ok first off before you post a hijack this log you should probably do a basic spyware/virus scan with ad-aware, spybot S&D, and you anti virus software software.

Also make sure that when fixing problems to back up the files either via system restore or hijackthis will do it for you.

Now when you scan with hijack this you arent really going to understand what it is saying so to help you out here are somethings to watch for.

1.Things that are potentially viruses:

Sometimes you can tell if something is a virus by the name i would watch out for things that are like random series of letters of numbers i.e gf324sd.exe or 123fre786.exe these are probably viruses.

2. Here are some basic spyware things that you should watch out for:
webrebates
ebatesmoneymaker
mysearch bar
myfunstart
bargain buddy
cydoor
cool websearch
gator
xxxtoolbar
well those are just some of the main ones the occur frequently.

3.How to make sure spyware and viruses dont return or are properly deleted:
Well first off you should make sure that you have proper firewalls in place most makers of anti-virus software also make firewalls. The windows firewall should be up (if running sp2 it well inform you when either anti-virus or firewall software is disabled).
A good way to make sure that spyware does not return is to get something like spyware blaster which blocks sites and active x controllers associated with spyware send info onto your computer.
Now to make sure that spyware and viruses are deleted you should scan for spyware after restarting your computer. Now when using hijackthis it will not show you things like what processes are running while you are in the program so you have to save the log and exit out and when you open the log it should have a list of programs and their locations that where running on your computer while scanning. Now if one of these processes looks like it could be a virus or is known to be a virus then open up your task manager stop that process (make sure it doesn't restart) goto the location that is in your log (usually C:\WINDOWS\System32) then find the file (you might have to turn on view hidden files and folders in the folders properties) and delete it (make sure that you have set a restore point before deleting) then empty you recycle bin and restart. When restarting hit Esc+F8 and choose boot into safe mode. when you boot into safe mode check to see that the file is gone and then reboot normally.

that covers some pretty basic stuff you should look for in hijack this.

Dani AI

Generated

Good, practical start from — scanning and backing up before you touch anything is exactly the right mentality. Add two pre‑flight items: make a full disk image (so you can recover a known‑good state) and gather minimal context for helpers (OS version, anti‑malware product + last update, and the saved HJT logfile). For stubborn or high‑risk compromises, rebuilding/reimaging is the safest eradication strategy rather than endless manual edits. ([CISA guidance on rebuilding/reimaging])(https://www.cisa.gov/eviction-strategies-tool/info-countermeasures/CM0027). (cisa.gov)

How to read HJT quickly: the tool lists categories (browser helper objects, autostart entries, services, DNS/search changes). Example lines and what they mean:

O2 - BHO: Example BHO - {CLSID} - C:\Users\Alice\AppData\Roaming\example.dll
O4 - HKCU\..\Run: [ExampleStart] "C:\Users\Alice\AppData\Roaming\example.exe" /run
O23 - Service: ExampleService - Unknown owner - C:\Program Files\Example\svc.exe
O17 - NameServer = 1.2.3.4

Red flags: entries that show “(no file)”, executables living in temporary or roaming folders, randomized filenames, changed DNS/search settings, or services with no publisher. Use an HJT reference and community lists before fixing anything — HJT is a diagnostic enumerator, not an automated cure. ([HJT tutorial])(https://aumha.org/a/hjttutor.php) · ([community HJT help])(https://www.bleepingcomputer.com/forums/t/67882/hijack-log-analysis/page-1). (aumha.org)

Safe triage workflow: disable (don’t immediately delete) suspicious autostarts with Autoruns and inspect live behavior with Process Explorer. Check unknown file hashes or URLs on VirusTotal and run an up‑to‑date anti‑malware scanner (see vendor cleanup guides). If files are locked, use offline rescue media or a clean image to remove them; reimage when persistence or rootkit behavior is suspected. ([Autoruns / Process Explorer docs])(https://learn.microsoft.com/) · ([Malware removal steps])(https://www.malwarebytes.com/cybersecurity/basics/how-to-remove-virus-from-computer). (learn.microsoft.com)

Finally, don’t paste your HJT into someone else’s thread — open a fresh topic, include the HJT log and the context items above, and helpers can give targeted advice.

please add your own add ons and comments.

Also it is not nice to post your log in someone elses thread because everyone usually has different logs.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.