Results 1 to 18 of 18

Thread: Spybot problem + webcoolsearch crap

  1. #1
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94

    Spybot problem + webcoolsearch crap

    Say gang, for about the past week I've had problems with Spybot such that it won't open win I click the link. It attempts to open then just disappears. I tried to uninstall it and it says some items couldn't be removed but can manually. I try to and I keep getting the message that file SDHelper.dll cannot be deleted and may be in use, blah blah. WTF is going on all of a sudden. This coincided about the same time with my IE homepage changing to http://webcoolsearch.com.....can someone help me?!
    Peace,
    Stevie B.

  2. #2
    R.I.P. 2013-11-22 blebs's Avatar
    Join Date
    Dec 2000
    Location
    North Canton, Ohio
    Posts
    12,819
    Restart in safe mode and delete the rest from there then reinstall. If you still have problems, let me know.

  3. #3
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Originally posted by blebs99
    Restart in safe mode and delete the rest from there then reinstall. If you still have problems, let me know.
    No dice, don't have admin rights to this pc, its a company laptop....just found the cwshredder.zip and am running it...hope it works but we'll see....will update here either way.
    Peace,
    Stevie B.

  4. #4
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Originally posted by blebs99
    Restart in safe mode and delete the rest from there then reinstall. If you still have problems, let me know.
    Thanks Blebs..I was able to start up in safe mode and removed all the files. Also got rid of the webcoolsearch crap and then re-downloaded the exe file for spybot but it still won't work. It pops up the warning page about legal issues then I hit OK and nothing happens..it just closes, no errors or anything. Any further suggestions will be greatly appreciated.
    Peace,
    Stevie B.

  5. #5
    R.I.P. 2013-11-22 blebs's Avatar
    Join Date
    Dec 2000
    Location
    North Canton, Ohio
    Posts
    12,819
    At this point, just uninstall Spybot and continue or get Ad Aware 6 personal edition for now. I'll have to do some researching on what the problem might be. It may only need to have the registry entries cleaned out for Spybot before installing again. I'll check on it.

  6. #6
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Originally posted by blebs99
    At this point, just uninstall Spybot and continue or get Ad Aware 6 personal edition for now. I'll have to do some researching on what the problem might be. It may only need to have the registry entries cleaned out for Spybot before installing again. I'll check on it.
    Thanks Blebs...I've used them both for some time now so I'll just uninstall it and wait to hear from you and the fellow experts. fyi, I ran HijackThis.exe and had an entry showing up for Spybot..I've copied it below.
    BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} c:\~\Spybot\SDhelper.dll(file missing)

    That was the file that kept stoping my uninstall of Spybot initially..kept saying it was in use when I had closed just about everything including some services..Anyway, hope that helps, I feel naked with Spybot as it always finds a few items that Adaware doesn't, and vice versa....I do have Spywareguard and SpywareBlaster so hopefully I'm good for the short term....Again thanks for your help.

    One last thing which may not mean anything...I've been in China, then Korea, and am now in Singapore over the last 4 weeks...this only started a week or two ago...I've been using hotel broadband everywhere I've been...gotta crash now, I have a flight out to the good ol' USofA tomorrow AM! Will get any responses Sunday evening EST
    Peace,
    Stevie B.

  7. #7
    Elite Member Norm's Avatar
    Join Date
    Mar 2001
    Posts
    14,140
    Here's what spybot adds to the registry when installed

    Keys added:1
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1


    Values added:20
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Setup Version: "My Inno Setup Extensions 3.0.6.2"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: App Path: "E:\Program Files\Spybot - Search & Destroy"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Icon Group: "Spybot - Search & Destroy"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: User: "TopRung"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Setup Type: "custom"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Selected Components: "main"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Deselected Components: "blind,language"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Selected Tasks: "desktopicon,quicklaunchicon"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Inno Setup: Deselected Tasks: ""
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\DisplayName: "Spybot - Search & Destroy 1.2"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\DisplayIcon: "E:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\UninstallString: ""E:\Program Files\Spybot - Search & Destroy\unins000.exe""
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\DisplayVersion: "1.2"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\Publisher: "PepiMK Software"
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spybot - Search & Destroy_is1\URLInfoAbout: "http://security.kolla.de/"
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:R:\Qbphzragf naq Frggvatf\GbcEhat\Qrfxgbc\fclobgfq12.rkr: 2F 00 00 00 06 00 00 00 F0 00 2B A7 A6 C6 C3 01
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Fclobg - Frnepu & Qrfgebl: 2F 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Fclobg - Frnepu & Qrfgebl\Fclobg-F&Q (nqinaprq zbqr).yax: 2F 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Fclobg - Frnepu & Qrfgebl\Fclobg-F&Q (rnfl zbqr).yax: 2F 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACVQY:%pfvqy2%\Fclobg - Frnepu & Qrfgebl\Havafgnyy Fclobg-F&Q.yax: 2F 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00


