Unsolved
This post is more than 5 years old
12 Elder
•
45.2K Posts
•
172.6K Points
0
5203
December 27th, 2004 03:00
Delete these registry keys?
Found some XPpro (SP2) registry keys on Dimension 8400 that may be left after spyware was removed. Need to know if/how to remove them safely. Two of them are related to something called "Deal Info". Up-to-date Ad-aware, Spy-bot, CWshredder, McAfee don't detect it, and I can't find any related files by searches that include hidden and system files.
HKEY_USERS\S-1-5-21-4186795036-2291062689-4051603708-1007\Software\Microsoft\Installer\Products\843B25AA38603B94EB42D840C2A75C44
and:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-4186795036-2291062689-4051603708-1007\Products\843B25AA38603B94EB42D840C2A75C44\InstallProperties
msconfig also lists active startup item named (blank), command line (blank) at:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
(Default) REG_SZ (value not set)
SpySweeper REG_SZ
SpySweeper REG_SZ
Never downloaded/installed Spy Sweeper which seems to be legitimate(?) software so I don't know where it came from, or if it's responsible for "Deal Info".
Any recomendations/suggestions?
Thanks!
Ron
Message Edited by RoHe on 12-26-2004 09:52 PM
No Events found!


RoHe
12 Elder
•
45.2K Posts
•
172.6K Points
0
December 27th, 2004 04:00
I figured you'd what to do! Many thanks. I'll export the .reg and then delete those keys. It seems that no matter how vigilant we are, somebody still finds a way to sneak things onto our PCs...
Have a happy new year!
Ron
Denny Denham
2 Intern
•
18.8K Posts
0
December 27th, 2004 04:00
The safest thing to do is export those two keys and save the *.reg files in a safe place, then delete the keys. If nothing unexpected happens for a couple of weeks or so, you can delete the *.reg files (or leave them, since they will take up almost no hard drive space). If somthing unexpected does happen (unlikely, given their association) you can just double-click them or right-click and select Merge and restore them.
RoHe
12 Elder
•
45.2K Posts
•
172.6K Points
0
December 27th, 2004 05:00
Deleted those keys and wiped out my Earthlink dialup connection! Modem would open a pre-dial terminal screen (never did that before!), dial out but get refused by ELN. Re-imported the .reg but no go, so had to recreate the whole network connection from scratch... Am back online (obviously) and will have to poke around some more to see what those keys are really doing. Am open to further suggestions!
Thanks for your help.
Ron
Denny Denham
2 Intern
•
18.8K Posts
0
December 27th, 2004 15:00
My last suggestion was so remarkably ineffective I'm out of ideas.
JRosenfeld
2 Intern
•
4.4K Posts
0
December 27th, 2004 23:00
SpySweeper REG_SZ
RoHe
12 Elder
•
45.2K Posts
•
172.6K Points
0
December 28th, 2004 00:00
Thanks! Followed your tip and looks like "Deal Info" is related to Earthlink, possibly part of that 6-months free offer Dell installed.
So guess it isn't spyware, and I can probably just leave it there.
Deleted the spysweeper key as you suggested so lets hope that's the end of that problem.
Thanks again,
Ron