View Single Post
Join Date: Dec 2003
Posts: 6,439
Reputation: DMR will become famous soon enough DMR will become famous soon enough 
Solved Threads: 363
Team Colleague
DMR's Avatar
DMR DMR is offline Offline
Wombat At Large

Re: IT is in my REGISTRY!

 
0
  #6
May 27th, 2005
1. This entry in your log does indicate that HJT is running from a Temp folder:

Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

Another strange thing about that entry is that it makes reference to hijackthis[1].zip. The version of HJT I gave you the link to isn't a zipped file at all (it's just the regular hijackthis.exe executable); downloading it shouldn't have created a Temp zip folder.

Have you ever downloaded HJT before? The version offered at many sites is in .zip format, which might explain things.


2. A lot of P2P programs create registry entries under the folowing Registry keys; these are probably what AOL is detecting:

HKEY_CLASSES_ROOT\: magnet
HKEY_LOCAL_MACHINE\software\magnet
HKEY_LOCAL_MACHINE\: software\classes\magnet

Please do the following:

- Open the Windows Registry Editor. To do so, click on the "Run..." item in your Start menu, type the following in the resulting "Open:" box, and then click OK:

regedit

- Navigate through the Registry folder structures to the three locations I just listed above and tell us what entries exist under each.

!! DO NOT actually delete or change anything in the Registry at this time!!
"May the Wombat of Happiness snuffle through your underbrush."
- Ancient Aborigine blessing


Please do not contact me by email or PM for help. We're all volunteers here, and only have so much free time to dedicate to our efforts.

However, if I've been working on a thread with you already, and seem to have "forgotten" your thread, please do send me a message. I try not to let things slip through the cracks, but it does happen sometimes.
Reply With Quote