    Values modified:5
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 0E 9F 73 4A A0 91 93 64 A1 04 49 95 44 0B 7C 95 10 7B EC 9A EC 01 3E 6C 61 1B D3 7C 19 47 4D BA 7F 50 08 94 B1 F5 2C 9A 31 01 F9 09 97 D4 A7 77 FF FE 26 01 1A 36 DC 82 13 7D B8 EB DD 31 BF 37 92 4A F8 02 AC 46 37 F0 B1 29 4A A9 29 BC 40 B2
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: F5 32 8D 01 E0 DB 43 0A 99 0B 16 69 66 FE 6C 69 1D 8F 7A 53 97 54 34 0C AE 2E B9 40 A4 11 F8 45 87 F5 B7 1D ED 62 3B EA 0B 26 86 8E 8D B3 A1 B0 12 81 62 F6 E4 79 1A 51 D3 CB DC 0A C6 50 51 DF 00 F5 18 D3 AC D9 D2 DF 63 07 3A 15 DE 10 38 95
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Order: 08 00 00 00 02 00 00 00 7E 09 00 00 01 00 00 00 21 00 00 00 5E 00 00 00 19 00 00 00 50 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 3A 00 31 00 00 00 00 00 8C 2F C5 66 10 00 37 74 6F 6F 6C 73 20 50 61 72 74 69 74 69 6F 6E 20 4D 61 6E 61 67 65 72 20 32 30 30 33 20 44 65 6D 6F 00 37 54 4F 4F 4C 53 7E 31 00 00 00 00 00 0D 00 00 00 3A 00 00 00 12 00 00 00 2B 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 15 00 31 00 00 00 00 00 88 2F AE 4B 10 00 37 2D 5A 69 70 00 00 00 00 00 00 00 0D 04 00 00 70 00 00 00 00 00 00 00 62 00 00 00 41 75 67 4D 01 00 00 00 02 00 00 00 00 00 00 00 23 00 31 00 00 00 00 00 E2 2E 76 1C 10 00 41 63 63 65 73 73 6F 72 69 65 73 00 41 43 43 45 53 53 7E 31 00 00 00 01 00 00 00 23 00 31 00 00 00 00 00 E1 2E 48 BB 10 00 41 63 63 65 73 73 6F 72 69 65 73 00 41 43 43 45 53 53 7E 31 00 00 00 00 00 0D 00 00 00 48
    00 00 00 15 00 00 00 39 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 23 00 31 00 00 00 00 00 8A 2F 3D 7E 10 00 41 43 44 20 53 79 73 74 65 6D 73 00 41 43 44 53 59 53 7E 31 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 05 00 00 00 38 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 22 00 31 00 00 00 00 00 E2 2E 54 1E 10 00 41 68 65 61 64 20 4E 65 72 6F 00 41 48 45 41 44 4E 7E 31 00 00 00 00 00 0D 00 00 00 58 00 00 00 07 00 00 00 49 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 33 00 31 00 00 00 00 00 07 2F 33 78 10 00 41 56 47 20 36 2E 30 20 41 6E 74 69 2D 56 69 72 75 73 20 53 79 73 74 65 6D 00 41 56 47 36 7E 31 2E 30 41 4E 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 0E 00 00 00 37 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 21 00 31 00 00 00 00 00 85 2F 51 68 10 00 43 61 6C 79 70 73 6F 20 33 00 43 41 4C 59 50 53 7E 31 00 00 00 00 00 00 0D 04 00 00 3C 00 00 00 09 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 18 00 31 00 00 00
    00 00 1C 2F 99 85 10 00 43 65 6C 65 73 74 69 61 00 00 00 00 00 00 0D 04 00 00 4A 00 00 00 0A 00 00 00 3B 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 25 00 31 00 00 00 00 00 1C 2F FB 85 10 00 43 72 61 63 6B 20 41 74 74 61 63 6B 21 00 43 52 41 43 4B 41 7E 31 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 0B 00 00 00 38 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 22 00 31 00 00 00 00 00 1C 2F 5D 88 10 00 46 6C 69 67 68 74 47 65 61 72 00 46 4C 49 47 48 54 7E 31 00 00 00 00 00 0D 04 00 00 3A 00 00 00 13 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 88 2F 38 7B 10 00 47 65 6E 69 75 73 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 11 00 00 00 37 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 21 00 31 00 00 00 00 00 86 2F A0 6A 10 00 49 50 53 63 61 6E 6E 65 72 00 49 50 53 43 41 4E 7E 31 00 00 00 00 00 00 0D 04 00 00 3C 00 00 00 10 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 18 00 31 00 00 00 00 0
    0 86 2F 6D 68 10 00 49 50 2D 54 6F 6F 6C 73 00 00 00 00 00 00 0D 00 00 00 46 00 00 00 0D 00 00 00 37 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 21 00 31 00 00 00 00 00 5C 2F 6A B6 10 00 49 72 66 61 6E 56 69 65 77 00 49 52 46 41 4E 56 7E 31 00 00 00 00 00 00 0D 00 00 00 38 00 00 00 14 00 00 00 29 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 13 00 31 00 00 00 00 00 88 2F E3 82 10 00 4B 4C 43 00 00 00 00 00 00 00 0D 04 00 00 50 00 00 00 1D 00 00 00 41 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 2B 00 31 00 00 00 00 00 93 2F CC 08 10 00 4C 61 76 61 73 6F 66 74 20 41 64 2D 61 77 61 72 65 20 36 00 4C 41 56 41 53 4F 7E 31 00 00 00 00 00 00 0D 00 00 00 3A 00 00 00 1A 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 16 00 31 00 00 00 00 00 8D 2F 64 99 10 00 6D 79 48 54 50 43 00 00 00 00 00 00 0D 00 00 00 4E 00 00 00 0F 00 00 00 3F 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 29 00 31 00 00 00 00 00 86 2F E6 46 10 00 4E 6F 72
