Remember to SAS in our Good , Bad and Unknown 5 Newest Bad EntriesO9 - Extra \'Tools\' menuitem: Quick-Launch Area -{10954C80-4F0F-11d3-B17C-00C0DFE39736} -C:\\Program Files (x86)\\Acer BioProtection\\PwdBank.exe O9 - Extra button: Quick-Launch Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do:If you don't With the help of this automatic analyzer you are able to get some additional support.

They are very inaccurate and often flag things that are not bad and miss many things that are. HijackThis uses a whitelist of several very common SSODL items, so whenever an item is displayed in the log it is unknown and possibly malicious.

They rarely get hijacked, only Lop.com has been known to do this. Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone. Prefix: http://ehttp.cc/?What to do:These are always bad.

If everything has FAILED, please see: Format and reinstall section Of course some of the things HJT says are unknown that I know to be OK on my machine, but I would not necessarily know so on some one else's computer, In the last case, have HijackThis fix it.O19 - User style sheet hijackWhat it looks like: O19 - User style sheet: c:\WINDOWS\Java\my.css What to do:In the case of a browser slowdown

Here attached is my log. If you see the following error message, click OK. is, you probably don't have any use for this section of exeLibrary. :-) Our HiJack This!

Article Which Apps Will Help Keep Your Personal Computer Safe? F2 - Reg:system.ini: Userinit= log file analyzer will take your log file and give you a set of useful information based on what is running on your computer, your settings, and much more - this Well I won't go searching for them, as it sotr of falls into the 'everybody already knows this' part of my post. How do I download and use Trend Micro HijackThis?

I have been to that site RT and others. Rename "hosts" to "hosts_old".

DataBase Summary There are a total of 20,082 Entries classified as BAD in our Database. If there is some abnormality detected on your computer, HijackThis will save them into a logfile. Click the Analyze button.

We don't want users to start picking away at their Hijack logs when they don't understand the process involved. I'm not hinting ! So you can always have HijackThis fix this.O12 - IE pluginsWhat it looks like: O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dllWhat to do:Most

Click the Do a System Scan and Save a Logfile button. In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo! Did not catch on to that one line I had at first but then I had a light go off in my head on what was said in that line and

Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it.O1 - Hostsfile redirectionsWhat it looks like:O1 - Hosts: auto.search.msn.comO1 - Hosts:

Any other items marked with an 'X' in the analysis log should be investigated by you before deleting. In order to find out what entries are nasty and what are installed by the user, you need some background information.A logfile is not so easy to analyze.

in the Information field. It will show programs that are currently running on your computer, addins to Internet Explorer and Netscape, and certain parts of the Windows registry that may contain malicious information. Guess it made the " O1 - Hosts: To add to hosts file" because of the two below it. Save the file to your Desktop.

Rather, HijackThis looks for the tricks and methods used by malware to infect your system and redirect your browser.Not everything that shows up in the HijackThis logs is bad stuff and