LastActivityView reveals too much.

Discussion in 'privacy problems' started by zmechys, Feb 14, 2013.

  1. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    ...
    8. Search options
     
  2. zmechys

    zmechys Registered Member

    Joined:
    Dec 29, 2012
    Posts:
    1,155
    Location:
    usa
    Now, ShellBag Analyzer & Cleaner cannot find that CLSID any more on my XP computers.
    Why?
    I've cheated - I used CCleaner with Enhancer.
     
  3. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    You removed all your ShellBags, including those of the "System" and '"Control Panel".
    I presume that your OS will recreate it while you are using your PC.
    Just a question of time.

    We will add an option in new ShellBag analyZer v1.6 enabling users to remove all ShellBags (for testing purposes).
     
  4. zmechys

    zmechys Registered Member

    Joined:
    Dec 29, 2012
    Posts:
    1,155
    Location:
    usa
    I think it's a very good idea to give more choices for those, "living - dangerously" advanced users. Please, make sure that an average user does not have easy access to the option "Remove All ShellBags" , otherwise, all reviewers will start screaming, "I would not recommend it to my parents, friends, colleagues etc. - it can easily mess up your computer".
     
  5. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Hello,

    we've just released a new version of Shellbag AnalyZer + Cleaner :p


    Shellbag AnalyZer + Cleaner v1.6
    http://privazer.com/download-shellbag-analyzer-shellbag-cleaner.php


    Changelog :
    - Fixed bug : unable to recreate Shellbags
    - Improved detection of
    . USB drive
    . Network drive
    . CD-ROM drive
    - New option for advanced users :
    . "Control panel" Shellbags cleanup
    . "Systeml" Shellbags cleanup
    -> "Desktop" Shellbag is protected
    - Improved UI
    . New "advanced Options"
    . New window size
     
    Last edited: Mar 19, 2013
  6. noone_particular

    noone_particular Registered Member

    Joined:
    Aug 8, 2008
    Posts:
    3,798
    Any user who wants to experiment with something like this should already have system and/or registry backups made. As long as a user has functional backups, there's no risk.
     
  7. zmechys

    zmechys Registered Member

    Joined:
    Dec 29, 2012
    Posts:
    1,155
    Location:
    usa
    Thank you.

    Are you going to keep ShellBag AnalyZer & Cleaner as a separate program or, eventually, merge it with Privazer?

    "This features will also be included in PrivaZer pretty soon."
     
  8. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Yes we will :D
    We are doing our best.
     
  9. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
  10. 1337

    1337 Registered Member

    Joined:
    Mar 16, 2013
    Posts:
    8
  11. TheWindBringeth

    TheWindBringeth Registered Member

    Joined:
    Feb 29, 2012
    Posts:
    2,171
    Thanks, quick feedback, test box XP SP3...

    This version did clean NAS related entries when the "Folders on network/external devices" options was checked. The cleaning of Truecrypt related test entries required enabling the "Existing folders" option. After performing a clean with all options checked, I still saw many keys under .../ShellNoRoam/Bags such as

    ../ShellNoRoam/Bags/5
    ../ShellNoRoam/Bags/2
    ../ShellNoRoam/Bags/2/Shell

    with no settings/values (don't seem to be a threat) but which make me wonder if the cleanup process is missing something that could be eliminated for thoroughness.
     
  12. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Downloading from your website it says from the properties for the file that I have 1.50. Then when I open, it says v1.6.

    However, I am trying to get v1.7. What is going on?

    ScreenShot_ShellBag_which version.jpg
     
  13. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    We will fix that.
     
  14. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    5,296
    Still not available. ;)
     
  15. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Hello,
    sorry for delay.
    We hope you will appreciate the new ShellBag AnalyZer + Cleaner version :

    ShellBag AnalyZer + Cleaner v1.8
    http://privazer.com/download-shellbag-analyzer-shellbag-cleaner.php

    Changelog :
    - New option : ShellBags Optimization
    - Improved "Last visit" date recovery
    - Improved ShellBags selection
    - Improved UI
     
  16. focus

    focus Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    503
    Location:
    USA
    Nod32 did not like this file:
    -http://privazer.com/shellbag_analyzer_cleaner.exe- » UPX v13_m8 probably unknown NewHeur_PE virus

    Something else went off on it too, not sure just what, thinking sandboxie since Nod32 blocked it.
     
