-
-
Notifications
You must be signed in to change notification settings - Fork 124
HJT: Tutorial
- Updated tutorial (Russian only)
- Additions (Russian only)
- Outdated tutorial on English (for original HJT v2.0.5)
- Outdated tutorial on French (for original HJT v2.0.5)
- Outdated tutorial on German (for original HJT v2.0.5)
- Outdated tutorial on Spanish (for original HJT v2.0.5)
- Outdated tutorial on Portuguese (for original HJT v2.0.5)
- Outdated tutorial on Dutch (for original HJT v2.0.5)
Note. 1: This tutorial is updated to use with HiJackThis Fork v.2.8.0.50 and newer.
Note. 2: Look full tutorial by links above.
Note. 3: This description available on English, Russian and Ukrainian within HiJackThis menu -> Help -> Users' manual -> Sections' description.
The different sections of hijacking influences have been separated into the following groups:
- R - Changes in basic Internet Explorer settings:
- R0 - Changed registry value
- R1 - Created registry value
- R2 - Created registry key
- R3 - Created extra registry parameter where only one should be
- R4 - Search providers (SearchScopes)
- F - Autoloading from INI-files and corresponding registry locations
- F0 - Changed ini-file value (system.ini)
- F1 - Created ini-file parameter (win.ini)
- F2 - Changed registry value that is override ini-file settings (shell, userinit)
- F3 - Created registry parameter that is override ini-file settings (load, run)
- O - Other sections:
- O1 - Hijack of Hosts and hosts.ics files / DNSApi hijacking
- O2 - Internet Explorer: BHO
- O3 - Internet Explorer: toolbars
- O4 - Autoloading Registry entries and 'Autostart' folder / msconfig disabled items
- O5 - Hiding of Control Panel items
- O6 - IE Policy: Disabling of 'Internet Options' main tab
- O7 - Policies: Regedit, Explorer, TaskMgr / IP Security / Certificates / OS troubleshoot
- O8 - Internet Explorer: Extra context menu items
- O9 - Internet Explorer: Extra services and buttons
- O10 - Breaking of Internet access due to the damage or infection in Winsock LSP
- O11 - Internet Explorer: options in 'Advanced' settings tab
- O12 - Internet Explorer: plugins for file extensions or MIME types
- O13 - Internet Explorer: Hijacking of URL prefixes
- O14 - Internet Explorer: Changing of IERESET.INF
- O15 - Internet Explorer: Web-sites and protocols in 'Trusted Zone'
- O16 - Downloaded Program Files items (DPF)
- O17 - Domain and DNS hijack / DNS issued by router through DHCP
- O18 - Protocols and filters hijack
- O19 - User stylesheet hijack
- O20 - AppInit_DLLs, Winlogon Notify
- O21 - Shell Service Object Delay Load (SSODL), Shell Icon Overlay (SIOI), ShellExecuteHooks (SEH)
- O22 - Shared Task Scheduler jobs
- O23 - Windows Services and Drivers, Dependencies
- O24 - ActiveX Desktop Components
- O25 - WMI permanent event consumers
- O26 - Image File Execution Options (IFEO)
R0 - Changed registry value
A registry value that has been changed from the default, resulting in a changed IE Home page, Search Page, Search Bar Address or Search Assistant.
Action taken by HiJackThis:
- registry value is restored to preset URL.
R1 - Created registry value
A registry value that has been created and is not present in a default Windows install nor needed, possibly resulting in a changed characteristics related to Internet search and other (IE Window Title, ProxyServer, ProxyOverride, Internet Connection Wizard, ShellNext etc.)
Action taken by HiJackThis:
- Registry value is deleted.
R2 - Created registry key
A registry key that has been created and is not present in a default Windows install nor needed. Currently, this section is not used (no database entries).
Action taken by HiJackThis:
- Registry key is deleted, with everything in it.
R3 - Created extra registry parameter where only one should be
Detected more than one value inside URLSearchHooks regkey. If you specify URL address without http://, ftp:// prefix, browser will attempt to figure out the correct protocol on its own using the list in UrlSearchHook.
Action taken by HiJackThis:
- Registry value is deleted;
- default URLSearchHook value is restored.
