Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\: DatabasePath If you see entries like the above example, and they are not their for a specific reason that you know about, you can safely remove them. When you fix these types of entries, HijackThis will not delete the offending file listed. When using the standalone version you should not run it from your Temporary Internet Files folder as your backup folder will not be saved after you close the program.

C:\Users\Brenda\Downloads\ZipExtractorSetup(1).exe => Moved successfully.

A common use is to post the logfile to a forum where more experienced users can help decipher which entries need to be removed. Some Registry Keys: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page HKCU\Software\Microsoft\Internet Explorer\Main: Start Page HKLM\Software\Microsoft\Internet Explorer\Main: Default_Page_URL HKCU\Software\Microsoft\Internet Explorer\Main: Default_Page_URL HKLM\Software\Microsoft\Internet Explorer\Main: Search Page HKCU\Software\Microsoft\Internet Explorer\Main: Search Page HKCU\Software\Microsoft\Internet If you would like to see what sites they are, you can go to the site, and if it's a lot of popups and links, you can almost always delete it.

In order to avoid the deletion of your backups, please save the executable to a specific folder before running it. O13 Section This section corresponds to an IE DefaultPrefix hijack. An example of a legitimate program that you may find here is the Google Toolbar.

Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions Example Listing O11 - Options group: [CommonName] CommonName According to Merijn, of HijackThis, there is only one known Hijacker that uses this and it is CommonName.

  1. Figure 3.
  2. Please be aware that when these entries are fixed HijackThis does not delete the file associated with it.
  3. O18 Section This section corresponds to extra protocols and protocol hijackers.
  4. Run keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Microsoft\Windows\CurrentVersion\Run The RunOnce keys are used to launch a service or background process whenever a user, or all users, logs on to the computer.
  Register a free account to unlock additional features at BleepingComputer.com
  6. The log file should now be opened in your Notepad.

Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} FW: Ad-Aware Firewall *Disabled* {E040E464-58CE-DBB2-2B6C-32B5A979FEED} SP: Ad-Aware Antivirus *Disabled/Outdated* {631A84A5-349B-D564-3A83-A0F22C2DF32B} SP: avast!

This would have a value of http=4 and any future IP addresses added to the restricted sites will be placed in that key. You should have the user reboot into safe mode and manually delete the offending file. As most Windows executables use the user32.dll, that means that any DLL that is listed in the AppInit_DLLs registry key will be loaded also. When examining O4 entries and trying to determine what they are for you should consult one of the following lists: Bleeping Computer Startup Database Answers that work Greatis Startup Application Database

When Internet Explorer is started, these programs will be loaded as well to provide extra functionality. To find a listing of all of the installed ActiveX component's CLSIDs, you can look under the HEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ Windows Registry key.

How to use the Uninstall Manager The Uninstall Manager allows you to manage the entries found in your control panel's Add/Remove Programs list. O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe - This entry corresponds to a program started by the All Users Startup Folder located at C:\Documents and Settings\All Users

How to use the Hosts File Manager HijackThis also has a rudimentary Hosts file manager.

To exit the Hosts file manager you need to click on the back button twice which will place you at the main screen. Scan Results At this point, you will have a listing of all items found by HijackThis. When you reset a setting, it will read that file and change the particular setting to what is stated in the file.

You will then be presented with the main HijackThis screen as seen in Figure 2 below. Site to use for research on these entries: Bleeping Computer Startup Database Answers that work Greatis Startup Application Database Pacman's Startup Programs List Pacman's Startup Lists for Offline Reading Kephyr File Wow6432Node-HKLM-Run-Conime - c:\windows\system32\conime.exe Wow6432Node-HKLM-Run-SunJavaUpdateSched - c:\program files (x86)\Java\jre7\bin\jusched.exe HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre7\bin\jusched.exe AddRemove-Quiknowledge - c:\program files (x86)\Quiknowledge\Uninstall.exe AddRemove-Zip Extractor Packages - c:\users\Brenda\AppData\Roaming\0D0S1L2Z1P1B\Zip Extractor Packages\uninstaller.exe .

When you are done, press the Back button next to the Remove selected until you are at the main HijackThis screen. Starting Screen of Hijack This You should first click on the Config button, which is designated by the blue arrow in Figure 2, and confirm that your settings match those

Introduction HijackThis is a utility that produces a listing of certain settings found in your computer. Figure 4. You can generally delete these entries, but you should consult Google and the sites listed below. R0 is for Internet Explorers starting page and search assistant.