|
|||||||||||
|
Re: 030 ignkeywords igetnet follow up
From: Ryan Yagatich <ryany(at)pantek.com>
Date: Thu Nov 14 2002 - 13:48:13 EST It appears that the uninstaller does the following (at first glance) Removes the following files: c:\Program Files\Internet Explorer\winstart.exe c:\program files\internet explorer\bho.dll c:\progra~1\intern~1\bho.dll c:\WinIE\winstart.exe c:\WinIE\bho.dll c:\WinIe\bho.dll %windir%\system\winstart.exe %windir%\system32\shell322.exe %windir%\system32\IGNinstaller.exe %windir%\system32\winstart.exe %windir%\winfile2.dat %windir%\system\rsp.dl %windir%\system\bho.dll %windir%\system32\bho.dll Removes the following registry keys: HKEY_(LOCALMACHINE|CURRENT_USER)\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{730F2451-A3FE-4A72-938C-FC8A74F15978} HKEY_(LOCALMACHINE|CURRENT_USER)\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA76C2D7-15A9-4E80-A942-191F02BDCA91} HKEY_(LOCALMACHINE|CURRENT_USER)\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0740576F-730B-11D6-8A8B-0050BA8452C0} HKEY_(LOCALMACHINE|CURRENT_USER)\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E6B67CDC-81F8-11D6-8A8C-0050BA8452C0} It then appears to modify: %windir%\hosts or %windir%\system32\drivers\etc\hosts to remove the lines: ieautosearch search.netscape.com auto.search.msn.com and finally, creates an uninstall log in %systemdrive% Like I mentioned, this is only a first glance, of it, and more is possible.
<OPINION>
</OPINION>
Thanks,
Pantek, Incorporated
9C 80 D8 81 D4 D3 79 05 85 37 BE 21 F5 2F 14 FA 63 54 C1 1A C5 77 34 FB If builders built buildings they way programmers wrote programs, the first woodpecker that comes along would destroy civilization On 11 Nov 2002, Waitman C. Gobble wrote: This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Sat Nov 16 00:18:59 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:51 EDT |
||||||||||
|
|||||||||||