This is a read-only archive. No new posts or registrations. Privacy Page
Software

Windows Antispyware/defender Beta

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok……..basically, i installed windows antispyware when it first came out…..now the new 'Beta' is out, i wanted that one. it said i needed to get rid of the old antispyware i had, but i no longer have the .exe file to uninstall it. i've removed it out the program files and due to a few system restores (other virus problems), my add/remove programs has the: 'windows defender' name, but when i click remove it doesn't do anything. Can someone help me get it all out the registry? Then i should be able to re-install the fresh microsoft antispyware/denfender Thanks for reading, i tried to be clear, but the problem is a bit complicated!
Welcome back bizarrebob :wavey:

Let's try this:

Please download/unzip this:

Registry Search by Bobbi Flekman

on regsearch.exe, and search for this:

defender

Be sure all the boxes are checked under "Search".

It may take a while to run, so be patient. When finished, the search results will appear in your text editor,

Paste the contents of the search results into your next post.
:)
hi. thanks for the welcome…..yet again more probs! , sorry i took a long while to reply, i've just got online….here it is: REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 15/08/2006 15:35:27 for strings: ; 'defender' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}\InprocHandler32] @="C:\\Program Files\\Windows Defender\\MpShHook.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\InprocHandler32] @="C:\\Program Files\\Windows Defender\\MpShHook.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}] @="Windows Defender IOfficeAntiVirus implementation" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocHandler32] @="C:\\Program Files\\Windows Defender\\MpOAV.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}] "InfoTip"="@C:\\Program Files\\Windows Defender\\\\MsMpRes.dll,-3069" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}\DefaultIcon] ; Contents of value: ; c:\program files\windows defender\msmpres.dll,-332 @=hex(2):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,6e,64,6f,77,\ 73,20,44,65,66,65,6e,64,65,72,5c,4d,73,4d,70,52,65,73,2e,64,6c,6c,2c,2d,33,\ 33,32,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}\Shell\Open\Command] ; Contents of value: ; "c:\program files\windows defender\\msascui.exe" -showswe @=hex(2):22,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,6e,64,6f,\ 77,73,20,44,65,66,65,6e,64,65,72,5c,5c,4d,53,41,53,43,75,69,2e,65,78,65,22,\ 20,2d,53,68,6f,77,53,57,45,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2D75874-6750-4931-94C1-C99D3BC9D0C7}\InprocHandler32] @="C:\\Program Files\\Windows Defender\\MsMpCom.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2] "ProductName"="Windows Defender Signatures" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\SourceList] ; Contents of value: ; n;1;c:\program files\windows defender\ "LastUsedSource"=hex(2):6e,3b,31,3b,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,\ 65,73,5c,57,69,6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\SourceList\Net] ; Contents of value: ; c:\program files\windows defender\ "1"=hex(2):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,6e,64,6f,\ 77,73,20,44,65,66,65,6e,64,65,72,5c,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\92EC7D2BA416CCA4B8EF00E93B2A449C] "ProductName"="Windows Defender" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\92EC7D2BA416CCA4B8EF00E93B2A449C\SourceList] "PackageName"="WindowsDefender.msi" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{879BD313-38C7-4052-9663-20BF58113873}\1.0\HELPDIR] @="C:\\Program Files\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C389764-F036-48F2-9AE2-88C260DCF43B}\1.0\HELPDIR] @="C:\\Program Files\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Quarantine\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Scans\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\LocalCopy\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Support\\"="1" "C:\\Program Files\\Windows Defender\\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A8E750CF6CD35A448B018E4080404DB] "92EC7D2BA416CCA4B8EF00E93B2A449C"="02:\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\LocalCopyDirectory" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0ACD1F881D6C4E64793591D317746703] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MSASCui.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C487CD9BFC90E1499E9F99E18A15999] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MsMpEng.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F58A70DBADD45F4F864B41C7A89C85C] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29E6D2B3A9847BD4F9EDB4D92A48B422] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\mpevmsg.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F05DC6C96514674DB82DF9095B6D4BB] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpRtMon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E08DCF6FC9218B45B7BB16EE9DEDE9E] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Quarantine\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EF190087EC54C14BA5720D634692F26] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Scans\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7AB83C9771AC71245B1F9A103891B490] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\mpasbase.vdm" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1F98A3BFAD0B949978F1DBE6A87DEA] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Support\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\911851C5F7D5D3C44B395816E85E33D6] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\AS_Sigs.MSI" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9ACB0204FD56BCA4DADBFD477F8BF1FC] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpSigDwn.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4ACC9E2C327F7240BA2337804B52B89] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpCmdRun.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7B2F8991943C1E4A941BD39C4D0905B] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\MpEngine.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C63DEE588DAFB3844B2039B681D2D323] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB34A407239073245B0846E66B5CE018] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpClient.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD659B668413B3747B3D3064C3F76EC7] "92EC7D2BA416CCA4B8EF00E93B2A449C"="02:\\SOFTWARE\\Microsoft\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA824E2F74A9D7B44873B3C5EF694A2C] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpOAv.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\InstallProperties] "InstallSource"="C:\\Program Files\\Windows Defender\\" "DisplayName"="Windows Defender Signatures" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\92EC7D2BA416CCA4B8EF00E93B2A449C\InstallProperties] "DisplayName"="Windows Defender" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}] "InstallSource"="C:\\Program Files\\Windows Defender\\" "DisplayName"="Windows Defender Signatures" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B2D7CE29-614A-4ACC-8BFE-009EB3A244C9}] "DisplayName"="Windows Defender" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "InstallLocation"="C:\\Program Files\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Miscellaneous Configuration] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Quarantine] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection] "LocalCopyDirectory"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\LocalCopy\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection\Checkpoints] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Reporting] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Scan] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Signature Updates] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Signature Updates] "SignatureLocation"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\{4685E9A0-6CED-44FC-B072-5364A85319B6}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Software Explorers] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\SpyNet] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatTypeDefaultAction] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\UX Configuration] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINDEFEND\0000] "DeviceDesc"="Windows Defender Service" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\WinDefendRtp] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\WinDefend] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinDefend] ; Contents of value: ; "c:\program files\windows defender\msmpeng.exe" "ImagePath"=hex(2):22,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,\ 6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,73,4d,70,45,6e,67,2e,65,78,\ 65,22,00 "DisplayName"="Windows Defender Service" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINDEFEND\0000] "DeviceDesc"="Windows Defender Service" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\WinDefendRtp] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\WinDefend] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\WinDefend] ; Contents of value: ; "c:\program files\windows defender\msmpeng.exe" "ImagePath"=hex(2):22,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,\ 6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,73,4d,70,45,6e,67,2e,65,78,\ 65,22,00 "DisplayName"="Windows Defender Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDEFEND\0000] "DeviceDesc"="Windows Defender Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinDefendRtp] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend] ; Contents of value: ; "c:\program files\windows defender\msmpeng.exe" "ImagePath"=hex(2):22,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,\ 6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,73,4d,70,45,6e,67,2e,65,78,\ 65,22,00 "DisplayName"="Windows Defender Service" ; End Of The Log…
yes, here it is:


