![]() |
|
#1
|
||||
|
||||
|
Quote:
|
|
#2
|
||||
|
||||
|
Thanks Ron!
![]() |
|
#4
|
|||
|
|||
|
I ran Autoruns immediately and it found this very suspicious object in my online and even off-line system partition under :
HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components Autorun Entry: 0 Description...: blank (very suspicous) Publisher......: blank (very suspicious, unknown source) Image Path...: File not found about:Home (very suspicious, completely hidden) I was stupified, because that was in theory impossible. Was this a sneaky rootkit or keylogger ? Was this a malware that infected the firmware of all my hardware components ? Was this an object caused by one of these "invisible" things of Joanna ? Was I infected by Rustock A upto Z ? Was this malware telling me I'm a zero as a bad joke ? I don't know. After the first panic and taking a valium pill, I got my common sense back. I have an image of WinXPproSP2 only, which has never been on-line, not even for activation. If that image also contained this suspicious object, I was malware-free. So I restored that image, ran Autoruns and this suspicious object appeared again in the Autoruns List, which means it was NOT a malicious object. Case closed and back to normal. This is typical M$ : scaring the user about nothing. This is the second time. ![]()
__________________
ErikAlbert Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR Malware Survival Rate = 0.00%, but each malware has my sympathy.
Last edited by ErikAlbert : December 19th, 2007 at 04:22 AM. |
|
#5
|
||||
|
||||
|
Ta
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#6
|
||||
|
||||
|
@Erik, fwiw I have that also, so perhaps that provides additional reassurance that it actually is an MS entry.
![]() |
|
#7
|
||||
|
||||
|
Quote:
![]()
__________________
Now that I'm older, I seem to have more patience. It turns out I just don't give a crap. WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
|
|
#8
|
||||
|
||||
|
I just replace all 4 existing files with the 4 new ones...
|
|
#9
|
||||
|
||||
|
Quote:
|
|
#10
|
||||
|
||||
|
Quote:
Ah Ron -- 10Q!
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#11
|
||||
|
||||
|
Thanks all.
![]()
__________________
Now that I'm older, I seem to have more patience. It turns out I just don't give a crap. WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
|
|
#12
|
||||
|
||||
|
Quote:
Autoruns isn't a blacklist scanner. It only informs you about certain system variables and it's up to you to verify/decide on them. It's a forensic tool (like HijackThis, Runscanner, anti-rootkits, integrity checkers, etc) and it isn't targeted to "newbies", although you can learn how to use it without fear.
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder". "Perfect is the enemy of good enough". Voltaire. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|