<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; hijackthis</title>
	<atom:link href="http://www.ghacks.net/tag/hijackthis/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Mon, 09 Nov 2009 23:09:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Unknown File in Winsock LSP NWPROVAU.DLL</title>
		<link>http://www.ghacks.net/2009/04/27/unknown-file-in-winsock-lsp-nwprovaudll/</link>
		<comments>http://www.ghacks.net/2009/04/27/unknown-file-in-winsock-lsp-nwprovaudll/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 08:09:22 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[hijackthis]]></category>
		<category><![CDATA[lsp-fix]]></category>
		<category><![CDATA[nwprovau.dll]]></category>
		<category><![CDATA[winsock]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2009/04/27/unknown-file-in-winsock-lsp-nwprovaudll/</guid>
		<description><![CDATA[A recent scan of a Windows XP SP3 computer system with HijackThis displayed the following entry in the results: O10 &#8211; Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll. Nwprovau.dll is usually installed for the IPX / SPX protocol, something that is rarely &#8211; if at all &#8211; used anymore these days. It is still in most [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/microsoft_windows.jpg" alt="microsoft windows" title="microsoft windows" width="128" height="128" class="alignleft size-full wp-image-11907" />A recent scan of a Windows XP SP3 computer system with <a href="http://www.ghacks.net/2007/03/12/hijack-this-20-beta/">HijackThis</a> displayed the following entry in the results: <strong>O10 &#8211; Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll</strong>. Nwprovau.dll is usually installed for the IPX / SPX protocol, something that is rarely &#8211; if at all &#8211; used anymore these days. It is still in most cases a legit dynamic link library and most would suggest leaving it alone because of this. It is on the other hand not really needed if Netware is not being used on the computer system.</p>
<p><span id="more-12393"></span>It is however not possible to fix the item directly in HijackThis. A portable software program called <a href="http://www.cexx.org/lspfix.htm">LSP-Fix</a> comes to the rescue. It has been primarily designed to fix Winsock errors.</p>
<p><img src="http://www.ghacks.net/wp-content/uploads/2009/04/winsock2-500x401.jpg" alt="winsock 2" title="winsock 2" width="500" height="401" class="alignnone size-medium wp-image-12392" /></p>
<p>The program is interesting in this case as it can be used to remove the nwprovau.dll dynamic link library from the computer system. The box &#8220;I know what I&#8217;m doing&#8221; has to be checked before that option becomes available. The program lists the currently installed dll files in the left column, nwprovau.dll should be one of them. All that needs to be done is to select this dll and click on the arrow that is pointing to the right to move it to the Remove column. Keep in mind that this will remove the dll permanently from the computer system (creating a backup before proceeding might be a good idea)</p>
<p>A click on the Finish button will complete the process and remove all files that are listed in the Remove column from the computer system. </p>

	Tags: <a href="http://www.ghacks.net/tag/hijackthis/" title="hijackthis" rel="tag">hijackthis</a>, <a href="http://www.ghacks.net/tag/lsp-fix/" title="lsp-fix" rel="tag">lsp-fix</a>, <a href="http://www.ghacks.net/tag/nwprovaudll/" title="nwprovau.dll" rel="tag">nwprovau.dll</a>, <a href="http://www.ghacks.net/tag/software/" title="software" rel="tag">software</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a>, <a href="http://www.ghacks.net/tag/winsock/" title="winsock" rel="tag">winsock</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/" title="HijackReader analyse HijackThis results (February 8, 2008)">HijackReader analyse HijackThis results</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/06/08/zip-repair/" title="Zip Repair (June 8, 2008)">Zip Repair</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/07/15/zen-key-an-all-purpose-application-manager/" title="Zen Key An All Purpose Application Manager (July 15, 2008)">Zen Key An All Purpose Application Manager</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/05/13/youtube-batch-downloader/" title="Youtube Batch Downloader (May 13, 2008)">Youtube Batch Downloader</a> (13)</li>
	<li><a href="http://www.ghacks.net/2008/07/10/yahoo-widget-position-restorer/" title="Yahoo Widget Position Restorer (July 10, 2008)">Yahoo Widget Position Restorer</a> (1)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2009/04/27/unknown-file-in-winsock-lsp-nwprovaudll/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>HijackReader analyse HijackThis results</title>
