PDA

View Full Version : http://runonce.msn.com/runonce2.aspx



Imrahil
2008-05-19, 18:32
After downloading and running SB ver 1.5.2, IE opens up to:

"http://runonce.msn.com/runonce2.aspx"
Welcome to Internet Explorer 7
Customize Your Settings

every time it is launched. Also my menu bar is gone. This happens in the guest account as well. How can I get it back to normal, ie: goto home page (Google) and display menu bar when launched.

md usa spybot fan
2008-05-19, 19:21
Imrahil:

Did you interact with Spybot's TeaTimer feature which issued a registry change dialog that said "Spybot - Search & Destroy has detected an important registry entry that has been changed" and indicated?
Cateory: Browser page
Entry: First Home Page
Are you getting any pop-up notifications that are displayed in the lower right hand corner of the screen indicating with a title "Resident" indicating a registry change has either been allowed or denied?

Imrahil
2008-05-20, 01:17
Yes, I did enable Tea Timer during the install, then turned it off after discovering the IE issue, but then turned it back on. I don't recall any specific message about "First Home Page" but YES, there were a lot of pop up notifications about registry changes, although most of them came while running spybot's system startup tool which was run after the IE issue was discovered.
I don't remember the exact messages, but I enabled "remember this decision" whenever possible.

drragostea
2008-05-20, 01:26
The runonce only occurs when you first install IE7. It allows you to customize your browsing experience. Nothing more.
---------

In TeaTimer 1.5:

If you check "Remember this decision" on a registry change, the information concerning that change it is stored in a file. TeaTimer uses that information to automatically "Allow" or "Deny" similar registry changes for all future changes. To edit that information: Right click on the TeaTimer system tray icon (labeled "Spybot-SD Resident") and select Settings. This will bring up TeaTimer's "White & Black List". There are four (4) Buttons across the top of the "White & Black List":
Allowed registry changes
Blocked registry changes
Allowed processes
Blocked processes
You can review all the entries that you have stored by clicking on these buttons. If entries you are interested in are for registry changes, the entries that you should review are in "Allowed registry changes" and "Blocked registry changes". You can delete stored entries by clicking on the scripted black "X" to the right of the entry that you want to delete, answering "Yes" to the confirmation dialog and then clicking the "OK" button when you're done.
---------

I'm assuming you clicked denied and then remember this decision?

To undo this, go to settings when you right click on TeaTimer. Under one of the tabs, find the "runonce" entry and there will be a red X next to the entry. Double-click the X and it would be like TeaTimer undoing that decision. More like an ignore or forgetting that decsion.

Imrahil
2008-05-20, 02:12
My IE is opening to runonce every time I launch it.

Right clicking on Resident in the "sytem tray" (the list of items under tools to the left? eg: View Report, Secure Shredder, Resident....... etc?) results in no pop up action window. Right clicking on Resident in the tools window proper (to the right) results in in a pop up action window with "Display as list" or "Display as icons" as the available actions to choose from.
Under "Resident" SDHelper is disabled (by me, forgot to re-enable it); and TeaTimer is enabled, then in the window proper is a long list of actions (a log).

Short answer I'm unable to do what you've asked me to do.

When I clicked in the window proper, I got a "system settings protector" error.

THIS IS NOT AN HJT REPORT! It is the error log.

