Hijack This Log Tutorial


A style sheet is a template for how page layouts, colors, and fonts are viewed from an html page. Note: In the listing below, HKLM stands for HKEY_LOCAL_MACHINE and HKCU stands for HKEY_CURRENT_USER. If the Hosts file is located in a location that is not the default for your operating system, see table above, then you should have HijackThis fix this as it is

To access the Hosts file manager, you should click on the Config button and then click on the Misc Tools button. Figure 12: Listing of found Alternate Data Streams To remove one of the displayed ADS files, simply place a checkmark next to its entry and click on the Remove selected O13 - WWW.

It is possible to change this to a default prefix of your choice by editing the registry. The Shell= statement in the system.ini file is used to designate what program would act as the shell for the operating system.

When you fix O4 entries, Hijackthis will not delete the files associated with the entry.

This location, for the newer versions of Windows, are C:\Documents and Settings\All Users\Start Menu\Programs\Startup or under C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup in Vista. The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'O?'ŽrtñåȲ$Ó'.

In the last case, have HijackThis fix it. -------------------------------------------------------------------------- O19 - User style sheet hijack What it looks like: O19 - User style sheet: c:\WINDOWS\Java\my.css By default Windows will attach a http:// to the beginning, as that is the default Windows Prefix. You can always have HijackThis fix these, unless you knowingly put those lines in your Hosts file.The last item sometimes occurs on Windows 2000/XP with a Coolwebsearch infection. Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it. -------------------------------------------------------------------------- O1 - Hostsfile redirections What it looks like: O1 - Hosts:

HiJackThis includes a process manager tool that acts like an enhanced version of the Windows Task manager. If it's not on the list and the name seems a random string of characters and the file is in the 'Application Data' folder (like the last one in the examples Check the box next to each entry that you want to restore to your system. 4 Restore the selected items. How to use the Delete on Reboot tool At times you may find a file that stubbornly refuses to be deleted by conventional means.