    74 6F 6E 20 47 68 6F 73 74 20 32 30 30 33 00 4E 4F 52 54 4F 4E 7E 31 00 00 00 00 00 00 0D 04 00 00 48 00 00 00 1C 00 00 00 3A 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 24 00 31 00 00 00 00 00 91 2F C2 71 10 00 50 79 74 68 6F 6E 20 32 2E 33 00 50 59 54 48 4F 4E 7E 31 2E 33 00 00 00 00 00 0D 00 00 00 3C 00 00 00 1E 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 18 00 31 00 00 00 00 00 93 2F 63 33 10 00 53 6C 6F 77 56 69 65 77 00 00 00 00 00 00 0D 00 00 00 58 00 00 00 01 00 00 00 4A 00 00 00 41 75 67 4D 01 00 00 00 02 00 00 00 00 00 00 00 17 00 31 00 00 00 00 00 8A 2F F1 99 10 00 53 74 61 72 74 75 70 00 00 00 00 01 00 00 00 17 00 31 00 00 00 00 00 E1 2E 80 BA 10 00 53 74 61 72 74 75 70 00 00 00 00 00 00 0D 04 00 00 3C 00 00 00 1F 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 18 00 31 00 00 00 00 00 93 2F CC 43 10 00 53 75 70 65 72 42 6F 74 00 00 00 00 00 00 0D 00 00 00 4E 00 00 00 06 00 00 00 40 00 00 00 41 75 67 4D 01 00 00 00
    01 00 00 00 01 00 00 00 2A 00 31 00 00 00 00 00 E7 2E B8 21 10 00 54 68 65 20 39 31 31 20 43 44 20 42 75 69 6C 64 65 72 00 54 48 45 39 31 31 7E 31 00 00 00 00 00 0D 04 00 00 4C 00 00 00 0C 00 00 00 3D 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 27 00 31 00 00 00 00 00 2B 2F 2D 1C 10 00 54 6F 74 61 6C 20 43 6F 6D 6D 61 6E 64 65 72 00 54 4F 54 41 4C 43 7E 31 00 00 00 00 00 00 0D 04 00 00 4E 00 00 00 16 00 00 00 3F 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 29 00 31 00 00 00 00 00 8A 2F AC 94 10 00 55 6C 74 69 6D 61 74 65 5A 69 70 20 32 2E 37 00 55 4C 54 49 4D 41 7E 31 2E 37 00 00 00 00 00 00 0D 00 00 00 46 00 00 00 20 00 00 00 38 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 22 00 31 00 00 00 00 00 93 2F E1 46 10 00 57 69 6E 48 54 54 72 61 63 6B 00 57 49 4E 48 54 54 7E 31 00 00 00 00 00 0D 00 00 00 3A 00 00 00 1B 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 8E 2F 27 4C 10 00 57 69 6E 49 53 4F 00 00 00 0
    0 00 00 0D 04 00 00 56 00 00 00 18 00 00 00 48 00 00 00 41 75 67 4D 01 00 00 00 02 00 00 00 00 00 00 00 16 00 31 00 00 00 00 00 8C 2F D1 31 10 00 57 69 6E 52 41 52 00 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 8C 2F D1 31 10 00 57 69 6E 52 41 52 00 00 00 00 00 00 0D 00 00 00 5A 00 00 00 02 00 00 00 4C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 36 00 31 00 00 00 00 00 E2 2E 02 1D 10 00 57 69 6E 74 65 72 6E 61 6C 73 20 41 64 6D 69 6E 69 73 74 72 61 74 6F 72 27 73 20 50 61 6B 00 57 49 4E 54 45 52 7E 31 00 00 00 00 00 0D 04 00 00 3A 00 00 00 08 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 07 2F 80 7B 10 00 57 69 6E 5A 69 70 00 00 00 00 00 00 0D 04 00 00 56 00 00 00 03 00 00 00 47 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 31 00 32 00 D5 02 00 00 E2 2E 75 1C 20 00 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 2E 6C 6E 6B 00 49 4E 54 45 52 4E 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 05 04 00 00 54 00 00 00 04 00 00
    00 45 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 2F 00 32 00 A9 02 00 00 E2 2E 76 1C 20 00 4F 75 74 6C 6F 6F 6B 20 45 78 70 72 65 73 73 2E 6C 6E 6B 00 4F 55 54 4C 4F 4F 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 05 04 00 00 4C 00 00 00 17 00 00 00 3E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 28 00 32 00 71 05 00 00 8B 2F 97 50 20 00 54 68 65 20 42 61 74 21 2E 4C 4E 4B 00 54 48 45 42 41 54 7E 31 2E 4C 4E 4B 00 00 00 00 00 05 04 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Order: 08 00 00 00 02 00 00 00 7E 0A 00 00 01 00 00 00 24 00 00 00 5E 00 00 00 19 00 00 00 50 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 3A 00 31 00 00 00 00 00 8C 2F C5 66 10 00 37 74 6F 6F 6C 73 20 50 61 72 74 69 74 69 6F 6E 20 4D 61 6E 61 67 65 72 20 32 30 30 33 20 44 65 6D 6F 00 37 54 4F 4F 4C 53 7E 31 00 00 00 00 00 0D 00 00 00 3A 00 00 00 12 00 00 00 2B 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 15 00 31 00 00 00 00 00 88 2F AE 4B 10 00 37 2D 5A 69 70 00 00 00 00 00 00 00 0D 04 00 00 70 00 00 00 00 00 00 00 62 00 00 00 41 75 67 4D 01 00 00 00 02 00 00 00 00 00 00 00 23 00 31 00 00 00 00 00 E2 2E 76 1C 10 00 41 63 63 65 73 73 6F 72 69 65 73 00 41 43 43 45 53 53 7E 31 00 00 00 01 00 00 00 23 00 31 00 00 00 00 00 E1 2E 48 BB 10 00 41 63 63 65 73 73 6F 72 69 65 73 00 41 43 43 45 53 53 7E 31 00 00 00 00 00 0D 00 00 00 48
    00 00 00 15 00 00 00 39 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 23 00 31 00 00 00 00 00 8A 2F 3D 7E 10 00 41 43 44 20 53 79 73 74 65 6D 73 00 41 43 44 53 59 53 7E 31 00 00 00 00 00 00 0D 04 00 00 52 00 00 00 21 00 00 00 43 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 2D 00 31 00 00 00 00 00 94 2F AC 15 10 00 41 64 76 61 6E 63 65 64 20 50 6F 72 74 20 53 63 61 6E 6E 65 72 00 41 44 56 41 4E 43 7E 31 00 00 00 00 00 00 0D 00 00 00 46 00 00 00 05 00 00 00 38 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 22 00 31 00 00 00 00 00 E2 2E 54 1E 10 00 41 68 65 61 64 20 4E 65 72 6F 00 41 48 45 41 44 4E 7E 31 00 00 00 00 00 0D 00 00 00 58 00 00 00 07 00 00 00 49 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 33 00 31 00 00 00 00 00 07 2F 33 78 10 00 41 56 47 20 36 2E 30 20 41 6E 74 69 2D 56 69 72 75 73 20 53 79 73 74 65 6D 00 41 56 47 36 7E 31 2E 30 41 4E 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 0E 00 00 00 37 00 00 00 41 75 67 4D 01 00 00 00 01 00
