Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

[Fixed] Hijackthis! Logs - browser hijacked? posted in the Security & Safety forums; This should help answer that question. The steps below will have you download a different copy of regedit and then use that copy to search for "finder". Download the xp_emergencyutil.zip ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #43  
Old 01-23-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 547
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: browser hijacked?

This should help answer that question. The steps below will have you download a different copy of regedit and then use that copy to search for "finder".

Download the xp_emergencyutil.zip file and save it to your hard drive. Double-click the xp_emergencyutil.zip file and extract xp_emergencyutil.exe to your hard disk. To run the EXE just double click it, there is no installer. You will have the option of running the programs automatically, after the copies are created.


__________________
Steve
  #44  
Old 01-23-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

finder found!


  #45  
Old 01-23-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 547
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: browser hijacked?

GOOD! - we are making progress. are you able to copy the locations where it was found?


__________________
Steve
  #46  
Old 01-23-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

Not so fast. I find I was able to find the first instance of finder with standard regedit as well.

As I used the replacement regedit and continued "find next" the system eventually crashed again.

I don't know if the following analysis might help, but here goes. I did selective exports to txt files of the registry and found that I could export:
HKEY_CLASSES_ROOT
HKEY_LOCAL_MACHINE
HKEY_CURRENT_CONFIG

The system crashes when I try to export:
HKEY_CURRENT_USER
HKEY_USERS

Using HKEY_CURRENT_USER, I selectively exported each and every sub-heading successfully:
AppEvents
Console
Control Panel
Environment
Identities
Keyboard Layout
Network
Printers
Software
SYSTEM
UNICODE Program Groups
Volatile Environment
Windows 3.1 Migration Status

but upon exporting the whole of HKEY_CURRENT_USER the system crashes.


  #47  
Old 01-23-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 547
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: browser hijacked?

The reason you cannot export the entire HKEY_CURRENT_USER and HKEY_USER is that you are a user on the system.

Try doing a search for the entire site's name using the new regedit. There should be very few entries with that. Let me know the results.


__________________
Steve
  #48  
Old 01-23-2008
Bronze Member
 
Join Date: Jan 2008
Posts: 42
PC Experience: Some Experience
keller130 - See this Members User comments on their Profile page
Default Re: browser hijacked?

system crashed and rebooted before it found anything.


  #49  
Old 01-23-2008
Senior Security Analyst
 
Join Date: Dec 2006
Location: In a van, down by the river
Posts: 547
PC Experience: Experienced
dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page dahli - See this Members User comments on their Profile page
Default Re: browser hijacked?

Things are not looking good at all. You better make copies of all your stuff in case a reformat/reinstall is called for. I will do some more research and post back when I think I found something.


__________________
Steve

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 10:30 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
Loans
Loans information and advice from the experts at ThisIsMoney.co.uk

News
Workwide news from the UK paper - the mirror.

Debt Help
Having problems with debt? Maybe moneyextra can help.