If you see an entry Hosts file is located at C:\Windows\Help\hosts, that means you are infected with the CoolWebSearch. With this manager you can view your hosts file and delete lines in the file or toggle lines on or off. As of HijackThis version 2.0, HijackThis will also list entries for other users that are actively logged into a computer at the time of the scan by reading the information from

If an entry starts with a long series of numbers and contains a username surrounded by parenthesis at the end, then this is a O4 entry for a user logged on You should therefore seek advice from an experienced user when fixing these errors. While that key is pressed, click once on each process that you want to be terminated.

N1 corresponds to the Netscape 4's Startup Page and default search page. A StartupList will not be needed with every forum posting, but if it is needed it will be asked for, so please refrain from posting one unless asked.

If you see another entry with userinit.exe, then that could potentially be a trojan or other malware.

Then click on the Misc Tools button and finally click on the ADS Spy button.

HijackThis can be downloaded from the following link: HijackThis Download Link If you have downloaded the standalone application, then simply double-click on the HijackThis.exe file. Click the button labeled Do a system scan and save a logfile.

Click the "Open the Misc Tools section" button. R3 is for a Url Search Hook.

Download HijackThis from http://www.trendsecure.com/portal/en-US/_download/HiJackThis.exeSave it in your desktop. O12 Section This section corresponds to Internet Explorer Plugins.

O4 keys are the HJT entries that the majority of programs use to autostart, so particular care must be used when examining these keys. Registry Keys: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar Example Listing O3 - Toolbar: Norton Antivirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Antivirus\NavShExt.dll There is an excellent list of known CSLIDs associated with Browser Helper Objects and

These entries are the Windows NT equivalent of those found in the F1 entries as described above. R1 is for Internet Explorers Search functions and other characteristics.

Some Registry Keys: HKLM\Software\Microsoft\Internet Explorer\Main,Start Page HKCU\Software\Microsoft\Internet Explorer\Main: Start Page HKLM\Software\Microsoft\Internet Explorer\Main: Default_Page_URL HKCU\Software\Microsoft\Internet Explorer\Main: Default_Page_URL HKLM\Software\Microsoft\Internet Explorer\Main: Search Page HKCU\Software\Microsoft\Internet Explorer\Main: Search Page HKCU\Software\Microsoft\Internet

Registry Keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults If the default settings are changed you will see a HJT entry similar to the one below: Example Listing O15 - ProtocolDefaults: 'http' protocol

R0 is for Internet Explorers starting page and search assistant. Example Listing O18 - Protocol: relatedlinks - {5AB65DD4-01FB-44D5-9537-3767AB80F790} - C:\PROGRA~1\COMMON~1\MSIETS\msielink.dll Common offenders to this are CoolWebSearch, Related Links, and Lop.com. This particular key is typically used by installation or update programs.

Figure 9. It's usually posted with your first topic on a forum, along with a description of your problem(s). If a Hijacker changes the information in that file, then you will get re infected when you reset that setting, as it will read the incorrect information from the iereset.inf file.

Let's break down the examples one by one. 04 - HKLM\..\Run: [nwiz] nwiz.exe /install - This entry corresponds to a startup launching from HKLM\Software\Microsoft\Windows\CurrentVersion\Run for the currently logged in user. If you feel they are not, you can have them fixed.

A F0 entry corresponds to the Shell= statement, under the [Boot] section, of the System.ini file. An example of a legitimate program that you may find here is the Google Toolbar.

Clicking the AnalyzeThis button will submit the contents of your HJT log to TrendMicro. When you enter such an address, the browser will attempt to figure out the correct protocol on its own, and if it fails to do so, will use the UrlSearchHook listed. The rest of the entry is the same as a normal one, with the program being launched from a user's Start Menu Startup folder and the program being launched is numlock.vbs.

please help. Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\: DatabasePath If you see entries like the above example, and they are not their for a specific reason that you know about, you can safely remove them.