    00 00 01 00 00 00 21 00 31 00 00 00 00 00 85 2F 51 68 10 00 43 61 6C 79 70 73 6F 20 33 00 43 41 4C 59 50 53 7E 31 00 00 00 00 00 00 0D 00 00 00 3C 00 00 00 09 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 18 00 31 00 00 00 00 00 1C 2F 99 85 10 00 43 65 6C 65 73 74 69 61 00 00 00 00 00 00 0D 04 00 00 4A 00 00 00 0A 00 00 00 3B 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 25 00 31 00 00 00 00 00 1C 2F FB 85 10 00 43 72 61 63 6B 20 41 74 74 61 63 6B 21 00 43 52 41 43 4B 41 7E 31 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 0B 00 00 00 38 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 22 00 31 00 00 00 00 00 1C 2F 5D 88 10 00 46 6C 69 67 68 74 47 65 61 72 00 46 4C 49 47 48 54 7E 31 00 00 00 00 00 0D 04 00 00 3A 00 00 00 13 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 88 2F 38 7B 10 00 47 65 6E 69 75 73 00 00 00 00 00 00 0D 04 00 00 46 00 00 00 11 00 00 00 37 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 0
    0 00 00 00 00 21 00 31 00 00 00 00 00 86 2F A0 6A 10 00 49 50 53 63 61 6E 6E 65 72 00 49 50 53 43 41 4E 7E 31 00 00 00 00 00 00 0D 04 00 00 3C 00 00 00 10 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 18 00 31 00 00 00 00 00 86 2F 6D 68 10 00 49 50 2D 54 6F 6F 6C 73 00 00 00 00 00 00 0D 00 00 00 46 00 00 00 0D 00 00 00 37 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 21 00 31 00 00 00 00 00 5C 2F 6A B6 10 00 49 72 66 61 6E 56 69 65 77 00 49 52 46 41 4E 56 7E 31 00 00 00 00 00 00 0D 00 00 00 38 00 00 00 14 00 00 00 29 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 13 00 31 00 00 00 00 00 88 2F E3 82 10 00 4B 4C 43 00 00 00 00 00 00 00 0D 04 00 00 50 00 00 00 1D 00 00 00 41 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 2B 00 31 00 00 00 00 00 93 2F CC 08 10 00 4C 61 76 61 73 6F 66 74 20 41 64 2D 61 77 61 72 65 20 36 00 4C 41 56 41 53 4F 7E 31 00 00 00 00 00 00 0D 00 00 00 3A 00 00 00 1A 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01
    00 00 00 00 00 00 00 16 00 31 00 00 00 00 00 8D 2F 64 99 10 00 6D 79 48 54 50 43 00 00 00 00 00 00 0D 00 00 00 4E 00 00 00 0F 00 00 00 3F 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 29 00 31 00 00 00 00 00 86 2F E6 46 10 00 4E 6F 72 74 6F 6E 20 47 68 6F 73 74 20 32 30 30 33 00 4E 4F 52 54 4F 4E 7E 31 00 00 00 00 00 00 0D 04 00 00 48 00 00 00 1C 00 00 00 3A 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 24 00 31 00 00 00 00 00 91 2F C2 71 10 00 50 79 74 68 6F 6E 20 32 2E 33 00 50 59 54 48 4F 4E 7E 31 2E 33 00 00 00 00 00 0D 00 00 00 58 00 00 00 22 00 00 00 49 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 33 00 31 00 00 00 00 00 94 2F 72 16 10 00 52 65 6D 6F 74 65 20 41 64 6D 69 6E 69 73 74 72 61 74 6F 72 20 76 32 2E 31 00 52 45 4D 4F 54 45 7E 31 2E 31 00 00 00 00 00 00 0D 00 00 00 3C 00 00 00 1E 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 18 00 31 00 00 00 00 00 93 2F 63 33 10 00 53 6C 6F 77 56 69 65 77 00 00 00 00 00 00 0D 00
    00 00 56 00 00 00 23 00 00 00 47 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 31 00 31 00 00 00 00 00 94 2F 35 19 10 00 53 70 79 62 6F 74 20 2D 20 53 65 61 72 63 68 20 26 20 44 65 73 74 72 6F 79 00 53 50 59 42 4F 54 7E 31 00 00 00 00 00 00 0D 00 00 00 58 00 00 00 01 00 00 00 4A 00 00 00 41 75 67 4D 01 00 00 00 02 00 00 00 00 00 00 00 17 00 31 00 00 00 00 00 8A 2F F1 99 10 00 53 74 61 72 74 75 70 00 00 00 00 01 00 00 00 17 00 31 00 00 00 00 00 E1 2E 80 BA 10 00 53 74 61 72 74 75 70 00 00 00 00 00 00 0D 04 00 00 3C 00 00 00 1F 00 00 00 2E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 18 00 31 00 00 00 00 00 93 2F CC 43 10 00 53 75 70 65 72 42 6F 74 00 00 00 00 00 00 0D 00 00 00 4E 00 00 00 06 00 00 00 40 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 2A 00 31 00 00 00 00 00 E7 2E B8 21 10 00 54 68 65 20 39 31 31 20 43 44 20 42 75 69 6C 64 65 72 00 54 48 45 39 31 31 7E 31 00 00 00 00 00 0D 04 00 00 4C 00 00 00 0C 00 00 00 3D 00 00 00 41 75 67 4D 01 00 00 0
    0 01 00 00 00 01 00 00 00 27 00 31 00 00 00 00 00 2B 2F 2D 1C 10 00 54 6F 74 61 6C 20 43 6F 6D 6D 61 6E 64 65 72 00 54 4F 54 41 4C 43 7E 31 00 00 00 00 00 00 0D 04 00 00 4E 00 00 00 16 00 00 00 3F 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 29 00 31 00 00 00 00 00 8A 2F AC 94 10 00 55 6C 74 69 6D 61 74 65 5A 69 70 20 32 2E 37 00 55 4C 54 49 4D 41 7E 31 2E 37 00 00 00 00 00 00 0D 00 00 00 46 00 00 00 20 00 00 00 38 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 22 00 31 00 00 00 00 00 93 2F E2 46 10 00 57 69 6E 48 54 54 72 61 63 6B 00 57 49 4E 48 54 54 7E 31 00 00 00 00 00 0D 00 00 00 3A 00 00 00 1B 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 8E 2F 27 4C 10 00 57 69 6E 49 53 4F 00 00 00 00 00 00 0D 04 00 00 56 00 00 00 18 00 00 00 48 00 00 00 41 75 67 4D 01 00 00 00 02 00 00 00 00 00 00 00 16 00 31 00 00 00 00 00 8C 2F D1 31 10 00 57 69 6E 52 41 52 00 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 8C 2F D1 31 10 00 57
