This will comment out the line so that it will not be used by Windows. When consulting the list, using the CLSID which is the number between the curly brackets in the listing. If you would like to learn more detailed information about what exactly each section in a scan log means, then continue reading. It is possible to select multiple lines at once using the shift and control keys or dragging your mouse over the lines you would like to interact with.

Internet Explorer Plugins are pieces of software that get loaded when Internet Explorer starts to add functionality to the browser. As of HijackThis version 2.0, HijackThis will also list entries for other users that are actively logged into a computer at the time of the scan by reading the information from Registry Keys: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar Example Listing O3 - Toolbar: Norton Antivirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Antivirus\NavShExt.dll There is an excellent list of known CSLIDs associated with Browser Helper Objects and

  1. When the install starts, click on the Install button to have HijackThis installed into the C:\Program Files\Trend Micro\HijackThis folder, create a desktop shortcut that can be used to run the program
  3. To exit the Hosts file manager you need to click on the back button twice which will place you at the main screen.
  4. There is no reason why you should not understand what it is you are fixing when people examine your logs and tell you what to do.
  5. You must do your research when deciding whether or not to remove any of these as some may be legitimate.
If you see another entry with userinit.exe, then that could potentially be a trojan or other malware. Every line on the Scan List for HijackThis starts with a section name.

The default program for this key is C:\windows\system32\userinit.exe. When working on HijackThis logs it is not advised to use HijackThis to fix entries in a person's log when the user has multiple accounts logged in. Example Listing O1 - Hosts: www.google.com Files Used: The hosts file is a text file that can be edited by any text editor and is stored by default in the

These zones with their associated numbers are: Zone Zone Mapping My Computer 0 Intranet 1 Trusted 2 Internet 3 Restricted 4 Each of the protocols that you use to connect to To delete a line in your hosts file you would click on a line like the one designated by the blue arrow in Figure 10 above. O14 Section This section corresponds to a 'Reset Web Settings' hijack. http://uberbandwidth.com/hijackthis-download/please-help-with-this-hijack-this-log.php Therefore, we typically recommend HijackThis for Windows XP only.

R3 is for a Url Search Hook.

If an actual executable resides in the Global Startup or Startup directories then the offending file WILL be deleted.

Non-experts need to submit the log to a malware-removal forum for analysis; there are several available. If you delete the lines, those lines will be deleted from your HOSTS file.

Windows 95, 98, and ME all used Explorer.exe as their shell by default. Instead for backwards compatibility they use a function called IniFileMapping.

A F1 entry corresponds to the Run= or Load= entry in the win.ini file. O3 Section This section corresponds to Internet Explorer toolbars. HijackThis will then prompt you to confirm if you would like to remove those items. From within that file you can specify which specific control panels should not be visible.

All the text should now be selected. These entries will be executed when any user logs onto the computer.