HijackThis opens you a possibility to find and fix nasty entries on your computer easier. Therefore it will scan special parts in the registry and on your harddisk and compare them with the default settings. If there is some abnormality detected on your computer HijackThis will save them into a logfile. In order to find out what entries are nasty and what are installed by the user, you need some background information.
A HijackThis logfile is not so easy to analyze. Even for an advanced computer user. Previously I’ve shared with you a few websites that is able to help you identify which startup program is good or bad but it’s still a tedious job because you have to analyze line by line. Today I am going to share with you 5 ways to automatically analyze HijackThis! log file. All you need to do is just paste your complete logfile into the textbox, wait for a few seconds and the report will give get recommendations based on that analysis.
Do take note that the results and recommendation generated by these hijackthis log analyzers are not 100% accurate and is to be used for reference purposes only. An automatic analysis should NEVER substitute an expert’s analysis.
1. HijackThis.DE Logfile Analyzer

You can either paste the log file to the text box or upload the log file from your computer to HijackThis.DE Logfile analyzer. This is one of the best automated HijackThis log file analyzer because the report is easy to read and it shows visitors rating. Instead of having the long analysis, you can opt for short analysis at the end of the report. Short analysis will only display the entries that it advice you to remove.
[ Visit HijackThis.de Logfile Analyzer ]
2. HiJackThis! Log Auto Analyzer V2

Everything is color coded to help you determine which category each item falls under. It uses Tony Kleins BHO DB + our its additions to find to help you figure out which items in your log are OK and which ones are bad! To display more information about the entry, just move your mouse over the line. This is also one of my favorite.
[ Visit HijackThis! Log Auto Analyzer V2 ]
3. Help2Go Detective

Help2Go Detective is able to detect 11504 malware, including the Peper and CoolWebSearch trojans. It will only let you know the malicious, suspicious and suggestions. The safe ones won’t be displayed.
[ Visit Help2Go Detective ]
4. Prevx HijackThis Log Analyzer

Prevx HijackThis Log Analyzer is the worst among all. It only scans the filenames and path. I’ve tried analyzing a few log files from computers that is infected by spywares but it couldn’t determine anything bad in the HijackThis Log. Maybe this analyzer is fake, but I’ll include the link if you’d like to check it out.
[ Visit Prevx HijackThis Log Analyzer ]
5. HijackReader v1.03 Beta