<?xml version="1.0" encoding="UTF-16"?>
<DATABASE>
<EXE NAME="TeaTimer.exe" FILTER="GRABMI_FILTER_PRIVACY">
<MATCHING_FILE NAME="advcheck.dll" SIZE="915280" CHECKSUM="0x95082AF3" BIN_FILE_VERSION="1.5.4.5" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Dateiüberprüfungs-Bibliothek" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 5, 4, 5" ORIGINAL_FILENAME="advcheck.dll" INTERNAL_NAME="advtools" LEGAL_COPYRIGHT="© 2003-2008 Safer Networking Limited. Alle Rechte vorbehalten." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xEDBFD" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.5.4.5" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="aports.dll" SIZE="34472" CHECKSUM="0x4C0FBB09" BIN_FILE_VERSION="2.1.0.0" BIN_PRODUCT_VERSION="2.1.0.0" PRODUCT_VERSION="2, 1, 0, 0" FILE_DESCRIPTION="Maps TCP and UDP ports to the owning processes" COMPANY_NAME="SmartLine Inc." PRODUCT_NAME="Active Ports" FILE_VERSION="2, 1, 0, 0" ORIGINAL_FILENAME="aports.dll" INTERNAL_NAME="aports" LEGAL_COPYRIGHT="Copyright © 2000-2005 SmartLine Inc." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x14009" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="2.1.0.0" UPTO_BIN_PRODUCT_VERSION="2.1.0.0" LINK_DATE="05/14/2005 08:15:35" UPTO_LINK_DATE="05/14/2005 08:15:35" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="blindman.exe" SIZE="428880" CHECKSUM="0xB25ED3FA" BIN_FILE_VERSION="1.0.0.7" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Dummy" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 0, 0, 7" ORIGINAL_FILENAME="blindman.exe" INTERNAL_NAME="" LEGAL_COPYRIGHT="© 2002-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x787D0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.0.7" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="borlndmm.dll" SIZE="22528" CHECKSUM="0x150CDD67" BIN_FILE_VERSION="7.0.4.453" BIN_PRODUCT_VERSION="7.0.0.0" PRODUCT_VERSION="7.0" FILE_DESCRIPTION="Borland Memory Manager" COMPANY_NAME="Borland Software Corporation" PRODUCT_NAME="Borland Memory Manager" FILE_VERSION="7.0.4.453" ORIGINAL_FILENAME="Borlndmm.Dll" INTERNAL_NAME="Borlndmm" LEGAL_COPYRIGHT="Copyright © 1996,2001 Borland Software Corporation" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x10004" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0xD4DE" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="7.0.4.453" UPTO_BIN_PRODUCT_VERSION="7.0.0.0" LINK_DATE="08/09/2002 21:54:37" UPTO_LINK_DATE="08/09/2002 21:54:37" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="delphimm.dll" SIZE="15872" CHECKSUM="0xA28CCB36" BIN_FILE_VERSION="7.0.4.453" BIN_PRODUCT_VERSION="7.0.0.0" PRODUCT_VERSION="7.0" FILE_DESCRIPTION="Borland Compatability Memory Manager" COMPANY_NAME="Borland Software Corporation" PRODUCT_NAME="Borland Delphi" FILE_VERSION="7.0.4.453" ORIGINAL_FILENAME="Delphimm.Dll" INTERNAL_NAME="Delphimm" LEGAL_COPYRIGHT="Copyright © 1996,2001 Borland Software Corporation" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x10004" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="7.0.4.453" UPTO_BIN_PRODUCT_VERSION="7.0.0.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="DelZip179.dll" SIZE="252320" CHECKSUM="0xD98CB40" BIN_FILE_VERSION="1.79.7.4" BIN_PRODUCT_VERSION="1.79.7.4" PRODUCT_VERSION="1.79.07.04" FILE_DESCRIPTION="Freeware Zip/Unzip" COMPANY_NAME="DelphiZip" PRODUCT_NAME="DelphiZip" FILE_VERSION="1.79.07.04" ORIGINAL_FILENAME="DelZip179.dll" INTERNAL_NAME="DelZip.dll" LEGAL_COPYRIGHT="Copyright © 2007, Russell Peters" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x4B73A" LINKER_VERSION="0x40000" UPTO_BIN_FILE_VERSION="1.79.7.4" UPTO_BIN_PRODUCT_VERSION="1.79.7.4" LINK_DATE="08/25/2007 05:11:20" UPTO_LINK_DATE="08/25/2007 05:11:20" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="SDDelFile.exe" SIZE="1026560" CHECKSUM="0x3935CEC" BIN_FILE_VERSION="1.0.2.4" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Command line file remover for Spybot-S&amp;D" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 0, 2, 4" ORIGINAL_FILENAME="SDDelFile.exe" INTERNAL_NAME="" LEGAL_COPYRIGHT="© 2007-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.2.4" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="SDFiles.dll" SIZE="841728" CHECKSUM="0xAFDDDB24" BIN_FILE_VERSION="1.5.1.19" BIN_PRODUCT_VERSION="1.5.0.0" PRODUCT_VERSION="1, 5, 0, 0" FILE_DESCRIPTION="Spybot - Search &amp; Destroy File Scanner" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="SpyBot-S&amp;D" FILE_VERSION="1, 5, 1, 19" ORIGINAL_FILENAME="SpyBotSD.exe" INTERNAL_NAME="SpyBotSD" LEGAL_COPYRIGHT="© 2000-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.5.1.19" UPTO_BIN_PRODUCT_VERSION="1.5.0.