The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.
|
 |
|
Dev Shed Forums
> System Administration
> Antivirus Protection
|
Basic Registry editing advice needed
Discuss Basic Registry editing advice needed in the Antivirus Protection forum on Dev Shed. Basic Registry editing advice needed Antivirus Protection forum discussing issues relating to antivirus programs, spyware, hijack protection, and personal firewalls for all operating systems. Keep your systems protected from hackers and other hazards.
|
|
 |
|
|
|
|

Dev Shed Forums Sponsor:
|
|
|

September 5th, 2010, 11:57 AM
|
|
Registered User
|
|
Join Date: Sep 2010
Posts: 3
Time spent in forums: 1 h 11 m 6 sec
Reputation Power: 0
|
|
|
Basic Registry editing advice needed
I'm removing the Antivirlock Security Suite mess and going by the guides of various sites listing which registry entries are troublesome. I don't want to download and use these sites' removal tools either.
So my question is, do we have to delete every listed entry or do some of them just need editing? I ask because:
1)Were these entries already present, but only modified by the malware? If so, would removing them cause issue?
2) A registry entry listed on guide might not be exactly the same value as that in my registry. For instance, a guide may tell you to delete this:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
But what if your registry's entry is a 0 instead of a 1?
The blatantly obvious entries that were clearly specific to Antivirlock I deleted without hesistancy, but there are some ambiguous ones I'm concerned about (like above) so I came here.
Here's a list of targeted registries that we're told to delete (at least, these are the ones I'm unsure about):
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0′
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache “%UserProfile%\Desktop\flash_player_installer\flash_player_installer.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” =”1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1′
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ?ProxyOverride” = “”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation? = “1′
Any help would be appreciated, thanks!
|

September 5th, 2010, 08:09 PM
|
|
|
|
I don't have a definitive answer for you, sorry, but what you posted is a good example of why I recommend wiping a disk, reformatting and reinstalling after a virus infection. I am not convinced antivirus/antimalware programs really identify all possible alterations to a registry or filesystem, and if one bad guy is missed and left behind after cleanup it may be enough to open your machine back up to new infections. And if you have gotten a rootkit there is no guarantee at all that your a/v cleanup is working right.
[
__________________
======
Doug G
======
It is a truism of American politics that no man who can win an election deserves to. --Trevanian, from the novel Shibumi
|

September 5th, 2010, 09:27 PM
|
|
Registered User
|
|
Join Date: Sep 2010
Posts: 3
Time spent in forums: 1 h 11 m 6 sec
Reputation Power: 0
|
|
Quote: | Originally Posted by Doug G I don't have a definitive answer for you, sorry, but what you posted is a good example of why I recommend wiping a disk, reformatting and reinstalling after a virus infection. I am not convinced antivirus/antimalware programs really identify all possible alterations to a registry or filesystem, and if one bad guy is missed and left behind after cleanup it may be enough to open your machine back up to new infections. And if you have gotten a rootkit there is no guarantee at all that your a/v cleanup is working right.
[ |
Thanks for the reply, Doug. None of the registry listings I pasted were results pulled from antivirus programs, but from various sites that have posted guides for manually removing the virus.
I've tried other sites asking if these entries should be outright deleted or do the values just need altering, but no dice.
Again I don't want to remove registry listings that were previously there before the virus. I suppose I could check another computer which never had this virus (or any of it's variants) to see if the listings I pasted are present there as well (and therefore maybe legit/necessary) , or if not present and I find out that the ones on the infected machine are just creations of the malware.
I also doubt that this warrants the tedious task of wiping everything and rebuilding from start, since the system can be recovered. Actually I managed to stop it before it fully unloaded anyhow, so I never even suffered it's symptoms. Of course I'd like to be clean of the remnant registry pieces.
|

September 5th, 2010, 09:46 PM
|
 |
Still alive
|
|
Join Date: Mar 2007
Location: Washington, USA
|
|
Google is your friend.
Code:
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PhishingFilter “Enabled” = “0′
Leave it. Configure the phishing filter in IE directly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations “LowRiskFileTypes” = “.exe”
Remove it
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache “%UserProfile%\Desktop\flash_player_installer\flash_player_installer.exe”
Doesn't matter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings “ProxyEnable” =”1′
Leave it. Configure proxy settings in IE directly
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “RunInvalidSignatures” = “1′
Change to "0"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download “CheckExeSignatures” = “no”
Leave it
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings ?ProxyOverride” = “”
Leave it. Configure proxy settings in IE directly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments “SaveZoneInformation? = “1′
Leave it
Standard disclaimers of "muck with the registry at your own risk" and "not my fault if something gets screwed up".
|

September 6th, 2010, 04:05 PM
|
|
Registered User
|
|
Join Date: Sep 2010
Posts: 3
Time spent in forums: 1 h 11 m 6 sec
Reputation Power: 0
|
|
Nicely done, thanks, Requinix!
|
Developer Shed Advertisers and Affiliates
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Rate This Thread |
Linear Mode
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|