View Single Post
Old 08-11-2007, 10:17 AM   #17 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,494
OS: N/A


Re: Browser hijacker, backdoor.haxdoor, etc

Your Registry entry for the legitimate Windows service got wiped out by Trojan Remover. Let's attempt to repair it.

Open NOTEPAD.exe and copy/paste the text in the quotebox below:
(don't forget to copy and paste REGEDIT4)

Quote:
REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sr]
"ImagePath"=hex(2):73,79,73,74,65,6d,33,32,5c,44,52,49,56,45,52,53,5c,73,72,2e,\
73,79,73,00
Save this as fix.reg Choose to "Save type as - All Files"
It should look like this:
Double click on fix.reg & allow it to merge into the registry


---------------


Then verify/check if this folder exist - C:\WINDOWS\SystemRoot

Also check if this file still exist - C:\Windows\system32\DRIVERS\sr.sys


--------------


Test if System Restore still works.
Go to Start > Run - type C:\Windows\system32\restore\rstrui.exe
__________________

Question - what have you done for the community today?
sUBs is offline