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="SDHelper.dll" SIZE="1554256" CHECKSUM="0xDF9164C2" BIN_FILE_VERSION="1.5.0.11" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="SBSD IE Protection" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 5, 0, 11" ORIGINAL_FILENAME="sdhelper.dll" INTERNAL_NAME="SDHelper" LEGAL_COPYRIGHT="© 2000-2008 Safer Networking Limited. Alle Rechte vorbehalten." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x17B8D2" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.5.0.11" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="SDMain.exe" SIZE="414544" CHECKSUM="0xDADBFCD5" BIN_FILE_VERSION="1.0.0.5" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Spybot-S&amp;D Security Center launcher" COMPANY_NAME="Safer Networking Ltd." PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 0, 0, 5" ORIGINAL_FILENAME="SDMain.exe" INTERNAL_NAME="SDMain" LEGAL_COPYRIGHT="© 2006-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x0" MODULE_TYPE="WIN32" PE_CHECKSUM="0x6CBBB" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.0.5" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="English (Ireland) [0x1809]" />
<MATCHING_FILE NAME="SDShred.exe" SIZE="855896" CHECKSUM="0xB6755433" BIN_FILE_VERSION="1.0.1.2" BIN_PRODUCT_VERSION="1.0.1.2" PRODUCT_VERSION="1.9.0.0" FILE_DESCRIPTION="File shredder formerly integrated into Spybot-S&amp;D" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Secure Shredder" FILE_VERSION="1.0.1.2" ORIGINAL_FILENAME="SDShred.exe" INTERNAL_NAME="SecureShredder" LEGAL_COPYRIGHT="© 2007 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0xDF41D" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.1.2" UPTO_BIN_PRODUCT_VERSION="1.0.1.2" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="German (Germany) [0x407]" />
<MATCHING_FILE NAME="SDUpdate.exe" SIZE="1404240" CHECKSUM="0xEE5DC5FB" BIN_FILE_VERSION="1.0.8.8" BIN_PRODUCT_VERSION="1.0.8.8" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Updater for Spybot-S&amp;D" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1.0.8.7" ORIGINAL_FILENAME="SDUpdate.exe" INTERNAL_NAME="SDUpdate" LEGAL_COPYRIGHT="© 2007-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x159B9A" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.8.8" UPTO_BIN_PRODUCT_VERSION="1.0.8.8" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="English (Ireland) [0x1809]" />
<MATCHING_FILE NAME="SDWinSec.exe" SIZE="810320" CHECKSUM="0x7B58E523" BIN_FILE_VERSION="1.0.0.11" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Spybot-S&amp;D Security Center integration" COMPANY_NAME="Safer Networking Ltd." PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 0, 0, 11" ORIGINAL_FILENAME="SDWinSec.exe" INTERNAL_NAME="SDWinSec" LEGAL_COPYRIGHT="© 2006-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x0" MODULE_TYPE="WIN32" PE_CHECKSUM="0xCACDA" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.0.11" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="English (Ireland) [0x1809]" />
<MATCHING_FILE NAME="SpybotSD.exe" SIZE="5146448" CHECKSUM="0x66DEDD76" BIN_FILE_VERSION="1.5.2.20" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Spybot - Search &amp; Destroy" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="SpyBot-S&amp;D" FILE_VERSION="1, 5, 2, 20" ORIGINAL_FILENAME="SpyBotSD.exe" INTERNAL_NAME="SpyBotSD" LEGAL_COPYRIGHT="© 2000-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x4F5B8B" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.5.2.20" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="TeaTimer.exe" SIZE="2097488" CHECKSUM="0x853DF04C" BIN_FILE_VERSION="1.5.2.16" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="System settings protector" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 5, 2, 16" ORIGINAL_FILENAME="TeaTimer.exe" INTERNAL_NAME="TeaTimer" LEGAL_COPYRIGHT="© 2000-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x2001E3" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.5.2.16" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="Tools.dll" SIZE="836432" CHECKSUM="0xE7D636EF" BIN_FILE_VERSION="2.1.3.3" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="Library for Spybot-S&amp;D" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="2, 1, 3, 3" ORIGINAL_FILENAME="tools.dll" INTERNAL_NAME="" LEGAL_COPYRIGHT="© 2003-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xD0160" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="2.1.3.3" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="unins000.exe" SIZE="77153" CHECKSUM="0x3C8E0292" BIN_FILE_VERSION="51.13.0.0" BIN_PRODUCT_VERSION="51.13.0.0" PRODUCT_VERSION=" " FILE_DESCRIPTION="Uninstaller" COMPANY_NAME="" PRODUCT_NAME="Inno Setup" FILE_VERSION="51.13.0.0" ORIGINAL_FILENAME="" INTERNAL_NAME="" LEGAL_COPYRIGHT="Copyright (C) 1997-2004 Jordan Russell" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="51.13.0.0" UPTO_BIN_PRODUCT_VERSION="51.13.0.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="unins001.exe" SIZE="692104" CHECKSUM="0x7BC2DD37" BIN_FILE_VERSION="51.49.0.0" BIN_PRODUCT_VERSION="51.49.0.0" PRODUCT_VERSION="0.0.0.0" FILE_DESCRIPTION="Setup/Uninstall" COMPANY_NAME="" PRODUCT_NAME="" FILE_VERSION="51.49.0.0" ORIGINAL_FILENAME="" INTERNAL_NAME="" LEGAL_COPYRIGHT="" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0xB2D41" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="51.49.0.0" UPTO_BIN_PRODUCT_VERSION="51.49.0.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="UnzDll.dll" SIZE="122368" CHECKSUM="0xC145EBA" BIN_FILE_VERSION="1.73.1.1" BIN_PRODUCT_VERSION="1.73.1.1" PRODUCT_VERSION="1.73" FILE_DESCRIPTION="UnzDLL" COMPANY_NAME="" PRODUCT_NAME="Delphi Zip" FILE_VERSION="1.73.1.1" ORIGINAL_FILENAME="UnzDLL.dll" INTERNAL_NAME="UnzDLL" LEGAL_COPYRIGHT="Copyright © 2002, Eric W. Engler" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x40000" UPTO_BIN_FILE_VERSION="1.73.1.1" UPTO_BIN_PRODUCT_VERSION="1.73.1.1" LINK_DATE="07/15/2003 04:32:30" UPTO_LINK_DATE="07/15/2003 04:32:30" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="Update.exe" SIZE="464720" CHECKSUM="0xE262990" BIN_FILE_VERSION="1.4.0.6" BIN_PRODUCT_VERSION="1.5.2.0" PRODUCT_VERSION="1, 5, 2, 0" FILE_DESCRIPTION="External updater" COMPANY_NAME="Safer Networking Limited" PRODUCT_NAME="Spybot - Search &amp; Destroy" FILE_VERSION="1, 4, 0, 6" ORIGINAL_FILENAME="update.exe" INTERNAL_NAME="" LEGAL_COPYRIGHT="© 2000-2008 Safer Networking Limited. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x1" MODULE_TYPE="WIN32" PE_CHECKSUM="0x7807B" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.4.0.6" UPTO_BIN_PRODUCT_VERSION="1.5.2.0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="ZipDll.dll" SIZE="139776" CHECKSUM="0xB529EB48" BIN_FILE_VERSION="1.73.2.0" BIN_PRODUCT_VERSION="1.73.2.0" PRODUCT_VERSION="1.73" FILE_DESCRIPTION="ZipDLL" COMPANY_NAME="" PRODUCT_NAME="Delphi Zip" FILE_VERSION="1.73.2.0" ORIGINAL_FILENAME="ZipDLL.dll" INTERNAL_NAME="ZipDLL" LEGAL_COPYRIGHT="Copyright © 2002, Eric W. Engler" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x40000" UPTO_BIN_FILE_VERSION="1.73.2.0" UPTO_BIN_PRODUCT_VERSION="1.73.2.0" LINK_DATE="09/01/2003 04:16:10" UPTO_LINK_DATE="09/01/2003 04:16:10" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="Dummies\dummy.cd_clint.dll" SIZE="48640" CHECKSUM="0x597A2093" BIN_FILE_VERSION="1.0.0.0" BIN_PRODUCT_VERSION="1.0.0.0" PRODUCT_VERSION="1.0.0.0" FILE_DESCRIPTION="DLL (GUI)" COMPANY_NAME="CEXX Labs - www.cexx.org" PRODUCT_NAME="CEXX.ORG Spyware Condom (CYDOOR-Compatible)" FILE_VERSION="1.0.0.0" ORIGINAL_FILENAME="project1.dll" INTERNAL_NAME="ProjectOne" LEGAL_COPYRIGHT="CEXX Labs + Mike Dombrowski" VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x4" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="1.0.0.0" UPTO_BIN_PRODUCT_VERSION="1.0.0.0" LINK_DATE="01/12/2002 18:06:00" UPTO_LINK_DATE="01/12/2002 18:06:00" VER_LANGUAGE="English (United States) [0x409]" />
<MATCHING_FILE NAME="Plugins\Chai.dll" SIZE="790392" CHECKSUM="0x665C95AC" MODULE_TYPE="WIN32" PE_CHECKSUM="0xCAEF7" LINKER_VERSION="0x0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="Plugins\Fennel.dll" SIZE="795520" CHECKSUM="0x82EA3752" MODULE_TYPE="WIN32" PE_CHECKSUM="0xC4EBF" LINKER_VERSION="0x0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="Plugins\Mate.dll" SIZE="717176" CHECKSUM="0x10AE34C" MODULE_TYPE="WIN32" PE_CHECKSUM="0xBA2C0" LINKER_VERSION="0x0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
<MATCHING_FILE NAME="Plugins\TCPIPAddress.dll" SIZE="121344" CHECKSUM="0x231C4D7B" MODULE_TYPE="WIN32" PE_CHECKSUM="0x0" LINKER_VERSION="0x0" LINK_DATE="06/19/1992 22:22:17" UPTO_LINK_DATE="06/19/1992 22:22:17" />
</EXE>
<EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY">
<MATCHING_FILE NAME="kernel32.dll" SIZE="984576" CHECKSUM="0xF0B331F6" BIN_FILE_VERSION="5.1.2600.3119" BIN_PRODUCT_VERSION="5.1.2600.3119" PRODUCT_VERSION="5.1.2600.3119" FILE_DESCRIPTION="Windows NT BASE API Client DLL" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Microsoft® Windows® Operating System" FILE_VERSION="5.1.2600.3119 (xpsp_sp2_gdr.070416-1301)" ORIGINAL_FILENAME="kernel32" INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="© Microsoft Corporation. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0xF9293" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.3119" UPTO_BIN_PRODUCT_VERSION="5.1.2600.3119" LINK_DATE="04/16/2007 15:52:53" UPTO_LINK_DATE="04/16/2007 15:52:53" VER_LANGUAGE="English (United States) [0x409]" />
</EXE>
</DATABASE>
I think my system's going to crash after I send the error report. I'll let you know.
:oops:

