O11 Section This section corresponds to a non-default option group that has been added to the Advanced Options Tab in Internet Options on IE. Example Listing O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPix ActiveX Control) - http://www.ipix.com/download/ipixx.cab If you see names or addresses that you do not recognize, you should Google them to see if they are

O7 Section This section corresponds to Regedit not being allowed to run by changing an entry in the registry.

There are certain R3 entries that end with a underscore ( _ ) . It is also possible to list other programs that will launch as Windows loads in the same Shell = line, such as Shell=explorer.exe badprogram.exe. When you see the file, double click on it. Registry Key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\: User Stylesheets Example Listing O19 - User style sheet: c:\WINDOWS\Java\my.css You can generally remove these unless you have actually set up a style sheet for your use.

Introduction HijackThis is a utility that produces a listing of certain settings found in your computer. You can also download the program HostsXpert which gives you the ability to restore the default host file back onto your machine.

If you would like to learn more detailed information about what exactly each section in a scan log means, then continue reading. If you see web sites listed in here that you have not set, you can use HijackThis to fix it.

If you know that this is a program you use, then it's OK. Registry Key: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt Example Listing O8 - Extra context menu item: &Google Search - res://c:\windows\GoogleToolbar1.dll/cmsearch.html Each O8 entry will be a menu option that is shown when you right-click on This tutorial, in addition, to showing how to use HijackThis, will also go into detail about each of the sections and what they actually mean.

Additional Details + - Last Updated 2016-10-08 Registered 2011-12-29 Maintainers merces License GNU General Public License version 2.0 (GPLv2) Categories Anti-Malware User Interface Win32 (MS Windows) Intended Audience Advanced End Users, These entries are the Windows NT equivalent of those found in the F1 entries as described above. How To Use Hijackthis

There are times that the file may be in use even if Internet Explorer is shut down. It should be noted that the Userinit and the Shell F2 entries will not show in HijackThis unless there is a non-whitelisted value listed.

While that key is pressed, click once on each process that you want to be terminated. If an entry starts with a long series of numbers and contains a username surrounded by parenthesis at the end, then this is a O4 entry for a user logged on They can be used by spyware as well as legitimate programs such as Google Toolbar and Adobe Acrobat Reader. Table of Contents Warning Introduction How to use HijackThis How to restore items mistakenly deleted How to Generate a Startup Listing How to use the Process Manager How to use the

Registry Keys: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects Example Listing O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Antivirus\NavShExt.dll There is an excellent list of known CSLIDs associated with Browser Helper Objects

Browser helper objects are plugins to your browser that extend the functionality of it.

Many users understandably like to have a clean Add/Remove Programs list and have difficulty removing these errant entries. If it finds any, it will display them similar to figure 12 below. You must manually delete these files. Autoruns Bleeping Computer When you fix O16 entries, HijackThis will attempt to delete them from your hard drive.

Interpreting these results can be tricky as there are many legitimate programs that are installed in your operating system in a similar manner that Hijackers get installed. If you have run any malware removal software (Ad-aware, AVG Antispyware, SuperAntiSpyware…), please reboot before scanning. 1. There are many legitimate plugins available such as PDF viewing and non-standard image viewers. To disable this white list you can start hijackthis in this method instead: hijackthis.exe /ihatewhitelists.

When you fix these types of entries, HijackThis will not delete the offending file listed. Loading... Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\: DatabasePath If you see entries like the above example, and they are not their for a specific reason that you know about, you can safely remove them. Figure 2.

The Run keys are used to launch a program automatically when a user, or all users, logs on to the machine. Unless you recognize the software being used as the UrlSearchHook, you should generally Google it and after doing some research, allow HijackThis to fix it F0, F1, F2, F3 Sections