New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1211
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin   Your Favorite ForumsFavForums 

Undocumented Entry in HijackThis

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Spyware Tools
View previous topic :: View next topic  
Author Message
itsdanky

Cadet
Cadet



Joined: May 05, 2004
Posts: 4
Location: USA

PostPosted: Sat May 08, 2004 2:35 pm    Post subject: Undocumented Entry in HijackThis
Reply with quote

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,

Anyone have an idea what this is? Not so much the program but the "F2" category.

Thanks.
Back to top
View users profile Send private message
helpless

1st Responder
1st Responder



Joined: Jan 29, 2004
Posts: 736
Location: Belgium

PostPosted: Sat May 08, 2004 3:16 pm    Post subject:
Reply with quote

this is what i could find on it at bleepingcomp

F2(and F3) entries correspond to the equivalent locations as F0 and F1, but they are instead stored in the registry for Windows versions XP, 2000, and NT. These versions of Windows do not generally use the system.ini and win.ini files. Instead of backwards compatibility they use a function called IniFileMapping.IniFileMapping, puts a all the contents of a an .ini file in the registry, with keys for each line found in the .ini key stored there. Then when you run a program that normally reads their settings from an .ini file, it will first check the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping, for an .ini mapping, and if found will read the settings from there instead. You can see that this key is referring to the registry as it will contain REG and then the .ini file which IniFileMapping is referring to.

also notice that when it contains a " , " (comma) then it can be a bad thing and it is for sure when another fille is linked to it.

Another entry commonly found in F2 is the UserInit entry which corresponds to the key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit which is found in Windows 95 and above. This key specifies what program should be launched right after a user logs into Windows. The default program for this key is C:\windows\system32\userinit.exe. Userinit.exe is a program that restores your profile, fonts, colors, etc for your uname. It is possible to add further programs that will launch from this key by separating the programs with a comma. For example: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit =C:\windows\system32\userinit.exe,c:\windows\badprogram.exe. This will make both programs launch when you log in and is a common place for trojans, hijackers, and spyware to launch from.


hope it helps

_________________
Learning everyday something new.
-----------------------------------------
There are always 2 correct answers, the "Microsoft correct answer" and "answers that work"
Back to top
View users profile Send private message Visit posters website
itsdanky

Cadet
Cadet



Joined: May 05, 2004
Posts: 4
Location: USA

PostPosted: Sun May 09, 2004 2:46 pm    Post subject:
Reply with quote

Great information. Thanks a lot! Smile
Back to top
View users profile Send private message
lilliebet65

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Dec 03, 2003
Posts: 2235
Location: UK

PostPosted: Wed Jun 02, 2004 2:09 pm    Post subject:
Reply with quote

Glad we were able to help. Smile

NOTE: This thread is now closed. Should you need it reopened, please PM a mod.
Everyone else having a similar issue, please launch a new topic for yourselves.

_________________
I'm Spartacus!
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Spyware Tools All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops