PDA

View Full Version : unwanted registry changes



boago
2006-03-15, 04:43
http://img208.imageshack.us/img208/861/oop8yn.jpg (http://imageshack.us)

Hello,
I had 1.4 spybot installed for a long time, but either some trojan/vir or other application disabled it from autostart(and i didnt notice it), so i was running pc for few days without protection. When i realized that it wont load, i ran update without any success(had problems with connecting to server/downloading), then i did full scan, but Spybot found nothing. After few hours of trying to download update, i decided to redownload and resintall Spybot, and of course after this it was all fine with updating, but scan showed nothing again(kinda strange, althro i didnt install/download anything new in few weeks atleast). But that resident thing is showing all this crap at my screen all the time... sometimes im getting full screen spammed with this, its like 300+ popups every 60 seconds! I know that i can hide Spybot window, but id rather solve this problem otherwise, by eliminating source... althro firewall, antivirus, spybot... not even Hijackthis is possible to find anything. Any help?

md usa spybot fan
2006-03-15, 06:31
You are continually denying changes for Google and Adobe Acrobat toolbars because you used the "Remember this decision" option in answering TeaTimer registry change dialog.

I can't tell from the screen print if the these toolbar are being added or deleted so I would like to see the log entries for the changes. Go into Spybot > Mode > Advanced Mode > Tools > Resident > page (scroll) to the bottom of the listing and highlight a portion of the log that shows the registry change that are being denied for the following CLSIDs:
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
Then right click and select Copy. Paste the log entries to another post in this thread.

boago
2006-03-15, 18:17
2006-03-15 18:14:43 Odmówiono value "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (new data: "") usunięte in User-specific browser toolbar!
2006-03-15 18:14:43 Odmówiono value "{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (new data: "") usunięte in User-specific browser toolbar!

Both are related to toolbar removal. :scratch:

md usa spybot fan
2006-03-15, 21:05
If you check "Remember this decision" in TeaTimer on a change the information concerning that change it is stored in a file. TeaTimer uses that information to automatically "Allow" or "Deny" changes. It seems that you may have checked "Remember this decision" and "Deny change" when the toolbars were being remove. Go into TeaTimer's "White & Black List", look for and remove any entry relating to that change from the "Blocked registry changes". To do this:Right click on the TeaTimer system tray icon and select Settings. This will bring up TeaTimer's "White & Black List". There are four (4) Buttons across the top of the "White & Black List":

Allowed processes
Blocked processes
Allowed registry changes
Blocked registry changes

Note: If you don't see all four buttons, try expanding the window to the right.
The entries that you should review are "Blocked registry changes". You can delete entries by clicking on the scripted black "X" to the right of the entry that you want to delete and then clicking the "OK" button when you're done. Delete the entries for both of the following:
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{47833539-D0C5-4125-9FA8-0819E2EAAC93}
This will in effect make TeaTimer forget what you told it to remember so that during future changes to these items TeaTimer will issue a pop-up dialog rather then just a notification pop-up.

After removing the above entries, when you get a pop-up dialog for the removal of those registry entry do a "Allow change" without the "Remember this decision" option. After you have allow the removal of the registry entry, refresh TeaTimer's snapshot files as follows:
Right click Spybot's TeaTimer System Tray Icon > click Exit Spybot-S&D Resident. [LIST]
TeaTimer closes.
TeaTimer's snapshot files are refreshed at this time.

Restart TeaTimer:
Using Windows Explorer, navigate to C:\Program Files\Spybot - Search & Destroy.
Double click TeaTimer.exe to start it.

boago
2006-03-16, 00:05
Solved, thanks :)