R4 - Search providers (SearchScopes)
Internet Explorer browser uses search provider (DefaultScope) to show list of tips in the search bar when you are typing search query in the address bar. IE allows replacing default provider with any from the list (SearchScopes).
Action taken by HiJackThis:
- key of particular provider is deleted;
- default value of DefaultScope (Microsoft Bing) and provider parameters are recovered.
F0 - Changed ini-file value (system.ini)
An inifile value that has been changed from the default value, possibly resulting in program(s) loading at Windows startup. Often used to autostart a program.
File been checked: C:\Windows\system.ini
Default: Shell=explorer.exe Infected example: Shell=explorer.exe,openme.exe
Action taken by HiJackThis:
- default inifile value is restored;
- corresponding file is NOT deleted.
F1 - Created ini-file parameter (win.ini)
An inifile value that has been created and is not present in a default Windows install nor needed, possibly resulting in program(s) loading at Windows startup. Often used to autostart a program.
File been checked: C:\Windows\win.ini
Default: run= load=
Infected example: run=dialer.exe
Action taken by HiJackThis:
- inifile value is deleted;
- corresponding file is NOT deleted.
F2 - Changed registry value that is override ini-file settings (shell, userinit)
F2 section corresponds to the equivalent location in registry for system.ini file (F0).
A registry value that has been changed from the default value, possibly resulting in program(s) loading at Windows startup. Often used to autostart a program.
To be checked: \Software\Microsoft\Windows NT\CurrentVersion\WinLogon => Shell, UserInit
Default: UserInit=C:\Windows\System32\UserInit.exe, Infected example: UserInit=C:\Windows\System32\UserInit.exe,C:\Windows\apppatch\capejw.exe,
Default values: UserInit=C:\Windows\System32\UserInit.exe, Shell=explorer.exe Shell=%WINDIR%\explorer.exe
Infected examples: UserInit=C:\Windows\System32\UserInit.exe,C:\Windows\apppatch\capejw.exe, Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
Action taken by HiJackThis:
- default registry value is restored;
- corresponding file is NOT deleted.
F3 - Created registry parameter that is override ini-file settings (load, run)
F3 section corresponds to the equivalent location in registry for win.ini file (F1).
A registry value that has been created and is not present in a default Windows install nor needed, possibly resulting in program(s) loading at Windows startup. Often used to autostart a program.
To be checked: \Software\Microsoft\Windows NT\CurrentVersion\Windows => run, load
Default: run= Default: load= Infected example: run=С:\WINDOWS\inet20001\services.exe
Action taken by HiJackThis:
- registry value is deleted;
- corresponding file is NOT deleted.
O1 - Hijack of Hosts and hosts.ics files / DNSApi hijacking
-
Windows uses records in the 'hosts' file to lookup domain names before querying internet DNS servers. Changes to 'hosts' file effectively making Windows believe that e.g. 'google.com' has a different IP than it really has and thus making browser open the wrong page. It also uses to block some site(s) usual antivirus one by redirecting it to localhost or any other incorrect IP.
-
Attacker can also hijack DNSApi.dll file to alter location where the system loads hosts file (all OS versions). Example: Hijacker.DNS.Hosts / Trojan.Win32.Patched.qw.
-
For the same reason attacker can change registry DatabasePath value (Win XP/2003 and older).
-
Hosts.ics file is created automatically when you share internet access. It contains a mapping between IP and home (local) network domain and can be hijacked in the same way as hosts file.
Infected examples: 213.67.109.7 google.com 127.0.0.1 kaspersky.ru DNSApi: File is patched - c:\Windows\system32\dnsapi.dll Hosts file is located at: c:\windows\System32\drivers\etc\hoctc
Legal entry example: Hosts.ics: 192.168.137.1 AnakonDA.mshome.net # 2018 5 2 22 8 3 40 685
Action taken by HiJackThis:
- For hosts and hosts.ics entries - Line is deleted from file.
- For DNSApi - dll file is recovered if available using SFC subsystem.
- For altered hosts location - default registry value is restored.
- Also, DNS cache entries are flushes and DNS caching service will be restarted.