		<link>http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/</link>
		<comments>http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 10:42:01 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[hijackreader]]></category>
		<category><![CDATA[hijackthis]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/</guid>
		<description><![CDATA[HiJackThis</a> is a sophisticated security tool that checks a computer running Windows 2000 or higher for possible signs of hijacked applications. It does check lots of different elements like startup items, Browser Helper Objects, running processes and the like and presents a log of the results at the end. This log is hard to read for beginners because it contains "good" and possible "bad" elements in it and it requires knowledge of those elements to make a distinction between elements that you have to keep and those that are indeed malicious in nature.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.spywareinfo.com/~merijn/programs.php#hijackthis">HiJackThis</a> is a sophisticated security tool that checks a computer running Windows 2000 or higher for possible signs of hijacked applications. It does check lots of different elements like startup items, Browser Helper Objects, running processes and the like and presents a log of the results at the end. This log is hard to read for beginners because it contains &#8220;good&#8221; and possible &#8220;bad&#8221; elements in it and it requires knowledge of those elements to make a distinction between elements that you have to keep and those that are indeed malicious in nature.</p>
<p>Most users tend to post their logs in forums so that experienced users can take a look at them and recommend actions. There are actually several forums that can be used. </p>
<p>If you would like fast results you could also use the software <a href="http://www.hollmen.dk/content/view/69/31">HijackReader</a> which analyzes an HijackThis logfile and tries to make the distinction between good and bad results automatically. The HijackReader uses mainly two lists to analyze the logfile. </p>
<p><span id="more-3164"></span><img src='http://www.ghacks.net/wp-content/uploads/2008/02/hijackreader.jpg' alt='hijackreader' /></p>
<p><a href="http://www.sysinfo.org/">Those</a> two lists are the CLSID list by Tony Klein and the Startup info list by Paul Collins. A single html file is created after the analysis has finished displaying information and recommendations about the found elements. Attributes can either be OK (no fix needed), FIX IF UNKNOWN (check for more information if you do not know the element), FIX (CHECK NOTES!) (read the description and fix the issue because it is indeed malicious) and UNDETERMINED (find out for yourself).</p>
<p>The HijackReader application can be of help especially if items are found that are marked as Fix (Check Notes). The user can fix those without having to wait for someone else to analyze his logfile and tell him the exact same thing. It does not help that much for elements that are undetermined or marked as fix if unknown and users will still have to get professional help or do extensive research before they can be sure if the item is malicious or not.</p>

	Tags: <a href="http://www.ghacks.net/tag/hijackreader/" title="hijackreader" rel="tag">hijackreader</a>, <a href="http://www.ghacks.net/tag/hijackthis/" title="hijackthis" rel="tag">hijackthis</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/software/" title="software" rel="tag">software</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/04/27/unknown-file-in-winsock-lsp-nwprovaudll/" title="Unknown File in Winsock LSP NWPROVAU.DLL (April 27, 2009)">Unknown File in Winsock LSP NWPROVAU.DLL</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/07/07/true-crypt-6-released/" title="True Crypt 6 released (July 7, 2008)">True Crypt 6 released</a> (3)</li>
	<li><a href="http://www.ghacks.net/2008/03/21/protect-files-in-windows-by-locking-them/" title="Protect Files in Windows by locking them (March 21, 2008)">Protect Files in Windows by locking them</a> (6)</li>
	<li><a href="http://www.ghacks.net/2006/05/08/open-ports-10/" title="Open Ports 1.0 (May 8, 2006)">Open Ports 1.0</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/03/06/norton-antibot-free-1-year-license/" title="Norton Antibot Free 1 Year License (March 6, 2008)">Norton Antibot Free 1 Year License</a> (15)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Runscanner</title>
		<link>http://www.ghacks.net/2007/12/29/runscanner/</link>
		<comments>http://www.ghacks.net/2007/12/29/runscanner/#comments</comments>
		<pubDate>Sat, 29 Dec 2007 10:52:30 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[hijackthis]]></category>
		<category><![CDATA[malware protection]]></category>
		<category><![CDATA[windows software]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/12/29/runscanner/</guid>
		<description><![CDATA[Runscanner is a security scanner much like Hijack This but aims to be helpful for all kinds of users. It has three different modes depending on the experience level of the user, they are called Beginner, Classic and Expert Mode. The Beginner Mode scans the system and writes the results in a log file that can be given to security experts in various forums that are mentioned on the Runscanner homepage.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.runscanner.net/">Runscanner</a> is a security scanner much like Hijack This but aims to be helpful for all kinds of users. It has three different modes depending on the experience level of the user, they are called Beginner, Classic and Expert Mode. The Beginner Mode scans the system and writes the results in a log file that can be given to security experts in various forums that are mentioned on the Runscanner homepage.</p>
<p>It is aimed at novice users who suspect that something is wrong with their computer but do not have the knowledge to interpretate and fix the issues by themselves. The Classic Mode is giving the user more information and a way to quickly fix common problems. It does not provide full information like the Expert Mode that displays lots of information.</p>
<p>Users of all three modes can always use a service called Online Malware Analysis which can be of great help. It compares the MD5 hash of the scanned files on the user&#8217;s system with those in the Runscanner database. MD5 hashes have to be the same if the same unaltered program version is used.</p>
<p><span id="more-2671"></span>The Online Malware Analysis uses green, purple and red icons to rate the item. Green items are checked and safe, purple items are not yet checked and red items are not safe.</p>
<p><img src='http://www.ghacks.net/wp-content/uploads/2007/12/online-malware-analysis.jpg' alt='online malware analysis' /></p>
<p>This is a great way of getting more information about current services, programs and processes on your system without having to consult another person.</p>
<p>Runscanner has several features that make it stand out even more. It offers right-click options to compare the MD5 hash with authority websites like Castle Cops and File Advisor, perform a Google search on the item, upload the file to Virus Total and open the file folder and Registry location.</p>
<p>Another aspect that is worth mentioning are so called Run files. As I said earlier novice users can create a log file that they can send to experts who analyze it. These experts can create a so called Fun file specifically designed to be run in Runscanner. The novice user can load the run file and execute the fixes that the expert has authorized.</p>
<p>Oh, it is free of course and portable. You can run it from any location on your computer.</p>

	Tags: <a href="http://www.ghacks.net/tag/hijackthis/" title="hijackthis" rel="tag">hijackthis</a>, <a href="http://www.ghacks.net/tag/malware-protection/" title="malware protection" rel="tag">malware protection</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/windows-software/" title="windows software" rel="tag">windows software</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2007/11/27/use-returnil-to-create-a-virtual-system-in-memory/" title="Use Returnil to create a Virtual System in Memory (November 27, 2007)">Use Returnil to create a Virtual System in Memory</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/03/16/secure-windows-services-configuration/" title="Secure Windows Services Configuration (March 16, 2009)">Secure Windows Services Configuration</a> (2)</li>
	<li><a href="http://www.ghacks.net/2007/11/26/prevent-that-unknown-executables-are-started-in-windows/" title="Prevent that unknown executables are started in Windows (November 26, 2007)">Prevent that unknown executables are started in Windows</a> (2)</li>
	<li><a href="http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/" title="HijackReader analyse HijackThis results (February 8, 2008)">HijackReader analyse HijackThis results</a> (6)</li>
	<li><a href="http://www.ghacks.net/2007/03/12/hijack-this-20-beta/" title="Hijack This 2.0 beta (March 12, 2007)">Hijack This 2.0 beta</a> (8)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/12/29/runscanner/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hijack This 2.0 beta</title>
		<link>http://www.ghacks.net/2007/03/12/hijack-this-20-beta/</link>
		<comments>http://www.ghacks.net/2007/03/12/hijack-this-20-beta/#comments</comments>
		<pubDate>Mon, 12 Mar 2007 12:57:27 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[hijack]]></category>
		<category><![CDATA[hijack-this]]></category>
		<category><![CDATA[hijackthis]]></category>
		<category><![CDATA[registry]]></category>
		<category><![CDATA[security-scan]]></category>
