O9 Section This section corresponds to having buttons on main Internet Explorer toolbar or items in the Internet Explorer 'Tools' menu that are not part of the default installation.

Registry Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System Example Listing O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System: DisableRegedit=1 N3 corresponds to Netscape 7' Startup Page and default search page.

RunServicesOnce keys: HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce The RunOnceEx keys are used to launch a program once and then remove itself from the Registry.

Example Listing O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.com Please be aware that it is possible for this setting to have been legitimately changed by a Computer Manufacturer or the Administrator of machine.

Press Submit If you would like to see information about any of the objects listed, you can click once on a listing, and then press the "Info on selected item..." button.

These entries are stored in the prefs.js files stored in different places under the C:\Documents and Settings\YourUserName\Application Data folder. When you fix O4 entries, Hijackthis will not delete the files associated with the entry.

Click the *UserAgent$* button and follow the prompts. You can then click once on a process to select it, and then click on the Kill Process button designated by the red arrow in Figure 9 above.

Service Type: Own Process Path: c:\windows\system32\dllhost.exe /processid:{261ff5d6-55b3-4d28-8348-7dbc93e219f0} State: Stopped Process ID: 0 Started: False Exit Code: 1077 Accept Pause: False Accept Stop: False Check all instances of "calsp.dll and aklsp.dll" (and nothing else), and move them to the "Remove" pane.

How to interpret the scan listings This next section is to help you diagnose the output from a HijackThis scan. Hijackthis Portable If this ... Then you can either delete the line, by clicking on the Delete line(s) button, or toggle the line on or off, by clicking on the Toggle line(s) button.

Figure 12: Listing of found Alternate Data Streams To remove one of the displayed ADS files, simply place a checkmark next to its entry and click on the Remove selected

For a great list of LSP and whether or not they are valid you can visit SystemLookup's LSP List Page. You will have a listing of all the items that you had fixed previously and have the option of restoring them. Click on the button with the red circle and an X in the middle after you enter each file (see the files below). Hijackthis Alternative If they are assigned a *=4 value, that domain will be entered into the Restricted Sites zone.

Use google to see if the files are legitimate. Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL O2 - BHO: You may also... pop over to these guys R0,R1,R2,R3 Sections This section covers the Internet Explorer Start Page, Home Page, and Url Search Hooks.

This would have a value of http=4 and any future IP addresses added to the restricted sites will be placed in that key. As for your question, I have no idea what is going on with those two lines you posted - I don't even know what the lines refer to or even mean. If you would like to see what DLLs are loaded in a selected process, you can put a checkmark in the checkbox labeled Show DLLs, designated by the blue arrow in If you are experiencing problems similar to the one in the example above, you should run CWShredder.

LSPs are a way to chain a piece of software to your Winsock 2 implementation on your computer. CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!! These versions of Windows do not use the system.ini and win.ini files. Please back up the *notify* key by exporting it to a safe location.

O6 Section This section corresponds to an Administrative lock down for changing the options or homepage in Internet explorer by changing certain settings in the registry. Run a Home Web Server Run FullFledged Webapps from Your Home Computer Build Your Personal Wikipedia Remotely Control Your Home Computer Give Your Home Computer a Web Address Optimize Your Laptop The first section will list the processes like before, but now when you click on a particular process, the bottom section will list the DLLs loaded in that process. This tutorial is also available in German.

I do not have Windows Blinds installed. You will now be presented with a screen similar to the one below: Figure 13: HijackThis Uninstall Manager To delete an entry simply click on the entry you would like Spyware and Hijackers can use LSPs to see all traffic being transported over your Internet connection. When cleaning malware from a machine entries in the Add/Remove Programs list invariably get left behind.

You should now see a screen similar to the figure below: Figure 1.