Section Name Description R0, R1, R2, R3 Internet Explorer Start/Search pages URLs F0, F1, F2,F3 Auto loading programs N1, N2, N3, N4 Netscape/Mozilla Start/Search pages URLs O1 Hosts file redirection O2 When you have selected all the processes you would like to terminate you would then press the Kill Process button. O18 Section This section corresponds to extra protocols and protocol hijackers. If you do not recognize the web site that either R0 and R1 are pointing to, and you want to change it, then you can have HijackThis safely fix these, as

I did update my windows to SP3.. The name of the Registry value is user32.dll and its data is C:\Program Files\Video ActiveX Access\iesmn.exe. R0,R1,R2,R3 Sections This section covers the Internet Explorer Start Page, Home Page, and Url Search Hooks. scan completed successfully hidden files: 0 ************************************************************************** .

F3 entries are displayed when there is a value that is not whitelisted in the registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows under the values load and run. If you see these you can have HijackThis fix it.

Figure 3. Hijackthis Windows 7 If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members. As of now there are no known malware that causes this, but we may see differently now that HJT is enumerating this key. When you are done, press the Back button next to the Remove selected until you are at the main HijackThis screen.

Internet Explorer Plugins are pieces of software that get loaded when Internet Explorer starts to add functionality to the browser.

This continues on for each protocol and security zone setting combination. There is one known site that does change these settings, and that is Lop.com which is discussed here. Site to use for research on these entries: Bleeping Computer Startup Database Answers that work Greatis Startup Application Database Pacman's Startup Programs List Pacman's Startup Lists for Offline Reading Kephyr File

You should now see a new screen with one of the buttons being Open Process Manager. In order to avoid the deletion of your backups, please save the executable to a specific folder before running it.

Under the Policies\Explorer\Run key are a series of values, which have a program name as their data.

There are times that the file may be in use even if Internet Explorer is shut down.

How to use the Process Manager HijackThis has a built in process manager that can be used to end processes as well as see what DLLs are loaded in that process. These files can not be seen or deleted using normal methods.

As long as you hold down the control button while selecting the additional processes, you will be able to select multiple processes at one time. How to use the Uninstall Manager The Uninstall Manager allows you to manage the entries found in your control panel's Add/Remove Programs list.

HijackThis Configuration Options When you are done setting these options, press the back key and continue with the rest of the tutorial. A F0 entry corresponds to the Shell= statement, under the [Boot] section, of the System.ini file. As I say so many times, anything YOU might be experiencing has probably been experienced by someone else before you. You will now be presented with a screen similar to the one below: Figure 13: HijackThis Uninstall Manager To delete an entry simply click on the entry you would like

For F1 entries you should google the entries found here to determine if they are legitimate programs. The Global Startup and Startup entries work a little differently. If they are given a *=2 value, then that domain will be added to the Trusted Sites zone. There is a security zone called the Trusted Zone.

To delete a line in your hosts file you would click on a line like the one designated by the blue arrow in Figure 10 above. Figure 7. Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersio Log in or Sign up Computer Forum Home Forums > Computer Software > Computer Security > HiJackThis Log (Plz look over) Discussion in 'Computer Security' started by They rarely get hijacked, only Lop.com has been known to do this.

Adding an IP address works a bit differently. When you press Save button a notepad will open with the contents of that file. With this manager you can view your hosts file and delete lines in the file or toggle lines on or off. When a user, or all users, logs on to the computer each of the values under the Run key is executed and the corresponding programs are launched.

Pacman's Startup List can help with identifying an item.N1, N2, N3, N4 - Netscape/Mozilla Start & Search pageWhat it looks like:N1 - Netscape 4: user_pref "browser.startup.homepage", "www.google.com"); (C:\Program Files\Netscape\Users\default\prefs.js)N2 - Netscape