Author Topic: Important Autoruns question: IE Image Hijack!  (Read 42651 times)

0 Members and 1 Guest are viewing this topic.

Offline ehmen

  • Poster
  • *
  • Posts: 498
Important Autoruns question: IE Image Hijack!
« on: August 16, 2015, 04:56:26 AM »
Hi, I've seen in my Autoruns that Internet explorer is listed in Image Hijacks, though I don't see any other program listed anywhere that could be hijacking it (like it seems should be the case from here in the Image Hijack section).
In fact when I go to the registry entry listed below, there's only one value:
"C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome

Would anyone know how I could find out why IE is considered to be Image Hijacked?

Thank you very much!
« Last Edit: October 15, 2015, 01:47:07 AM by ehmen »

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: Important Autoruns question: IE Image Hijack!
« Reply #1 on: August 16, 2015, 06:44:20 AM »
that's afaik default entry, Autoruns don't show only bad things , it shows everything including the usual ...
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #2 on: August 16, 2015, 03:36:33 PM »
You're saying everyone has IE listed in their Autoruns as being Image Hijacked?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Important Autoruns question: IE Image Hijack!
« Reply #3 on: August 16, 2015, 03:39:14 PM »
Nope it is the wording of that tab ...  If you could expand it, it would say "these are the main areas where you would be likely to see a hijacked item "

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #4 on: August 16, 2015, 03:44:47 PM »
Nope it is the wording of that tab ...  If you could expand it, it would say "these are the main areas where you would be likely to see a hijacked item "
I'm not sure I understand, what should I expand?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Important Autoruns question: IE Image Hijack!
« Reply #5 on: August 16, 2015, 03:50:08 PM »
Nope basically that is what that tab means...  My own wording

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #6 on: August 16, 2015, 06:06:13 PM »
So is there a way for me to find out why IE is listed as Image Hijacked?
« Last Edit: August 18, 2015, 08:37:35 PM by ehmen »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Important Autoruns question: IE Image Hijack!
« Reply #7 on: August 16, 2015, 06:06:54 PM »
It is not hijacked ...

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #8 on: August 16, 2015, 06:37:36 PM »
...is there a way for me to find out why IE is listed as Image Hijacked?
It is not hijacked ...
That's good.
« Last Edit: August 18, 2015, 08:38:20 PM by ehmen »

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #9 on: August 17, 2015, 08:50:39 PM »
Do you know why it's listed as such?
« Last Edit: August 18, 2015, 08:38:27 PM by ehmen »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Important Autoruns question: IE Image Hijack!
« Reply #10 on: August 17, 2015, 09:07:12 PM »
All that is saying is this is the place to look for hijacks that is all not that you have one

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #11 on: August 18, 2015, 12:52:01 AM »
All that is saying is this is the place to look for hijacks that is all not that you have one
By telling me IE is hijacked that's how they show that this is the tab to look for Image Hijacks? I don't understand.
« Last Edit: August 18, 2015, 09:18:38 PM by ehmen »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Important Autoruns question: IE Image Hijack!
« Reply #12 on: August 18, 2015, 03:42:06 PM »
If you do not know the purpose of a tool then it would be best not to use it

Offline ehmen

  • Poster
  • *
  • Posts: 498
Re: Important Autoruns question: IE Image Hijack!
« Reply #13 on: August 18, 2015, 06:37:42 PM »
If you do not know the purpose of a tool then it would be best not to use it




Quote
http://www.howtogeek.com/school/sysinternals-pro/lesson6/all/

Image Hijack

If you read our second lesson about Process Explorer, you would have learned that you can replace Task Manager with Process Explorer, but you probably had no idea how this actually happens, much less that malware can and does use the same technique to hijack applications on your computer.

You can  set a number of  settings in the registry that control how  things are loaded, including hijacking all executables and running them through another process, or even assigning a “debugger” to any executable — even if that application is not a debugger.

Essentially, you can assign values in the registry so that if you try to load notepad.exe, it will load calc.exe instead. Or any application can be swapped out and replaced with another application. This is one of the ways that malware blocks you from loading MalwareBytes or other anti-malware tools.



You can see it for yourself — on the left-hand side is the name of the executable, and on the right-hand side the “Debugger” key is set to the instance of Process Explorer that is running off my desktop. But you can change that to anything you want on either side and it will work. It would probably make a great prank that almost nobody would ever be able to figure out.



If you see anything in the Image Hijacks tab other than the values for Process Explorer, you should immediately disable them.

Please enlighten me on what I'm missing.
« Last Edit: August 18, 2015, 09:19:00 PM by ehmen »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Important Autoruns question: IE Image Hijack!
« Reply #14 on: August 18, 2015, 06:49:44 PM »
The original screenshot tells you that IE will be the programme to open html files... as expected