O2 - Internet Explorer: BHO
A BHO (Browser Helper Object) is a specially crafted program that integrates into IE, and has virtually unlimited access rights on your system. Though BHO's can be helpful (like the Google Toolbar), hijackers often use them for malicious purposes such as tracking your online behavior, displaying popup ads etc.
Action taken by HiJackThis:
- BHO registry key and all corresponding keys (like CLSID and special IE BHO policies) are deleted;
- BHO dll file is deleted.
O3 - Internet Explorer: toolbars
IE Toolbars are part of BHO's (Browser Helper Objects) like the Google Toolbar that are helpful, but can also be annoying and malicious by tracking your behavior and displaying popup ads.
Action taken by HiJackThis:
- Registry value and all corresponding keys (like settings and special IE BHO policies) are deleted.
- dll file is deleted.
O4 - Autoloading Registry entries and 'Autostart' folder / msconfig disabled items
This part of the scan checks for several suspicious entries that autoload when Windows starts. Autoloading registry entries may cause loading a script (VBS, JS, HTA file and so on) possibly causing the Start Page, Search Page, Search Bar and Search Assistant to revert back to a hijacker's page. Besides, a DLL file can be loaded that can hook into several parts of your system. Also, script, other program or fileless registry entry (e.g. legit system file PowerShell.exe with arguments) in autostart can be used as a dropper and cause a loading another malicious files via internet, ensure the survival of malware after OS reboot. O4 section also includes listing of autorun disabled items (MSConfig / TaskMgr).
Area to be checked: registry keys and 'Autostart' folder.
Infected example: regedit c:\windows\system\sp.tmp /s
Action taken by HiJackThis:
- in case autostarting registry entries - registry value is deleted.
- also, corresponding process will be killed or freezed.
- in case 'AutoStart' folder - autoloading file is deleted.
- in case disabled autorun items - registry entry is deleted (For Windows 8+: autoloading file is deleted too. For Windows 7 and older: autoloading file left in the folder: C:\Windows\pss).
O5 - Internet Explorer: Blocking of loading Internet Options in Control Panel
Modifying CONTROL.INI can cause Windows to hide certain icons in the Control Panel. Though originally meant to speed up loading of Control Panel and reducing clutter, it can be used by a hijacker to prevent access to the 'Internet Options' window.
Area to be checked: control.ini file and equivalent locations in the registry.
Infected examples: control.ini: [don't load] inetcpl.cpl = yes (Internet Control Panel) HKCU\Control Panel\don't load: [Firewall.cpl] (Windows Firewall Control Panel)
Action taken by HiJackThis:
- depending on location, line is deleted from Control.ini file or registry value is deleted.
O6 - IE Policy: Disabling of 'Internet Options' main tab
Disabling of the 'Internet Options' menu menu entry in the 'Tools' menu of IE is done by using Windows Policies. Normally used by administrators to restrict their users, it can be used by hijackers to prevent access to the 'Internet Options' window.
StartPage Guard also uses Policies to restrict homepage changes, done by hijackers.
Action taken by HiJackThis:
- corresponding information is deleted from the registry.
O7 - Policies: Regedit, Explorer / IP Security settings / Certificates / OS troubleshoot
O7 - Policies: Regedit, TaskMgr, Explorer and "Start" menu
Disabling of Regedit is done by using Windows Policies. Normally used by administrators to restrict their users, it can be used by hijackers to prevent access to the Registry editor. This results in a message saying that your administrator has not given you privilege to use Regedit when running it. Malicious programs also disable access to the Task Manager to protect themselves from termination. Some items may be blocked in Explorer and Start menu, making navigation difficult. For instance, the disc is hidden in "My Computer" folder.
O7 - IPSec
IP Security Policies provides the ability to allow or block network data packets, as well as fine-tune the source and destination packet filter, for instance, IP address (including subnet), type, port number and more.
O7 - Untrusted Certificate
Malicious programs can add antivirus digital signature hashes to the list of untrusted certificates, thereby blocking the launch of executable files.
O7 - TroubleShoot
Here, incorrect OS settings are displayed, which potentially lead to various malfunctions in the software and the system as generally. These include:
- [EV] Incorrect value and/or type of environment variable. Check for important paths in the %PATH% variable.
- [Disk] Lack of free space on the system disk (less than 1 GB.)
