For example: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit =C:\windows\system32\userinit.exe,c:\windows\badprogram.exe. The first step is to download HijackThis to your computer in a location that you know where to find it again. When you fix O16 entries, HijackThis will attempt to delete them from your hard drive. Figure 11: ADS Spy Press the Scan button and the program will start to scan your Windows folder for any files that are Alternate Data Streams. check over here

If you see these you can have HijackThis fix it. thanks Sep 5, 2005 #1 RealBlackStuff TS Rookie Posts: 6,503 see How to post your Hijackthis log-files as an attachment with .txt. These files will require further investigation.Select only items recommended for removal, then click "Clean up checked items". Figure 6. https://www.bleepingcomputer.com/forums/t/346144/hijackthis-log-file-please-help/

Source code is available SourceForge, under Code and also as a zip file under Files. There is a file on your computer that Internet Explorer uses when you reset options back to their Windows default. There are times that the file may be in use even if Internet Explorer is shut down.

When the ADS Spy utility opens you will see a screen similar to figure 11 below. They can be used by spyware as well as legitimate programs such as Google Toolbar and Adobe Acrobat Reader. This program is used to remove all the known varieties of CoolWebSearch that may be on your machine. Hijackthis Windows 10 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004

If you are asked to save this list and post it so someone can examine it and advise you as to what you should remove, you can click on the Save How To Use Hijackthis You should now see a new screen with one of the buttons being Hosts File Manager. Logfile of Trend Micro HijackThis v2.0.5 Scan saved at 9:25:26 AM, on 6/6/2013 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v9.00 (9.00.8112.16483) FIREFOX: 21.0 (en-US) Boot mode: Normal Running http://www.bleepingcomputer.com/forums/t/12590/hijack-this-log-file-please-help/ Log File..

or read our Welcome Guide to learn how to use this site. All Users Startup Folder: These items refer to applications that load by having them in the All Users profile Start Menu Startup Folder and will be listed as O4 - Global Hijackthis Log Analyzer How to use the Uninstall Manager The Uninstall Manager allows you to manage the entries found in your control panel's Add/Remove Programs list. Hijackthis Download O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe - This entry corresponds to a program started by the All Users Startup Folder located at C:\Documents and Settings\All

Once the program is successfully launched for the first time its entry will be removed from the Registry so it does not run again on subsequent logons. For a great list of LSP and whether or not they are valid you can visit SystemLookup's LSP List Page. Registry Keys: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects Example Listing O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Antivirus\NavShExt.dll There is an excellent list of known CSLIDs associated with Browser Helper Objects this content Click on File and Open, and navigate to the directory where you saved the Log file.

O11 Section This section corresponds to a non-default option group that has been added to the Advanced Options Tab in Internet Options on IE. Trend Micro Hijackthis When you enter such an address, the browser will attempt to figure out the correct protocol on its own, and if it fails to do so, will use the UrlSearchHook listed No, create an account now.

It is possible to change this to a default prefix of your choice by editing the registry.

HijackThis will scan your registry and various other files for entries that are similar to what a Spyware or Hijacker program would leave behind. This is just another example of HijackThis listing other logged in user's autostart entries. In order to do this go into the Config option when you start HijackThis, which is designated by the blue arrow in Figure 2, and then click on the Misc Tools Autoruns Bleeping Computer We recommend Gmail.   The notifications won't even be in your Spam folder - they just go down a black hole.

Click here to Register a free account now! You should have the user reboot into safe mode and manually delete the offending file. We suggest that you use the HijackThis installer as that has become the standard way of using the program and provides a safe location for HijackThis backups. have a peek at these guys Send me the log file or a screenshot of the windows showing if there is any infection: http://housecall.trendmicro.com/index.html Download and also scan your machine with rootkit buster tool, it may help

This location, for the newer versions of Windows, are C:\Documents and Settings\All Users\Start Menu\Programs\Startup or under C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup in Vista. All Rights Reserved. There were some programs that acted as valid shell replacements, but they are generally no longer used. How to use HijackThis HijackThis can be downloaded as a standalone executable or as an installer.

An example of a legitimate program that you may find here is the Google Toolbar. Figure 3. Sorry for the delay, the board has been quite busy. Ask a question and give support.