Are you looking for the solution to your computer problem?

Click Check for Problems and when the scan is finished let Spybot fix/remove all it finds marked in RED.

You will now be asked if you would like to reboot your computer to delete the file.

HijackThis lists the contents of key areas of the Registry and hard drive--areas that are used by malware. This zone has the lowest security and allows scripts and applications from sites in this zone to run without your knowledge. Instead, you must delete these manually afterwards, usually by having the user first reboot into safe mode.

The same goes for F2 Shell=; if you see explorer.exe by itself, it should be fine, if you don't, as in the above example listing, then it could be a potential issue. You should also attempt to clean the Spyware/Hijacker/Trojan with all other methods before using HijackThis. As most Windows executables use the user32.dll, that means that any DLL that is listed in the AppInit_DLLs registry key will be loaded also.

I personally remove all entries from the Trusted Zone as they are ultimately unnecessary to be there. Example Listing O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPix ActiveX Control) - http://www.ipix.com/download/ipixx.cab If you see names or addresses that you do not recognize, you should Google them to see if they are malicious.

If you see UserInit=userinit.exe (notice no comma) that is still ok, so you should leave it alone.

It requires expertise to interpret the results, though - it doesn't tell you which items are bad. HijackThis will display a list of areas on your computer that might have been changed by spyware.

When consulting the list, using the CLSID which is the number between the curly brackets in the listing.

HijackThis scan results make no separation between safe and unsafe settings , which gives you the ability to selectively remove items from your machine. O4 - S-1-5-21-1222272861-2000431354-1005 Startup: numlock.vbs (User 'BleepingComputer.com') - This particular entry is a little different.

Britec09 314.949 görüntüleme 8:08 How to remove a computer virus / malware - Süre: 5:27.

Otherwise, if you downloaded the installer, navigate to the location where it was saved and double-click on the HiJackThis.msi file in order to start the installation of HijackThis. If you look in your Internet Options for Internet Explorer you will see an Advanced Options tab.

Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\: DatabasePath If you see entries like the above example, and they are not their for a specific reason that you know about, you can safely remove them. Any future trusted http:// IP addresses will be added to the Range1 key. When Internet Explorer is started, these programs will be loaded as well to provide extra functionality.

You should now see a screen similar to the figure below: Figure 1. The file remains in the Recycle Bin until you empty the Recycle Bin or restore the file.The Recycler folder is used only on NTFS partitions. HijackThis makes no separation between safe and unsafe settings in its scan results giving you the ability to selectively remove items from your machine.

To delete a line in your hosts file you would click on a line like the one designated by the blue arrow in Figure 10 above. If an actual executable resides in the Global Startup or Startup directories then the offending file WILL be deleted.