In order to analyze your logfiles and find out what entries are nasty and what are installed by you, you will need to go to "hijackthis.de" web page. To access the Uninstall Manager you would do the following: Start HijackThis Click on the Config button Click on the Misc Tools button Click on the Open Uninstall Manager button. You can also download the program HostsXpert which gives you the ability to restore the default host file back onto your machine.

That file is stored in c:\windows\inf\iereset.inf and contains all the default settings that will be used. A new window will open asking you to select the file that you would like to delete on reboot. HijackThis will then prompt you to confirm if you would like to remove those items.

If you are still unsure of what to do, or would like to ask us to interpret your log, paste your log into a post in our Privacy Forum. For example: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit =C:\windows\system32\userinit.exe,c:\windows\badprogram.exe. This tutorial, in addition, to showing how to use HijackThis, will also go into detail about each of the sections and what they actually mean.

Example Listing 017 - HKLM\System\CS1\Services\VxD\MSTCP: NameServer =, If you see entries for this and do not recognize the domain as belonging to your ISP or company, and the DNS servers HijackThis introduced, in version 1.98.2, a method to have Windows delete the file as it boots up, before the file has the chance to load.

If you click on that button you will see a new screen similar to Figure 10 below. To delete a line in your hosts file you would click on a line like the one designated by the blue arrow in Figure 10 above. This would have a value of http=4 and any future IP addresses added to the restricted sites will be placed in that key.

You will now be presented with a screen similar to the one below: Figure 13: HijackThis Uninstall Manager To delete an entry simply click on the entry you would like

The Userinit value specifies what program should be launched right after a user logs into Windows.

O13 Section This section corresponds to an IE DefaultPrefix hijack. It is possible to change this to a default prefix of your choice by editing the registry. Registry Keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults If the default settings are changed you will see a HJT entry similar to the one below: Example Listing O15 - ProtocolDefaults: 'http' protocol Hijackthis Download The first step is to download HijackThis to your computer in a location that you know where to find it again.

O4 - HKLM\..\Policies\Explorer\Run: [user32.dll] C:\Program Files\Video ActiveX Access\iesmn.exe - This entry corresponds to a value located under the HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run key. Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: Adult Messenger.lnk = C:\Program Files\Exo Adult\ExoAdult.exe O4 - Global Startup: Kodak EasyShare software.lnk = They are also referenced in the registry by their CLSID which is the long string of numbers between the curly braces. his comment is here There are two prevalent tutorials about HijackThis on the Internet currently, but neither of them explain what each of the sections actually mean in a way that a layman can understand.

There is no reason why you should not understand what it is you are fixing when people examine your logs and tell you what to do. N2 corresponds to the Netscape 6's Startup Page and default search page. Choose YES.Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery

Spyware and Hijackers can use LSPs to see all traffic being transported over your Internet connection.

Title the message: HijackThis Log: Please help Diagnose Right click in the message area where you would normally type your message, and click on the paste option. HijackThis has a built in tool that will allow you to do this. Sorry There was an error emailing this page. Each of these subkeys correspond to a particular security zone/protocol.

Each of these subkeys correspond to a particular security zone/protocol. A F0 entry corresponds to the Shell= statement, under the [Boot] section, of the System.ini file.

This location, for the newer versions of Windows, are C:\Documents and Settings\USERNAME\Start Menu\Programs\Startup or under C:\Users\USERNAME\AppData\Roaming\Microsoft\Windows\Start Menu in Vista. Just paste your complete logfile into the textbox at the bottom of that page, click "Analyze" and you will get the result.