Freezes in Registry

  • Thread starter Thread starter Kyle
  • Start date Start date
K

Kyle

When I run any scan full or quick it always freezes when
it gets to this file in the registry...

HKEY_LOCAL_MACHINE:Software:Microsoft:Windows:Current
Version:Explorer:Browser Helper Objects

Is that supposed to be there if and so why is it freezing
there every time?
 
Hi mate its either a bug in the antispy or its a trojan
which Microsoft antispy cannot deal with,If you have
service pack 2 open a internet browser and then go to
tools on the top bar and choose manage add ons check this
screen carefully for any BHO's you know you havent
installed and disable any you think are suspicious then
reboot into safe mode and run another scan with MS antispy

If you are unsure about any of the add on names just post
them on here and i will tell you if they are genuine or
malicious and then we can take if from there

Malicious BHO builds upon existing IE exploits to install
software that records keystrokes on the machines of
unsuspecting Internet users. The keylogger is coded as a
Browser Helper Object (BHO), an add-on technology
introduced by Microsoft to allow programmers to customize
Internet Explorer. Browser helpers are DLL components
that load with Internet Explorer and share the browser's
access and permissions. "In short, a BHO works as a spy
we send to infiltrate the browser's land," Microsoft
writes in its description.

That's just the ticket for hackers, who have coded some
of the most innovative and insidious uses of BHO
technology, initially in the form of spyware and browser
hijackers. Keylogging trojans can now be added to the
growing list of BHO malware.

Try the add on screen and post back if you have any
problems,Plus try a MS Scan in safe mode to see if it
completes a scan

Also when you are back in normal mode run a online virus
scan at Trend's housecall

http://housecall.trendmicro.com/housecall/start_corp.asp

And Follow these basic tips if it becomes clear you have
a Trojan

As this isnt reversable if you think you have recently
picked this up assuming this is a trojan then try use the
system restore to go back to when you know your system is
clean otherwise

Disable System Restore temporarily if you are infected;
Any trojans, spyware, etc. you may have picked up could
have been saved in System Restore and are waiting to re-
infect you. Since System Restore is a protected
directory, your tools can not access it to delete files,
trapping viruses inside. Please follow instructions to do
that here:
(Start>Right click my computer>Properties>System
Restore>Disable then apply and exit)

Enable viewing of hidden files and folders and
extensions; Some programs can hide this way by not being
visible in Windows. Start Windows Explorer and click on
your main hard drive, usually c:\. Then select Tools from
the top of Windows Explorer and then Folder Options. Go
to the View tab. Scroll down to the folder icon that says
Hidden files and folders and check show hidden files and
folders. Also, right below it, uncheck the hide file
extensions for known types. Not doing this could allow
file extensions commonly used by trojans and spyware to
be hidden, for example a file ending in .exe or dll
making manually finding it, if needed, difficult to
impossible.

Delete Temp Internet files :
Open a internet browser window, click Tools then Internet
Options.
Click on the Delete Cookies and the Delete Files buttons,
then click OK and close the browser window.

Delete Windows Temporary Files - (start,run then
type %temp% delete all files you can in this folder
The Windows temporary directory (usually located at
C:\windows\temp).
This directory should not be confused with the Internet
Explorer "Temporary Internet Files Directory".
The Windows temporary directory stores temporary files
that are used during installation of programs and at
other various times.
Cleaning this directory regularly is generally a good
idea.

Then rescan with housecall and MS Antispy again then post
back if you still have problems

Good luck Mate

Andy
 
Back
Top