<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>R1, R2, R3 not showing in hijackthis? in Security</title>
<link>http://www.dslreports.com/forum/r10807481</link>
<description></description>
<language>en</language>
<pubDate>Wed, 09 Dec 2009 11:55:46 EDT</pubDate>
<lastBuildDate>Wed, 09 Dec 2009 11:55:46 EDT</lastBuildDate>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10825527</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> :  <BLOCKQUOTE><SMALL>said by  John2g <A HREF="/useremail/u/448758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>R0,R1,R2,R3 Sections<br><br>This section covers the Internet Explorer Start Page, Home Page, and Url Search Hooks.<br><br>R0 is for Internet Explorers starting page and search assistant.<br><br>R1 is for Internet Explorers Search functions and other characteristics.<br><br>R2 is not used currently. <br><br>R3 is for a Url Search Hook.  An Url Search Hook is used when you type an address in the location field of the browser, but do not include a protocol such as &raquo;<A HREF="http://" ></A> or &raquo;<small>ftp</small>://<A HREF="ftp://"></A> in the address.  When you enter such an address, the browser will attempt to figure out the correct protocol on its own, and if it fails to do so, will use the UrlSearchHook listed in the R3 section to try to find the location you entered.  <br><br>Some Registry Keys: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Start Page  <br>  HKLM\Software\Microsoft\Internet Explorer\Main: Default_Page_URL <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Default_Page_URL <br>  HKLM\Software\Microsoft\Internet Explorer\Main: Search Page <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Search Page <br>  HKCU\Software\Microsoft\Internet Explorer\SearchURL: (Default) <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Window Title <br>  HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: ProxyOverride <br>  HKCU\Software\Microsoft\Internet Connection Wizard: ShellNext <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Search Bar  <br>  HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks <br>  HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =  <br>  HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch <br>  HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant  <br><br>Example Listing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.com/" >www.google.com/</A> <br><br>A common question is what does it mean when the word Obfuscated is next to one of these entries. When something is obfuscated that means that it is being made difficult to perceive or understand. In Spyware terms that means the Spyware or Hijacker is hiding an entry it made by converting the values into some other form that it understands easily, but humans would have trouble recognizing, such as adding entries into the registry in Hexadecimal. This is just another method of hiding its presence and making it difficult to be removed.<br><br>If you do not recognize the web site that either R0 and R1 are pointing to, and you want to change it, then you can have HijackThis safely fix these, as they will not be detrimental to your Internet Explorer install.  If you would like to see what sites they are, you can go to the site, and if it's a lot of popups and links, you can almost always delete it. It is important to note that if an RO/R1 points to a file, and you fix the entry with HijackThis, Hijackthis will not delete that particular file and you will have to do it manually.<br><br>There are certain R3 entries that end with a underscore ( _ ) . An example of what one would look like is:<br><br>R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)<br><br>Notice the CLSID, the numbers between the { }, have a _ at the end of it and they may sometimes difficult to remove with HijackThis. To fix this you will need to delete the particular registry entry manually by going to the following key:<br><br>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks<br><br>Then delete the CLSID entry under it that you would like to remove. Please leave the CLSID , CFBFAE00-17A6-11D0-99CB-00C04FD64497, as it is the valid default one.<br><br>Unless you recognize the software being used as the UrlSearchHook, you should generally Google it and after doing some research, allow HijackThis to fix it<br> <HR></BLOCKQUOTE><br><br> John2g <A HREF="/useremail/u/448758"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> didn't write this...Bleeping Computer did.<br><br>The full article is here and many of you will find it useful and extremely well written in layman's terms, however, if you are going to quote it you should respect their copyright ;)<br><br><B><br>Welcome to the BleepingComputer.com Tutorial Center<br><br>HijackThis Tutorial<br>How to use HijackThis to remove Browser Hijackers & Spyware</B><br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/index.php?showtutorial=42" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;orial=42</A><br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR> Created: 03/25/2004<br><br>This article is published and created for &raquo;<A HREF="http://www.bleepingcomputer.com" >www.bleepingcomputer.com</A>, otherwise known as Bleeping Computer, and is covered by all copyright laws. All articles on this website are copyright ©  2004 by Bleeping Computer, LLC. All right reserved. Use of these articles is limited to viewing and printing for personal use only. If you would like to use this material or portions of this material for other purposes you must receive explicit permission from Bleeping Computer before reprinting or redistributing this article in any medium. <HR></BLOCKQUOTE><br><br>Knowing the true author and how much work went into that tutorial, credit should be given where credit is due.<br><br>Bleeping Computers has done an excellent job with all their tutorials and they are frequently updated to stay current<br>&raquo;<A HREF="http://www.bleepingcomputer.com/forums/index.php?s=c57a558e68aa5ba2ea35f61c3824cbd4&act=Tutorials" >www.bleepingcomputer.com/forums/&middot;&middot;&middot;utorials</A><br><SMALL>--<br>It takes a disaster to make a woman out of a female<BR><A HREF="http://forum.gladiator-antivirus.com">Gladiator Security Forum</A><BR>Proud Member of ASAP (Alliance of Security Analysis Professionals) &raquo;<A HREF="http://www.a-sap.org/" >www.a-sap.org/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10825527</guid>
<pubDate>Tue, 20 Jul 2004 08:21:09 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10824707</link>
<description><![CDATA[<A HREF="/useremail/u/673579"><b>DSLfanpal</b></A> : OK, This is my hijackthis log. Please advice. Will the Rx not showing up if I set my homepage to blank?<br><br>Logfile of HijackThis v1.98.0<br>Scan saved at 2:44:21 PM, on 20/7/2004<br>Platform: Windows XP  (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 (6.00.2600.0000)<br><br>Running processes:<br>C:\WINDOWS\System32\smss.exe<br>C:\WINDOWS\system32\winlogon.exe<br>C:\WINDOWS\system32\services.exe<br>C:\WINDOWS\system32\lsass.exe<br>C:\WINDOWS\system32\svchost.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\WINDOWS\system32\LEXBCES.EXE<br>C:\WINDOWS\system32\LEXPPS.EXE<br>C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe<br>C:\WINDOWS\System32\Fast.exe<br>C:\Program Files\Norton AntiVirus\navapsvc.exe<br>C:\Program Files\Norton Internet Security\NISUM.EXE<br>C:\WINDOWS\system32\pctspk.exe<br>C:\WINDOWS\System32\svchost.exe<br>C:\Program Files\Norton Internet Security\SymProxySvc.exe<br>C:\WINDOWS\System32\WFXSVC.EXE<br>C:\Program Files\Norton Internet Security\NISSERV.EXE<br>C:\WINDOWS\Explorer.EXE<br>C:\WINDOWS\System32\wfxsnt40.exe<br>C:\Program Files\Cerience\RepliGo\RepliGoMon.exe<br>C:\Program Files\Babylon\Babylon.exe<br>C:\PROGRA~1\NORTON~2\navapw32.exe<br>C:\Program Files\Norton Internet Security\IAMAPP.EXE<br>C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe<br>C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe<br>C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe<br>C:\Program Files\Messenger Plus! 3\MsgPlus.exe<br>C:\WINDOWS\System32\ctfmon.exe<br>C:\Program Files\Norton CleanSweep\csinsmnt.exe<br>C:\WINDOWS\system32\ntvdm.exe<br>C:\Program Files\Palm\HOTSYNC.EXE<br>C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe<br>C:\WINDOWS\system32\spoolsv.exe<br>C:\Program Files\MYIE2\MyIE.exe<br>C:\Program Files\MSN Messenger\msnmsgr.exe<br>C:\Download\HijackThis.exe<br><br>O2 - BHO: DAPBHO Class - {0096CC0A-623C-4829-AD9C-19AF0DC9D8FE} - C:\Program Files\DAP\DAPIEBar.dll<br>O2 - BHO: FlpLauncher Class - {4401FDC3-7996-4774-8D2B-C1AE9CD6CC25} - C:\PROGRA~1\E-BOOK~1\FLIPAL~1\FpLaunch.DLL<br>O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll<br>O2 - BHO: RepliGoIEHelperCtl Class - {91DE4477-9CDC-4806-9BCB-28A963988E94} - C:\Program Files\Cerience\RepliGo\RepliGoIEHelper.dll<br>O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FLASHGET\jccatch.dll<br>O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O3 - Toolbar: (no name) - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - (no file)<br>O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx<br>O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\fgiebar.dll<br>O3 - Toolbar: &RepliGo - {81F4066B-F330-4872-8094-3E9FBCCEC8C1} - C:\Program Files\Cerience\RepliGo\RepliGoIEBar.dll<br>O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll<br>O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32<br>O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC<br>O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName<br>O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe<br>O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe<br>O4 - HKLM\..\Run: [RepliGo Assistant] "C:\Program Files\Cerience\RepliGo\RepliGoMon.exe"<br>O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon.exe -AutoStart<br>O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\navapw32.exe<br>O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE<br>O4 - HKLM\..\Run: [pdfFactory Pro Dispatcher v2] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fppdis2a.exe<br>O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"<br>O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"<br>O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"<br>O4 - HKLM\..\Run: [CountrySelection] pctptt.exe<br>O4 - HKLM\..\Run: [Ad-watch] "C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe"<br>O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe<br>O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe<br>O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE<br>O4 - Global Startup: CleanSweep Smart Sweep-Internet Sweep.LNK = C:\Program Files\Norton CleanSweep\csinsmnt.exe<br>O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe<br>O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm<br>O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm<br>O8 - Extra context menu item: Add to Ad Hunter - C:\Program Files\MYIE2\config/blacklist.htm<br>O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm<br>O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm<br>O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm<br>O8 - Extra context menu item: Get siteinfo data (fsc) - C:\Program Files\EMS Free Surfer Companion\fslauncher.htm<br>O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)<br>O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe<br>O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE<br>O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - &raquo;<A HREF="http://pcpitstop.com/internet/pcpConnCheck.cab" >pcpitstop.com/internet/pcpConnCheck.cab</A><br>O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - &raquo;<A HREF="http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab" >security.symantec.com/sscv6/Shar&middot;&middot;&middot;absa.cab</A><br>O17 - HKLM\System\CCS\Services\Tcpip\..\{10FF0C2A-0D9B-4F6E-85D1-45FFFC93D055}: NameServer = 202.188.0.133 202.188.1.5<br>O17 - HKLM\System\CS1\Services\Tcpip\..\{10FF0C2A-0D9B-4F6E-85D1-45FFFC93D055}: NameServer = 202.188.0.133 202.188.1.5<br>O20 - AppInit_DLLs: apitrap.dll]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10824707</guid>
<pubDate>Tue, 20 Jul 2004 02:47:10 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10816585</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> : Now if you think you actually do have some of those and your hijack log should be displaying them..do me a favor and post the hijack log in your next post and let us take a look at it.<br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> <br>Missing Kids<br>&raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10816585</guid>
<pubDate>Mon, 19 Jul 2004 10:53:25 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10816583</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> :  <BLOCKQUOTE><SMALL>said by  Name Game <A HREF="/useremail/u/655093"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR> <br>i under stood your question..and i think John2g did also. :)   <HR></BLOCKQUOTE><br><br>I did. <br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10816583</guid>
<pubDate>Mon, 19 Jul 2004 10:53:15 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10816556</link>
<description><![CDATA[<A HREF="/useremail/u/655093"><b>Name Game</b></A> :  <BLOCKQUOTE><SMALL>said by  DSLfanpal <A HREF="/useremail/u/673579"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR>No, You misunderstood my question. I know what is R0 to R3. My question is why my scan result has no R1, R2 & R3 but the log starts from O1 onwards. A normal scan will consist log that starts from R1 or R0 onwards but mine is that R0 to R3 is missing from the log.<br><br>Hope your understand my question.<br><br>Please advice and thanks in advance.<br> <HR></BLOCKQUOTE><br><br>i under stood your question..and i think John2g did also. :)  Fact is I also do not have any R1, R2 & R3 or R0 in my log either..that is not odd..<br><br>I do have the O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX<br><br>but I could also take that one out if I did not want the Mplayer in my browser.<br><br>I have no need for any of these...<br><br>R - Registry, StartPage/SearchPage changes<br>R0 - Changed registry value<br>R1 - Created registry value<br>R2 - Created registry key<br>R3 - Created extra registry value where only one should be<br><br>Do you ? ;)<br><br>Here are the rest of those two letter codes for General Info if anyone else reads this thread.<br><br>***************************<br><br>Two Letter Codes<br><br>After the running processes, the list of entries found by Hijack This begins. Each entry starts with a 2-letter code to say what it is. According to Hijack This' Info, heres what each code means:<br>R - Registry, StartPage/SearchPage changes<br>R0 - Changed registry value<br>R1 - Created registry value<br>R2 - Created registry key<br>R3 - Created extra registry value where only one should be<br>F - IniFiles, autoloading entries<br>F0 - Changed inifile value<br>F1 - Created inifile value<br>N - Netscape/Mozilla StartPage/SearchPage changes<br>N1 - Change in prefs.js of Netscape 4.x<br>N2 - Change in prefs.js of Netscape 6<br>N3 - Change in prefs.js of Netscape 7<br>N4 - Change in prefs.js of Mozilla<br>O - Other, several sections which represent:<br>O1 - Hijack of auto.search.msn.com with Hosts file<br>O2 - Enumeration of existing MSIE BHO's<br>O3 - Enumeration of existing MSIE toolbars<br>O4 - Enumeration of suspicious autoloading Registry entries<br>O5 - Blocking of loading Internet Options in Control Panel<br>O6 - Disabling of 'Internet Options' Main tab with Policies<br>O7 - Disabling of Regedit with Policies<br>O8 - Extra MSIE context menu items<br>O9 - Extra 'Tools' menuitems and buttons<br>O10 - Breaking of Internet access by New.Net or WebHancer<br>O11 - Extra options in MSIE 'Advanced' settings tab<br>O12 - MSIE plugins for file extensions or MIME types<br>O13 - Hijack of default URL prefixes<br>O14 - Changing of IERESET.INF<br>O15 - Trusted Zone Autoadd<br>O16 - Download Program Files item<br>O17 - Domain hijack<br>O18 - Enumeration of existing protocols<br>O19 - User stylesheet hijack<br><br> <br><SMALL>--<br>Gladiator Security Forum  &raquo;<A HREF="http://www.gladiator-antivirus.com/" >www.gladiator-antivirus.com/</A> Missing Kids&raquo;<A HREF="http://www.missingkids.com/" >www.missingkids.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10816556</guid>
<pubDate>Mon, 19 Jul 2004 10:48:44 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10816221</link>
<description><![CDATA[<A HREF="/useremail/u/675365"><b>Bubba</b></A> : Did you by chance use the....<I>Add check to ignorelist</I>....function of HJT and forget ?<br><br>Also....as you may be aware....you hope NOT to have any <B>R3</B> entries.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10816221</guid>
<pubDate>Mon, 19 Jul 2004 09:58:15 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10815060</link>
<description><![CDATA[<A HREF="/useremail/u/673579"><b>DSLfanpal</b></A> : No, You misunderstood my question. I know what is R0 to R3. My question is why my scan result has no R1, R2 & R3 but the log starts from O1 onwards. A normal scan will consist log that starts from R1 or R0 onwards but mine is that R0 to R3 is missing from the log.<br><br>Hope your understand my question.<br><br>Please advice and thanks in advance.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10815060</guid>
<pubDate>Mon, 19 Jul 2004 03:46:39 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10807582</link>
<description><![CDATA[<A HREF="/useremail/u/382639"><b>seqrets</b></A> : Excellent explanation John! ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10807582</guid>
<pubDate>Sun, 18 Jul 2004 06:12:13 EDT</pubDate>
</item>

<item>
<title>Re: R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10807543</link>
