toolbar!
03/12/2007 13:07:14 Allowed value "{32683183-48a0-441b-a342-7c2a440a9478}" (new data: "") deleted in User-specific browser toolbar!
03/12/2007 13:21:19 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 13:21:28 Allowed value "" (new data: "") deleted in Global browser toolbar!
03/12/2007 13:21:29 Allowed value "{31D1CA78-F919-4198-8DA5-AB6F44E4AB28}" (new data: "") deleted in Global browser toolbar!
03/12/2007 13:37:39 Allowed value "{32683183-48a0-441b-a342-7c2a440a9478}" (new data: "") deleted in User-specific browser toolbar!
03/12/2007 13:40:47 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 13:40:51 Allowed value "" (new data: "") deleted in Global browser toolbar!
03/12/2007 13:40:54 Allowed value "{31D1CA78-F919-4198-8DA5-AB6F44E4AB28}" (new data: "") deleted in Global browser toolbar!
03/12/2007 14:31:42 Allowed value "KernelFaultCheck" (new data: "") deleted in System Startup global entry!
03/12/2007 14:32:08 Allowed value "" (new data: "") deleted in Global browser toolbar!
03/12/2007 14:32:23 Allowed value "{31D1CA78-F919-4198-8DA5-AB6F44E4AB28}" (new data: "") deleted in Global browser toolbar!

md usa spybot fan
2007-12-03, 16:50
Graham:

Upgrading to Spybot 1.5 should fix both problems.



Now every time I reload I get a message to say Kernelfaultcheck changed, then two about global toolbar value deleted.
The most likely cause of repetitive registry changes at startup is because TeaTimer's snapshot files are out of sync with the registry.

TeaTimer takes snapshots of Registry entries and compares these with the Registry at startup. Until these snapshots are updated you are likely to get pop-ups (at startup) of changes you made in the past. In other words, TeaTimer attempts to return the Registry to the state it was in when the snapshots were taken. This happens primarily when you reboot the system.

To refresh TeaTimer's snapshot files and correct the problem:
Right click Spybot's TeaTimer System Tray Icon > click Exit Spybot-S&D Resident.
TeaTimer closes.
TeaTimer's snapshot files are refreshed at this time.

Restart TeaTimer:
Using Windows Explorer, navigate to C:\Program Files\Spybot - Search & Destroy.
Double click TeaTimer.exe to start it.

I this behavior in TeaTimer 1.3 and 1.4 is because of the following:
When TeaTimer starts the snapshot files are read into memory and maintained there. The snapshot files are only rewritten when TeaTimer closes. During system shutdown (or restart) it appears that TeaTimer is terminated before it has a chance to rewrite the snapshot files.
The problem has been corrected in TeaTimer 1.5.


my spybot version is 1.4.
I also have the problem where the warning message is covered up, and you have to try and click around the edge ?
You are running an old version of Spybot (Spybot 1.5 is the latest).

There was a bug in TeaTimer 1.4. Portions of TeaTimer's popup dialog overlay the "Allow change" and "Deny change" buttons. On my system the very top edges of the "Allow change" button (on the left) and "Deny change" button (on the right) are showing and I am still able to select the options. I also can check "Remember this decision" since it is visible. If no portion of the "Allow change" and "Deny change" buttons are showing, you can answer TeaTimer's popup dialog (English language version) by pressing "A" on your keyboard for "Allow change" or "D" for "Deny change". Note: If you close the dialog without answering "Allow change" or "Deny change" the registry change is denied.

If you can't deal with the problem that way, you can:
Download and install Spybot 1.5.
The downloads can be found here:
Mirror selection - The home of Spybot-S&D!
http://www.spybot.info/en/mirrors/index.html



Apply one of the workarounds found in the following thread that fixes the pop-up dialog so the buttons are visible:
Solution to fix the pop-ups in TeaTimer
http://forums.spybot.info/showthread.php?t=122

There are three (3) fixes published in that thread. They are:


The ResHacker fix published by ElPiedra (http://forums.spybot.info/member.php?u=128) here:
http://forums.spybot.info/showpost.php?p=423&postcount=1
The murdo (http://forums.spybot.info/member.php?u=440) patch published here:
http://forums.spybot.info/showpost.php?p=775&postcount=9
Also republished by RuggeR29 (http://forums.spybot.info/member.php?u=7292) (which I have never tried) here:
http://www.fureyonline.com/downloads/patch.zip
The patch originally by SyreneD (http://forums.spybot.info/member.php?u=1735) that I published here:
http://forums.spybot.info/showpost.php?p=2670&postcount=38
Also republished by SyreneD (http://forums.spybot.info/member.php?u=1735) himself here:
http://forums.spybot.info/showpost.php?p=23575&postcount=125


Disable TeaTimer as follows:
Go into Spybot > Mode > Advanced Mode > Tools > Resident.
Uncheck the following:Resident "TeaTimer" (Protection of over-all system settings) Active.

********************

Notes about the patches (b. and c. above):
If you installed Spybot in the default location:
C:\Program Files\Spybot - Search & Destroy
The following patch (c.) defaults to that location:
The patch originally by SyreneD (http://forums.spybot.info/member.php?u=1735) that I published here:
http://forums.spybot.info/showpost.php?p=2670&postcount=38
Also republished by SyreneD (http://forums.spybot.info/member.php?u=1735) himself here:
http://forums.spybot.info/showpost.php?p=23575&postcount=125
If you use the following patch (b.) you have to navigate to the correct location (See Note #1) unless you execute the patch from within the "C:\Program Files\Spybot - Search & Destroy" folder:
The murdo (http://forums.spybot.info/member.php?u=440) patch published here:
http://forums.spybot.info/showpost.php?p=775&postcount=9
Also republished by RuggeR29 (http://forums.spybot.info/member.php?u=7292) (which I have never tried) here:
http://www.fureyonline.com/downloads/patch.zip

Note# 1: To the right of the Target File (TeaTimer.exe) there is a button that looks like "[ . . . ]". Click on that button, navigate to the correct folder, click "Open" and then "Start".

graham
2007-12-03, 17:31
thanks for that I have installled and now running 1.5, but two reloads and no repeated messages so looks good.