    69 6E 52 41 52 00 00 00 00 00 00 0D 00 00 00 5A 00 00 00 02 00 00 00 4C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 36 00 31 00 00 00 00 00 E2 2E 02 1D 10 00 57 69 6E 74 65 72 6E 61 6C 73 20 41 64 6D 69 6E 69 73 74 72 61 74 6F 72 27 73 20 50 61 6B 00 57 49 4E 54 45 52 7E 31 00 00 00 00 00 0D 04 00 00 3A 00 00 00 08 00 00 00 2C 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 01 00 00 00 16 00 31 00 00 00 00 00 07 2F 80 7B 10 00 57 69 6E 5A 69 70 00 00 00 00 00 00 0D 04 00 00 56 00 00 00 03 00 00 00 47 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 31 00 32 00 D5 02 00 00 E2 2E 75 1C 20 00 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 2E 6C 6E 6B 00 49 4E 54 45 52 4E 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 05 04 00 00 54 00 00 00 04 00 00 00 45 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 2F 00 32 00 A9 02 00 00 E2 2E 76 1C 20 00 4F 75 74 6C 6F 6F 6B 20 45 78 70 72 65 73 73 2E 6C 6E 6B 00 4F 55 54 4C 4F 4F 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 05 04 00 00
    4C 00 00 00 17 00 00 00 3E 00 00 00 41 75 67 4D 01 00 00 00 01 00 00 00 00 00 00 00 28 00 32 00 71 05 00 00 8B 2F 97 50 20 00 54 68 65 20 42 61 74 21 2E 4C 4E 4B 00 54 48 45 42 41 54 7E 31 2E 4C 4E 4B 00 00 00 00 00 05 04 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop\Taskbar: 0C 00 00 00 08 00 00 00 02 00 00 00 00 00 00 00 B0 E2 2B D8 64 57 D0 11 A9 6E 00 C0 4F D7 05 A2 22 00 1C 00 0A 01 00 00 1A 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46 83 00 00 00 10 00 00 00 30 CB 6F 03 4B 40 C3 01 70 B0 E5 6C 23 C6 C3 01 70 3F EF C9 0D C6 C3 01 00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A 01 14 00 1F 50 E0 4F D0 20 EA 3A 69 10 A2 D8 08 00 2B 30 30 9D 19 00 23 45 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E9 6D 2E 00 31 00 00 00 00 00 E2 2E 73 1C 30 00 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 00 44 4F 43 55 4D 45 7E 31 00 17 00 31 00 00 00 00 00 E2 2E 74 1C 10 00 54 6F 70 52 75 6E 67 00 00 28 00 31 00 00 00 00 00 8A 2F 94 93 12 00 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61 00 41 50 50 4C 49 43
    7E 31 00 21 00 31 00 00 00 00 00 C5 22 9D 91 10 00 4D 69 63 72 6F 73 6F 66 74 00 4D 49 43 52 4F 53 7E 31 00 29 00 31 00 00 00 00 00 D3 22 32 A6 10 00 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 00 49 4E 54 45 52 4E 7E 31 00 24 00 31 00 00 00 00 00 DB 22 76 BA 10 00 51 75 69 63 6B 20 4C 61 75 6E 63 68 00 51 55 49 43 4B 4C 7E 31 00 00 00 8C 00 00 00 1C 00 00 00 01 00 00 00 1C 00 00 00 2F 00 00 00 00 00 00 00 8B 00 00 00 13 00 00 00 03 00 00 00 C9 92 0D F4 10 00 00 00 32 4B 00 45 3A 5C 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 5C 54 6F 70 52 75 6E 67 5C 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61 5C 4D 69 63 72 6F 73 6F 66 74 5C 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 5C 51 75 69 63 6B 20 4C 61 75 6E 63 68 00 00 60 00 00 00 03 00 00 A0 58 00 00 00 00 00 00 00 74 6F 70 64 6F 67 00 00 00 00 00 00 00 00 00 00 CC 85 8F A4 8F BA B3 47 A0 AF A4 A3 B2 62 34 64 45 D8 8B 40 3E AC D7 11 86 73 00 60 97 08 22 DF CC 85 8F A4 8F BA B3 47 A0 AF A4 A3 B2 62
    34 64 45 D8 8B 40 3E AC D7 11 86 73 00 60 97 08 22 DF 10 00 00 00 05 00 00 A0 1A 00 00 00 9A 00 00 00 00 00 00 00 08 00 00 00 02 00 00 00 C8 01 00 00 01 00 00 00 07 00 00 00 44 00 00 00 06 00 00 00 36 00 32 00 31 02 00 00 93 2F E2 46 20 00 48 54 54 72 61 63 6B 20 57 65 62 73 69 74 65 20 43 6F 70 69 65 72 2E 6C 6E 6B 00 48 54 54 52 41 43 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 4E 00 00 00 01 00 00 00 40 00 32 00 65 02 00 00 E2 2E 76 1C 20 00 4C 61 75 6E 63 68 20 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 20 42 72 6F 77 73 65 72 2E 6C 6E 6B 00 4C 41 55 4E 43 48 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 44 00 00 00 03 00 00 00 36 00 32 00 A3 08 00 00 E2 2E 76 1C 01 00 4C 61 75 6E 63 68 20 4F 75 74 6C 6F 6F 6B 20 45 78 70 72 65 73 73 2E 6C 6E 6B 00 4C 41 55 4E 43 48 7E 32 2E 4C 4E 4B 00 00 00 00 00 00 00 4A 00 00 00 02 00 00 00 3C 00 32 00 E7 01 00 00 65 2F AF 8B 20 00 53 68 6F 72 74 63 75 74 20 74 6F 20 42 6C 61 6E 6B 20 53 63 72 65 65 6E 2E 73 63 72 2E 6C 6E 6B 00 53 48 4F 52 54 43 7
