Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

hijack.shell.gen.a [Closed]


  • This topic is locked This topic is locked

#46
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
Hi Taurus76, :)

Download the attached .bat file and save it to your Desktop. Right-click on it and choose Run as administrator and it will create a .txt file in C drive. Post the contents of the file C:\CheckUp.txt.
[attachment=69296:CheckUp.bat]

Regards,
Valinorum
  • 0

Advertisements


#47
Taurus76

Taurus76

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Another strange thing I just noticed: the Google Chrome shortcut was missing from my desktop. I had to access it via the Start menu. Anyway, here is the log:


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
ZonesSecurityUpgrade REG_BINARY 2E9981177E31CF01
EnableNegotiate REG_DWORD 0x1
MigrateProxy REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
Signature REG_SZ Client UrlCache MMF Ver 5.2

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix REG_SZ
CacheLimit REG_DWORD 0x3e800

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix REG_SZ Cookie:
CacheLimit REG_DWORD 0x2000

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CachePath REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\DOMStore
CachePrefix REG_SZ DOMStore
CacheLimit REG_DWORD 0x3e8
CacheOptions REG_DWORD 0x8
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
CachePath REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Feeds Cache
CachePrefix REG_SZ feedplat:
CacheLimit REG_DWORD 0x2000
CacheOptions REG_DWORD 0x0
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iedownload
CachePath REG_EXPAND_SZ %APPDATA%\Microsoft\Windows\IEDownloadHistory
CachePrefix REG_SZ iedownload:
CacheLimit REG_DWORD 0x2000
CacheOptions REG_DWORD 0x9
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014022520140226
CachePath REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012014022520140226
CachePrefix REG_SZ :2014022520140226:
CacheLimit REG_DWORD 0x2000
CacheOptions REG_DWORD 0xb
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014022620140227
CachePath REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012014022620140227
CachePrefix REG_SZ :2014022620140227:
CacheLimit REG_DWORD 0x2000
CacheOptions REG_DWORD 0xb
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014022720140228
CachePath REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012014022720140228
CachePrefix REG_SZ :2014022720140228:
CacheLimit REG_DWORD 0x2000
CacheOptions REG_DWORD 0xb
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012014022820140301
CachePath REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012014022820140301
CachePrefix REG_SZ :2014022820140301:
CacheLimit REG_DWORD 0x2000
CacheOptions REG_DWORD 0xb
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
CachePath REG_EXPAND_SZ %APPDATA%\Microsoft\Windows\PrivacIE
CachePrefix REG_SZ PrivacIE:
CacheLimit REG_DWORD 0x400
CacheOptions REG_DWORD 0x9
CacheRepair REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix REG_SZ Visited:
CacheLimit REG_DWORD 0x2000

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
DefaultConnectionSettings REG_BINARY 46000000030000000100000000000000000000000000000004000000000000006E93FA317E31CF010000000000000000000000000200000002000000C0A803060000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001700000000000000200100009D386ABD34941C6C3F57FCF90000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
SavedLegacySettings REG_BINARY 46000000440000000100000000000000000000000000000004000000000000006E93FA317E31CF010000000000000000000000000200000002000000C0A803060000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001700000000000000200100009D386ABD34941C6C3F57FCF90000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
au.NET(PacketWIN) REG_BINARY 4600000002000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
UK REG_BINARY 4600000002000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
(Default) REG_SZ
DisplayName REG_SZ Computer
PMDisplayName REG_SZ Computer [Protected Mode]
Description REG_SZ Your computer
Icon REG_SZ shell32.dll#0016
LowIcon REG_SZ inetcpl.cpl#005422
CurrentLevel REG_DWORD 0x0
Flags REG_DWORD 0x21
1200 REG_DWORD 0x3
1400 REG_DWORD 0x1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
(Default) REG_SZ
DisplayName REG_SZ Local intranet
PMDisplayName REG_SZ Local intranet [Protected Mode]
Description REG_SZ This zone contains all Web sites that are on your organization's intranet.
Icon REG_SZ shell32.dll#0018
LowIcon REG_SZ inetcpl.cpl#005423
CurrentLevel REG_DWORD 0x0
Flags REG_DWORD 0x143
1200 REG_DWORD 0x3
1400 REG_DWORD 0x1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
(Default) REG_SZ
DisplayName REG_SZ Trusted sites
PMDisplayName REG_SZ Trusted sites [Protected Mode]
Description REG_SZ This zone contains Web sites that you trust not to damage your computer or data.
Icon REG_SZ inetcpl.cpl#00004480
LowIcon REG_SZ inetcpl.cpl#005424
CurrentLevel REG_DWORD 0x0
Flags REG_DWORD 0x21
1200 REG_DWORD 0x3
1400 REG_DWORD 0x1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
(Default) REG_SZ
DisplayName REG_SZ Internet
PMDisplayName REG_SZ Internet [Protected Mode]
Description REG_SZ This zone contains all Web sites you haven't placed in other zones
Icon REG_SZ inetcpl.cpl#001313
LowIcon REG_SZ inetcpl.cpl#005425
CurrentLevel REG_DWORD 0x0
Flags REG_DWORD 0x21
1200 REG_DWORD 0x3
1400 REG_DWORD 0x1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
(Default) REG_SZ
DisplayName REG_SZ Restricted sites
PMDisplayName REG_SZ Restricted sites [Protected Mode]
Description REG_SZ This zone contains Web sites that could potentially damage your computer or data.
Icon REG_SZ inetcpl.cpl#00004481
LowIcon REG_SZ inetcpl.cpl#005426
CurrentLevel REG_DWORD 0x0
Flags REG_DWORD 0x21
1200 REG_DWORD 0x3
1400 REG_DWORD 0x3

