Internet / Network Security

  1. Home
  2. Computing & Technology
  3. Internet / Network Security

How To Analyze HijackThis Logs

Interpreting Log Data To Help Remove Spyware and Browser Hijackers

From Tony Bradley, CISSP-ISSAP, for About.com

May 23 2008

O5 - IE Options not visible in Control Panel


What it looks like:
O5 - control.ini: inetcpl.cpl=no

What to do:
Unless you or your system administrator have knowingly hidden the icon from Control Panel, have HijackThis fix it.

O6 - IE Options access restricted by Administrator


What it looks like:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present

What to do:
Unless you have the Spybot S&D option 'Lock homepage from changes' active, or your system administrator put this into place, have HijackThis fix this.

O7 - Regedit access restricted by Administrator


What it looks like:
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

What to do:
Always have HijackThis fix this, unless your system administrator has put this restriction into place.

O8 - Extra items in IE right-click menu

What it looks like:
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\DOWNLOADED PROGRAM FILES\GOOGLETOOLBAR_EN_1.1.68-DELEON.DLL/cmsearch.html
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Zoom &In - C:\WINDOWS\WEB\zoomin.htm
O8 - Extra context menu item: Zoom O&ut - C:\WINDOWS\WEB\zoomout.htm

What to do:
If you don't recognize the name of the item in the right-click menu in IE, have HijackThis fix it.

O9 - Extra buttons on main IE toolbar, or extra items in IE 'Tools' menu


What it looks like:
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: AIM (HKLM)

What to do:
If you don't recognize the name of the button or menuitem, have HijackThis fix it.

O10 - Winsock hijackers


What it looks like:
O10 - Hijacked Internet access by New.Net
O10 - Broken Internet access because of LSP provider 'c:\progra~1\common~2\toolbar\cnmib.dll' missing
O10 - Unknown file in Winsock LSP: c:\program files\newton knows\vmain.dll

What to do:
It's best to fix these using LSPFix from Cexx.org, or Spybot S&D from Kolla.de.

Note that 'unknown' files in the LSP stack will not be fixed by HijackThis, for safety issues.

O11 - Extra group in IE 'Advanced Options' window


What it looks like:
O11 - Options group: [CommonName] CommonName

What to do:
The only hijacker as of now that adds its own options group to the IE Advanced Options window is CommonName. So you can always have HijackThis fix this.

O12 - IE plugins


What it looks like:
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll

What to do:
Most of the time these are safe. Only OnFlow adds a plugin here that you don't want (.ofb).

O13 - IE DefaultPrefix hijack


What it looks like:
O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=
O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?
O13 - WWW. Prefix: http://ehttp.cc/?

What to do:
These are always bad. Have HijackThis fix them.

O14 - 'Reset Web Settings' hijack


What it looks like:
O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.com

What to do:
If the URL is not the provider of your computer or your ISP, have HijackThis fix it.

O15 - Unwanted sites in Trusted Zone

What it looks like:
O15 - Trusted Zone: http://free.aol.com
O15 - Trusted Zone: *.coolwebsearch.com
O15 - Trusted Zone: *.msn.com

What to do:
Most of the time only AOL and Coolwebsearch silently add sites to the Trusted Zone. If you didn't add the listed domain to the Trusted Zone yourself, have HijackThis fix it.

O16 - ActiveX Objects (aka Downloaded Program Files)


What it looks like:
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

What to do:
If you don't recognize the name of the object, or the URL it was downloaded from, have HijackThis fix it. If the name or URL contains words like 'dialer', 'casino', 'free_plugin' etc, definitely fix it. Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.)

Explore Internet / Network Security

About.com Special Features

Internet / Network Security

  1. Home
  2. Computing & Technology
  3. Internet / Network Security
  4. Pop-Ups and Spyware
  5. How To Analyze HijackThis Logs

©2009 About.com, a part of The New York Times Company.

All rights reserved.