G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

I recently did an online check with Pest Patrol. One of the things that
showed up was SpyKeyLogger followed by a registry entry as follows:

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell

Is this something that can be deleted and why did it show under the above
title?


--
Adiletante
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

1) Download the following three items...

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend Pattern File.
http://www.trendmicro.com/download/pattern.asp

Adaware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download Sysclean.com and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt307.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adaware with the latest definitions.
3) Disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
(e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point



* * * Please report your results ! * * *

Dave




"Adiletante" <adiletante@hotmail.com.(donotspam)> wrote in message
news:028F51BD-A3A8-48E2-A605-50DC4AB09369@microsoft.com...
| I recently did an online check with Pest Patrol. One of the things that
| showed up was SpyKeyLogger followed by a registry entry as follows:
|
| HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell
|
| Is this something that can be deleted and why did it show under the above
| title?
|
|
| --
| Adiletante
 

map

Distinguished
Apr 6, 2004
783
0
18,980
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

"Adiletante" wrote:

> I recently did an online check with Pest Patrol. One of the things that
> showed up was SpyKeyLogger followed by a registry entry as follows:
>
> HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\Bags\7\Shell
>
> Is this something that can be deleted and why did it show under the above
> title?
>
>
> --
> Adiletante

The few times that I have used Pest Patrol's online scan it reported several
"false" positive's. Just something for you to keep in mind if David's
suggestion shows your system is clean.
 
G

Guest

Guest
Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

"MAP1" wrote:
> "Adiletante" wrote:
>
> > I recently did an online check with Pest Patrol. One of the
> things that
> > showed up was SpyKeyLogger followed by a registry entry as
> follows:
> >
> >
> HKEY_CURRENT_USERSoftwareMicrosoftWindowsShellNoRoamBags
> 7Shell
> >
> > Is this something that can be deleted and why did it show
> under the above
> > title?
> >
> >
> > --
> > Adiletante
>
> The few times that I have used Pest Patrol's online scan it
> reported several
> "false" positive's. Just something for you to keep in mind if
> David's
> suggestion shows your system is clean.

This is a false positive. Confirmed by PestPatrol. They say that it
will be rectified during the next update.

Erskine

--
http://www.WindowsForumz.com/ This article was posted by author's request
Articles individually checked for conformance to usenet standards
Topic URL: http://www.WindowsForumz.com/Security-Admin-Keylogger-ftopict239343.html
Visit Topic URL to contact author (reg. req'd). Report abuse: http://www.WindowsForumz.com/eform.php?p=735645