Logfile of HijackThis v1.99.1
Scan saved at 00:02:29, on 16/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\Program Files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Microsoft Hardware\Keyboard\type32.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE
C:\WINDOWS\system32\bcmwltry.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\tunebite\tunebite.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Quick ShutDown\qsd.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\opera5\Opera.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\Simon.D9T4YV1J\Desktop\Sorting Box\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.btbroadbandoffice.com/bbhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BT Business Broadband
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 195.13.63.187 irc.westwood.com
O1 - Hosts: 195.13.63.187 servserv.westwood.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [IntelliType] "C:\Program Files\Microsoft Hardware\Keyboard\type32.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus C86 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE /P23 "EPSON Stylus C86 Series" /O6 "USB001" /M "Stylus C86"
O4 - HKLM\..\Run: [bcmwltry] bcmwltry.exe
O4 - HKLM\..\Run: [RemoveCpl] RemoveCpl.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [TWCU] "C:\Program Files\Wireless\TWCU\TWCU.exe" -nogui
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [tunebite.exe] C:\Program Files\tunebite\tunebite.exe -hidden
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Quick ShutDown.lnk = C:\Program Files\Quick ShutDown\qsd.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesuk.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.btbroadbandoffice.com/bbhome
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1137701946281
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {A243F6C2-34D2-4549-BCCD-A7BEF759B236} (Seekford Solutions, Inc.'s ssiPictureUploader Control) - http://img.funtigo.com/images/uploader/ssi…ureUploader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - blank
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Wireless Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - Unknown owner - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe (file missing)
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - C:\Program Files\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Defender Service (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)
Fix this with HijaclkThis!:

O23 - Service: Windows Defender Service (WinDefend) - Unknown owner - C:\Program Files\Windows Defender\MsMpEng.exe (file missing)

Copy the text in the following quote box into Notepad:

sc stop WinDefend
sc delete WinDefend


Save it to your desktop as ff.bat

Now, the ff.bat file on the desktop. A DOS window will briefly open/close.

