At the end of the document we have included some basic ways to interpret the information in these log files. Once the program is successfully launched for the first time its entry will be removed from the Registry so it does not run again on subsequent logons.

R0 is for Internet Explorers starting page and search assistant. Registry Key: HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions Example Listing O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions These options should only appear if your administrator set them on purpose or if you used Spybots Home Page and Option If you look in your Internet Options for Internet Explorer you will see an Advanced Options tab. By no means is this information extensive enough to cover all decisions, but should help you determine what is legitimate or not.

Hijackthis Log Analyzer

Hijackthis Download

O12 Section This section corresponds to Internet Explorer Plugins. Most modern programs do not use this ini setting, and if you do not use older program you can rightfully be suspicious.

It takes time to properly investigate your log and prepare the appropriate fix response.Once you have posted your log and are waiting, please DO NOT "bump" your post or make another For example: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit =C:\windows\system32\userinit.exe,c:\windows\badprogram.exe.

Host file redirection is when a hijacker changes your hosts file to redirect your attempts to reach a certain web site to another site. RunOnceEx key: HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx The Policies\Explorer\Run keys are used by network administrator's to set a group policy settings that has a program automatically launch when a user, or all users, logs Let's break down the examples one by one. 04 - HKLM\..\Run: [nwiz] nwiz.exe /install - This entry corresponds to a startup launching from HKLM\Software\Microsoft\Windows\CurrentVersion\Run for the currently logged in user.

For a more detailed explanation, please refer to:What is WoW, Windows on Windows, WoW64, WoWx86 emulator … in 64-bit computing platformHow does WoW64 work?Making the Move to x64: File System RedirectionSince If you do not have advanced knowledge about computers you should NOT fix entries using HijackThis without consulting an expert on using this program. Simply copy and paste the contents of that notepad into a reply in the topic you are getting help in.

You must manually delete these files. In our explanations of each section we will try to explain in layman terms what they mean.

If you see another entry with userinit.exe, then that could potentially be a trojan or other malware. The O4 Registry keys and directory locations are listed below and apply, for the most part, to all versions of Windows.

You will then be presented with a screen listing all the items found by the program as seen in Figure 4. To access the Uninstall Manager you would do the following: Start HijackThis Click on the Config button Click on the Misc Tools button Click on the Open Uninstall Manager button. Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.You also don't appear to have any sufficient anti-virus protection, which is a big

LSPs are a way to chain a piece of software to your Winsock 2 implementation on your computer. O2 Section This section corresponds to Browser Helper Objects.


