Javacool's SpywareBlaster has a huge database of malicious ActiveX objects that can be used for looking up CLSIDs. (Right-click the list to use the Find function.) O17 - Lop.com domain hijacksWhat You can skip the rest of this post. Just paste your complete logfile into the textbox at the bottom of that page, click "Analyze" and you will get the result.

Instructions on how to properly create a GMER log can be found here: How to create a GMER log. In order to find out what entries are nasty and what are installed by the user, you need some background information. A logfile is not so easy to analyze. The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'Ort'.

Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers. In case of a 'hidden' DLL loading from this Registry value, other types of malware can even terminate your security tools by changing the permissions on targeted programs so that they cannot run or complete scans.

If the name or URL contains words like 'dialer', 'casino', 'free_plugin' etc, definitely fix it. It requires expertise to interpret the results, though - it doesn't tell you which items are bad.

Even then, with some types of malware infections, the task can be arduous. Items listed at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad are loaded by Explorer when Windows starts.

However, HijackThis does not make value based calls between what is considered good or bad.

You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file. The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection. Only OnFlow adds a plugin here that you don't want (.ofb). O13 - IE DefaultPrefix hijack What it looks like: O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?O13 - WWW.

HijackThis uses a whitelist of several very common SSODL items, so whenever an item is displayed in the log it is unknown and possibly malicious.

HiJackThis is very good at what it does - providing a log of system settings and startup programs.

In order to analyze your logfiles and find out what entries are nasty and what are installed by you, you will need to go to "hijackthis.de" web page. Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do: If you don't recognize the toolbar, have HijackThis fix it.

The same goes for the 'SearchList' entries.

It is almost guaranteed that some of the items in your HijackThis logs will be legitimate software and removing those items may adversely impact your system or render it completely inoperable. Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing.

the CLSID has been changed) by spyware.

With the help of this automatic analyzer you are able to get some additional support.

Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it. O1 - Hostsfile redirections What it looks like: O1 - Hosts: auto.search.msn.com O1 - Hosts: This folder contains all the 32-bit .dll files required for compatibility which run on top of the 64-bit version of Windows.

In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this.

In the last case, have HijackThis fix it. O19 - User style sheet hijack What it looks like: O19 - User style sheet: c:\WINDOWS\Java\my.css What to do: In the case of a browser slowdown. In addition to scan and remove capabilities, HijackThis comes with several useful tools to manually remove malware from your computer.

Have HijackThis fix them. O14 - 'Reset Web Settings' hijack What it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.com What to do: If the URL is not the provider of your computer or your ISP, have HijackThis fix it.