		<category><![CDATA[security-software]]></category>
		<category><![CDATA[trojans]]></category>
		<category><![CDATA[virii]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2007/03/12/hijack-this-20-beta/</guid>
		<description><![CDATA[HiJack This is a very sophisticated security analyzer that generates an advanced report of various registry settings and files in your computer. The difference to many other security analyzers such as trojan scanners is that Hijack This makes not difference between "good" and "bad" settings but displays everything that it founds in its security log. It is then up to the user to find potentially harmful files and settings and remove them from his computer.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php" target="_blank">HiJack This</a> is a very sophisticated security analyzer that generates an advanced report of various registry settings and files in your computer. The difference to many other security analyzers such as Trojan scanners is that Hijack This makes not difference between &#8220;good&#8221; and &#8220;bad&#8221; settings but displays everything that it founds in its security log. It is then up to the user to find potentially harmful files and settings and remove them from his computer.</p>
<p>It is no security software for beginners but excellent for advanced users and users who know someone who is able to draw the right conclusions from the security logs that have been generated. Another way to receive fast results would be to use the online script  <a href="http://www.hijackthis.de/en" target="_blank">Hijack This logfile analysis</a>. You can paste the logfile into the form field or upload the log from your computer and the script analyzes the logfile of Hijack This automatically.</p>
<p><span id="more-1295"></span></p>
<p>It uses user input to determine whether something is a potential threat or not. This works most of the time but leads sometimes to unjustified ratings. I installed AV Antivir in a custom directory and the analyzer used this to indicate a possible problem. I think the best way to cope with this situation would be to briefly analyze the elements that could be malicious and decided if that is really the case. To use the above example: I knew that I did install it in that directory and therefor decided that the warning was not justified in this case.</p>
<p>If you are insecure about a certain setting ask in the well frequented support forum or search the internet for clues on the subject. Hijack This has a similar analyze this button build in which takes you to the website of the developer of Hijack This. They display information about everything that was found on your computer and how frequent it was found in other computers. </p>
<p>This could be an indicator for safeness but I would suggest that you perform additional searches to be on the safe side. You can download the newest version of Hijack This from TrendSecure by following the link in the first paragraph.</p>

	Tags: <a href="http://www.ghacks.net/tag/hijack/" title="hijack" rel="tag">hijack</a>, <a href="http://www.ghacks.net/tag/hijack-this/" title="hijack-this" rel="tag">hijack-this</a>, <a href="http://www.ghacks.net/tag/hijackthis/" title="hijackthis" rel="tag">hijackthis</a>, <a href="http://www.ghacks.net/tag/registry/" title="registry" rel="tag">registry</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/security-scan/" title="security-scan" rel="tag">security-scan</a>, <a href="http://www.ghacks.net/tag/security-software/" title="security-software" rel="tag">security-software</a>, <a href="http://www.ghacks.net/tag/trojans/" title="trojans" rel="tag">trojans</a>, <a href="http://www.ghacks.net/tag/virii/" title="virii" rel="tag">virii</a>, <a href="http://www.ghacks.net/tag/windows/" title="Windows" rel="tag">Windows</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/02/08/hijackreader-analyse-hijackthis-results/" title="HijackReader analyse HijackThis results (February 8, 2008)">HijackReader analyse HijackThis results</a> (6)</li>
	<li><a href="http://www.ghacks.net/2008/07/05/gernova-keylock/" title="Gernova Keylock (July 5, 2008)">Gernova Keylock</a> (2)</li>
	<li><a href="http://www.ghacks.net/2006/03/12/windows-worms-door-cleaner/" title="Windows Worms Door Cleaner (March 12, 2006)">Windows Worms Door Cleaner</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/03/20/windows-registry-watcher/" title="Windows Registry Watcher (March 20, 2009)">Windows Registry Watcher</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/01/11/what-is-connecting-to-the-internet/" title="What is connecting to the Internet (January 11, 2008)">What is connecting to the Internet</a> (4)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2007/03/12/hijack-this-20-beta/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
	</channel>
</rss>
