Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone.

Alternative and archived versions of HijackThis: 2.0.2: HijackThis (installer) | HijackThis.zip | HijackThis (executable) 1.99.1: HijackThis.exe | HijackThis.zip | HijackThis (self-extracting) 1.98.2: HijackThis.exe | HijackThis.zip
If there is some abnormality detected on your computer HijackThis will save them into a logfile.

Hijackthis Log Analyzer

This led to the joint development of HijackPro, a professional version of HijackThis with the built-in capabilities to kill processes similar to killbox.

AnalyzeThis is new to HijackThis.

Other types of malware can even terminate your security tools by changing the permissions on targeted programs so that they cannot run or complete scans.
O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll

However, since only Coolwebsearch does this, it's better to use CWShredder to fix it.O20 - AppInit_DLLs Registry value autorunWhat it looks like: O20 - AppInit_DLLs: msconfd.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{F30B90D7-A542-4DAD-A7EF-4FF23D23587B}: NameServer = sectionAny protocol hijackers will be shown here.

Hijackthis Download

Close all applications and windows so that you have nothing open and are at your Desktop.
In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo!

Several trojan hijackers use a homemade service in adittion to other startups to reinstall themselves.

HijackThis is used primarily for diagnosis of malware, not to remove or detect spyware—as uninformed use of its removal facilities can cause significant software damage to a computer.

Using HijackThis is a lot like editing the Windows Registry itself. Click Apply, and then click OK.

the CLSID has been changed) by spyware.

Click on the View tab and make sure that "Show hidden files and folders" is checked. Yes, my password is: Forgot your password? TrendMicro uses the data you submit to improve their products. Hijackthis Portable Malware fix forumIf I don't reply within 24 hours please PM me!

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe.O24 sectionFinally, the O24 section is any Microsoft Windows Active Desktop components that are installed on the computer.

HijackThis will quickly scan your system, and then open two new windows.
O24 - Desktop Component 1: (no name) - http://mbox.personals.yahoo.com/mbox/mboxlist.
In order to find out what entries are nasty and what are installed by the user, you need some background information.A logfile is not so easy to analyze.

In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this.
Often malware attack these pulled Registry values to change your default homepage, search page, etc.

Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing.
It was originally developed by Merijn Bellekom, a student in The Netherlands.
By default it will be saved to C:\HijackThis, or you can chose "Save As…", and save to another location.

The list should be the same as the one you see in the Msconfig utility of Windows XP.
This file is used when restoring Microsoft Internet Explorer settings back to the default settings.O15 sectionDisplays any Microsoft Internet Explorer Trusted Zone changes.