Copy and paste the contents of the quote box below into notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}\InprocHandler32]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14427C58-FFDA-DC11-C543-A85CDB4A49C1}\InprocHandler32]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}\InprocHandler32]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A2D75874-6750-4931-94C1-C99D3BC9D0C7}\InprocHandler32]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{879BD313-38C7-4052-9663-20BF58113873}\1.0\HELPDIR]

[-KEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C389764-F036-48F2-9AE2-88C260DCF43B}\1.0\HELPDIR]

[-KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]

Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Reboot.

See if you have better result now.
:)
thanks, just done that now, i'll re-boot, i'll edit this post soon if all is working :)

EDIT:

it wont let me remove the program from the add/remove programs, here is the error i am getting:

http://img107.imageshack.us/img107/7532/bizarrebobfe3.jpg

(hosted on imageshack)

Windows Defender Beta 2 wont let me install it until the other version i have gone. But i no longer have the files for it on my PC……

*gulps*


hope we can solve this!
Copy the text in the following quote box into Notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B2D7CE29-614A-4ACC-8BFE-009EB3A244C9}]

Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Reboot.

Cross your fingers and try again.

If I knew exactly what it's "balking at", I could fix it in a heartbeat.

As it is, I really hate to go "mucking around" in the registry any more than necessary.
:)
When i go into my add/remove programs, it doesn't have the option to remove 'windows defender' now. It still wont let in install Beta 2 because it says there is already a different version of windows defender installed….
Oh well…

I'll go for a "total erasure" this time around….

Use the registry search tool, and search for:

defender

Once more, and post the results.

