The new update solved the problem. In this version there are no ballons, not even the field (entry, button) for the ballons does exist any more. Version 1.6.0.30
Besides of this, I think ICQ 5.1 partly caused the problems, because the ballon-popups stated something about ICQ if I so opened Outlook, or something else (the same thing also without ICQ running). In this Spybot version there is no such information any more (probably still the same odd behaviour - or a false positive?).
The information is nice to have, but is there a cure about this too?
I have now once again uninstalled ICQ 5.1 and Spybot. I cleaned everything in the registry as well (ICQ, Spybot, Teatimer, Safer Networking) with Registry First Aid's "Search the Registry", as in the filesystem. Then I installed Spybot first (Version 1.6.0.30 - Digital Signature: Montag, 07. Juli 2008 09:57:41). After that Netvigator ICQ (the Hongkong version of ICQ 5.1, still available on
www.icq.com).
In the earlier Spybot versions I could disable the ICQ-Trayboot by putting this Registry information (key) to the blocked (disabled) registry changes (Blockierte Reg-Änderungen) as this information came the first time. Now I don't get this option. I just get a ballon popup telling me, that this is allowed and the entry is back:
Resident
07:59 Änderung an der Registrierungsdatenbank erlaubt
Resident erlaubt die Änderung von ICQ Lite
(Kategorie System Startup user entry)
basierend auf Ihre Erlaubnis-Liste.
But I have not permitted anything!?
If I manually delete the following entry (because deleting this in Spybot does not delete the entry),...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runonce]
"ICQ Lite"="C:\\Programme\\ICQLite\\ICQLite.exe -trayboot"
... I get the same Spybot popup (ballon) again and immediatelly:
Resident
07:59 Änderung an der Registrierungsdatenbank erlaubt
Resident erlaubt die Änderung von ICQ Lite
(Kategorie System Startup user entry)
basierend auf Ihre Erlaubnis-Liste.
As I now start ICQ, the same statement comes again and the entry is back in Spybot, as also in the registry.
I'm wondering how I can put this entry (disable this in the registry) there (Blocked Reg-changes) manually?
In which Spybot file I may make this entry, or is it a registry key?
How's the syntax?
It is nice, that Spybot is telling me, that this entry is possibly bad and as I had disabled this in the earlier versions, ICQ still worked fine and my PC too. But I'm missing a possibility to disable this now. If I uncheck the entry in Spybot Systemstart, I get a new entry with the same information. If I erase the entry, it is simply back there again.
I am missing more possibilities to do something durable in Spybots "Systemstart" and/or manual changes (editing) in the Settings (Options - "Blocked Reg-changes").
This is the entry coming again and again:
Located: HK_CU:RunOnce, ICQ Lite (DISABLED)
where: S-1-5-21-527237240-583907252-682003330-500...
command: C:\Programme\ICQLite\ICQLite.exe -trayboot
file: C:\Programme\ICQLite\ICQLite.exe
size: 3142236
MD5: 2EAD5900356FD61DFDF27B1A819126E1
This is the Spybot information about this entry:
Aktuelle Datei: C:\Programme\ICQLite\ICQLite.exe -trayboot
Datenbank-Status: Üblicherweise nicht benötigt
Wert: ICQ Lite
Dateiname: ICQLite.exe
Beschreibung
_ICQ Lite_ - compact version of the popular messaging program
Quelle: Paul Collins Startup list
____________________
Aktuelle Datei: C:\Programme\ICQLite\ICQLite.exe -trayboot
Datenbank-Status: Nicht benötigt - Viren, Spyware, Malware oder sonstiges Unnötiges
Wert: ICQ Lite
Dateiname: scvhost.exe
Beschreibung
Added by the _AGENT-DSF_ TROJAN!
Quelle: Paul Collins Startup list
____________________
Aktuelle Datei: C:\Programme\ICQLite\ICQLite.exe -trayboot
Datenbank-Status: Nicht benötigt - Viren, Spyware, Malware oder sonstiges Unnötiges
Wert: ICQ Lite
Dateiname: winlog.exe
Beschreibung
Added by the _IRCBOT-TJ_ TROJAN!
Quelle: Paul Collins Startup list
____________________
The contents of the Resident.log:
09.08.2008 22:04:16 Erlaubt (based on lassh blacklist) value "ICQ Lite" (new data: "C:\Programme\ICQLite\ICQLite.exe -trayboot") hinzugefügt in System Startup user entry!
10.08.2008 06:47:26 Erlaubt (based on lassh blacklist) value "ICQ Lite" (new data: "") gelöscht in System Startup user entry!
10.08.2008 07:59:09 Erlaubt (based on lassh blacklist) value "ICQ Lite" (new data: "C:\Programme\ICQLite\ICQLite.exe -trayboot") hinzugefügt in System Startup user entry!
10.08.2008 08:08:53 Erlaubt (based on lassh blacklist) value "ICQ Lite" (new data: "") gelöscht in System Startup user entry!
10.08.2008 08:12:39 Erlaubt (based on lassh blacklist) value "ICQ Lite" (new data: "C:\Programme\ICQLite\ICQLite.exe -trayboot") hinzugefügt in System Startup user entry!
Is it possible, that this "lassh blacklist" is allowing the entry and it is not possible to put it to the blocked registry entries any more?
I'm wondering about the Spybot-settings (blocked and permitted list - Permitted Reg-changes, Blocked Reg-changes, Permitted processes, Blocked processes):
There is no possibility to edit these entries.
How comes that here are never any entries in Permitted processes, or in Blocked processes?
How can I put back C:\Programme\ICQLite\ICQLite.exe -trayboot in the Blocked Reg-changes?
Is it really a process which is active if I open Outlook and other programs, or is it a false alarm?