• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

HijackThis – your first tool for remove homepage hijackers

Myantispyware team December 5, 2005    

HijackThis examines certain key areas of the Registry and Hard Drive and lists their contents. These are areas which are used by both legitimate programmers and hijackers. It’s up to you to decide what should be removed. Some items are perfectly fine. You should not remove them. Never remove everything. Doing that could leave you with missing items needed to run legitimate programs and add-ins.

free antispyware

How to make a HijackThis log.

  • Download HijackThis and save it to your Desktop.
  • Doubleclick on the HJTinstall.exe icon for install (By default it will install to C:\Program Files\Trend Micro\HijackThis). Click on Install, It will create a HijackThis icon on the desktop.
  • Once installed, it will launch Hijackthis. Click on the Do a system scan and save a logfile button. It will scan and the log should open in Notepad.

How to remove malware using HijackThis.

  • Run HijackThis.
  • Click on the Do a system scan only button.
  • Place a checkmark in the box in front of each item you plan to remove.
  • Click the Fix checked button.
  • A confirmation box will appear. Click Yes. HijackThis will now remove the checked items.

How to make a Startup List using HijackThis.

StartupList is a utility which creates a list of everything which starts up when you boot your computer plus a few other items.

  • Run HijackThis.
  • Click on the Open the Misc Tools Section button.
  • Click the Generate StartupList log button. A confirmation box will pop up. Click Yes.
  • The Startup list text file will now be generated and opened on the screen.
  • If you are posting at a Forum, please highlight all, and then copy and paste the contents into your Reply in the same post where you originally asked your question.

Note: If you have run and fixed anything with Spybot Search and Destroy or AdAware, please reboot before scanning.

Download HijackThis

Use the following link: HijackThis download link.

If you are seeking help, then I would recommend that you follow the instructions and post your HijackThis log in the spyware removal forum. Myantispyware.com team will help you.

Free Software
download

 Previous Post

Browser Hijacking

Next Post 

Hijack Removal “How to”

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

27 Comments

  1. Patrik
    ― June 30, 2007 - 8:47 am  Reply

    Don`t post HijackThis logs here, go to Myantispyware forum for get free help!

  2. Jim
    ― December 30, 2007 - 9:24 pm  Reply

    Thanks

  3. charlie johnson
    ― February 25, 2008 - 7:31 pm  Reply

    i need help with these browswer hijackers!

  4. Patrik
    ― February 25, 2008 - 9:04 pm  Reply

    Johnson, read How to use Spyware Removal Forum – MUST READ for get free help.

  5. hemant
    ― November 21, 2008 - 3:09 am  Reply

    i can not remove w32.virut.w
    virus
    by
    combofix smithfroudfix & hijackthis
    help me

  6. Patrik
    ― November 21, 2008 - 3:24 am  Reply

    Hemant, make a new topic at our spyware removal forum. I will help you.

  7. ruth
    ― December 20, 2008 - 11:26 am  Reply

    When I dowloaded hjtinstall to my mac onto a usb drive to install into my PC. I rebooted my PC into use original boot,ini on the sys config utility. (it may have rebooted into a rogue boot.ini beause I get a weird prompt about access denied when I try to restart in a safe mode) and tried to open the hjtinstall.exe from both the usb drive and the desk top. I get the following prompt: THE SERVICE CANNOT BE STARTED, EITHER BECAUSE IT IS DISABLED OR BECAUSE IT HAS NO ENABLED DEVICES ASSOCIATED WITH IT. Any ideas?

  8. Patrik
    ― December 20, 2008 - 9:03 pm  Reply

    ruth, the problem only with HijackThis ? Standart windows apps, notepad for example, works ok ?
    Please read and follow these instructions, skip HijacThis section.

  9. njoro
    ― January 14, 2009 - 2:49 am  Reply

    thanx

  10. Esi
    ― January 22, 2009 - 3:11 pm  Reply

    how to remove Autorun.inf

  11. Patrik
    ― January 22, 2009 - 10:27 pm  Reply

    Esi, use Flash Disinfector.

  12. Crisjoshua
    ― January 29, 2009 - 9:20 am  Reply

    Thanx…

  13. rainbow
    ― April 9, 2009 - 7:45 am  Reply

    I cannot install Hijack, what can I do?

  14. Patrik
    ― April 9, 2009 - 9:18 pm  Reply

    Probably malware blocked it. Ask help at our forum.

