Re: Hangover from the spyaxe trojan



Yea, you see some "strange numbers" - GUIDS (Globally Unique IDentifiers),
to search files you need to find corresponding entries in
HKEY_CLASSES_ROOT\CLSID section. So, suppose, you have folloding BHO
registered as:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser
Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

You need to take this GUID - 06849E9F-C8D7-4D59-B87D-784B7D6BE0B3 and search
it in the HKEY_CLASSES_ROOT\CLSID section, it's present on my machine at:

HKEY_CLASSES_ROOT\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}.

When you locate it look at subnode "InprocServer32", open it and you will
see "default" value that contains path to dll. In my case this path is
H:\Program Files\Acrobat Reader\Reader\ActiveX\AcroIEHelper.dll

--
Vladimir

"nlscb" <nlscb@xxxxxxxxx> wrote in message
news:1137876282.867312.253970@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
> Dear Vladimir,
> Do these registered files have extensions that I can search for? I
> am having trouble finding the path you are describing? Is it normally
> hidden?
>
> Niels
>


.



Relevant Pages

  • Re: 16x16Matrix
    ... assume int, but you can pick any other type (including the ones you ... then other replies in the thread might. ... Vladimir ... Prev by Date: ...
    (comp.lang.c)
  • =?iso-8859-1?q?Warenverkauf_=FCber_das_Internet?=
    ... Artikel am besten über das Internet verkauft werden? ... Vielen Dank! ... Vladimir ... Prev by Date: ...
    (de.soc.wirtschaft)
  • Miserly Knight Sergei Leiferkus
    ... starring Sergei Leiferkus with London PO, conducted by Vladimir ... Jurowski ... Substantial, Informative interviews included. ... Prev by Date: ...
    (rec.music.classical.recordings)
  • Re: Warenverkauf über das Internet
    ... Genau so etwas habe ich gesucht:) ... Vladimir ... Prev by Date: ...
    (de.soc.wirtschaft)