O23 - NT ServicesWhat it looks like: O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exeWhat to do:This is the listing of non-Microsoft services. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 11:45:09 PM, on 10/21/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: Treat with extreme care.O22 - SharedTaskSchedulerWhat it looks like: O22 - SharedTaskScheduler: (no name) - {3F143C3A-1457-6CCA-03A7-7AA23B61E40F} - c:\windows\system32\mtwirl32.dll What to do:This is an undocumented autorun for Windows NT/2000/XP only

The F1 items are usually very old programs that are safe, so you should find some more info on the filename to see if it's good or bad. You'll be able to further disable some of these through Windows system settings or with additional Windows optimizing software like Glary Utilities.

Please make a new folder to put your HijackThis.exe into. You can select an individual item by highlighting it or clicking the check box and hitting the "Info on Selected Item" button. Double click on RSIT.exe to run RSIT.

In the BHO List, 'X' means spyware and 'L' means safe.O3 - IE toolbarsWhat it looks like: O3 - Toolbar: &Yahoo! All passwords should be changed immediately to to include those used for banking, email, eBay, paypal and any online activities which require a username and password. The known baddies are 'cn' (CommonName), 'ayb' (Lop.com) and 'relatedlinks' (Huntbar), you should have HijackThis fix those.

O15 - Unwanted sites in Trusted ZoneWhat it looks like: O15 - Trusted Zone: http://free.aol.comO15 - Trusted Zone: *.coolwebsearch.comO15 - Trusted Zone: *.msn.comWhat to do:Most of the time only AOL and Problem with these infections nowadays is, it causes a lot of damage.

See here for specific instructions and screen shots to help: http://russelltexas.com/malware/createhjtfolder.htmThis is to ensure it makes the necessary backups for recovery if needed. Running the program and interpreting its results can be confusing.

If not, an attacker may get the new passwords and transaction information. Click Continue at the disclaimer screen. I will be working on your Malware issues. You will see it in the 09's and the 023s especially.

Most of the databases used to lookup HJT items have links for reference to the file names - very useful in these cases :)In other words, just finding out a file Much more indispensable is the Backups menu that's right next to the Miscellaneous Tools list on the configuration menu. It's a standard prerequisite, but free and relatively quick. I prefer a CD because a storage device can get infected.

When disinfection is attempted, the files often become corrupted and the system may become unstable or irreparable. Thank you for signing up. If you don't know or understand something, please don't hesitate to ask.4.

The first defense against infection is a properly patched system and browser.http://v5.windowsupdate.microsoft.com/en/default.aspEncourage them to set their PC for automatic updates so that they won't miss any. GMER will produce a log. Help: I Got Hacked.

When completed, a log will open in Notepad. For the R3 items, always fix them unless it mentions a program you recognize, like Copernic.F0, F1, F2, F3 - Autoloading programs from INI filesWhat it looks like:F0 - system.ini: Shell=Explorer.exe

The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper', but the internal name (between brackets) is a string of garbage, like 'Ort'.

A case like this could easily cost hundreds of thousands of dollars. We suggest you use something like "C:\Program Files\HijackThis" but feel free to use any name. I will be helping you out with your particular problem on your computer.

Record Number: 82 Source Name: Userenv Time Written: 20090621134352.000000+570 Event Type: warning User: NT AUTHORITY\SYSTEM Computer Name: BAR Event Code: 1517 Message: Windows saved user BAR\Admin registry while an application or