For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackers

and post the DDS logs to continue the cleaning process. Firewalls and other important programs but rogue cleaning programs like AlfaCleaner may also load here. Re: Can't delete UCGuard yazzybee, Hi, Sorry if i'm doing this the wrong way but i have the same problem as pedromatt. And when I reboot in safe mode, the computer restarts every time I get back to my desktop.

O2 - BHO: Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO2 - BHO: (no name) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C:\PROGRAM FILES\POPUP ELIMINATOR\AUTODISPLAY401.DLL (file missing)O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLLWhat to do:If If the name or URL contains words like 'dialer', 'casino', 'free_plugin' etc, definitely fix it.

You canupload your log to the Hijackthis.de Online Analyzer O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key What it looks like: O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O21 - SSODL:

This is a basic guide to understanding the HijackThis logs, what specific sections mean and some tips on reading it yourself.

In March 2007, Merijn sold Hijackthis to TrendMicro because he didnt have the time and energy to update it and support it. O14 - 'Reset Web Settings' hijack What it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.com What to do: If the URL is not the provider of your computer or your ISP, have HijackThis fix it.

O18 - Extra protocols and protocol hijackers What it looks like: O18 - Protocol: relatedlinks - {5AB65DD4-01FB-44D5-9537-3767AB80F790} - C:PROGRA~1\COMMON~1\MSIETS\msielink.dll O18 - Protocol: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} O18 - Protocol hijack: http -

Continue Reading Up Next Up Next Article 4 Tips for Preventing Browser Hijacking Up Next Article How To Configure The Windows XP Firewall Up Next Article Wireshark Network Protocol Analyzer Up http://exomatik.net/hijackthis-log/hijackthis-log-what-to-keep-and-get-rid-of.php icazzy Posts: 4Joined: Tue Feb 16, 2010 1:18 pmLocation: Gainesboro, TN Top Reply with quote Re: can't run Malwarebytes or Hijackthis by patrik » Tue Feb 23, 2010 6:21 pm Last #blog post https://t.co/Y5VLTAalDC Stay tuned… https://t.co/DRLPpFxJ5E » from ToolsLib, Keep in touch © 2017 ToolsLib My Anti Spyware Post your problems with Spyware, Hijackers, Trojans... But on the infected computer, I keep getting the same message above. Hijackthis Windows 7

In HijackThis 1.99.1 or higher, the button 'Delete NT Service' in the Misc Tools section can be used for this. Thanks. This version will download a zip. http://exomatik.net/hijackthis-log/hijackthis-log-aky.php If it does not automatically open, then these logs can be found at %systemdrive%\rsit folder (typically C:\rsit)Post back with both RSIT logs.

O10 - Winsock hijackers What it looks like: O10 - Hijacked Internet access by New.Net O10 - Broken Internet access because of LSP provider 'c:progra~1\common~2\toolbarcnmib.dll' missing O10 - Unknown file in

The F1 items are usually very old programs that are safe, so you should find some more info on the filename to see if it's good or bad.

F0, F1, F2, F3 - Autoloading programs F0 - Changed inifile value F1 - Created inifile value F2 - Changed inifile value, mapped to Registry F3 - Created inifile value, mapped

O1 - Hosts file redirection What it looks like: O1 - Hosts: auto.search.msn.com O1 - Hosts: search.netscape.com O1 - Hosts: ieautosearch What to do: This hijack will redirect Trend Micro has incorporated many of Merijn's changes, updates, and fixes and released a version 2 of Hijackthis.

In the last case, have HijackThis fix it.

In the last case, have HijackThis fix it. It's time for a cup of coffee.