The final one is a free tool (not website). HijackReader automatically searches Pacman’s startup list as well as Tony Klein’s Browser Helper Object (BHO) list. After scanning all entries from the HijackThis log that you pasted, it will create a HTML report file.
[ Download HijackReader ]
You can use all 5 methods for better accuracy to determine if an entry is good or bad. Again, I just want to make it clear that the 4 websites and 1 tool is to provide only an analysis on the log file created by HijackThis. If you’re looking for the HijackThis program, you can get it from the link.
Related posts:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:32:09, on 21.11.2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Trident Software\Pragma6\pkernel.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\uTorrent\uTorrent.exe
D:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trident Software\Pragma6\pservice.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtblfs.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Program Files\Download Master\Download Master\dmaster.exe
C:\WINDOWS\system32\msiexec.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = yahoo.com
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = yandex.ru/
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com/fwlink/?LinkId=69157
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com/fwlink/?LinkId=54896
R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com/fwlink/?LinkId=54896
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
O2 – BHO: IEVkbdBHO Class – {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
O2 – BHO: EWPBrowseObject Class – {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} – C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 – BHO: Groove GFS Browser Helper – {72853161-30C5-4D22-B7F9-0BBC1D38A37E} – C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 – BHO: IE 4.x-6.x BHO for Download Master – {9961627E-4059-41B4-8E0E-A7D6B3854ADF} – D:\PROGRA~1\DOWNLO~2\DOWNLO~1\dmiehlp.dll
O2 – BHO: Google Toolbar Notifier BHO – {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} – C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 – BHO: Java(tm) Plug-In 2 SSV Helper – {DBC80044-A445-435b-BC74-9C25C1C588A9} – C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 – BHO: FilterBHO Class – {E33CF602-D945-461A-83F0-819F76A199F8} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O2 – BHO: JQSIEStartDetectorImpl – {E7E6F031-17CE-4C07-BC86-EABFE594F69C} – C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 – Toolbar: DM Bar – {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} – D:\Program Files\Download Master\Download Master\dmbar.dll
O3 – Toolbar: Easy-WebPrint – {327C2873-E90D-4c37-AA9D-10AC9BABA46C} – C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 – HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 – HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 – HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 – HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 – HKLM\..\Run: [Pragma6] C:\Program Files\Trident Software\Pragma6\pkernel.exe
O4 – HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
O4 – HKLM\..\Run: [AVP] “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe”
O4 – HKCU\..\Run: [Hotmail] C:\WINDOWS\system32\rundll32.exe
O4 – HKCU\..\Run: [swg] “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”
O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 – HKCU\..\Run: [uTorrent] “C:\Program Files\uTorrent\uTorrent.exe”
O4 – HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘LOCAL SERVICE’)
O4 – HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘NETWORK SERVICE’)
O4 – HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
O4 – HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
O4 – Startup: HDDlife.lnk = D:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
O8 – Extra context menu item: Translate with Lingvo – res://D:\Program Files\Lingvo.exe/3000
O8 – Extra context menu item: Высокоскоростная печать Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 – Extra context menu item: Добавление в список для печати Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 – Extra context menu item: Закачать ВСЕ при помощи Download Master – D:\Program Files\Download Master\Download Master\dmieall.htm
O8 – Extra context menu item: Закачать при помощи Download Master – D:\Program Files\Download Master\Download Master\dmie.htm
O8 – Extra context menu item: Передать на удаленную закачку DM – D:\Program Files\Download Master\Download Master\remdown.htm
O8 – Extra context menu item: Печать Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O8 – Extra context menu item: Предварительный просмотр Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O9 – Extra button: Отправить в OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 – Extra ‘Tools’ menuitem: &Отправить в OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 – Extra button: &Виртуальная клавиатура – {4248FE82-7FCB-46AC-B270-339F08212110} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O9 – Extra button: Download Master – {8DAE90AD-4583-4977-9DD4-4360F7A45C74} – D:\Program Files\Download Master\Download Master\dmaster.exe
O9 – Extra ‘Tools’ menuitem: &Download Master – {8DAE90AD-4583-4977-9DD4-4360F7A45C74} – D:\Program Files\Download Master\Download Master\dmaster.exe
O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 – Extra button: Проверка ссы&лок – {CCF151D8-D089-449F-A5A4-D9909053F20F} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
O9 – Extra button: (no name) – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 – Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 – DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} – platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 – HKLM\System\CCS\Services\Tcpip\..\{E0346D98-39F7-410D-B76E-73A08B334F55}: NameServer = 192.168.1.1,195.5.21.188
O18 – Protocol: grooveLocalGWS – {88FED34C-F0CA-4636-A375-3CB6248B04CD} – C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 – Protocol: hddlife – {BD758015-47D9-477A-8873-4B688A2BC0E2} – “C:\Program Files\Common Files\BinarySense\hlAPP.dll” (file missing)
O20 – AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~3\mzvkbd3.dll
O23 – Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) – ABBYY (BIT Software) – D:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
O23 – Service: Acronis Scheduler2 Service (AcrSch2Svc) – Acronis – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 – Service: Ati HotKey Poller – ATI Technologies Inc. – C:\WINDOWS\system32\Ati2evxx.exe
O23 – Service: Kaspersky Anti-Virus Service (AVP) – Kaspersky Lab ZAO – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
O23 – Service: Журнал событий (Eventlog) – Корпорация Майкрософт – C:\WINDOWS\system32\services.exe
O23 – Service: FLEXnet Licensing Service – Macrovision Europe Ltd. – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 – Service: Google Software Updater (gusvc) – Google – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 – Service: HDDlife HDD Access service – BinarySense, Inc. – C:\Program Files\Common Files\BinarySense\hldasvc.exe
O23 – Service: Служба COM записи компакт-дисков IMAPI (ImapiService) – Корпорация Майкрософт – C:\WINDOWS\system32\imapi.exe
O23 – Service: Java Quick Starter (JavaQuickStarterService) – Sun Microsystems, Inc. – C:\Program Files\Java\jre6\bin\jqs.exe
O23 – Service: NetMeeting Remote Desktop Sharing (mnmsrvc) – Корпорация Майкрософт – C:\WINDOWS\system32\mnmsrvc.exe
O23 – Service: Plug and Play (PlugPlay) – Корпорация Майкрософт – C:\WINDOWS\system32\services.exe
O23 – Service: Pragma6Serv – Trident Software, Ltd. – C:\Program Files\Trident Software\Pragma6\pservice.exe
O23 – Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) – Корпорация Майкрософт – C:\WINDOWS\system32\sessmgr.exe
O23 – Service: Смарт-карты (SCardSvr) – Корпорация Майкрософт – C:\WINDOWS\System32\SCardSvr.exe
O23 – Service: Журналы и оповещения производительности (SysmonLog) – Корпорация Майкрософт – C:\WINDOWS\system32\smlogsvc.exe
O23 – Service: Теневое копирование тома (VSS) – Корпорация Майкрософт – C:\WINDOWS\System32\vssvc.exe
O23 – Service: Адаптер производительности WMI (WmiApSrv) – Корпорация Майкрософт – C:\WINDOWS\system32\wbem\wmiapsrv.exe
–
End of file – 10383 bytes
El HijackThis log file analysis en dos entradas me indica \”Fuzzy Algorithmcheck (x.xx / x.xx) Nasty\” , las x representan unos valores que pone.
Es correcto darle fix a estas entradas?
very helpful!
Dear Raymond Sir,
I used the 3 of the analysers you stated above. One said that there is no error. one said i should remove ctfmon. and another one said that ctfmon is good. What should i do?
From: A puzzled person…
my task manager always show the “conime.exe” , use antivirus also cannot delete it. What is that ? a virus?
What about HiJackFree. How good is it compared to HJT?
HJT is not enough. It wont never show u for example bagle infection – so i use combofix to fix this ;>
great! nice software! thanks a lot! :D