Notes:1. [color=#FF0000;]Do not mouse-click Combofix's window while it is running.

Below is a list of these section names and their explanations. This would have a value of http=4 and any future IP addresses added to the restricted sites will be placed in that key.

Hijackthis Log Analyzer

If you would like to see what DLLs are loaded in a selected process, you can put a checkmark in the checkbox labeled Show DLLs, designated by the blue arrow in A new window will open asking you to select the file that you would like to delete on reboot. When you see the file, double click on it.

Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value If you allow HijackThis to remove entries before another removal tool scans your computer, the files from the Hijacker/Spyware will still be left on your computer and future removal tools will

Object Information When you are done looking at the information for the various listings, and you feel that you are knowledgeable enough to continue, look through the listings and select

You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file.The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection. For a great list of LSP and whether or not they are valid you can visit SystemLookup's LSP List Page.

Hijackthis Download

To access the Uninstall Manager you would do the following: Start HijackThis Click on the Config button Click on the Misc Tools button Click on the Open Uninstall Manager button. Spybot can generally fix these but make sure you get the latest version as the older ones had problems. It should be noted that the Userinit and the Shell F2 entries will not show in HijackThis unless there is a non-whitelisted value listed.

Startup Registry Keys: O4 entries that utilize registry keys will start with the abbreviated registry key in the entry listing. You should therefore seek advice from an experienced user when fixing these errors. Example Listings: F2 - REG:system.ini: UserInit=userinit,nddeagnt.exe F2 - REG:system.ini: Shell=explorer.exe beta.exe Registry Keys: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell The Shell registry value is equivalent to the function of Examples and their descriptions can be seen below.

When a user, or all users, logs on to the computer each of the values under the Run key is executed and the corresponding programs are launched. As long as you hold down the control button while selecting the additional processes, you will be able to select multiple processes at one time.

However, since only Coolwebsearch does this, it's better to use CWShredder to fix it.O20 - AppInit_DLLs Registry value autorunWhat it looks like: O20 - AppInit_DLLs: msconfd.dll What to do:This Registry value If you toggle the lines, HijackThis will add a # sign in front of the line.

These versions of Windows do not use the system.ini and win.ini files.

Once you restore an item that is listed in this screen, upon scanning again with HijackThis, the entries will show up again. Any program listed after the shell statement will be loaded when Windows starts, and act as the default shell. Let's break down the examples one by one. 04 - HKLM\..\Run: [nwiz] nwiz.exe /install - This entry corresponds to a startup launching from HKLM\Software\Microsoft\Windows\CurrentVersion\Run for the currently logged in user. Items listed at HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ ShellServiceObjectDelayLoad are loaded by Explorer when Windows starts.

O17 Section This section corresponds to Lop.com Domain Hacks. To find a listing of all of the installed ActiveX component's CLSIDs, you can look under the HEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ Windows Registry key.

O7 Section This section corresponds to Regedit not being allowed to run by changing an entry in the registry. This line will make both programs start when Windows loads. Since the LSPs are chained together, when Winsock is used, the data is also transported through each of the LSPs in the chain.

When Internet Explorer is started, these programs will be loaded as well to provide extra functionality.