nct35
2007-01-18, 00:13
Hi all. This is my first post on this forum.
I am concerned that resident seems to be coming up with many registry value changes. It would seem that they relate to IE, but my main browser is Mozilla and I only use IE occasionally. I think that something is trying to gain access and change my homepage or whatever. Below you will find logs from the past two days. I have only just been able to reset the dialogue box with ResHack for Tea Timer issues, so I have been pressing CTRL A and CTRL D. However, if I deny the change, it keeps coming back until I allow it.
Really need to sort this out soon. Thanks
2007/01/16 08:34:40 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 08:34:41 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 15:29:42 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 15:29:42 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 16:51:48 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 16:51:48 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 18:43:18 Allowed value "{E36C5562-C4E0-4220-BCB2-1C671E3A5916}" (new data: "") added in ActiveX Distribution Unit!
2007/01/16 19:30:11 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 19:30:11 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 20:04:04 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 20:06:23 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/17 17:19:38 Allowed value "Uniblue Quick Access" (new data: "") deleted in System Startup user entry!
2007/01/17 17:19:44 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/17 17:19:45 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/17 23:00:08 Denied value "Uniblue Quick Access" (new data: "") deleted in System Startup user entry!
2007/01/17 23:00:15 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/17 23:00:16 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/17 23:01:30 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:01:47 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:01:53 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:02 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:12 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:14 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:18 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:31 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:39 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:42 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:48 Allowed value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:52 Allowed value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
I am concerned that resident seems to be coming up with many registry value changes. It would seem that they relate to IE, but my main browser is Mozilla and I only use IE occasionally. I think that something is trying to gain access and change my homepage or whatever. Below you will find logs from the past two days. I have only just been able to reset the dialogue box with ResHack for Tea Timer issues, so I have been pressing CTRL A and CTRL D. However, if I deny the change, it keeps coming back until I allow it.
Really need to sort this out soon. Thanks
2007/01/16 08:34:40 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 08:34:41 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 15:29:42 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 15:29:42 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 16:51:48 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 16:51:48 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 18:43:18 Allowed value "{E36C5562-C4E0-4220-BCB2-1C671E3A5916}" (new data: "") added in ActiveX Distribution Unit!
2007/01/16 19:30:11 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 19:30:11 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/16 20:04:04 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/16 20:06:23 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/17 17:19:38 Allowed value "Uniblue Quick Access" (new data: "") deleted in System Startup user entry!
2007/01/17 17:19:44 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/17 17:19:45 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/17 23:00:08 Denied value "Uniblue Quick Access" (new data: "") deleted in System Startup user entry!
2007/01/17 23:00:15 Allowed value "" (new data: "http://www.google.com/search?q=%s") changed in Browser page!
2007/01/17 23:00:16 Allowed value "SearchAssistant" (new data: "http://www.google.com/ie") changed in Browser page!
2007/01/17 23:01:30 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:01:47 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:01:53 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:02 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:12 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:14 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:18 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:31 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:39 Denied value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:42 Denied value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!
2007/01/17 23:02:48 Allowed value "BootExecute" (new data: "") deleted in Session manager!
2007/01/17 23:02:52 Allowed value "ExcludeFromKnownDlls" (new data: "") deleted in Session manager!