G
Guest
Another anti-spyware program deleted some registry keys as possible trojans.
I have found out that this was a false positive and that those keys usually
have a value of 0 or are blank for home users. Apparently they had the value
of 1. I also understand from another forum that the change to 1 could have
been made by a program providing protection for my PC. My question is, if
MSAS was the program providing such protection, could MSAS be used to restore
those keys? I was thinking maybe a re-install might accomplish it. Of course,
I don't know if MSAS did this to begin with. I would appreciate any info
anyone can provide. The log giving the deleted registry items follows:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:18:40 PM, 1/26/2006
+ Report-Checksum: AC22E743
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges -> Trojan.Small : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableTaskMgr -> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoChangingWallPaper
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoAddingComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoDeletingComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoEditingComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoCloseDragDropBands
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoMovingBands
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoHTMLWallPaper
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktop
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoThemesTab
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispAppearancePage
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoColorChoice
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoSizeChoice
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispBackgroundPage
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispScrSavPage
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispCPL
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoVisualStyleChoice
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispSettingsPage
-> Trojan.Small : Cleaned with backup
::Report End
I have found out that this was a false positive and that those keys usually
have a value of 0 or are blank for home users. Apparently they had the value
of 1. I also understand from another forum that the change to 1 could have
been made by a program providing protection for my PC. My question is, if
MSAS was the program providing such protection, could MSAS be used to restore
those keys? I was thinking maybe a re-install might accomplish it. Of course,
I don't know if MSAS did this to begin with. I would appreciate any info
anyone can provide. The log giving the deleted registry items follows:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:18:40 PM, 1/26/2006
+ Report-Checksum: AC22E743
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges -> Trojan.Small : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\DisableTaskMgr -> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoChangingWallPaper
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoAddingComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoDeletingComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoEditingComponents
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoCloseDragDropBands
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoMovingBands
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\\NoHTMLWallPaper
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoActiveDesktop
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoSaveSettings
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoThemesTab
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\DisableTaskMgr
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispAppearancePage
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoColorChoice
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoSizeChoice
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispBackgroundPage
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispScrSavPage
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispCPL
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoVisualStyleChoice
-> Trojan.Small : Cleaned with backup
HKU\S-1-5-21-4018711648-284700086-2646643178-1010\Software\Microsoft\Windows\CurrentVersion\Policies\System\\NoDispSettingsPage
-> Trojan.Small : Cleaned with backup
::Report End