    E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 3A 00 00 00 00 00 00 00 2C 00 32 00 4F 00 00 00 E2 2E 78 1C 20 00 53 68 6F 77 20 44 65 73 6B 74 6F 70 2E 73 63 66 00 53 48 4F 57 44 45 7E 31 2E 53 43 46 00 00 00 00 00 00 00 2A 00 00 00 05 00 00 00 1C 00 32 00 41 02 00 00 93 2F 64 33 20 00 53 6C 6F 77 76 69 65 77 2E 6C 6E 6B 00 00 00 00 00 00 00 00 38 00 00 00 04 00 00 00 29 00 32 00 C0 01 00 00 69 2F E5 A3 20 00 57 49 4E 54 49 50 43 46 47 2E 6C 6E 6B 00 57 49 4E 54 49 50 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 00 83 00 00 00 E0 06 00 00 00 00 00 00 16 00 00 00 00 00 00 00 00 00 00 00 16 00 00 00 00 00 00 00 01 00 00 00 01 00 00 00 AA 4F 28 68 48 6A D0 11 8C 78 00 C0 4F D9 18 B4 C9 02 00 00 E0 04 00 00 00 00 00 00 16 00 00 00 00 00 00 00 00 00 00 00 16 00 00 00 00 00 00 00 01 00 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop\Taskbar: 0C 00 00 00 08 00 00 00 02 00 00 00 00 00 00 00 B0 E2 2B D8 64 57 D0 11 A9 6E 00 C0 4F D7 05 A2 22 00 1C 00 0A 01 00 00 1A 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46 83 00 00 00 10 00 00 00 30 CB 6F 03 4B 40 C3 01 50 95 E5 B6 A6 C6 C3 01 60 1A A0 B5 A6 C6 C3 01 00 10 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0A 01 14 00 1F 50 E0 4F D0 20 EA 3A 69 10 A2 D8 08 00 2B 30 30 9D 19 00 23 45 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E9 6D 2E 00 31 00 00 00 00 00 E2 2E 73 1C 30 00 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 00 44 4F 43 55 4D 45 7E 31 00 17 00 31 00 00 00 00 00 E2 2E 74 1C 10 00 54 6F 70 52 75 6E 67 00 00 28 00 31 00 00 00 00 00 8A 2F 94 93 12 00 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61 00 41 50 50 4C 49 43
    7E 31 00 21 00 31 00 00 00 00 00 C5 22 9D 91 10 00 4D 69 63 72 6F 73 6F 66 74 00 4D 49 43 52 4F 53 7E 31 00 29 00 31 00 00 00 00 00 D3 22 32 A6 10 00 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 00 49 4E 54 45 52 4E 7E 31 00 24 00 31 00 00 00 00 00 DB 22 76 BA 10 00 51 75 69 63 6B 20 4C 61 75 6E 63 68 00 51 55 49 43 4B 4C 7E 31 00 00 00 8C 00 00 00 1C 00 00 00 01 00 00 00 1C 00 00 00 2F 00 00 00 00 00 00 00 8B 00 00 00 13 00 00 00 03 00 00 00 C9 92 0D F4 10 00 00 00 32 4B 00 45 3A 5C 44 6F 63 75 6D 65 6E 74 73 20 61 6E 64 20 53 65 74 74 69 6E 67 73 5C 54 6F 70 52 75 6E 67 5C 41 70 70 6C 69 63 61 74 69 6F 6E 20 44 61 74 61 5C 4D 69 63 72 6F 73 6F 66 74 5C 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 5C 51 75 69 63 6B 20 4C 61 75 6E 63 68 00 00 60 00 00 00 03 00 00 A0 58 00 00 00 00 00 00 00 74 6F 70 64 6F 67 00 00 00 00 00 00 00 00 00 00 CC 85 8F A4 8F BA B3 47 A0 AF A4 A3 B2 62 34 64 45 D8 8B 40 3E AC D7 11 86 73 00 60 97 08 22 DF CC 85 8F A4 8F BA B3 47 A0 AF A4 A3 B2 62
    34 64 45 D8 8B 40 3E AC D7 11 86 73 00 60 97 08 22 DF 10 00 00 00 05 00 00 A0 1A 00 00 00 9A 00 00 00 00 00 00 00 08 00 00 00 02 00 00 00 10 02 00 00 01 00 00 00 08 00 00 00 44 00 00 00 06 00 00 00 36 00 32 00 31 02 00 00 93 2F E2 46 20 00 48 54 54 72 61 63 6B 20 57 65 62 73 69 74 65 20 43 6F 70 69 65 72 2E 6C 6E 6B 00 48 54 54 52 41 43 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 4E 00 00 00 01 00 00 00 40 00 32 00 65 02 00 00 E2 2E 76 1C 20 00 4C 61 75 6E 63 68 20 49 6E 74 65 72 6E 65 74 20 45 78 70 6C 6F 72 65 72 20 42 72 6F 77 73 65 72 2E 6C 6E 6B 00 4C 41 55 4E 43 48 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 44 00 00 00 03 00 00 00 36 00 32 00 A3 08 00 00 E2 2E 76 1C 01 00 4C 61 75 6E 63 68 20 4F 75 74 6C 6F 6F 6B 20 45 78 70 72 65 73 73 2E 6C 6E 6B 00 4C 41 55 4E 43 48 7E 32 2E 4C 4E 4B 00 00 00 00 00 00 00 4A 00 00 00 02 00 00 00 3C 00 32 00 E7 01 00 00 65 2F AF 8B 20 00 53 68 6F 72 74 63 75 74 20 74 6F 20 42 6C 61 6E 6B 20 53 63 72 65 65 6E 2E 73 63 72 2E 6C 6E 6B 00 53 48 4F 52 54 43 7
    E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 3A 00 00 00 00 00 00 00 2C 00 32 00 4F 00 00 00 E2 2E 78 1C 20 00 53 68 6F 77 20 44 65 73 6B 74 6F 70 2E 73 63 66 00 53 48 4F 57 44 45 7E 31 2E 53 43 46 00 00 00 00 00 00 00 2A 00 00 00 05 00 00 00 1C 00 32 00 41 02 00 00 93 2F 64 33 20 00 53 6C 6F 77 76 69 65 77 2E 6C 6E 6B 00 00 00 00 00 00 00 00 48 00 00 00 07 00 00 00 3A 00 32 00 DD 02 00 00 94 2F 35 19 20 00 53 70 79 62 6F 74 2D 53 26 44 20 28 61 64 76 61 6E 63 65 64 20 6D 6F 64 65 29 2E 6C 6E 6B 00 53 50 59 42 4F 54 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 38 00 00 00 04 00 00 00 29 00 32 00 C0 01 00 00 69 2F E5 A3 20 00 57 49 4E 54 49 50 43 46 47 2E 6C 6E 6B 00 57 49 4E 54 49 50 7E 31 2E 4C 4E 4B 00 00 00 00 00 00 00 00 83 00 00 00 E0 06 00 00 00 00 00 00 16 00 00 00 00 00 00 00 00 00 00 00 16 00 00 00 00 00 00 00 01 00 00 00 01 00 00 00 AA 4F 28 68 48 6A D0 11 8C 78 00 C0 4F D9 18 B4 C9 02 00 00 E0 04 00 00 00 00 00 00 16 00 00 00 00 00 00 00 00 00 00 00 16 00 00 00 00 00 00 00 01 00 00 00
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 2F 00 00 00 A9 09 00 00 40 35 88 98 A6 C6 C3 01
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 2F 00 00 00 AA 09 00 00 F0 00 2B A7 A6 C6 C3 01
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG: 2F 00 00 00 11 01 00 00 10 0E 03 B8 A4 C6 C3 01
    HKEY_USERS\S-1-5-21-1409082233-1677128483-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG: 2F 00 00 00 12 01 00 00 70 E6 24 A7 A6 C6 C3 01