<description><![CDATA[<A HREF="/useremail/u/448758"><b>John2g</b></A> : R0,R1,R2,R3 Sections<br><br>This section covers the Internet Explorer Start Page, Home Page, and Url Search Hooks.<br><br>R0 is for Internet Explorers starting page and search assistant.<br><br>R1 is for Internet Explorers Search functions and other characteristics.<br><br>R2 is not used currently. <br><br>R3 is for a Url Search Hook.  An Url Search Hook is used when you type an address in the location field of the browser, but do not include a protocol such as &raquo;<A HREF="http://" ></A> or &raquo;<small>ftp</small>://<A HREF="ftp://"></A> in the address.  When you enter such an address, the browser will attempt to figure out the correct protocol on its own, and if it fails to do so, will use the UrlSearchHook listed in the R3 section to try to find the location you entered.  <br><br>Some Registry Keys: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Start Page  <br>  HKLM\Software\Microsoft\Internet Explorer\Main: Default_Page_URL <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Default_Page_URL <br>  HKLM\Software\Microsoft\Internet Explorer\Main: Search Page <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Search Page <br>  HKCU\Software\Microsoft\Internet Explorer\SearchURL: (Default) <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Window Title <br>  HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: ProxyOverride <br>  HKCU\Software\Microsoft\Internet Connection Wizard: ShellNext <br>  HKCU\Software\Microsoft\Internet Explorer\Main: Search Bar  <br>  HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks <br>  HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =  <br>  HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch <br>  HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant  <br><br>Example Listing R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.google.com/" >www.google.com/</A> <br><br>A common question is what does it mean when the word Obfuscated is next to one of these entries. When something is obfuscated that means that it is being made difficult to perceive or understand. In Spyware terms that means the Spyware or Hijacker is hiding an entry it made by converting the values into some other form that it understands easily, but humans would have trouble recognizing, such as adding entries into the registry in Hexadecimal. This is just another method of hiding its presence and making it difficult to be removed.<br><br>If you do not recognize the web site that either R0 and R1 are pointing to, and you want to change it, then you can have HijackThis safely fix these, as they will not be detrimental to your Internet Explorer install.  If you would like to see what sites they are, you can go to the site, and if it's a lot of popups and links, you can almost always delete it. It is important to note that if an RO/R1 points to a file, and you fix the entry with HijackThis, Hijackthis will not delete that particular file and you will have to do it manually.<br><br>There are certain R3 entries that end with a underscore ( _ ) . An example of what one would look like is:<br><br>R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file)<br><br>Notice the CLSID, the numbers between the { }, have a _ at the end of it and they may sometimes difficult to remove with HijackThis. To fix this you will need to delete the particular registry entry manually by going to the following key:<br><br>HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks<br><br>Then delete the CLSID entry under it that you would like to remove. Please leave the CLSID , CFBFAE00-17A6-11D0-99CB-00C04FD64497, as it is the valid default one.<br><br>Unless you recognize the software being used as the UrlSearchHook, you should generally Google it and after doing some research, allow HijackThis to fix it<br><SMALL>--<br>Better to remain silent and be thought a fool, than to speak and remove all doubt.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10807543</guid>
<pubDate>Sun, 18 Jul 2004 05:42:42 EDT</pubDate>
</item>

<item>
<title>R1, R2, R3 not showing in hijackthis?</title>
<link>http://www.dslreports.com/forum/remark,10807481</link>
<description><![CDATA[<A HREF="/useremail/u/673579"><b>DSLfanpal</b></A> : I run Hijackthis 1.98 and the scan result only shows O1 onwards but not R1, R2, R3.<br><br>Running MyIE2, WinXP<br><br>Please advice and thanks in advance.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,10807481</guid>
<pubDate>Sun, 18 Jul 2004 05:11:39 EDT</pubDate>
</item>

</channel>
</rss>