drragostea
2008-05-20, 03:04
Your system is not going to crash. I don't know :sad:. I cannot analyze your log, because:

1: I simply don't have the time.
2: I have no idea what the contents are as I am unfamiliar with the logs.
3: It would be a good bet for md to look into this.

Thanks.

Imrahil
2008-05-20, 03:41
My system didn't crash.
The log is an error report for MS. Forget it. (I guess).
My PC's Tech support recommended un-installing spybot, re-setting IE to my preferences, then re-installing spybot.
These registry changed denied boxes are piling up and I can't get anything done.
Resident & Ad-Watch are hogging my CPU.
I don't know what all these prompts mean, whether I should allow or deny a change? I don't understand what's being changed and even if I did, the box can't be expanded to read the entire message anyway (seem to be RAM Addresses mainly).
Resident has turned into a Major Pane in the Rear Flanks.

Greyfox
2008-05-20, 04:22
My IE is opening to runonce every time I launch it.

Right clicking on Resident in the "sytem tray" (the list of items under tools to the left? eg: View Report, Secure Shredder, Resident....... etc?) results in no pop up action window. Right clicking on Resident in the tools window proper (to the right) results in in a pop up action window with "Display as list" or "Display as icons" as the available actions to choose from.
Under "Resident" SDHelper is disabled (by me, forgot to re-enable it); and TeaTimer is enabled, then in the window proper is a long list of actions (a log).

Imrahil,
With Spybot in Advanced mode, select Tools then double click with the left mouse button on the Resident item. It will then open up a screen offering you tick boxes for Resident SD Helper and Resident Teatimer. For the time being, until you get your system back under control, remove any ticks from both of these boxes, then exit spybot and reboot. Teatimer and the resident IE browser should now both be inactive. You can add them back in later using the same process.

drragostea


1: I simply don't have the time.
2: I have no idea what the contents are as I am unfamiliar with the logs.
3: It would be a good bet for md to look into this.


How does this help Imrahil?

drragostea
2008-05-20, 05:00
@Greyfox. I never said that it will help him. I am just explaining that I cannot help him. It's not like I do not want to, but I cannot think of any other solution.

What I'm saying is that there is a good chance a Spybot-SD Advisor can resolve his problem. Simple.

