stevek:
Originally Posted by
stevek
It probably has to do with your authority to change registry keys.
You could be right because I've never heard of anything quite like this.
slotdr:
Are you running Windows XP?
If so, how many user accounts are there on the system by type (Computer Administrator, Limited, Power User and Guest).
Are you running the Spybot Immunize from the same user account with the same access rights that you were before the immunization count dropped? What type on account is that?
Have you re-booted again since Spybot’s immunization count dropped and if so has the count returned to 9239?
Between the time the count was 9239 and it was 7577 did you do anything that:
- Could have affected the user's access to the system Registry?
- May have changed the registry, like use a Registry cleaner, etc.?
***********
My first inclination is to suggest that you do a system restore to a point prior to when this happened.
***********
Assuming that you are running Windows XP, the user account that you are immunizing from is the same user account where the counts came from initially, no changes were made to that user account and that you did not perform some sort of cleanup of the registry; the only thing that I can think of is that the user lost access to an entire group of Registry keys.
If you can not figure out what may have happened:
- Download the attached RegExport.zip file.
- Extract RegExport.bat into its own folder (see Note #1).
- Execute RegExport.bat by double clicking on it.
- After the execution of RegExport.bat it should have created a RegExport.txt file (see Note #2). Copy the contents of the RegExport.txt file to the clipboard:
- Double click on the RegExport.txt file and it should open with Notepad.
- Select all (Ctrl+A)
- Copy (Ctrl+C)
- Then Paste (Ctrl+V) into a new post (reply) in this thread.
Then we can see what Registry keys are/are not accessible by the user.
Note #1: The code in the RegExport.bat.
Code:
Echo RegExport
del "RegExport.txt" "RegExport.tmp"
reg export "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com" "RegExport.tmp"
if exist "RegExport.txt" goto concat1
copy "RegExport.tmp" "RegExport.txt"
goto around1
:concat1
Copy "RegExport.txt"+"RegExport.tmp" "RegExport.txt"
:around1
del "RegExport.tmp"
reg export "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com" "RegExport.tmp"
if exist "RegExport.txt" goto concat2
copy "RegExport.tmp" "RegExport.txt"
goto around2
:concat2
Copy "RegExport.txt"+"RegExport.tmp" "RegExport.txt"
:around2
del "RegExport.tmp"
reg export "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com" "RegExport.tmp"
if exist "RegExport.txt" goto concat3
copy "RegExport.tmp" "RegExport.txt"
goto around3
:concat3
Copy "RegExport.txt"+"RegExport.tmp" "RegExport.txt"
:around3
del "RegExport.tmp"
reg export "HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com" "RegExport.tmp"
if exist "RegExport.txt" goto concat4
copy "RegExport.tmp" "RegExport.txt"
goto around4
:concat4
Copy "RegExport.txt"+"RegExport.tmp" "RegExport.txt"
:around4
del "RegExport.tmp"
reg export "HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com" "RegExport.tmp"
if exist "RegExport.txt" goto concat5
copy "RegExport.tmp" "RegExport.txt"
goto around5
:concat5
Copy "RegExport.txt"+"RegExport.tmp" "RegExport.txt"
:around5
del "RegExport.tmp"
reg export "HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com" "RegExport.tmp"
if exist "RegExport.txt" goto concat6
copy "RegExport.tmp" "RegExport.txt"
goto around6
:concat6
Copy "RegExport.txt"+"RegExport.tmp" "RegExport.txt"
:around6
del "RegExport.tmp"
Note #2: The output that I get (Windows XP Home from a Computer Administrator account).
Code:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com]
@=dword:00000005
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com]
@=dword:00000005
Windows Registry Editor Version 5.00
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com]
@=dword:00000005
Windows Registry Editor Version 5.00
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com]
@=dword:00000005
Windows Registry Editor Version 5.00
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com]
@=dword:00000005
Windows Registry Editor Version 5.00
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\180solutions.com]
@=dword:00000005