943,822 Members | Top Members by Rank

Ad:
Apr 2nd, 2004
0

Dangerous Bug in HijackThis 1.97.7 Restoral Procedure

Expand Post »
Dangerous Bug in HijackThis 1.97.7 Restoral Procedure

I have searched everywhere to see if this has already been reported to Merjin, but I can not seem to find any reference to this, so am letting people know.

VERY IMPORTANT. YOU MUST READ! Dangerous bug in HijackThis version 1.97.7 when restoring UserInit backups.

There is a dangerous bug in the restoral procedure for restoring keys to UserInit. If you using HijackThis to fix a incorrect UserInit setting, and then in the future want to restore that key from a backup, it will overwrite the values for the wrong key on restoral.

This was tested numerous times on numerous computers and it will changes the wrong key, and leaves the actual UserInit key alone.

Detailed Information:

If the key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit contains extra programs other than userinit.exe, it will list that error in the F2 section on a scan.

When you fix this error it will make a backup of that key. If you restore that key, it should go back and replace the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:UserInit with the information in the backup.

Instead, it adds that information to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogonhell, and replaces explorer.exe with the information found in the backup.

Needless to say doing a reboot after restoring that key, would not be pleasant.

Just be careful when advising people to restore entries from that Key. I will notify the other message boards and have already notified Merjin.
Similar Threads
Reputation Points: 13
Solved Threads: 0
Light Poster
Grinler is offline Offline
31 posts
since Apr 2004

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: 3 New Tutorials on SPyware and Hijackers
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: hijackthis.log





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC