Treat with extreme care.O22 - SharedTaskSchedulerWhat it looks like: O22 - SharedTaskScheduler: (no name) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c:\windows\system32\mtwirl32.dll What to do:This is an undocumented autorun for Windows NT/2000/XP only, which is In fact a HijackThis log is the first thing they ask for when you discuss your problem on forums.

Unlike typical anti-spyware software, HijackThis does not use signatures or target any specific programs or URL's to detect and block. It is almost guaranteed that some of the items in your HijackThis logs will be legitimate software and removing those items may adversely impact your system or render it completely inoperable.

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO3 - Toolbar: Popup Eliminator - {86BCA93E-457B-4054-AFB0-E428DA1563E1} - C:\PROGRAM FILES\POPUP ELIMINATOR\PETOOLBAR401.DLL (file missing)O3 - Toolbar: rzillcgthjx - {5996aaf3-5c08-44a9-ac12-1843fd03df0a} - C:\WINDOWS\APPLICATION DATA\CKSTPRLLNQUL.DLL What to do:If you don't O15 - Unwanted sites in Trusted ZoneWhat it looks like: O15 - Trusted Zone: http://free.aol.comO15 - Trusted Zone: *.coolwebsearch.comO15 - Trusted Zone: *.msn.comWhat to do:Most of the time only AOL and

Now he was unable to run Powerpoint, nor was he able to scan with the anti-virus as it won't start a scan due to the infections (see the irony). You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file.The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection.

Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone.

Luckily I had HijackThis in my USB drive and it helped analyse the problem and eventually we cleaned it to the point that he could deliver his presentation. Only OnFlow adds a plugin here that you don't want (.ofb).O13 - IE DefaultPrefix hijackWhat it looks like: O13 - DefaultPrefix: http://www.pixpox.com/cgi-bin/click.pl?url=O13 - WWW Prefix: http://prolivation.com/cgi-bin/r.cgi?O13 - WWW.

Article Malware 101: Understanding the Secret Digital War of the Internet Article 4 Tips for Preventing Browser Hijacking Article How To Configure The Windows XP Firewall Article Wireshark Network Protocol Analyzer The HijackThis web site also has a comprehensive listing of sites and forums that can help you out. I know the information can seem overwhelming at first but that's the point.

You will see a plethora of information in a window like the following, this can seem frightening as none of this makes sense at first but lets take a closer look. One of the best places to go is the official HijackThis forums at SpywareInfo. Prefix: http://ehttp.cc/?What to do:These are always bad. You can also check at Process Library or visit here and download the list for use in offline enviornments if you can't get to the Internet.

It was originally developed by Merijn Bellekom, a student in The Netherlands. I am passionate about Computers, Programming, Internet and the Technologies that drive them. Simply scan your system.

It is not rocket science, but you should definitely not do it without some expert guidance unless you really know what you are doing.Once you install HijackThis and run it to How To Analyze HijackThis Logs

They rarely get hijacked, only Lop.com has been known to do this.

Spyware removal software such as Adaware or Spybot S&D do a good job of detecting and removing most spyware programs, but some spyware and browser hijackers are too insidious for even

If you need more help you can connect with me at varun at makeuseof dot com