That means when you connect to a url, such as www.google.com, you will actually be going to http://ehttp.cc/?www.google.com, which is actually the web site for CoolWebSearch.

This will make both programs launch when you log in and is a common place for trojans, hijackers, and spyware to launch from.

Hijackthis Log Analyzer V2

That's the way to use the Internet for good purposes. It is also saying 'do you know this process' if so and you installed it then there is less likelihood of it being nasty. This method is known to be used by a CoolWebSearch variant and can only be seen in Regedit by right-clicking on the value, and selecting Modify binary data. HijackThis introduced, in version 1.98.2, a method to have Windows delete the file as it boots up, before the file has the chance to load.

As of HijackThis version 2.0, HijackThis will also list entries for other users that are actively logged into a computer at the time of the scan by reading the information from

Registry Keys: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults If the default settings are changed you will see a HJT entry similar to the one below: Example Listing O15 - ProtocolDefaults: 'http' protocol The F1 items are usually very old programs that are safe, so you should find some more info on the filename to see if it's good or bad.

The second part of the line is the owner of the file at the end, as seen in the file's properties. Note that fixing an O23 item will only stop the service. Example Listing O10 - Broken Internet access because of LSP provider 'spsublsp.dll' missing Many Virus Scanners are starting to scan for Viruses, Trojans, etc at the Winsock level.

Hijackthis Download

Use google to see if the files are legitimate. These entries will be executed when any user logs onto the computer. Registry Key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions registry key. You must manually delete these files.

Netscape 4's entries are stored in the prefs.js file in the program directory which is generally, DriveLetter:\Program Files\Netscape\Users\default\prefs.js. O23 - NT Services What it looks like: O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe What to do: This is the listing of non-Microsoft services. If you start HijackThis and click on Config, and then the Backup button you will be presented with a screen like Figure 7 below.

the CLSID has been changed) by spyware. To access the Uninstall Manager you would do the following: Start HijackThis Click on the Config button Click on the Misc Tools button Click on the Open Uninstall Manager button. Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it. O1 - Hostsfile redirections What it looks like: O1 - Hosts: Examples and their descriptions can be seen below.

The most common listing you will find here are free.aol.com which you can have fixed if you want. But please note they are far from perfect and should be used with extreme caution!!! The results of the HijackThis scan, and hijackthis.log in Notepad.

avatar2005 Avast Evangelist Poster Posts: 423 In search of Harmony in our lives hijackthis log analyzer

This last function should only be used if you know what you are doing. So far only CWS.Smartfinder uses it. HijackThis has a built in tool that will allow you to do this. Hijackthis Portable How to use ADS Spy There is a particular infection called Home Search Assistant or CWS_NS3 that will sometimes use a file called an Alternate Data Stream File to infect

The previously selected text should now be in the message.

O4 - HKUS\S-1-5-21-1222272861-2000431354-1005\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (User 'BleepingComputer.com') - This type of entry is similar to the first example, except that it belongs to the BleepingComputer.com user. When you fix these types of entries with HijackThis, HijackThis will attempt to the delete the offending file listed. When using the standalone version you should not run it from your Temporary Internet Files folder as your backup folder will not be saved after you close the program. It is possible to add further programs that will launch from this key by separating the programs with a comma.

F3 entries are displayed when there is a value that is not whitelisted in the registry key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows under the values load and run. Once installed open HijackThis by clicking Start -> Program Files -> HijackThis. This program is used to remove all the known varieties of CoolWebSearch that may be on your machine. If you see these you can have HijackThis fix it.

If you didn't add the listed domain to the Trusted Zone yourself, have HijackThis fix it. -------------------------------------------------------------------------- O16 - ActiveX Objects (aka Downloaded Program Files) What it looks like: O16 - You can generally delete these entries, but you should consult Google and the sites listed below.