    Last edited by a moderator: Apr 6, 2013
  17. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Thanks for the info.

    False positive from ESET Nod32.
    See here :
    ~ VirusTotal Results Removed per Policy ~

    ESET contacted. :p
    Waiting for reply.
     
    Last edited by a moderator: Apr 6, 2013
  18. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Here is the ESET reply :D

    -----------------------------------------------------
    Dear Valued Customer,
    Thank you for reporting us this false positive.
    shellbag_analyzer_cleaner.exe - is OK and won`t be detected since next update of virus signature database

    ~Private message contents removed~
     
    Last edited by a moderator: Apr 9, 2013
  19. focus

    focus Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    503
    Location:
    USA
    Downloaded fine this morning, thanks for the update.
     
  20. zmechys

    zmechys Registered Member

    Joined:
    Dec 29, 2012
    Posts:
    1,155
    Location:
    usa
    Today, I scanned my Vista laptop with HitmanPro.
    It detected one malicious software - ShellBag Analyzer & Cleaner.exe.
    Please be advised.

    ShellBagHitmanPro.PNG
     
    Last edited: Apr 18, 2013
  21. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Thanks for the info.

    We will investigate.
     
  22. The_PrivaZer_Team

    The_PrivaZer_Team Developer

    Joined:
    Feb 14, 2013
    Posts:
    1,082
    Location:
    France
    Please

    @focus
    try again with ESET Nod32. That should be fixed by ESET now.
    They have just emailed us.
     
  23. focus

    focus Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    503
    Location:
    USA
    Working fine. Thanks for the update.
     
  24. inka

    inka Registered Member

    Joined:
    Oct 21, 2009
    Posts:
    426
    As for (a), each app has opportunity to save MRU (most recently used) files
    and next time you use (for instance) Windows Media Player, if you click File}Open it might open to the directory containing the recently played file.

    For (b), I doubt the opened document would be referenced in an MRU entry. Only if you had right-clicked and used "OpenWith" from the (desktop, or windowsExplorer context menu) or if you had dragged the file's icon onto a player's icon to open it... that would create an entry in "Recent Documents". I'll say that I find it weird that, when browsed from the XP Start Menu, Recent only shows the last XX (count? or last xx days) worth of entries. If you browse to that folder (Documents and Settings}MyUsername}Recent) it may contain shortcuts to stuff you handled, dating all the way back to Day1 of installing the O/S.

    For (c), if that "long-lost" removable drive had a VolumeLabel, yes, a bag registry entry referencing it will probably still exist if, within Windows Explorer, Tools}View "remember the view settings for each folder" is checkmarked. Until reading your wonderment, I had never considered this to be a privacy issue -- I had always thought it "was awesome" that WinExplorer restored the selected columns/widths and sort order when I revisited a previously browsed directory (including root dir of a removable drive).

    HKCU\Software\Microsoft\Windows\Shell\Bags
    HKCU\Software\Microsoft\Windows\Shell\BagMRU
    HKCU\Software\Microsoft\Windows\ShellShellNoRoam\Bags
    HKCU\Software\Microsoft\Windows\ShellShellNoRoam\BagMRU

    I use Windows Explorer A LOT. Toward battling registry bloat, I have periodically navigated to each of these in regedit left pane, ctrl+a selectAll in right pane, and Delete. As far as I can tell, doing so in XP yields no unexpected negative side-effect. Yes, emptying the bags clears the remembered custom column widths + sort order for each target folder... but IMO clearing 5000+ accumulated bag entries (against 90K total regkeys) is good housekeeping.

    Each time Explorer fails in creating a regkey, the event is probably logged. I'll stick with the periodic bag cleaning approach.
     
  25. anniew

    anniew Registered Member

    Joined:
    Mar 15, 2013
    Posts:
    92
    Noob question, as I just learned about Shellbags...

    If I delete all shellbags, do I lose any "essential" functionality (e.g. persistent mapped network drives - used for scheduled backups), or are these entries largely for MRU type of capability (i.e. "nice to have" functionality).
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.