Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 11th, 2010, 09:54 AM
Biscuit Biscuit is offline
Frequent Poster
 
Join Date: May 2006
Location: Isle of Man
Posts: 976
Default Userinit

A userinit hijack was left on a laptop after a Malwarebytes clean & then a Prevx clean. I had to use Combofix to clean it. It was a definite infection, being picked up by HijackThis & it was continually changing the IE homepage & search defaults as well as making bootup very slow.

I'm a little concerned why did Prevx not see this infection?
__________________
Windows 7 32bit Ultimate SP1 | MS ISA 2004 Firewall | Malwarebytes | Firefox with NoScript | Acronis True Image
  #2  
Old January 11th, 2010, 01:08 PM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is online now
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,583
Default Re: Userinit

Hello,
It's hard to say without further information - could you get a scan log from this user's PC or a copy of any samples if they still have them?

Thanks!
  #3  
Old January 12th, 2010, 04:57 AM
Biscuit Biscuit is offline
Frequent Poster
 
Join Date: May 2006
Location: Isle of Man
Posts: 976
Default Re: Userinit

Sorry Joe, it's an end user pc. I was just surprised that Prevx didn't pick it up when it was glaringly obvious in HijackThis.
__________________
Windows 7 32bit Ultimate SP1 | MS ISA 2004 Firewall | Malwarebytes | Firefox with NoScript | Acronis True Image
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums