Overview
Each line in a HijackThis log starts with a section name. (For technical information on this, click 'Info' in the main window and scroll down. Highlight a line and click 'More info on this item'.)R0, R1, R2, R3 - IE Start & Search page
What it looks like:R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.google.com/What to do:
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL=http://www.google.com/
R3 - Default URLSearchHook is missing
F0, F1 - Autoloading programs
What it looks like:F0 - system.ini: Shell=Explorer.exe Openme.exeWhat to do:
F1 - win.ini: run=hpfsched
N1, N2, N3, N4 - Netscape/Mozilla Start & Search page
What it looks like:N1 - Netscape 4: user_pref("browser.startup.homepage", "www.google.com"); (C:\Program Files\Netscape\Users\default\prefs.js)What to do:
N2 - Netscape 6: user_pref("browser.startup.homepage", "http://www.google.com"); (C:\Documents and Settings\User\Application Data\Mozilla\Profiles\defaulto9t1tfl.slt\prefs.js)
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%206%5Csearchplugins%5CSBWeb_02.src"); (C:\Documents and Settings\User\Application Data\Mozilla\Profiles\defaulto9t1tfl.slt\prefs.js)
O1 - Hostsfile redirection
What it looks like:O1 - Hosts: 216.177.73.139 auto.search.msn.comWhat to do:
O1 - Hosts: 216.177.73.139 search.netscape.com
O1 - Hosts: 216.177.73.139 ieautosearch
O2 - Browser Helper Objects
What it looks like:O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLWhat to do:
O2 - BHO: (no name) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C:\PROGRAM FILES\POPUP ELIMINATOR\AUTODISPLAY401.DLL (file missing)
O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLL
O3 - IE toolbars
What it looks like:O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLWhat to do:
O3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)
O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL
O4 - Autoloading programs from Registry
What it looks like:O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorunWhat to do:
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O5 - IE Options not visible in Control Panel
What it looks like:O5 - control.ini: inetcpl.cpl=noWhat to do:
O6 - IE Options access restricted by Administrator
What it looks like:O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions presentWhat to do:
O7 - Regedit access restricted by Administrator
What it looks like:O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1What to do:
O8 - Extra items in IE right-click menu
What it looks like:O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.68-DELEON.DLL/cmsearch.htmlWhat to do:
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm
O9 - Extra buttons on main IE toolbar, or extra items in IE 'Tools' menu
What it looks like:O9 - Extra button: Messenger (HKLM)What to do:
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O10 - Winsock hijackers
What it looks like:O10 - Hijacked Internet access by New.NetWhat to do:
O10 - Broken Internet access because of LSP provider 'c:\progra~1\common~2\toolbar\cnmib.dll' missing
O10 - Unknown file in Winsock LSP: c:\program files\newton knows\vmain.dll
O11 - Extra group in IE 'Advanced Options' window
What it looks like:O11 - Options group: [CommonName] CommonNameWhat to do:
O12 - IE plugins
What it looks like:O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllWhat to do:
O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O13 - IE DefaultPrefix hijack
What it looks like:O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=What to do:
O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?
O14 - 'Reset Web Settings' hijack
What it looks like:O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comWhat to do:
O15 - Unwanted site in Trusted Zone
What it looks like:O15 - Trusted Zone: http://free.aol.comWhat to do:
O16 - ActiveX Objects (aka Downloaded Program Files)
What it looks like:O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cabWhat to do:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - Lop.com domain hijacks
What it looks like:O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.netWhat to do:
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = W21944.find-quick.com
O17 - HKLM\Software\..\Telephony: DomainName = W21944.find-quick.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{D196AB38-4D1F-45C1-9108-46D367F19F7E}: Domain = W21944.find-quick.com
O18 - Extra protocols and protocol hijackers
What it looks like:O18 - Protocol: relatedlinks - {5AB65DD4-01FB-44D5-9537-3767AB80F790} - C:\PROGRA~1\COMMON~1\MSIETS\msielink.dllWhat to do:
O18 - Protocol: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82}
O18 - Protocol hijack: http - {66993893-61B8-47DC-B10D-21E0C86DD9C8}
O19 - User style sheet hijack
What it looks like:O19 - User style sheet: c:\WINDOWS\Java\my.cssWhat to do:
If something in your log still puzzles you after this short tutorial, there is nothing stopping you from posting at the SpywareInfo forums.
Merijn