Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone.

O1 - Hostsfile redirections What it looks like: O1 - Hosts: What to do: Unless you have the Spybot S&D option 'Lock homepage from changes' active, or your system administrator put this into place, have HijackThis fix this. O7 - Regedit

RP372: 9/27/2011 12:05:32 PM - Installed Windows XP KB2544521. But we still have problems with Google and Bing searches in both IE and Firefox, so I don't thinkg it's a browser issue. The below information was originated from Merijn's official tutorial to using Hijack This. You need to investigate what you see.

Why am I getting an 'Unexpected error' about a missing OCX file when running HijackThis? It was originally developed by Merijn Bellekom, a student in The Netherlands. A case like this could easily cost hundreds of thousands of dollars. C:\WINDOWS\system32\nslsvice.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\DisplayLink Core Software\DisplayLinkUserAgent.exe svchost.exe svchost.exe C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe C:\WINDOWS\system32\spoolsv.exe c:\drivers\audio\r213367\stacsv.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe

For the R3 items, always fix them unless it mentions a program you recognize, like Copernic. F0, F1, F2, F3 - Autoloading programs from INI files What it looks like:

RP366: 9/27/2011 11:46:29 AM - Installed Windows XP KB2566454. The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'O?'ŽrtñåȲ$Ó'.

What to do: Most of the time only AOL and Coolwebsearch silently add sites to the Trusted Zone.

GMER will produce a log. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-11-1 66536] S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\drivers\nvtsp50.sys --> c:\windows\system32\drivers\NvtSp50.sys [?] S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952] . =============== Created Last 30 ================ . 2011-09-30 17:02:36 -------- d-----w- c:\windows\system32\CatRoot_bak 2011-09-27 21:23:51 472808 ----a-w- What should i do now? http://exomatik.net/hjt-log/hjt-log-persistant-browser-hijack.php SuperAntiSpyware - Files Infected: Adware.Tracking Cookie C:\DOCUMENTS AND SETTINGS\[%user%]\COOKIES\[%user%]@MICROSOFTWINDOWS.112.2O7[1].TXT Trojan.Agent/Gen-Cryptor[Egun] C:\WINDOWS\INSTALLER\MSI157.TMP Host file hack: #::1 localhost www.google-analytics.com. ad-emea.doubleclick.net. www.statcounter.com.

Go to this mirror of my site: and try to download there. RP357: 9/27/2011 11:11:40 AM - Installed Windows XP KB2509553.

RP361: 9/27/2011 11:28:28 AM - Installed Windows XP KB2567680. For example: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1 HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\2 What to do: If you did not add these Active Desktop Components yourself, you should run a good anti-spyware removal program

O7 - Regedit access restricted by AdministratorWhat it looks like:O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1What to do:Always have HijackThis fix this, unless your system administrator has put this restriction into place.O8 - Extra

This MGlogs.zip will then be attached to a message. Using CWShredder causes the CPU usage of SERVICES.EXE to go to 100%! BLEEPINGCOMPUTER NEEDS YOUR HELP! Ad aware finds it too deletes but after some time they appear again.

This procedure checks the Windows hosts file. They rarely get hijacked, only Lop.com has been known to do this.

Your system may take longer than usual to load; this isnormal.At the end of the fix, you may need to restart your computer again.Finally, please post a fresh HijackThis log

RP362: 9/27/2011 11:33:27 AM - Installed Windows XP KB2555917.