REGEDIT/HKCU: While unlinking 2 User folders, found something VERY odd

FishmanTx

New member
Local time
3:07 PM
Messages
1
REGEDIT/HKCU: While unlinking 2 User folders, found something VERY odd! Initially, was attempting to "un-crosslink" a duplicate User documents folder (delete file in one, deletes files in both) and found unusual ASCii characters and what appears as chinese pictogram. Now, I'm NOT new to regedit by any stretch and bought my first computer in 1983 (Sinclair Z-80), so I've been at this a long time, from Win 2.0 through 10. That said, I'm a power user, but no expert. Now, it is possible these are legit BUT let me say that in all the years doing this I've NEVER seen them in the User segment of the registry, in device and driver entries, yes, but never here.
Opinions?? Photo attached...
 

Attachments

  • REGEDIT 1.jpg
    REGEDIT 1.jpg
    51.5 KB · Views: 3

My Computer My Computer

At a glance

Windows 7 Ultimate x64AMD FX-835016 GBNVIDIA/EVGA GTX 780 TI
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Ultimate x64
CPU
AMD FX-8350
Motherboard
Asus M5A97
Memory
16 GB
Graphics Card(s)
NVIDIA/EVGA GTX 780 TI
Hard Drives
2X 4TB SEAGATE
Antivirus
AVAST
Just a guess, but it may be related to a Chinese made program you installed. That program may or may not still exist. The other possibility is that you have a rootkit or some malware. Check out TDssKilller and Herdprotect portable. I'd run them in safe mode. Herdprotect will have to be run in safe mode with networking.

https://usa.kaspersky.com/downloads/tdsskiller

https://www.softpedia.com/get/PORTABLE-SOFTWARE/Antivirus---Antispyware/Portable-herdProtect.shtml

What does it say in the software and uninstall folder?
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Another thought. The symbols in that key may be symbols because Windows can't ID the character type used.

Go to the first key there with the two Chinese characters and export, zip and upload here. I'd like to have a look.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64
Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Hi

the Default, (x2) user reg entries are also not presesnt, or you've over-ridden/renamed them.

might be usefull to run FRST, as it lists users and reg entries.

Download Farbar Recovery Scan Tool


Roy
 

My Computer My Computer

At a glance

W7 home premium 32bit/W7HP 64bit/w10 tp insid...E5300 dual core3gbNvidia Geforce 7100 Nforce 630i
Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Back
Top