    Here's what spybot adds to the registry when updated, after installing

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 78 B0 A1 4F 9F 36 7D 7E 15 5A 08 D8 AD EC 88 86 C7 0E 73 B2 94 13 F0 29 BC CB 3C 09 5D 58 B4 75 19 1C 4D 35 2F 20 94 76 21 0A FC 94 35 00 C8 74 25 97 2A 64 D6 94 6B 77 41 F8 1E 8E EB 2F 3B C3 EB 58 78 BD 02 16 F8 C5 E2 BA 1F 78 19 D9 3C FA
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 34 AF A2 0F 20 14 23 C2 53 FB D7 B8 21 53 86 43 44 8A BD BC 51 96 81 6C 9B 30 FA B7 84 FD C4 96 68 D7 D2 19 AE 78 B6 3E 28 97 12 64 FC CA D9 3E 84 CE 2E 8C BF CF 7A 01 E8 1C 29 02 60 18 AE 51 A1 DE 16 E3 BD 15 AD 12 19 0C C5 CB 1E 14 A0 C7

    BEFORE YOU DO ANYTHING

    Backup your registry

    Delete those keys in regedit.
    Also delete the key HKCU>Software>PepMK Software.
    Also delete the install dir c:\Program Files\Spybot Search and destroy.
    Check for any older versions you may have in c:\Program Files and delete those dirs as well.

    Reboot, and reinstall/update


    Let us know if that works

  8. #8
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Any suggestions on what program I might edit the registry with? Or is it just simple enough to use Regedit in Windows? Either way, I'll do as you suggest on Sunday afternoon Norm. Thank you in advance my friend.
    Peace,
    Stevie B.