  15. aaron
    ― June 7, 2009 - 11:48 am  Reply

    I registered a new account for the forum, received an email, but didnt see the return email address nor the fax number.

    Can someone help on the activation of the account?
    I was able to get rid of the Malware Catcher 2009 but now I cant connect to the Internet. Appreciate help!

  16. Patrik
    ― June 7, 2009 - 11:56 pm  Reply

    aaron, your account is activated.

  17. bo3bo3x86
    ― June 28, 2009 - 3:26 am  Reply

    StartupList report, 28/06/2009, 11:25:29 ص
    StartupList version: 1.52.2
    …

  18. Patrik
    ― June 28, 2009 - 6:53 am  Reply

    bo3bo3x86, please ask help at our Spyware removal forum.

  19. ralph of e
    ― August 14, 2009 - 3:28 pm  Reply

    Nice going. I dowloaded HijackThis, and it keeps shutting down. It won’t run on Vista Home

  20. Patrik
    ― August 15, 2009 - 8:29 am  Reply

    ralph, looks like you PC infected with malware that blocks it. Ask for help at our Spyware removal forum.

  21. amy
    ― September 16, 2009 - 3:15 pm  Reply

    I’ve been trying to get rid of windows police pro. I followed all the directions on you post but couldn’t get MBAM to launch.
    I wanted to post a HijackThis log on the forum but the program just shut down after a minute of scanning. I ran it from a USB drive in safe mode.

    Please help, thanks.

  22. filip
    ― April 22, 2010 - 4:27 am  Reply

    StartupList report, 22.4.2010, 11:26:19
    StartupList version: 1.52.2
    Started from : C:\Program Files\Trend Micro\HijackThis\hijackthis.EXE
    Detected: Windows XP SP2 (WinNT 5.01.2600)
    Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    * Using default options
    ==================================================

    Running processes:

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Prevx\prevx.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Prevx\prevx.exe
    C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\wuauclt.exe

    ————————————————–

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,

    ————————————————–

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

    ————————————————–

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

    ————————————————–

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [OptionalComponents]
    =

    ————————————————–

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    ————————————————–

    Enumerating Task Scheduler jobs:

    At1.job
    At10.job
    At11.job
    At12.job
    At13.job
    At14.job
    At15.job
    At16.job
    At17.job
    At18.job
    At19.job
    At2.job
    At20.job
    At21.job
    At22.job
    At23.job
    At24.job
    At3.job
    At4.job
    At5.job
    At6.job
    At7.job
    At8.job
    At9.job
    {BB65B0FB-5712-401b-B616-E69AC55E2757}.job

    ————————————————–

    Enumerating ShellServiceObjectDelayLoad items:

    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
    CDBurn: C:\WINDOWS\system32\SHELL32.dll
    WebCheck: C:\WINDOWS\System32\webcheck.dll
    SysTray: C:\WINDOWS\System32\stobject.dll
    WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

    ————————————————–
    End of report, 3.673 bytes
    Report generated in 0,063 seconds

    Command line options:
    /verbose – to add additional info on each section
    /complete – to include empty sections and unsuspicious data
    /full – to include several rarely-important sections
    /force9x – to include Win9x-only startups even if running on WinNT
    /forcent – to include WinNT-only startups even if running on Win9x
    /forceall – to include all Win9x and WinNT startups, regardless of platform
    /history – to list version history only

  23. Patrik
    ― April 22, 2010 - 8:54 am  Reply

    filip, please start a new topic in our Spyware removal forum. I will help you.

  24. alfreo
    ― May 7, 2010 - 11:12 pm  Reply

    nice program perfecttttttttttt

  25. Earl
    ― October 3, 2010 - 6:46 pm  Reply

    My computer is infected with “Windows Security Center” Please tell me how I can get rid of it. thank you in advance

  26. Patrik
    ― October 4, 2010 - 9:16 am  Reply

    Earl, open a new topic in our Spyware removal forum. I will help you.

  27. Dart
    ― June 3, 2011 - 5:42 am  Reply

    plz advise me how i get rid of fraudtool hijack as is keep coming up on security 360. is it a false readout. tks

Leave a Reply Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024
Smart Captcha Virus redirect
What is a Virus that Redirects Web Pages? A Comprehensive Guide
Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
How to reset Mozilla Firefox (Updated Apr. 2018)
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]

Recent Guides

Browser Hijacking
How to remove CWS Hijacker
IE flaw lets intruders into Google Desktop
More exploits out for Windows flaws
Vulnerability in the Internet Explorer

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.