PDA

View Full Version : Get prompted to install Spybot every time Windows starts up



martpol
2008-02-13, 08:52
Hi - just upgraded to v1.5.2.20. Everything seems to be working fine but every time I start up Windows I am now prompted to install Spybot (starting with the "choose installation language" screen).

I uninstalled and reinstalled, but it made no difference. I also ran a Spybot check plus an Avast virus scan, just in case. Nothing came up.

I'm running XP. Grateful for any ideas!

md usa spybot fan
2008-02-13, 15:10
martpol:

I suspect that there might be something in your System Startup entries causing this. If you post your System Startup entries, we can take a look. To do that:
Go into Spybot > Mode > Advanced Mode > Tools > System Startup.
Right click on the listing and select "Copy to Clipboard".
Paste (Ctrl+V) the contents of the Clipboard into a new post in this thread.

martpol
2008-02-13, 20:15
--- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

2008-02-12 unins000.exe (51.49.0.0)
2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDMain.exe (1.0.0.5)
2008-01-28 SDUpdate.exe (1.0.8.8)
2008-01-28 SDWinSec.exe (1.0.0.11)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SpybotSD.exe (1.5.2.20)
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2008-01-28 SDFiles.dll (1.5.1.19)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-02-06 Includes\Revision.sbi
2008-02-06 Includes\Cookies.sbi
2007-12-26 Includes\Dialer.sbi
2008-02-06 Includes\HeavyDuty.sbi
2008-02-06 Includes\Hijackers.sbi
2007-10-04 Includes\Keyloggers.sbi
2004-11-29 Includes\LSP.sbi
2008-01-16 Includes\Malware.sbi
2007-10-24 Includes\PUPS.sbi
2008-01-09 Includes\Security.sbi
2008-01-23 Includes\Spybots.sbi
2007-11-06 Includes\Tracks.uti
2008-02-06 Includes\Trojans.sbi
2008-02-06 Includes\DialerC.sbi
2008-02-06 Includes\HijackersC.sbi
2008-02-06 Includes\KeyloggersC.sbi
2008-02-06 Includes\MalwareC.sbi
2008-02-06 Includes\PUPSC.sbi
2008-02-06 Includes\SecurityC.sbi
2008-02-06 Includes\SpybotsC.sbi
2008-02-06 Includes\TrojansC.sbi
2007-12-24 Plugins\TCPIPAddress.dll

Located: HK_LM:Run, AdaptecDirectCD
command: C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
file: C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
size: 684032
MD5: BFA83B551ABD8084B4623887D0E3B53C

Located: HK_LM:Run, Adobe Photo Downloader
command: "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
file: C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
size: 63712
MD5: FC9E59FE8BC4FE05382CFF5C8FC59DE1

Located: HK_LM:Run, Adobe Reader Speed Launcher
command: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
file: C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
size: 39792
MD5: 8B9145D229D4E89D15ACB820D4A3A90F

Located: HK_LM:Run, AudioDrvEmulator
command: "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
file: C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
size: 49152
MD5: 54B3827A5E5B2ABD546D4CF059E4A742

Located: HK_LM:Run, avast!
command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
size: 79224
MD5: 88D86112DD9F2BB6A603674706C7E846

Located: HK_LM:Run, CTDVDDET
command: "C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE"
file: C:\Program Files\Creative\SBAudigy4\DVDAudio\CTDVDDET.EXE
size: 45056
MD5: DB20FCE248D269E1C396E70A91E587C8

Located: HK_LM:Run, CTHelper
command: CTHELPER.EXE
file: C:\WINDOWS\CTHELPER.EXE
size: 16384
MD5: 149CE3880849F5B200E252645DB0B64F

Located: HK_LM:Run, CTSysVol
command: C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe /r
file: C:\Program Files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe
size: 57344
MD5: B8C105215A4EE0680BD4A4F43622E48F

Located: HK_LM:Run, iTunesHelper
command: C:\Program Files\iTunes\iTunesHelper.exe
file: C:\Program Files\iTunes\iTunesHelper.exe
size: 278528
MD5: 2E0E2BE7BD6614EA4C86B9ECE793E31E

Located: HK_LM:Run, Microsoft Works Portfolio
command: C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
file: C:\Program Files\Microsoft Works\WksSb.exe
size: 311350
MD5: 98CB1B841FD1B0E12897352F18DDDAE1

Located: HK_LM:Run, Microsoft Works Update Detection
command: C:\Program Files\Microsoft Works\WkDetect.exe
file: C:\Program Files\Microsoft Works\WkDetect.exe
size: 28739
MD5: 3141750FAD211C6DADF7C2DC2EC74DA8

Located: HK_LM:Run, PCSuiteTrayApplication
command: C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
file: C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
size: 217088
MD5: 8565A3BCE1E003EC50D527592C18E78D

Located: HK_LM:Run, PCTVOICE
command: pctspk.exe
file: C:\WINDOWS\system32\pctspk.exe
size: 86016
MD5: 0275215D01C3985E682A661B8826F371

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 98304
MD5: 76A3A30B58405C2C6D833895253A51A9

Located: HK_LM:Run, SpeedTouch USB Diagnostics
command: "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
file: C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
size: 866816
MD5: D40191AA225638AB20E59524CDD74030

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
file: C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
size: 132496
MD5: D4F0F7437327DBAA264338BAAFB5E5AF

Located: HK_LM:Run, TalkTalk
command: "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
file: C:\Program Files\TalkTalk\bin\sprtcmd.exe
size: 192512
MD5: E7A42AE15A34EE32004E44FED0F407B2

