| | |
Dangerous Bug in HijackThis 1.97.7 Restoral Procedure
![]() |
•
•
Join Date: Apr 2004
Posts: 31
Reputation:
Solved Threads: 0
Dangerous Bug in HijackThis 1.97.7 Restoral Procedure
I have searched everywhere to see if this has already been reported to Merjin, but I can not seem to find any reference to this, so am letting people know.
VERY IMPORTANT. YOU MUST READ! Dangerous bug in HijackThis version 1.97.7 when restoring UserInit backups.
There is a dangerous bug in the restoral procedure for restoring keys to UserInit. If you using HijackThis to fix a incorrect UserInit setting, and then in the future want to restore that key from a backup, it will overwrite the values for the wrong key on restoral.
This was tested numerous times on numerous computers and it will changes the wrong key, and leaves the actual UserInit key alone.
Detailed Information:
If the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit contains extra programs other than userinit.exe, it will list that error in the F2 section on a scan.
When you fix this error it will make a backup of that key. If you restore that key, it should go back and replace the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit with the information in the backup.
Instead, it adds that information to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
hell, and replaces explorer.exe with the information found in the backup.
Needless to say doing a reboot after restoring that key, would not be pleasant.
Just be careful when advising people to restore entries from that Key. I will notify the other message boards and have already notified Merjin.
I have searched everywhere to see if this has already been reported to Merjin, but I can not seem to find any reference to this, so am letting people know.
VERY IMPORTANT. YOU MUST READ! Dangerous bug in HijackThis version 1.97.7 when restoring UserInit backups.
There is a dangerous bug in the restoral procedure for restoring keys to UserInit. If you using HijackThis to fix a incorrect UserInit setting, and then in the future want to restore that key from a backup, it will overwrite the values for the wrong key on restoral.
This was tested numerous times on numerous computers and it will changes the wrong key, and leaves the actual UserInit key alone.
Detailed Information:
If the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit contains extra programs other than userinit.exe, it will list that error in the F2 section on a scan.
When you fix this error it will make a backup of that key. If you restore that key, it should go back and replace the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit with the information in the backup.
Instead, it adds that information to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
hell, and replaces explorer.exe with the information found in the backup.Needless to say doing a reboot after restoring that key, would not be pleasant.
Just be careful when advising people to restore entries from that Key. I will notify the other message boards and have already notified Merjin.
![]() |
Similar Threads
- what is AshwebSv.exe? i think that's the one that's getting me (hijackthis log) (Viruses, Spyware and other Nasties)
- New Poly Win32 [For ScottyM] (Viruses, Spyware and other Nasties)
- Re: Hijack log-WMP Internal application error ha occured (Viruses, Spyware and other Nasties)
- Slow Internet Explorer 6 Response Time (Windows NT / 2000 / XP)
- Dangerous BUG in WINXP (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: 3 New Tutorials on SPyware and Hijackers
- Next Thread: hijackthis.log
| Thread Tools | Search this Thread |
adware anti-malware anti-virussitesaccessissue antivirus apple audio avg backtoschoolspeech bar blackhat botnet botnets censorship china commercial commercials conficker connect control crosssitescripting cyber cybercrime cyberwarfare domains e-mafia education email europe exam facebook fancheckvirus gaming gtaiv halloween hijack hosting internet iphone kaspersky legal logfiles mail malware mcafee messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile panel parents patch phishing police policeprovirusmba-mblockedinternetaccess president privacy pro problem reliability report research risk rogueantivirus samhain sans scareware school search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec teen translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses war warning windows worm yahoo zeroday





