Right, let's get the show on the road.... Trend Micro antispyware keeps picking up this on my system: Spyware_KEYL_PCAgent.40
I delete it an run another spyware scan straight away, and it's still there on my system. Delete it, run another scan and it comes up again. So on and so forth. It says it's located in: HKLM/SOFTWARE/Classes/.pca/, where-ever that is on my rig, the standard Windows search feature can't find the file or where it's located.
Interesting thing is, Trend Micro Anti-Spyware says that it is a low risk threat, yet it's a keylogger. Surely it would be higher risk being the fact it's a keylogger.
I ran a full NAV scan too, but NAV didn't pick up anything. I ran another anti-spyware program, Ad-Aware, and that too did not pick up Spyware_KEYL_PCAgent.40
I'd just like to point out that the Trend Micro anti-spyware program I've got is the trial version.
Anyway, this was yesterday, and I have used regedit since to try to find the file. I typed in "Spyware_KEYL_PCAgent.40" and it found four entries: that file itself, RP333, Paltalk and HKLM/SOFTWARE/Classes/.pca/.
I've now actually manually deleted those files. I shutdown and restart, run regedit again, search for those files.... and nothing comes up in the search.... So I'm thinking I've done it. I run Trend Micro anti-spyware again and.... It detects Spyware_KEYL_PCAgent.40 again. So I go back into regedit and search for the file again. Regedit turn up nothing again.
So it's evident that regedit is now saying those all of malware files have gone, but Trend Micro anti-spyware is still detecting Spyware_KEYL_PCAgent.40. Why?
Further to this, I have litterally just discovered two new registy keys in my My Documents folder that weren't there prior to this incident. One of them is blank (well almost, all it says is: Windows Registry Editor Version 5.00), the other one has in it all the software installed and all the software I've uninstalled etc. What I'd like to know is, is it OK to delete these new registry keys? They weren't there before this incident and my system worked just fine back then.
So guys, what's the verdict?
Many thanks in advance for reading this and helping me out.