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport\LowDAMap

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
WpadLastNetwork REG_SZ {0F59AC2D-F6F1-40B7-87B7-43FC5FC01028}

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\cc-af-78-17-da-12
WpadDecisionReason REG_DWORD 0x1
WpadDecisionTime REG_BINARY 90F1A93A7E31CF01
WpadDecision REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{0F59AC2D-F6F1-40B7-87B7-43FC5FC01028}
WpadDecisionReason REG_DWORD 0x1
WpadDecisionTime REG_BINARY 90F1A93A7E31CF01
WpadDecision REG_DWORD 0x0
WpadNetworkName REG_SZ CCAF7817DA11

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{0F59AC2D-F6F1-40B7-87B7-43FC5FC01028}\cc-af-78-17-da-12

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
(Default) REG_SZ
UNCAsIntranet REG_DWORD 0x0
AutoDetect REG_DWORD 0x1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains
(Default) REG_SZ

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
(Default) REG_SZ
http REG_DWORD 0x3
https REG_DWORD 0x3
ftp REG_DWORD 0x3
file REG_DWORD 0x3
@ivt REG_DWORD 0x1
shell REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges
(Default) REG_SZ

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
(Default) REG_SZ
SelfHealCount REG_DWORD 0x1
SecuritySafe REG_DWORD 0x1

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
(Default) REG_SZ
DisplayName REG_SZ Computer
PMDisplayName REG_SZ Computer [Protected Mode]
Description REG_SZ Your computer
Icon REG_SZ shell32.dll#0016
LowIcon REG_SZ inetcpl.cpl#005422
CurrentLevel REG_DWORD 0x0
Flags REG_DWORD 0x21
1200 REG_DWORD 0x0
1400 REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
(Default) REG_SZ
DisplayName REG_SZ Local intranet
PMDisplayName REG_SZ Local intranet [Protected Mode]
Description REG_SZ This zone contains all Web sites that are on your organization's intranet.
Icon REG_SZ shell32.dll#0018
LowIcon REG_SZ inetcpl.cpl#005423
CurrentLevel REG_DWORD 0x10500
Flags REG_DWORD 0x143
1200 REG_DWORD 0x0
1400 REG_DWORD 0x0
2500 REG_DWORD 0x3

