How To Analyze HijackThis Logs
Here is an overview of the HijackThis log entries which give you an idea of what component is involved:
# F0, F1 – Autoloading programs
# N1, N2, N3, N4 – Netscape/Mozilla Start/Search pages URLs
# O1 – Hosts file redirection
# O10 – Winsock hijacker
# O11 – Extra group in IE ‘Advanced Options’ window
# O12 – IE plugins
# O13 – IE DefaultPrefix hijack
# O14 – ‘Reset Web Settings’ hijack
# O15 – Unwanted site in Trusted Zone
# O16 – ActiveX Objects (aka Downloaded Program Files)
# O17 – Lop.com domain hijackers
# O18 – Extra protocols and protocol hijackers
# O19 – User style sheet hijack
# O2 – Browser Helper Objects
# O20 – AppInit_DLLs Registry value autorun
# O21 – ShellServiceObjectDelayLoad Registry key autorun
# O22 – SharedTaskScheduler Registry key autorun
# O23 – Windows NT Services
# O3 – Internet Explorer toolbars
# O4 – Autoloading programs from Registry
# O5 – IE Options icon not visible in Control Panel
# O6 – IE Options access restricted by Administrator
# O7 – Regedit access restricted by Administrator
# O8 – Extra items in IE right-click menu
# O9 – Extra buttons on main IE button toolbar, or extra items in IE ‘Tools’ menu
# R0, R1, R2, R3 – Internet Explorer Start/Search pages URLs
Leave a Reply
You must be logged in to post a comment.