There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash dns driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop lcd malware memory missing monitor motherboard network operating system printer problem ram registry router slow software sound toshiba trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless xbox
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Solved: Strange Key.

Reply  
Thread Tools
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
09-Aug-2009, 12:28 PM #1
Solved: Strange Key.
Does anyone know what software this represents:

HKEY_LOCAL_MACHINE\SOFTWARE\685D6D1C-D73A-4F37-B7E5E53660311DDB

It will not go away upon any type of removal and the only reference I can find to it are on two Chinese websites that need to be translated by Google and even then the translation is useless.
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,271 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
09-Aug-2009, 01:56 PM #2
If you highlight it in the registry, is there any information showing in the pane on the right side, such as a file name, etc.?

In the pane on the left side is there a + to the left of that entry? If so, please click on it and let me know what is listed below it.
__________________
Microsoft MVP - Consumer Security
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
12-Aug-2009, 03:18 PM #3
No. Just an empty key:

(Default) REG_SZ (value not set)
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,271 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
12-Aug-2009, 06:15 PM #4
Go to Start - Run and copy and paste the following:

regedit /e C:\look.txt "HKEY_LOCAL_MACHINE\SOFTWARE\685D6D1C-D73A-4F37-B7E5E53660311DDB"

You won't see anything happen and it will only take a second. You will find the report it creates at C:\look.txt. Please open it in Notepad and then copy and paste the report here.
__________________
Microsoft MVP - Consumer Security
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
14-Aug-2009, 06:44 PM #5
No results. I don't find a look.txt anywhere.
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,271 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
15-Aug-2009, 04:01 PM #6
Are you sure you copied and pasted it and didn't try typing it? Did you look in C: for the look.txt file?
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
16-Aug-2009, 10:37 AM #7
Yeah. Now I notice that the key in question is gone. That's why your suggestion didn't work is that now the key is missing.

I tried your suggestion on another key and it works just fine.

Is there a way to adjust the input so that the look.txt will still be created but contain a message saying the key was not found or some such thing?

Even though it is gone I still find it suspicious because it is empty but may have been cleaned out after it served its purpose and that I only find a reference to it in a search engine here on this site and on a Chinese website.

http://www.google.com/#hl=en&q=HKEY_...e34627c46f57f4

Even more suspicious is that I couldn't get rid of it by any known means but if I mention it publicly such as I have done then suddenly the key in question disappears without my intervention.

Very strange indeed.

Last edited by needafix; 16-Aug-2009 at 10:46 AM..
perfume's Avatar
perfume has a Photo Album
Computer Specs
Account Disabled with 2,011 posts.
 
Join Date: Sep 2008
Location: A DUDE WITH ATTITUDE! ALIEN.
Experience: Intermediate++
16-Aug-2009, 12:07 PM #8
What A-V and Firewall are you having? I keep getting these "Network Intrusion Attacks" from Chinese sites, but are always blocked by the Kaspersky internet Security Suite 2009, i have.Looks like the UDP attacks were virus attacks from sites which have a poor reputation!
Attached Thumbnails
Solved: Strange Key.-greenshot130.png  
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,271 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
16-Aug-2009, 12:17 PM #9
How did you first notice this key? Were you just looking in the registry or did some scanner detect it?
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
16-Aug-2009, 01:44 PM #10
Quote:
Originally Posted by Cookiegal View Post
How did you first notice this key? Were you just looking in the registry or did some scanner detect it?
I noticed it a week or two I suppose.

CCleaner 2.19 listed it as worth deleting under the registry cleaning function.

It was new on the list compared to things I see there regularly and I always check the new stuff to see what it is just in case.

Last edited by needafix; 16-Aug-2009 at 02:00 PM..
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,271 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
16-Aug-2009, 01:50 PM #11
Quote:
Originally Posted by needafix View Post
CCleaner 2.19 listed it as worth deleting under the registry cleaning function.

It was new on the list compared to things I see there regularly and I always check the new stuff to see what it is just in case.
Did you have CCleaner remove it? If not, if you run CCleaner again, does it still show up?

Last edited by Cookiegal; 16-Aug-2009 at 02:07 PM..
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
16-Aug-2009, 01:54 PM #12
Quote:
Originally Posted by perfume View Post
What A-V and Firewall are you having? I keep getting these "Network Intrusion Attacks" from Chinese sites, but are always blocked by the Kaspersky internet Security Suite 2009, i have.Looks like the UDP attacks were virus attacks from sites which have a poor reputation!
I have been using NIS 2009 but the firewall logs for it are pathetically lacking information.

I prefer Zone Alarm since it logs all blocks in detail.

I don't see that NIS 2009 has detailed in/out traffic control by the user when it could easily take 2 or more days to get Zone Alarm setting to what is approved to go in and out by the user.

I like the detail compared the the plug in and play protection.
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
16-Aug-2009, 02:02 PM #13
Quote:
Originally Posted by Cookiegal View Post
Did you have CClean remove it? If not, if you run CCleaner again, does it still show up?
It never did get rid of it though I tried many times. I suppose it may have gotten rid of it and it came back. I tried other cleaners too.

Now it's just plain gone as if it grew legs and walked away.

I know what I can do.

I can search all of my .reg backups for that key and in one of them may list what software was listed under that mysterious key.

Back in a bit.

Last edited by needafix; 16-Aug-2009 at 02:07 PM..
Cookiegal's Avatar
Administrator & Malware Removal Specialist with 79,271 posts.
 
Join Date: Aug 2003
Location: Quebec, Canada
16-Aug-2009, 02:16 PM #14
Quote:
Originally Posted by needafix View Post
It never did get rid of it though I tried many times. I suppose it may have gotten rid of it and it came back. I tried other cleaners too.

Now it's just plain gone as if it grew legs and walked away.

I know what I can do.

I can search all of my .reg backups for that key and in one of them may list what software was listed under that mysterious key.

Back in a bit.
Yes, that would be indeed be helpful.
needafix's Avatar
needafix has a Photo Album
Senior Member with 985 posts.
 
Join Date: Mar 2005
Experience: Advanced
16-Aug-2009, 02:36 PM #15
It is listed in all of my .reg backups but no data is listed for that key like there is all the others but the key in question does go back as far as 04/29/2009.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 07:10 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.