These entries are the Windows NT equivalent of those found in the F1 entries as described above. You will now be presented with a screen similar to the one below: Figure 13: HijackThis Uninstall Manager To delete an entry simply click on the entry you would like

Generating a StartupList Log. If you see another entry with userinit.exe, then that could potentially be a trojan or other malware. Got anti virus software?

  • The Run keys are used to launch a program automatically when a user, or all users, logs on to the machine.
  • Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions registry key.
  • In addition to scan and remove capabilities, HijackThis comes with several useful tools to manually remove malware from your computer.
  • You should therefore seek advice from an experienced user when fixing these errors.
  • Spyware and Hijackers can use LSPs to see all traffic being transported over your Internet connection.
  • An example of what one would look like is: R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497}_ - (no file) Notice the CLSID, the numbers between the { }, have a _

Certain ones, like "Browser Pal" should always be removed, and the rest should be researched using Google.

O4 keys are the HJT entries that the majority of programs use to autostart, so particular care must be used when examining these keys. In order to analyze your logfiles and find out what entries are nasty and what are installed by you, you will need to go to "hijackthis.de" web page. To do this follow these steps: Start Hijackthis Click on the Config button Click on the Misc Tools button Click on the button labeled Delete a file on reboot...

The Hijacker known as CoolWebSearch does this by changing the default prefix to a http://ehttp.cc/?. How to Generate a StartupList log file: Introduction StartupList is a utility which creates a list of everything which starts up when you boot your computer plus a few other items.

There is no reason why you should not understand what it is you are fixing when people examine your logs and tell you what to do. Click on the Yes button if you would like to reboot now, otherwise click on the No button to reboot later.

The default program for this key is C:\windows\system32\userinit.exe. Figure 9. Example Listing O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPix ActiveX Control) - http://www.ipix.com/download/ipixx.cab If you see names or addresses that you do not recognize, you should Google them to see if they are

Table of Contents Warning Introduction How to use HijackThis How to restore items mistakenly deleted How to Generate a Startup Listing How to use the Process Manager How to use the O9 Section This section corresponds to having buttons on main Internet Explorer toolbar or items in the Internet Explorer 'Tools' menu that are not part of the default installation.

This will remove the ADS file from your computer. How To Use Hijackthis An Url Search Hook is used when you type an address in the location field of the browser, but do not include a protocol such as http:// or ftp:// in the Thank you all!

There are times that the file may be in use even if Internet Explorer is shut down.

The program shown in the entry will be what is launched when you actually select this menu option. The AnalyzeThis function has never worked afaik, should have been deleted long ago. The rest of the entry is the same as a normal one, with the program being launched from a user's Start Menu Startup folder and the program being launched is numlock.vbs.

That will be done by the Help Forum Staff. Most modern programs do not use this ini setting, and if you do not use older program you can rightfully be suspicious. At the end of the document we have included some basic ways to interpret the information in these log files.

Anyways, I've got a hijackthis log but don't know what to do with it.

HijackThis has a built in tool that will allow you to do this.