- [Network] Wrong network settings, e.g. empty name of computer.
Action taken by HiJackThis:
- for O7 - Policies: registry value is deleted.
- for O7 - IPSec: all registry keys associated with the marked policy are deleted, including all the filters that apply to it.
- for O7 - Untrusted Certificate: registry key is deleted.
- for O7 - TroubleShoot: [EV] variables will be reset to defaults. For %PATH% - the missing path will be added.
- for O7 - TroubleShoot: [Disk] Microsoft disk cleanup manager CleanMgr will be launched in automatically mode.
- for O7 - TroubleShoot: [Network] standard settings will be applied.
O8 - Internet Explorer: Extra context menu items
Extra items in the context (right-click) menu can prove helpful or annoying. Some recent hijackers add an item to the context menu. The Internet Explorer PowerTweaks Web Accessory adds several useful items, among which "Highlight", "Zoom In/Out", "Links list", "Images list" and "Web Search".
Action taken by HiJackThis:
- Registry key is deleted.
O9 - Internet Explorer: Extra services and buttons
Extra items in the Internet Explorer 'Tools' menu and extra buttons in the main toolbar are usually present as branding (Dell Home button) or after system updates (MSN Messenger button) and rarely by hijackers. The Internet Explorer PowerTweaks Web Accessory adds two menu items, being "Add site to Trusted Zone" and "Add site to Restricted Zone".
Action taken by HiJackThis:
- Registry key is deleted.
O10 - Breaking of Internet access due to the damage or infection in Winsock LSP
The Windows Socket system (Winsock) uses a list of providers for resolving DNS names (i.e. translating www.microsoft.com into an IP address). This is called the Layered Service Provider (LSP). A few programs are capable of injecting their own (spyware) providers in the LSP. If files referenced by the LSP are missing or the 'chain' of providers is broken, none of the programs on your system can access the Internet. Removing references to missing files and repairing the chain will restore your Internet access.
Note: LSP fixing is a risky procedure. You can get WinSockReset from https://www.foolishit.com/vb6-projects/winsockreset/ to repair the Winsock stack.
Action taken by HiJackThis:
- Not provided. You will be asked to go to www.foolishit.com for downloading the WinSockReset program.
O11 - Internet Explorer: options in 'Advanced' settings tab
The options in the 'Advanced' tab of Internet Explorer options are stored in the Registry, and extra options can be added easily by creating extra Registry keys. Very rarely, spyware/hijackers add their own options there which are hard to remove. E.g. CommonName adds a section 'CommonName' with a few options.
Action taken by HiJackThis:
- Registry key is deleted.
O12 - Internet Explorer: plugins for file extensions or MIME types
Plugins handle file types that aren't supported natively by Internet Explorer. Common plugins handle Macromedia Flash, Acrobat PDF documents and Windows Media formats, enabling the browser to open these itself instead of launching a separate program. When hijackers or spyware add plugins for their file types, the danger exists that they get reinstalled if everything except the plugin has been removed, and the browser opens such a file.
Action taken by HiJackThis:
- Registry key and plugin file are deleted.
O13 - Internet Explorer: Hijacking of URL prefixes
When you type an URL into Internet Explorer's Address bar without the prefix (http://), it is automatically added when you hit Enter. This prefix is stored in the Registry, together with the default prefixes for FTP, Gopher and a few other protocols. When a hijacker changes these to the URL of his server, you always get redirected there when you forget to type the prefix. Prolivation uses this hijack.
Action taken by HiJackThis:
- Registry value is restored to default data.
O14 - Internet Explorer: Changing of IERESET.INF
When you hit 'Reset Web Settings' on the 'Programs' tab of the Internet Explorer Options dialog, your homepage, search page and a few other sites get reset to their defaults. These defaults are stored in C:\Windows\Inf\Iereset.inf. When a hijacker changes these to his own URLs, you get (re)infected rather than cured when you click 'Reset Web Settings'. SearchALot uses this hijack.
Action taken by HiJackThis:
- Value in the Inf file is restored to default data.
