OK,a few more links and tips to get you hooked!
search startups like this one ,O4 - HKLM\..\Run: [SystemTray] SysTray.Exe, you can search either ,this from inside the brackets,"SystemTray" or the EXE listed .
Startup link !=
http://castlecops.com/StartupList.html
Search BHOs' and CLSID ,like this ,O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL, by searching the large number ! with out the brackets,{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} search here =
http://castlecops.com/CLSID.html
Then i can use Spywareblaster to search this one ,using the large number as above .
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/...all/xscan53.cab
I use CSWShredder in Debug mode to search this line for CSW vairents
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://kon4ay.biz/k/
taking the ,kon4ay.biz and paste it in shredder debug mode and search and its a needles search site but not a cws variant .
but others aren't !!
I use this site to search the 020,021,022,023
http://www.fbeej.dk/NewHJTEntries.htm
this site for the 010s'
http://castlecops.com/LSPs.html
Another Hijackthis tutorial.
http://www.bleepingcomputer.com/foru...howtutorial=42