Software Registry: is "Advanced INF" legit Explorer?

From: Michelle (michelle775_at_hotmail.com)
Date: 10/07/05

  • Next message: Carey Frisch [MVP]: "Re: Software Registry: is "Advanced INF" legit Explorer?"
    Date: 6 Oct 2005 16:46:04 -0700
    
    

    Lately I've been having a lot of adware entering the system, trying to
    install the common round of searchbars, popups and the like. There's
    been a number of attempts to hijack the Internet Explorer startpage,
    and I know at some points the msiexec.exe process has been used for
    this ( i haven't modified the browser myself or installed any MS
    updates for some time). I try to keep the malware at bay with Norton
    Firewall /Antivirus, Adaware and so far I've avoided really grave
    attacks.
    The other day I had a look at the registry and deleted some keys that
    were obvious adware, but registry is a place where you need to know
    exactly what you're doing and I'm not a software pro...

    Now, next I found dozens of keys under the line HKEY_LOCAL_MACHINE
    Software\Microsoft\Advanced INF Setup. Some seemed limited in scope and
    not really part of the ordinary Internet Explorer registry. I ran a
    registry scan afterwards with Norton and had it delete a few other keys
    I was positive was adware. Tonight, when I just checked the registry
    again, some of these suspect keys I'd spotted seemed to be gone, others
    still there. Although they were stored under Microsoft, this would be
    an ordinary spot for any intruding adware, wouldn't it? Is this
    (HKEY_LOCAL_MACHINE Software\Microsoft\Advanced INF Setup) a default
    registry class for matters dealing with integration of Explorer with
    different kinds of multimedia, or is it a place primarily "used" to
    lodge spyware and adware? And just what does "Advanced INF" mean here?

    Hope to get enlightened on this,
    /Michelle

    Main software specs:

    Windows XP Pro + Service Pack 1
    Internet Explorer 6
    Opera 7 (second browser)
    Acrobat 6 Pro & Acrobat Reader


  • Next message: Carey Frisch [MVP]: "Re: Software Registry: is "Advanced INF" legit Explorer?"

    Relevant Pages

    • Re: Software Registry: is "Advanced INF" legit Explorer?
      ... Microsoft Windows AntiSpyware ... | Lately I've been having a lot of adware entering the system, ... but registry is a place where you need to know ... next I found dozens of keys under the line HKEY_LOCAL_MACHINE ...
      (comp.security.misc)
    • Re: TV Media Adware and Restore
      ... registry or on the filesystem. ... The Winsock XP fix didn't work. ... correspond to the adware, but now I don't. ... I am almost positive the worm came on my computer with the TV Media ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: adware
      ... i never had any proble after deleting these entry. ... spyware, so my advice is you get kazaalite, which can be found at ... > adware on a computer. ... > shows up in LOCAL Software etc. in my Registry. ...
      (microsoft.public.windowsxp.security_admin)
    • Registry Cleaner & Backup software
      ... I have some adware on my PC which neither Spybot S&D nor ... Norton Anti-Virus 2004 found the ... Registry. ... so I was thinking about software products to clean, ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Clarification Re: Event Viewer
      ... And THEN delete the TWO KEYS from THAT location! ... Release Notes for Internet Explorer 8 ... Windows cannot query DllName registry entry for ... I asked but never got an acknowledgement of any IE8 history. ...
      (microsoft.public.windowsxp.help_and_support)