Located: HK_LM:Run, UpdReg
command: C:\WINDOWS\UpdReg.EXE
file: C:\WINDOWS\UpdReg.EXE
size: 90112
MD5: C419DF63E0121D72411285780C2FC6CC

Located: HK_LM:Run, WorksFUD
command: C:\Program Files\Microsoft Works\wkfud.exe
file: C:\Program Files\Microsoft Works\wkfud.exe
size: 24576
MD5: 9D05D00E8631B7874D164D6DEDD6D801

Located: HK_CU:Run, CTFMON.EXE
where: .DEFAULT...
command: C:\WINDOWS\System32\CTFMON.EXE
file: C:\WINDOWS\System32\CTFMON.EXE
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, Picasa Media Detector
where: .DEFAULT...
command: C:\Program Files\Picasa2\PicasaMediaDetector.exe
file: C:\Program Files\Picasa2\PicasaMediaDetector.exe
size: 439872
MD5: 3AAFC1B4CA2256DB3786F33A88E06EF8

Located: HK_CU:Run, CTFMON.EXE
where: PE_C_ADMINISTRATOR...
command: C:\WINDOWS\System32\CTFMON.EXE
file: C:\WINDOWS\System32\CTFMON.EXE
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, CTFMON.EXE
where: PE_C_LIZ...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, MSMSGS
where: PE_C_LIZ...
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

Located: HK_CU:Run, swg
where: PE_C_LIZ...
command: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
file: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
size: 68856
MD5: E616A6A6E91B0A86F2F6217CDE835FFE

Located: HK_CU:Run, CTFMON.EXE
where: PE_C_USER...
command: C:\WINDOWS\System32\ctfmon.exe
file: C:\WINDOWS\System32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-19...
command: C:\WINDOWS\System32\CTFMON.EXE
file: C:\WINDOWS\System32\CTFMON.EXE
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-20...
command: C:\WINDOWS\System32\CTFMON.EXE
file: C:\WINDOWS\System32\CTFMON.EXE
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, Creative Detector
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
file: C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
size: 102400
MD5: C744293DFBE1A3347FEC5DBFE3FD123E

Located: HK_CU:Run, ctfmon.exe
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, H/PC Connection Agent
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: "C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
file: C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
size: 1289000
MD5: 5515EB5E3A8B073F66CFC697EB0D4B55

Located: HK_CU:Run, MSMSGS
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: "C:\Program Files\Messenger\msmsgs.exe" /background
file: C:\Program Files\Messenger\msmsgs.exe
size: 1694208
MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

Located: HK_CU:Run, PcSync
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
file: C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
size: 1306624
MD5: 3F0E2B39CB22591787A2B77FA1013B37

Located: HK_CU:Run, SpybotSD TeaTimer
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 2097488
MD5: A9A5DB6AC3721BE698B996913693D73F

Located: HK_CU:Run, swg
where: S-1-5-21-72323485-1465058494-1690550294-1006...
command: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
file: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
size: 68856
MD5: E616A6A6E91B0A86F2F6217CDE835FFE

Located: HK_CU:Run, CTFMON.EXE
where: S-1-5-18...
command: C:\WINDOWS\System32\CTFMON.EXE
file: C:\WINDOWS\System32\CTFMON.EXE
size: 15360
MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, Picasa Media Detector
where: S-1-5-18...
command: C:\Program Files\Picasa2\PicasaMediaDetector.exe
file: C:\Program Files\Picasa2\PicasaMediaDetector.exe
size: 439872
MD5: 3AAFC1B4CA2256DB3786F33A88E06EF8

Located: Startup (common), hp psc 1000 series.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
file: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
size: 147456
MD5: 03163BAF3A5DBF8742804093931D7D32

Located: Startup (common), hpoddt01.exe.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
file: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
size: 28672
MD5: A564A22308A3F55235BA2478EE82992D

Located: Startup (common), LG SyncManager.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\LG PC Suite\LG PC Sync\LGSyncManager.exe
file:
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: Startup (common), Microsoft Office.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Microsoft Office\Office\OSA9.EXE
file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
size: 65588
MD5: 6E2D9DA08879BF15BBC1832610090325

Located: Startup (common), Microsoft Works Calendar Reminders.lnk
where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
file: C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
size: 24633
MD5: 7084B58A098D2F83B304832251A8C6A8

Located: Startup (user), OpenOffice.org 1.1.0.lnk
where: C:\Documents and Settings\Martin\Start Menu\Programs\Startup...
command: C:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe
file: C:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe
size: 61440
MD5: 915C1968C59D0FCAD6A716AA6C90264A

Located: WinLogon, crypt32chain
command: crypt32.dll
file: crypt32.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
file: cryptnet.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
file: cscdll.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
file: sclgntfy.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
file: WlNotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, WgaLogon
command: WgaLogon.dll
file: WgaLogon.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
file: wlnotify.dll
size: 0
MD5: D41D8CD98F00B204E9800998ECF8427E
Warning: if the file is actually larger than 0 bytes,
the checksum could not be properly calculated!

md usa spybot fan
2008-02-13, 20:39
I'm sorry but I don't see anything there would repetitively cause Spybot to attempt to install.

129260
2008-02-14, 01:56
Hi - just upgraded to v1.5.2.20. Everything seems to be working fine but every time I start up Windows I am now prompted to install Spybot (starting with the "choose installation language" screen).

I uninstalled and reinstalled, but it made no difference. I also ran a Spybot check plus an Avast virus scan, just in case. Nothing came up.

I'm running XP. Grateful for any ideas!

does starting in safe mode make it go away? Are you sure you installed spybot? try going through the installation and see what happens. if its already installed, it prob will stop if you go through the prompts.