Dangerous Bug in HijackThis 1.97.7 Restoral Procedure

Reply

Join Date: Apr 2004
Posts: 31
Reputation: Grinler is an unknown quantity at this point 
Solved Threads: 0
Grinler Grinler is offline Offline
Light Poster

Dangerous Bug in HijackThis 1.97.7 Restoral Procedure

 
0
  #1
Apr 2nd, 2004
Dangerous Bug in HijackThis 1.97.7 Restoral Procedure

I have searched everywhere to see if this has already been reported to Merjin, but I can not seem to find any reference to this, so am letting people know.

VERY IMPORTANT. YOU MUST READ! Dangerous bug in HijackThis version 1.97.7 when restoring UserInit backups.

There is a dangerous bug in the restoral procedure for restoring keys to UserInit. If you using HijackThis to fix a incorrect UserInit setting, and then in the future want to restore that key from a backup, it will overwrite the values for the wrong key on restoral.

This was tested numerous times on numerous computers and it will changes the wrong key, and leaves the actual UserInit key alone.

Detailed Information:

If the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit contains extra programs other than userinit.exe, it will list that error in the F2 section on a scan.

When you fix this error it will make a backup of that key. If you restore that key, it should go back and replace the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit with the information in the backup.

Instead, it adds that information to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogonhell, and replaces explorer.exe with the information found in the backup.

Needless to say doing a reboot after restoring that key, would not be pleasant.

Just be careful when advising people to restore entries from that Key. I will notify the other message boards and have already notified Merjin.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC