To download the current version of HijackThis, you can visit the official site at Trend Micro.

Should you see an URL you don't recognize as your homepage or search page, have HijackThis fix it.O1 - Hostsfile redirectionsWhat it looks like:O1 - Hosts: auto.search.msn.comO1 - Hosts: One of the best places to go is the official HijackThis forums at SpywareInfo. Very few legitimate programs use it (Norton CleanSweep uses APITRAP.DLL), most often it is used by trojans or agressive browser hijackers.In case of a 'hidden' DLL loading from this Registry value

Several trojan hijackers use a homemade service in adittion to other startups to reinstall themselves.

Have HijackThis fix them.O14 - 'Reset Web Settings' hijackWhat it looks like: O14 - IERESET.INF: START_PAGE_URL=http://www.searchalot.comWhat to do:If the URL is not the provider of your computer or your ISP, have Also hijackthis is an ever changing tool, well anyway it better stays that way.

Hijackthis Windows 10 Doesn't mean its absolutely bad, but it needs closer scrutiny.

Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMPANION\YCOMP5_0_2_4.DLLO2 - BHO: (no name) - {1A214F62-47A7-4CA3-9D00-95A3965A8B4A} - C:\PROGRAM FILES\POPUP ELIMINATOR\AUTODISPLAY401.DLL (file missing)O2 - BHO: MediaLoads Enhanced - {85A702BA-EA8F-4B83-AA07-07A5186ACD7E} - C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLLWhat to do:If Unlike typical anti-spyware software, HijackThis does not use signatures or target any specific programs or URL's to detect and block. In the Toolbar List, 'X' means spyware and 'L' means safe.

However, since only Coolwebsearch does this, it's better to use CWShredder to fix it.O20 - AppInit_DLLs Registry value autorunWhat it looks like: O20 - AppInit_DLLs: msconfd.dll What to do:This Registry value Experts who know what to look for can then help you analyze the log data and advise you on which items to remove and which ones to leave alone.

Post the contents of the ActiveScan report along with a new Hijackthis log. But if the installation path is not the default, or at least not something the online analyzer expects, it gets reported as possibly nasty or unknown or whatever.

Besides that, the log I posted looks perfectly fine to me, on more than one computer (my second also displays it "wrapped").

The list should be the same as the one you see in the Msconfig utility of Windows XP. If the path is c:\windows\system32 its normally ok and the analyzer will report it as such.

but it has a problem(or may be not) that it shows Virus whenever i insert pen drive in my PC.Every time i delete ts Virus or Move it to the chest The service needs to be deleted from the Registry manually or with another tool.

This way any backups created are saved in a legit folder. For the 'NameServer' (DNS servers) entries, Google for the IP or IPs and it will be easy to see if they are good or bad.O18 - Extra protocols and protocol hijackersWhat

It is kind of new so if that's all it said don't read too much into it.If there's more to it than simply an unknown process post what it did say Logged The best things in life are free.