A Question About a Windows Registry Key Flagged by Norton Power Eraser

DASAstoria
DASAstoria Member Posts: 7 New User

My Acer Aspire E380 (Vista OS) is running fine but I did a Rootkit Check with Norton Power Eraser. (I know: why try to fix something if it ain't broke? I still have a lot to learn.) In any case, Power Eraser flagged a problem in the registry. It classified it as "Bad" and recommended that I remove it.

 

After doing some reading I realize that a newcomer like me probably shouldn't be using NPE, especially when I have no real reason to suspect a problem. In any case, now I'm left with having to figure out what to do with this issue. I've copied the registry key that NPE flagged here:

 

HKEY_USERS\S-1-5-21-1903139276-1064817428-3255128902-1000\Software\Microsoft\Windows\CurrentVersion\Run\"捁牥吠畯⁲敒業摮牥"

 

I would appreciate it if anyone has a suggestion about how I should proceed. Is it better to delete it or leave it alone? Can anyone tell me where I can go to learn more?

 

Thanks for your help. I promise to leave well enough alone in the future.

Answers

  • Alan-London
    Alan-London ACE Posts: 793 Pioneer

    I won't allow anything to exist in the 'Run' keys unless I know exactly what it is!! Ask yourself why any entry would likely use simplified Chinese. Not impossible I guess but highly unlikely. I have never seen it used before.

     

    Try running MSCONFIG and look under the startup tab. If it appears, check the path (Command). That should help you identify the program.

    Is there an undelete entry in Control Panel/Programs and Features?

    If you can't identify it, you could create a restore point and delete the registry entry. Should you then encounter problems you can always roll back.

     

    Don't forget to check all other 'Run' keys for similar entries.

     

    Check also that they don't reappear.

     

  • DASAstoria
    DASAstoria Member Posts: 7 New User

    Thanks for the reply and I apologize for not getting back to you sooner. I got sidetracked with trying to figure out why I couldn't do a system restore. I appears to have something to do with my Norton Internet Security program.

     

    In any case, I took your advice and checked MSCONFIG. The suspicious key appears to be there:

     

    1. Under Startup Item there are the same Chinese characters.

     

    2. Manufacturer is listed as Unknown.

     

    3. There are more Chinese characters under Command so I can't tell tell what the program is.

     

    4. Location is listed as HKCU\Software\Microsoft\Windows\CurrentVersion\Run.

     

    5. I recognize all the other entries under Startup. They are clearly ID'd and appear legitimate.

     

    6. This is the only entry with Chinese characters.

     

    7. If it's of any relation to this issue, the computer was manufactured in Taiwan.

     

    8. I've also scanned with Malwarebytes, Microsoft System Safety Scanner, Norton Internet Security, and CCleaner. They've found no problems.  

     

    9. Control Panel has an Uninstall function, but since I don't know what the entry does I can't find it on the list of Programs and Features. 

     

    I plan on updating the OS to Windows 7 soon. Since the hard drive is new and I won't lose any data, I've considered being extra careful and doing a System Recovery with the current Vista OS first to see what happens to the key. Then I would do a clean install of Windows 7.

     

    Thanks again for your help.

This discussion has been closed.