A new window will open asking you to select the file that you would like to delete on reboot. If you do not recognize the address, then you should have it fixed. When you reset a setting, it will read that file and change the particular setting to what is stated in the file. Notepad will now be open on your computer.

Please leave the CLSID , CFBFAE00-17A6-11D0-99CB-00C04FD64497, as it is the valid default one.

Hijackthis Log File Analyzer

Adware and Spyware and Malware..... Use the Windows Task Manager (TASKMGR.EXE) to close the process prior to fixing.

ProtocolDefaults When you use IE to connect to a site, the security permissions that are granted to that site are determined by the Zone it is in. One known plugin that you should delete is the Onflow plugin that has the extension of .OFB. HijackThis will scan your registry and various other files for entries that are similar to what a Spyware or Hijacker program would leave behind.

Several trojan hijackers use a homemade service in adittion to other startups to reinstall themselves. Files Used: prefs.js As most spyware and hijackers tend to target Internet Explorer these are usually safe. Then you can either delete the line, by clicking on the Delete line(s) button, or toggle the line on or off, by clicking on the Toggle line(s) button.

If you toggle the lines, HijackThis will add a # sign in front of the line. Let's break down the examples one by one. 04 - HKLM\..\Run: [nwiz] nwiz.exe /install - This entry corresponds to a startup launching from HKLM\Software\Microsoft\Windows\CurrentVersion\Run for the currently logged in user. We suggest that you use the HijackThis installer as that has become the standard way of using the program and provides a safe location for HijackThis backups.

Is Hijackthis Safe

O1 Section This section corresponds to Host file Redirection.

Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLLO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 This tutorial, in addition, to showing how to use HijackThis, will also go into detail about each of the sections and what they actually mean.

On Windows NT based systems (Windows 2000, XP, etc) HijackThis will show the entries found in win.ini and system.ini, but Windows NT based systems will not execute the files listed there. Trusted Zone Internet Explorer's security is based upon a set of zones.

N3 corresponds to Netscape 7' Startup Page and default search page. For all of the keys below, if the key is located under HKCU, then that means the program will only be launched when that particular user logs on to the computer.

That means when you connect to a url, such as www.google.com, you will actually be going to http://ehttp.cc/?www.google.com, which is actually the web site for CoolWebSearch.

O2 Section This section corresponds to Browser Helper Objects. Example Listing O9 - Extra Button: AIM (HKLM) If you do not need these buttons or menu items or recognize them as malware, you can remove them safely.

The file will not be moved.) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-10-13] (Intel Corporation) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe [822816 2009-10-29] (Acer It should be noted that the Userinit and the Shell F2 entries will not show in HijackThis unless there is a non-whitelisted value listed.

Registry Key: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System Example Listing O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System: DisableRegedit=1 Please note that many Administrators at offices lock this down on purpose so having HijackThis fix this may be a breach of O7 Section This section corresponds to Regedit not being allowed to run by changing an entry in the registry. With this manager you can view your hosts file and delete lines in the file or toggle lines on or off.

I appreciate your understanding and diligence.Thank you for your patience thus far.