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
(Default) REG_SZ
DisplayName REG_SZ Trusted sites
PMDisplayName REG_SZ Trusted sites [Protected Mode]
Description REG_SZ This zone contains Web sites that you trust not to damage your computer or data.
Icon REG_SZ inetcpl.cpl#00004480
LowIcon REG_SZ inetcpl.cpl#005424
CurrentLevel REG_DWORD 0x11000
Flags REG_DWORD 0x47
1200 REG_DWORD 0x0
1400 REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
(Default) REG_SZ
DisplayName REG_SZ Internet
PMDisplayName REG_SZ Internet [Protected Mode]
Description REG_SZ This zone contains all Web sites you haven't placed in other zones
Icon REG_SZ inetcpl.cpl#001313
LowIcon REG_SZ inetcpl.cpl#005425
CurrentLevel REG_DWORD 0x11500
Flags REG_DWORD 0x1
1200 REG_DWORD 0x0
1400 REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
(Default) REG_SZ
DisplayName REG_SZ Restricted sites
PMDisplayName REG_SZ Restricted sites [Protected Mode]
Description REG_SZ This zone contains Web sites that could potentially damage your computer or data.
Icon REG_SZ inetcpl.cpl#00004481
LowIcon REG_SZ inetcpl.cpl#005426
CurrentLevel REG_DWORD 0x12000
Flags REG_DWORD 0x3
1200 REG_DWORD 0x3
1400 REG_DWORD 0x3
  • 0

#48
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
Go to C:\Program Files (x86)\Google\Chrome\Application
Right-click on chrome.exe > Send to > Desktop (create shortcut)
  • 0

#49
Taurus76

Taurus76

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Yeah, sorry it wasn't so much that I don't know how to get it back as that I don't know why it disappeared!
  • 0

#50
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
While removing the registry key it may have removed the shortcut.
  • 0

#51
Taurus76

Taurus76

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Ah, I see. Thank you for letting me know!
  • 0

#52
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
Can you perform an IE reset and try downloading? I doubt it will work but it worth a try after the registry fix.
  • 0

#53
Taurus76

Taurus76

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Yep, still no joy I'm afraid!
  • 0

#54
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
Step 1.

Download AppRemover from here to your desktop.

Double click and run AppRemover.
Click Next
Select Remove Security Application
Click Next (It is now scanning for security applications) Note: This step can take some time as it searches.
When the scan finishes click Next
Click on any application it finds and remove it. This will involve a reboot, so reboot when instructed to reboot.

Repeat these steps for additional applications until this list is empty.


Step 2.

Double click and run AppRemover.
Click Next
Select Clean Up a Failed Uninstall
Click Continue (It is now scanning for security application fragments) Note: This step can take a long time as it searches.
When the scan finishes click Next
Click on any application(s) it finds and remove it(them). This will involve a reboot, so reboot when instructed to reboot.

 

Download the attached .bat file, Right-click and Run as administrator. Post the log in C:\RegCheck.txt
[attachment=69403:RegCheck.bat]

Edited by Valinorum, 04 March 2014 - 04:38 AM.

  • 0

#55
Taurus76

Taurus76

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Thanks again!

I was unable to carry out Step 2. It did not give me any option to clean a failed install - it just told me it could not find anything to uninstall.

Here is the log that you requested:


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments
ScanWithAntiVirus REG_DWORD 0x3
  • 0

Advertisements


#56
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
Fix IE Utility:

Please download the Fix IE Utility then unzip the file to your desktop.

  • Close all open windows, especially Internet Explorer.
  • Right-click on Fix IE Utility.exe and select Run as Administrator to run the application.
  • Now click on the Run Utility button as shown in the image:-
Posted Image

  • Wait until the following message appears:-
Posted Image

  • Then click on OK.
  • Restart your machine and then check if Internet Explorer is now working correctly again.

  • 0

#57
Taurus76

Taurus76

    Member

  • Topic Starter
  • Member
  • PipPip
  • 29 posts
Sadly I am getting the same error message!

I don't want to waste any more of your time with this. If you want to give up please feel free. (If you want to carry on for your own research or whatever, please also feel free!)
  • 0

#58
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
I know this is frustrating and I do not wish to keep you here with this issue as well. I consulted with my teachers and we are doing the best we could to rectify the issue.

If you want to give up please feel free. (If you want to carry on for your own research or whatever, please also feel free!)

Every user is a learning experience. Every machine is unique and you can always discontinue if you wish since we have disinfected your machine which was the prime concern of your thread. Try the repair tool here and see if it changes anything.
  • 0

#59
Valinorum

Valinorum

    GeekU Guardian Bot

  • GeekU Moderator
  • 3,330 posts
Just a little query, you are using your main administrative account, right? Can you create a new user account and try to download with IE from there?
  • 0

#60
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP