Logfile reports: In addition to presenting scan results in the main interface viewing window, this app also lets you save them to your computer as a log file. That makes it easy to refer back to it later, compare the results of multiple scans, and also to get help and advice from other users on forums when you're trying Please leave the CLSID , CFBFAE00-17A6-11D0-99CB-00C04FD64497, as it is the valid default one. When the ADS Spy utility opens you will see a screen similar to figure 11 below.

Hijackthis Log Analyzer

Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {20EE00CD-7A9D-90DF-F66A-CE9617C4E174}

O6 Section This section corresponds to an Administrative lock down for changing the options or homepage in Internet explorer by changing certain settings in the registry. It is possible to change this to a default prefix of your choice by editing the registry. O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3)

Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service: avast! It is possible to add further programs that will launch from this key by separating the programs with a comma. Windows 95, 98, and ME all used Explorer.exe as their shell by default.

You can download that and search through it's database for known ActiveX objects. O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) If an actual executable resides in the Global Startup or Startup directories then the offending file WILL be deleted.

Then click on the Misc Tools button and finally click on the ADS Spy button. Copy and paste these entries into a message and submit it. Figure 1.

Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exeO9 - Extra 'Tools' menuitem: Yahoo! There is no other software I know of that can analyze the way HijackThis does The current locations that O4 entries are listed from are: Directory Locations: User's Startup Folder: Any files located in a user's Start Menu Startup folder will be listed as a O4 O8 Section This section corresponds to extra items being found in the in the Context Menu of Internet Explorer.

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) Under the Hidden files and folders heading select Show hidden files and folders. The Global Startup and Startup entries work a little differently.

R2 is not used currently. Next press the Apply button and then the OK to exit the Internet Properties page.

Run keys: HKLM\Software\Microsoft\Windows\CurrentVersion\Run HKCU\Software\Microsoft\Windows\CurrentVersion\Run The RunOnce keys are used to launch a service or background process whenever a user, or all users, logs on to the computer.

button and specify where you would like to save this file. O3 Section This section corresponds to Internet Explorer toolbars. When domains are added as a Trusted Site or Restricted they are assigned a value to signify that. This can cause HijackThis to see a problem and issue a warning, which may be similar to the example above, even though the Internet is indeed still working.

There is no reason why you should not understand what it is you are fixing when people examine your logs and tell you what to do. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:") The name of the Registry value is nwiz and when the entry is started it will launch the nwiz.exe /install command.

In order to analyze your logfiles and find out what entries are nasty and what are installed by you, you will need to go to "hijackthis.de" web page. O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe - This entry corresponds to a program started by the All Users Startup Folder located at C:\Documents and Settings\All Users Open My Computer.

If you look in your Internet Options for Internet Explorer you will see an Advanced Options tab. Press Submit If you would like to see information about any of the objects listed, you can click once on a listing, and then press the "Info on selected item..." button. In September 2014, Trend Micro announced a new partnership with Interpol with a mission to thwart cybercrimes worldwide.

Click on Save Report As....