O15 - Internet Explorer: Web-sites and protocols in 'Trusted Zone'
Websites in the Trusted Zone (see Tools => Internet Options => Security => Trusted sites => Sites) are allowed to use normally dangerous scripts and ActiveX objects normal sites aren't allowed to use. Some programs will automatically add a site to the Trusted Zone without you knowing. Only a very few legitimate programs are known to do this. A lot of browser hijackers add sites with ActiveX content to them.
Action taken by HiJackThis:
- Registry key is deleted.
- Protocol to Zone mapping defaults is restored.
O16 - Downloaded Program Files items (DPF)
The Download Program Files (DPF) folder in your Windows base folder holds various types of programs that were downloaded from the Internet. These programs are loaded whenever Internet Explorer is active. Legitimate examples are the Java VM, Microsoft XML Parser and the Google Toolbar. When deleted, these objects are downloaded and installed again (after prompting). Unfortunately, due to the lack security of IE, it lets malicious sites automatically download porn dialers, bogus plugins, ActiveX Objects etc to this folder, which haunt you with popups, huge phone bills, random crashes, browser hijackings and whatnot.
Action taken by HiJackThis:
- registration of DPF CLSID is cancelled.
- dll file and downloaded file are deleted.
O17 - Domain and DNS hijack / DNS issued by router through DHCP
Windows uses several registry values as a help to resolve domain names into IP addresses. Hijacking these values can cause all programs that use the Internet to be redirected to other pages. Lop.com use this method, together with a (huge) list of cryptic domains.
DHCP DNS in this section displays the DNS address issued by the router by DHCP, i.e. when the "Automatically receive DNS address" checkbox is selected in the network connection settings.
Action taken by HiJackThis:
- Registry value is deleted.
- When fixing DHCP DNS, DNS Resolver Cache is flushed. The user must configure the router himself by entering the address specified in the contract with the provider before fixing this item in HiJackThis.
O18 - Protocols and filters hijack
A protocol is a 'language' Windows uses to 'talk' to programs, servers or itself. Webservers use the 'http:' protocol, FTP servers use the 'ftp:' protocol, Windows Explorer uses the 'file:' protocol. Introducing a new protocol to Windows or changing an existing one can burrow deep into how Windows handles files. CommonName and Lop.com both register a new protocol when installed (cn: and ayb:).
The filters are content types accepted by Internet Explorer (and internally by Windows). If a filter exists for a content type, it passes through the file handling that content type first. Several variants of the CWS trojan add a text/html and text/plain filters, allowing them to hook all of the webpage content passed through Internet Explorer.
Action taken by HiJackThis:
- Registry key and file are deleted.
O19 - User stylesheet hijack
IE has an option to use a user-defined stylesheet for all pages instead of the default one, to enable handicapped users to better view the pages. An especially vile hijacking method made by Datanotary has surfaced, which overwrites any stylesheet the user has setup and replaces it with one that causes popups, as well a system slowdown when typing or loading pages with many pictures.
Action taken by HiJackThis:
- Registry value is deleted.
- Style using is disabled.
O20 - AppInit_DLLs, Winlogon Notify
Files specified in the AppInit_DLLs Registry value are loaded very early in Windows startup and stay in memory until system shutdown. This way of loading a .dll is hardly ever used, except by trojans. Examples of legitimate records here can be libraries of video drivers and cryptographic systems. AppInit_DLLs will not load if Secure Boot is enabled. The WinLogon Notify Registry subkeys load dll files into memory at about the same point in the boot process, keeping them loaded into memory until the session ends. Apart from several Windows system components, the adware like VX2, ABetterInternet and Look2Me use this Registry key.
Since both methods ensure the dll file stays loaded in memory the entire time, fixing this won't help if the dll puts back the Registry value or key immediately. In such cases, the use of the 'Delete file on reboot' function or KillBox is recommended to first delete the file.
Action taken by HiJackThis:
- for AppInit_DLLs: Concrete registry value is cleared; parameter is NOT deleted.
- for Winlogon Notify: Registry key is deleted.
O21 - Shell Service Object Delay Load (SSODL) and Shell Icon Overlay (SIOI)
Registry key that contains a list of references to CLSIDs, which in turn reference .dll files that are then loaded by Explorer.exe to its address space at system startup. The dll files stay in memory until Explorer.exe quits, which is achieved either by shutting down the system or killing the shell process.