  9. #9
    Elite Member Norm's Avatar
    Join Date
    Mar 2001
    Posts
    14,140
    Start>Run>Regedit

    Regedit is simple enough.

    Just do yourself a big favor (in case of problems) BACKUP the registry first, before maiking any changes. You will be able to at least get back to the way it was before the edits.

    To back it up open regedit. Go to Registry (up top) and select Export. When the screen comes up, make sure "All" is checked, then name it, and save to a place easy to remember.
    If you need to restore it due to trouble. Boot to safe mode, and do the same as above, but this time you want to import. Then point to the file you made as the backup.

    Good luck

  10. #10
    Advanced Member fredra's Avatar
    Join Date
    Mar 2000
    Location
    Nepean, On, Canada
    Posts
    847

    Nice Work

    I agree with Norm...totally.
    I have another suggestion (or thought)...if your Home Page was changed (not by you), it is a possibility that you are infected with CoolWWWSearch or one of its variants.
    SpyBot does pick it up and says it removes it but it comes back (for some reason)..... I would go visit www.merijn.org/files/cwshredder.zip and get "cwshredder" and run it. Close all browsers (IE and Explorer) and turn off "system restore" before running "cwshredder". It will remove all the variants, then you can put back 'system restore".
    The author has methods that will help that this malicious code does not return, however, I would not suggest that you follow his reccomendations...you do at your own risk
    Cheers
    A man with a watch knows what time it is. A man with two watches is never sure.

  11. #11
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Originally posted by Norm
    Start>Run>Regedit

    Regedit is simple enough.

    Just do yourself a big favor (in case of problems) BACKUP the registry first, before maiking any changes. You will be able to at least get back to the way it was before the edits.

    To back it up open regedit. Go to Registry (up top) and select Export. When the screen comes up, make sure "All" is checked, then name it, and save to a place easy to remember.
    If you need to restore it due to trouble. Boot to safe mode, and do the same as above, but this time you want to import. Then point to the file you made as the backup.

    Good luck

    Did all that was suggested guys..no luck..same problem after rebooting and installing the executable....I'm at a loss here.
    Peace,
    Stevie B.

  12. #12
    Regular Member Richard(UK)'s Avatar
    Join Date
    Aug 2003
    Location
    Birmingham (UK)
    Posts
    128
    theres me thinking i was the only one who has problems with spybot, i get more or less the same thing, if it does finaly decide to load correctly it runs very bad, cause's severe system hang, and when i say hang i mean real bad hang! ( no problem with hanging untill i launch this software) click to shut it down..NOTHING!! starting to wonder if its worth all the hassle, my advice try a different sortware.

    i also use AdaWare 6 Pro, great software!!!

  13. #13
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Originally posted by srbarnes4ever
    Did all that was suggested guys..no luck..same problem after rebooting and installing the executable....I'm at a loss here.

    BUMP...after a few months of heavy travel, I'm back to square one here. I never resolved this issue with Spybot S&D...it will NOT open. I get an error regarding file retrieval sometimes, but in every case, the program flashes open then shuts mysteriously. I even see the Spybot executable file in Processes but it shuts down....any suggestions, I miss my Spybot checks!
    Peace,
    Stevie B.

  14. #14
    A+, S+, M+, C+, CySA+ Shinobi's Avatar
    Join Date
    Jan 2001
    Location
    South Carolina
    Posts
    4,436
    Blog Entries
    1
    srbarnes4ever:
    No dice, don't have admin rights to this pc, its a company laptop....
    You sure that your LAN Administrator didn't "lock down" your lappy when you weren't looking?

    Just a thought...

    Be Happy,
    Shinobi
    _______________________________________________
    Vendor neutral certified in IT Project Management, IT Security, Cisco Networking, Cisco Security, Wide Area Networks, IPv6, IT Hardware, Unix, Linux, and Windows server administration

  15. #15
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    Originally posted by Shinobi
    srbarnes4ever:


    You sure that your LAN Administrator didn't "lock down" your lappy when you weren't looking?

    Just a thought...

    Be Happy,
    Shinobi
    Not 'sure' but I do know that all my other programs work fine and I do have admin. rights that allow me to dl and install programs. I think its something else...just have no idea what.
    Peace,
    Stevie B.

  16. #16
    Senior Member ghettoside's Avatar
    Join Date
    Mar 2003
    Location
    At Large in the US
    Posts
    5,134
    check the spybot forum faq here and try the forums there. i'd try their uninstall method and reboot, run hijack this, make sure no items for spybot are there, then reinstall spybot.

    try running hijack this againhijack this. maybe you got a bad bho, a little info on bho's here i've removed numerous items from other people's boxes with this little app that others couldn't remove. post a screen shot of the scan.

    i also read somewhere recently about a virus (?) that shuts down anti spyware apps, can't remember if it was an alert from symantec or what, or if it was even a virus. will try to find it.
    Quote Originally Posted by Norm View Post

    There are idiots everywhere.

    At work, in forums, in poetry classes, everywhere!

  17. #17
    Member
    Join Date
    Dec 2002
    Location
    Lexington, KY
    Posts
    94
    [QUOTE]Originally posted by ghettoside
    [B]check the spybot forum faq here and try the forums there. i'd try their uninstall method and reboot, run hijack this, make sure no items for spybot are there, then reinstall spybot.

    Thanks ghettoside...I reset the config.ini file and all is working flawlessly! Much appreciate your links and assistance.
    Peace,
    Stevie B.

  18. #18
    Senior Member ghettoside's Avatar
    Join Date
    Mar 2003
    Location
    At Large in the US
    Posts
    5,134
    glad I could help
    Quote Originally Posted by Norm View Post

    There are idiots everywhere.

    At work, in forums, in poetry classes, everywhere!

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •