Author Topic: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks  (Read 2318 times)

0 Members and 1 Guest are viewing this topic.

Offline Aditza

  • Jr. Member
  • **
  • Posts: 54
Hello, i have a problem:

Can Avast prevent unwanted registry entries from being added such as my case below?

every 2 weeks or so a program spams the registry and re-adds a TON of spam hooks under HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run and other similar locations, even going so far as to add unwanted shell overlay icons in Windows Explorer and a (useless) auto-starting service that starts with LocalSystem privileges.

Every time they do this I have to manually scrub these entries out of the registry using Sysinternals' Autoruns and I have to repeat the scrub operation on multiple computers (my desktop and my laptop).  Even if i disable those registry entries (and the service) their program runs normally and doesn't have any issues in operation, so they are not really needed for me.

The program doesn't have ANY settings or other preferences to turn off this behaviour and it's been literally YEARS now that users have complained to the developers about this behaviour and they ignore us on purpose - I know I have complained to them ever since June 2014.

Except of uninstalling and stopping the use of their software, what options are there for blocking or automatically cleaning up the crap left by their updater program in the registry?
Can Avast help here?
« Last Edit: November 18, 2017, 04:30:34 PM by Aditza »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #1 on: November 18, 2017, 04:31:18 PM »
Test the file at VT (https://www.virustotal.com) and post the link to the result here.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Aditza

  • Jr. Member
  • **
  • Posts: 54
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #2 on: November 18, 2017, 04:35:13 PM »
already did.. they have millions of users of the software worldwide so they wouldn't risk making it into a virus... it's just a VERY ANNOYING "feature" of their program.

Screenshot is attached below

- the boxes unchecked are from the previous version that i had disabled manually
- the checked boxes are the entries newly added by their updater.

they have the same dates because Sysinternals Autoruns uses the timestamp of the file itself for that date there.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #3 on: November 18, 2017, 04:36:32 PM »
already did..
As said, post the link to the result here.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #5 on: November 18, 2017, 04:48:30 PM »
Nothing much Avast can do here, you could try CCleaner to clean the registry.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Aditza

  • Jr. Member
  • **
  • Posts: 54
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #6 on: November 18, 2017, 04:51:32 PM »
it's not a case of cleaning, more of unwanted software functionality.

I want to only start Dropbox manually from a desktop shortcut and not have it start with the system or as a service (and not have it load additional shell hooks when it runs) - it works just fine this way.
« Last Edit: November 18, 2017, 04:53:17 PM by Aditza »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #7 on: November 18, 2017, 04:59:43 PM »
The program doesn't have ANY settings or other preferences to turn off this behaviour and it's been literally YEARS now that users have complained to the developers about this behaviour and they ignore us on purpose - I know I have complained to them ever since June 2014.
If the devs aren't able/willing to fix it (since 2014), best to get rid of it...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Aditza

  • Jr. Member
  • **
  • Posts: 54
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #8 on: November 18, 2017, 05:14:49 PM »
If the devs aren't able/willing to fix it (since 2014), best to get rid of it...

my problem is that i have found no easy alternative that reliably preserves the file names, I use Dropbox to sync my World of Warcraft saved files between my desktop and my laptop.

Dropbox preserves file names and in case of a conflict will preserve the file name for the newer file and will rename the OLDER files.

Google Drive (recently renamed as Backup as Sync) does the opposite - it keeps the older file named as-is and will rename the NEWER file - and it tends to detect conflicts if you as much as sneeze at it - it will immediately stop syncing the proper file and will create a renamed file, appending "(1)" or other numbers to the file name.

Google's approach might be OK for documents but is a total train wreck when you consider the case of LUA script programs (such as WoW uses to save data). These scripts MUST have a very precise file name or WoW hits the fan.

When i used Google Drive for syncing WoW saves i was having random weird missing data, old WoW savedata making a comeback or other such things - and in the end i found it was directly caused by the way that Google was creating surprise random additional files instead of preserving the proper file name for LUA scripts.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #9 on: November 18, 2017, 06:09:33 PM »
Sorry, I'm no gamer but can't you just save it on an USB stick..?
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48586
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #10 on: November 18, 2017, 07:11:23 PM »
Have you tried OneDrive ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Aditza

  • Jr. Member
  • **
  • Posts: 54
Re: HELP! program keeps re-adding HKLM\...\Run and shell hooks every few weeks
« Reply #11 on: November 18, 2017, 08:22:06 PM »
when i start it, Dropbox acts as a real-time backup of the save game files on the main computer too... and i also have a habit of making weekly 7zip snapshot archives of the WoW save data - those will get synced over to the laptop too... so messing around with usb drives would be an inconvenience. (have some usb drives too.. but i don't use them much these days except for installing win10 from them)

Onedrive: haven't tried it. Back in 2014 i discovered that Dropbox was behaving much better than Google Drive at preserving file name integrity and i stuck with it... even if it has that annoying registry behaviour.