ShellIconOverlayIdentifiers - works similarly. This registry key contains several subkeys with identifiers referring to the files that are loaded to Explorer.exe. Usually, one program registers several such handlers at once. Name of the key often starts with a few spaces. These libraries are responsible for selecting the type of drawing the file icon in Windows Explorer, depending on certain conditions (the name of this file or other factors). An example of a legitimate program can be a client for cloud storage of Yandex.Disk, which changes the appearance of the icon depending on the state of file synchronization. The malicious program that installed the handler can execute any arbitrary code via dll.
Action taken by HiJackThis:
- Registry value or key is deleted together with CLSID identifier key.
- dll file is deleted.
- Explorer is restarted.
O22 - Shared Task Scheduler jobs
Task Scheduler is a service that can be configured to run an arbitrary process at a specified time or at a certain periodicity. One such setting is called a Job. Job (task) can be run with elevated privileges without requesting UAC, be bound to a specific user, contain the path to the process, arguments, state, and so on. Malware often uses tasks to provide autorun and survive after the process is restarted. Tasks can be managed through the Task Scheduler snap-in (taskschd.msc).
Action taken by HiJackThis:
- The task is disabled.
- Tasks' process is killed.
- The task file, executable file and all associated registry keys are deleted.
O23 - Windows Services
O23 - Service
The 'Services' are a special type of programs that are essential to the system and are required for proper functioning of the system. Service processes are started before the user logs in and are protected by Windows. They can only be stopped from the services dialog in the Administrative Tools window. Malware that registers itself as a service is subsequently also harder to kill.
O23 - Driver (the subsection is only available in the "Additional scan" mode)
The driver is a kind of service that is launched at an earlier stage of the system boot and runs with kernel privileges. Malicious programs can also install their drivers. For instance, this is used to prevent the deletion (programs running with Administrator or Local System rights can not kill kernel-level processes), as well as to mask their presence, files and processes (so-called rootkits). Note: the "Driver R" items without a digit character in log - is a dynamically loaded driver (not through the registry).
O23 - Dependency (the subsection is only available in the "Additional scan" mode)
Malicious programs can write themselves into the list of dependencies of the system service to protect themselves from deletion. After removing such a service, a legitimate Microsoft service will no longer be able to start. Some Windows services are critical for the normal operation of OS. Their non-launching can negatively affect the operation of other programs up to the whole OS boot fails. Some services are also combined into a service group, which has its name. If the service depends on the service group, it will not start until all services that belong to service group is start. HiJackThis also checks for third-party services that have been included in the Microsoft service group.
Action taken by HiJackThis:
- Service (or driver) is disabled, stopped and removed.
- Reboot will be prompted.
- For O23 - Dependency: the dependency will be deleted from the registry.
O24 - ActiveX Desktop Components
Desktop Components are ActiveX objects that can be made part of the desktop whenever Active Desktop is enabled. It runs as a (small) website widget. Malware misuses this feature by setting the desktop background to a local HTML file with a large, bogus warning, e.g. for Ransomware it's a text of ransom requirements.
Action taken by HiJackThis:
- Registry key and file are deleted.
- Explorer is restarted and desktop background is being updated.
O25 - WMI permanent event consumers
Windows Management Instrumentation is a default Windows service. It can be used to create permanent event consumer for both legitimate and malicious purposes. These events can collect hardware and software data to automate malware activities like spying. They can create a pipe to connect between machines, execute external script file or script code stored inside (fileless). Events can be triggered by WMI subsystem at intervals of time (like Task Scheduler) or manually when some application executes a special query to WMI.
Note: only the consumer is tested. If there are only a filter, binding and/or a timer (without consumer), the item is not displayed in the log.
Action taken by HiJackThis:
- event consumer, filter, timer and binding are deleted in WMI database;
- associated file is also deleted.
O26 - Image File Execution Options (IFEO)
In the 'Image File Execution' Registry key, a program can be setup to be used together with a debugger. Whenever the host program is started, the 'debugger' program is loaded instead. Note: when a debugger file deleted but still set, the host program will not start!
Action taken by HiJackThis:
- registry value is deleted.
Have a nice day, your HJT team.