Greyfox
2008-05-20, 05:13
Imrahil,

If your system doesn't settle down after disabling Teatimer and rebooting, could post back to this thread in the forum and when writing the post click on the paperclip to the right of the Fonts box, and in the "Manage Attachments" screen that opens, browse to C:\Documents & Settings\All Users\Application Data\Spybot - Search & Destroy\Logs, highlight the file Resident.Log, then click on Open, then click on Upload. This will attach a copy of the Resident log file so we may be able to see what occurred.

Incidentally in my last post it would perhaps have been more correct to say "left click on the Resident item in the left column, or double click with the left button on the Resident item in the right screen area", but a double click on either will produce the same result.

Imrahil
2008-05-20, 23:42
Thank you for your replies.
I will try your suggestions later tonight when I can devote more time to it.
I tried to disable the resident items and Spybot denied the registry change, I'll try again.
Today on boot-up McCafee was disabled and is no longer in my MSCONFIG start-up list, other star-up programs aren't running either, including SPYBOT!

Anyway, I'll look at it later tonight.

P.S.
I'm sure I seem like an Idiot but does anyone know how I can go directly to my thread. I spent more than a little time navigating this site but couldn't find a way to go directly to my own thread.

Greyfox
2008-05-21, 02:39
Imrahil,

In view of the problems indicated in your last post and if you are not able to untick/completely shut down Teatimer, then perhaps the option you mentioned "My PC's Tech support recommended un-installing spybot, re-setting IE to my preferences, then re-installing spybot" is the way to go.

In addition to resetting your IE preferences, you also need to ensure that you have a working antivirus system.

Short of saving the URL of the thread as a favorite, I can't give you any other suggestions for your query about quickly finding your thread.

Imrahil
2008-05-21, 09:05
OK
1st of all thank you so much for the help.
I did this:
For the time being, until you get your system back under control, remove any ticks from both of these boxes, then exit spybot and reboot. Teatimer and the resident IE browser should now both be inactive. You can add them back in later using the same process. [Thanx Greyfox, (I type so slow, & am so wordy (I know), that the forum has timed me out so I’m using MS Word then pasting into the thread)].

After going thru runonce & resetting IE7 seems back to normal for my account & for my ‘Limited Account’ (SpyBot has Issues with Limited accounts due to no admin rights).

Now I need help undoing the damage I did with SpyBot's system startup clean-up tool.

Do I need to start a new thread?

Greyfox
2008-05-21, 13:25
Imrahil,

Good to hear your browser is back working.
For the time being whilst this is still relevant to the original problem, keep posting to this thread. Now can you please answer some questions.

1. Can you confirm that you didn't need to completely uninstall Spybot?

2. Can you confirm that both the resident SD Browser helper and Teatimer are currently disabled (the ticks removed from the boxes in Tools>Resident)?

3. Can you state what individual problems you still have on your system?

4. Is you antivirus system back running? If so, have you done a scan with it, and was that scan all clear? If not can you please do this.

5. Have you done a complete scan with Spybot after getting your browser back working again? If so did it find any problems? If not can you please do a scan.

6. If you didn't uninstall Spybot, and you still have problems that you think may have been caused by Teatimer, can you please post a copy of the Resident log file as requested in previous posts.

7. I don't quite understand what you mean by "Now I need help undoing the damage I did with SpyBot's system startup clean-up tool. Can you explain this further.

tammy76
2008-07-02, 15:12
Imrahil:

Did you interact with Spybot's TeaTimer feature which issued a registry change dialog that said "Spybot - Search & Destroy has detected an important registry entry that has been changed" and indicated?
Cateory: Browser page
Entry: First Home Page
Are you getting any pop-up notifications that are displayed in the lower right hand corner of the screen indicating with a title "Resident" indicating a registry change has either been allowed or denied?

Hi i was wondering if you could kindly help me im gettingthis message on my browser when i click on internet explorer instead of it going straight to home page its very annoying...

Server Error in '/' Application.
________________________________________
The resource cannot be found.
Description: HTTP 404. The resource you are looking for (or one of its dependencies) could have been removed, had its name changed, or is temporarily unavailable. Please review the following URL and make sure that it is spelled correctly.

Requested URL: /runonce2.aspx

Thanks in anticipation
Tammy

md usa spybot fan
2008-07-02, 15:50
tammy76 (Tammy):


Hi i was wondering if you could kindly help me ...
I give it a try.

Let's see if an entry like that shows up in Spybot's "Browser Pages" listing:
Go into Spybot » Mode » Advanced mode » Tools.
In the right hand pane double click "Browser Pages".
Right click on the listing that is produced and select "Copy to clipboard".
Then paste (Ctrl+V) those results to a new post in this thread.