HijackThis attempts to create backups of the files and registry entries that it fixes, which can be used to restore the system in the event of a mistake. In order to do this go into the Config option when you start HijackThis, which is designated by the blue arrow in Figure 2, and then click on the Misc Tools

HijackThis can generate a plain-text logfile detailing all entries it finds, and some entries can be fixed by HijackThis. These are the toolbars that are underneath your navigation bar and menu in Internet Explorer.

O6 Section This section corresponds to an Administrative lock down for changing the options or homepage in Internet explorer by changing certain settings in the registry. The program shown in the entry will be what is launched when you actually select this menu option.

All Users Startup Folder: These items refer to applications that load by having them in the All Users profile Start Menu Startup Folder and will be listed as O4 - Global Registry Keys: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects Example Listing O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Antivirus\NavShExt.dll There is an excellent list of known CSLIDs associated with Browser Helper Objects

These entries will be executed when any user logs onto the computer. The Windows NT based versions are XP, 2000, 2003, and Vista. Copy and paste these entries into a message and submit it. When domains are added as a Trusted Site or Restricted they are assigned a value to signify that.

Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo!

Check the "Do not show this window..." box to prevent the menu from showing up in the future. Ensure the configuration is correct. For example, if you added as a trusted sites, Windows would create the first available Ranges key (Ranges1) and add a value of http=2. Preferably the fix should START with those steps and finish the cleanup of strays or undetected items with HJT. Just save the HijackThis report and let a friend with more troubleshooting experience take a look.

You can only rely on that to be true in the sections for BHOs and Toolbars (02s & 03s)When you see (file missing) in other sections, it may really NOT be Example Listing O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPix ActiveX Control) - http://www.ipix.com/download/ipixx.cab If you see names or addresses that you do not recognize, you should Google them to see if they are

This will open a new window with a description of the item. Domain hacks are when the Hijacker changes the DNS servers on your machine to point to their own server, where they can direct you to any site they want. Therefore you must use extreme caution when having HijackThis fix any problems.

O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe - This entry corresponds to a program started by the All Users Startup Folder located at C:\Documents and Settings\All Users

IniFileMapping, puts all of the contents of an .ini file in the registry, with keys for each line found in the .ini key stored there. Browser helper objects are plugins to your browser that extend the functionality of it.

O7 Section This section corresponds to Regedit not being allowed to run by changing an entry in the registry. This will make both programs launch when you log in and is a common place for trojans, hijackers, and spyware to launch from. Prefix: http://ehttp.cc/? Once you restore an item that is listed in this screen, upon scanning again with HijackThis, the entries will show up again.

An example of a legitimate program that you may find here is the Google Toolbar. The load= statement was used to load drivers for your hardware. If you add an IP address to a security zone, Windows will create a subkey starting with Ranges1 and designate that subkey as the one that will contain all IP addresses

If you see CommonName in the listing you can safely remove it. Clean the restore folder and set a new point AFTER the PC is clean and all programs are working properly.

Unlike the RunServices keys, when a program is launched from the RunServicesOnce key its entry will be removed from the Registry so it does not run again on subsequent logons.

The user32.dll file is also used by processes that are automatically started by the system when you log on. This can lead to a cluttered list of programs. When you post your log, you should tell what problems you are having and which antispyware and antivirus programs that you have already tried. If you see web sites listed in here that you have not set, you can use HijackThis to fix it.