I'll take what you post, and make a REG file to get rid of the whole ball of wax…
:)
thanks, sorry about this by the way……here's the results: REGEDIT4 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.1.0 ; Results at 16/08/2006 22:22:40 for strings: ; 'defender' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}] @="Windows Defender IOfficeAntiVirus implementation" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}] "InfoTip"="@C:\\Program Files\\Windows Defender\\\\MsMpRes.dll,-3069" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}\DefaultIcon] ; Contents of value: ; c:\program files\windows defender\msmpres.dll,-332 @=hex(2):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,6e,64,6f,77,\ 73,20,44,65,66,65,6e,64,65,72,5c,4d,73,4d,70,52,65,73,2e,64,6c,6c,2c,2d,33,\ 33,32,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}\Shell\Open\Command] ; Contents of value: ; "c:\program files\windows defender\\msascui.exe" -showswe @=hex(2):22,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,6e,64,6f,\ 77,73,20,44,65,66,65,6e,64,65,72,5c,5c,4d,53,41,53,43,75,69,2e,65,78,65,22,\ 20,2d,53,68,6f,77,53,57,45,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2] "ProductName"="Windows Defender Signatures" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\SourceList] ; Contents of value: ; n;1;c:\program files\windows defender\ "LastUsedSource"=hex(2):6e,3b,31,3b,43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,\ 65,73,5c,57,69,6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\SourceList\Net] ; Contents of value: ; c:\program files\windows defender\ "1"=hex(2):43,3a,5c,50,72,6f,67,72,61,6d,20,46,69,6c,65,73,5c,57,69,6e,64,6f,\ 77,73,20,44,65,66,65,6e,64,65,72,5c,00 [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\92EC7D2BA416CCA4B8EF00E93B2A449C] "ProductName"="Windows Defender" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\92EC7D2BA416CCA4B8EF00E93B2A449C\SourceList] "PackageName"="WindowsDefender.msi" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C389764-F036-48F2-9AE2-88C260DCF43B}\1.0\HELPDIR] @="C:\\Program Files\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders] "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Quarantine\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Scans\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\LocalCopy\\"="1" "C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Support\\"="1" "C:\\Program Files\\Windows Defender\\"="" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A8E750CF6CD35A448B018E4080404DB] "92EC7D2BA416CCA4B8EF00E93B2A449C"="02:\\SOFTWARE\\Microsoft\\Windows Defender\\Real-Time Protection\\LocalCopyDirectory" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0ACD1F881D6C4E64793591D317746703] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MSASCui.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C487CD9BFC90E1499E9F99E18A15999] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MsMpEng.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F58A70DBADD45F4F864B41C7A89C85C] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29E6D2B3A9847BD4F9EDB4D92A48B422] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\mpevmsg.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F05DC6C96514674DB82DF9095B6D4BB] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpRtMon.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E08DCF6FC9218B45B7BB16EE9DEDE9E] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Quarantine\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EF190087EC54C14BA5720D634692F26] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Scans\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7AB83C9771AC71245B1F9A103891B490] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\mpasbase.vdm" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1F98A3BFAD0B949978F1DBE6A87DEA] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Support\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\911851C5F7D5D3C44B395816E85E33D6] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\AS_Sigs.MSI" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9ACB0204FD56BCA4DADBFD477F8BF1FC] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpSigDwn.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4ACC9E2C327F7240BA2337804B52B89] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpCmdRun.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7B2F8991943C1E4A941BD39C4D0905B] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\MpEngine.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C63DEE588DAFB3844B2039B681D2D323] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB34A407239073245B0846E66B5CE018] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpClient.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD659B668413B3747B3D3064C3F76EC7] "92EC7D2BA416CCA4B8EF00E93B2A449C"="02:\\SOFTWARE\\Microsoft\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA824E2F74A9D7B44873B3C5EF694A2C] "92EC7D2BA416CCA4B8EF00E93B2A449C"="C:\\Program Files\\Windows Defender\\MpOAv.dll" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\InstallProperties] "InstallSource"="C:\\Program Files\\Windows Defender\\" "DisplayName"="Windows Defender Signatures" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\92EC7D2BA416CCA4B8EF00E93B2A449C\InstallProperties] "DisplayName"="Windows Defender" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "InstallLocation"="C:\\Program Files\\Windows Defender\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Miscellaneous Configuration] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Quarantine] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection] "LocalCopyDirectory"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\LocalCopy\\" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection\Checkpoints] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Reporting] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Scan] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Signature Updates] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Signature Updates] "SignatureLocation"="C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\{4685E9A0-6CED-44FC-B072-5364A85319B6}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Software Explorers] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\SpyNet] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatIDDefaultAction] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Threats\ThreatTypeDefaultAction] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\UX Configuration] [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\WinDefendRtp] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\WinDefend] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\WinDefendRtp] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\WinDefend] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinDefendRtp] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend] "EventMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" "ParameterMessageFile"="C:\\Program Files\\Windows Defender\\MpEvMsg.dll" [HKEY_USERS\S-1-5-21-1944272775-3020834720-2459681807-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*] "d"="C:\\Documents and Settings\\Simon.D9T4YV1J\\Desktop\\WindowsDefender.msi" [HKEY_USERS\S-1-5-21-1944272775-3020834720-2459681807-1006\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\msi] "a"="C:\\Documents and Settings\\Simon.D9T4YV1J\\Desktop\\WindowsDefender.msi" ; End Of The Log…
i ought to let you know, where it says i have windows defender.msi on the desktop, that is the installation file i plan on installing when i can….. :)
Copy the text in the following quote box into Notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2781761E-28E0-4109-99FE-B9D127C57AFE}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{785784CF-5C16-44D8-AB94-ABF876FB1D2E}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8C389764-F036-48F2-9AE2-88C260DCF43B}\1.0\HELPDIR]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Quarantine\\"=-
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\"=-
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Scans\\"=-
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\Default\\"=-
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Definition Updates\\"=-
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\LocalCopy\\"=-
"C:\\Documents and Settings\\All Users\\Application Data\\Microsoft\\Windows Defender\\Support\\"=-
"C:\\Program Files\\Windows Defender\\"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0A8E750CF6CD35A448B018E4080404DB]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0ACD1F881D6C4E64793591D317746703]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C487CD9BFC90E1499E9F99E18A15999]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F58A70DBADD45F4F864B41C7A89C85C]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29E6D2B3A9847BD4F9EDB4D92A48B422]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F05DC6C96514674DB82DF9095B6D4BB]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E08DCF6FC9218B45B7BB16EE9DEDE9E]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EF190087EC54C14BA5720D634692F26]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7AB83C9771AC71245B1F9A103891B490]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F1F98A3BFAD0B949978F1DBE6A87DEA]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\911851C5F7D5D3C44B395816E85E33D6]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9ACB0204FD56BCA4DADBFD477F8BF1FC]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A4ACC9E2C327F7240BA2337804B52B89]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A7B2F8991943C1E4A941BD39C4D0905B]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C63DEE588DAFB3844B2039B681D2D323]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB34A407239073245B0846E66B5CE018]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD659B668413B3747B3D3064C3F76EC7]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA824E2F74A9D7B44873B3C5EF694A2C]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\90A2CC5A3D9ECE9429D33078B4DBC4C2\InstallProperties]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\92EC7D2BA416CCA4B8EF00E93B2A449C\InstallProperties]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\WinDefendRtp]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\WinDefend]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\WinDefendRtp]

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\WinDefend]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinDefendRtp]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WinDefend]

Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Reboot.

You know the rest…..
;)
it's worked :D thanks Micah 6:8, once again you've saved the day :D EDIT: i've just got one question……. say in add/remove programs a file says it takes up 9mb for example, so when you delete something out the registry, does that sort of recycle the space like a recycle bin? So you aren't losing memory?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI