What to do: These are always bad. What to do: The only hijacker as of now that adds its own options group to the IE Advanced Options window is CommonName. What to do: These are always bad. That may cause it to stall Caution...Never run and remove files using ComboFix without being supervised by a security analyst. __________________ Eddy 02-06-2008, 08:51 PM #3 jbrown79 Registered Member get redirected here

Intended for the security illiterate, Essential Computer Security is a source of jargon-less advice everyone needs to operate their computer securely.* Written in easy to understand non-technical language that novices can Posting logs as suggested by evilfantasy Help2Go Detective recommended Hijack this log...need to know what to do? You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file. What to do: In the case of a browser slowdown and frequent popups, have HijackThis fix this item if it shows up in the log. https://www.bleepingcomputer.com/forums/t/160728/need-help-with-hijackthis-log/

F1 entries - Any programs listed after the run= or load= will load when Windows starts.

One of Merijn's programs, Hijackthis, is an essential utility to help find and remove spyware, viruses, worms, trojans and other pests.

O22 - SharedTaskScheduler Registry key autorun What it looks like: O22 - SharedTaskScheduler: (no name) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c:\windows\system32\mtwirl32.dll Or Upload your Hijackthis log to the Online HijackThis Analyzer and see if its safe.

C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\acs.exe C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\wanmpsvc.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe This does not necessarily mean it is bad, but in most cases, it will be malware.

There are hundreds of rogue anti-spyware programs that have used this method of displaying fake security warnings. In the BHO List, 'X' means spyware and 'L' means safe. O3 - IE toolbars What it looks like: O3 - Toolbar: &Yahoo!


The same goes for the 'SearchList' entries. Search - file:///C:Program FilesYahoo!Common/ycsrch.htm What to do: If you don't recognize the name of the item in the right-click menu in IE, have HijackThis fix it.

O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys What it looks like: O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers. O15 - Unwanted site in Trusted Zone What it looks like: O15 - Trusted Zone: http://www.badspyware.com What to do: Many different spyware and adware programs will add items to the Tursted Zone.

The below information was originated from Merijn's official tutorial to using Hijack This.

The known baddies are 'cn' (CommonName), 'ayb' (Lop.com) and 'relatedlinks' (Huntbar), you should have HijackThis fix those.

Yes, my password is: Forgot your password? Ce hoces brezplacno resitev, pa ti priporocam Avasta!