Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rating: Thread Rating: 1 votes, 5.00 average. Display Modes
Old 07-07-2004, 06:17 PM   #1
 
Statica's Avatar
 
Join Date: Jun 1999
Posts: 9,231
MUST READ before posting HijackThis Logs!

Folks:

Over the past little while, we've seen this rash of HijackThis logs being posted on this site. It's a wonderful tool that helps diagnose issues with your computer, but there are a couple of things that must be kept in mind before randomly posting it on the forum.

1) Tell us why you are running Hijack This. It is very unproductive to have us guess why you are posting your log in the first place. If you have a virus, let us know what the virus was, if you got spyware, tell us what it was.
2) Tell us what you have done before posting your logs. And it would be nice if you did something before someone suggests that you do what you should have done in the first place. Run an online virus scan like Housecall, run a spyware/adware scan like Spybot S&D, AdAware. As much as we would like to help you, you have to first learn to help yourself.
3) Help us help you by making our job easier. It is ridiculous to run your logger while you have a million other programs running in the background. The more unnecessary lines you make someone parse through, the more likely it is that the person will miss something important. Either take the time to shut down everything or run it as soon as you perform a reboot.

I hope that with these methods you will find help faster on these forums.

Cheers
Statica is offline   Reply With Quote
Old 07-07-2004, 07:28 PM   #2
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
This thread is open for procedural discussion, but NOT for posting logs or obtaining help. Please open your own threads for obtaining assistance.
glc is offline   Reply With Quote
Old 07-07-2004, 07:35 PM   #3
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,633
Send a message via AIM to Panama Red
I'm finding that one of the most difficult obstacles in using a Hijack This! log is finding a valid explanation for some of the files it finds. So many logs have been posted all over the web that a google search invariably lists a large number of these posts but no reference to a description of some of the items listed. Does anyone have a good source to id some of these files?
__________________
Getting old is not for sissies!
Panama Red is offline   Reply With Quote
Old 07-07-2004, 07:58 PM   #4
Member (13 bit)
 
Join Date: Aug 2003
Location: Richmond, VA
Posts: 7,835
Quote:
Originally posted by glc
This thread is open for procedural discussion, but NOT for posting logs or obtaining help. Please open your own threads for obtaining assistance.
Thanks - I was hoping this thread would be unlocked so I could post the links:

Adaware 6: (http://www.lavasoftusa.com/)

Spybot Search & Destroy 1.3: (http://www.safer-networking.org/)

TrendMicro's Housecall: (http://housecall.trendmicro.com)

HiJack This! and CWShredder: (http://www.spywareinfo.com/~merijn/downloads.html)

Hope that helps,
kram
__________________
"For today, goodbye. For tomorrow, good luck. And forever, Go Blue!"
University of Michigan President Mary Sue Coleman
kram 2.0 is offline   Reply With Quote
Old 07-07-2004, 08:03 PM   #5
Registered User
 
Join Date: Apr 2001
Location: The Northland
Posts: 44
If I understand your question correctly, the following might be of help to you.

HijackThis Tutorial

Pacmans Startup List for checking 04 entries and running processes.

BHO and Toolbar List for checking 02 and 03 entries.

LSP List for checking 010 entries.

CWS Domains for checking R0 and R1 entries to see if they are CoolWebSearch related.
Steve1 is offline   Reply With Quote
Old 07-07-2004, 08:49 PM   #6
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Great tutorial for hijackthis by Acsell


BHO's Tools Bars

Use this for 02's & 03's in the log

CLSID - BHO List - Toolbar List @ CC

Tony KleinsBHO's

Start Up Items

Use this for 04's in the log

answersthatwork

Startup Applications

Windows Startup Online

Startup Programs



Active X controls

Use this for 016's in the log

Spywareblaster

Lobos

Last edited by Lobos; 07-07-2004 at 08:52 PM.
Lobos is offline   Reply With Quote
Old 07-07-2004, 09:02 PM   #7
 
Statica's Avatar
 
Join Date: Jun 1999
Posts: 9,231
Thanx for the input guys.

Kram, the post was closed temporarily to make sure that the thread started off on the right foot. It seems to have.
Statica is offline   Reply With Quote
Old 07-07-2004, 09:06 PM   #8
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,633
Send a message via AIM to Panama Red
Steve1 and Lobos, Thank you very much. Those are all going to be bookmarked in a "spyware" folder!
Panama Red is offline   Reply With Quote
Old 07-07-2004, 09:10 PM   #9
Member (10 bit)
 
mikezel's Avatar
 
Join Date: Dec 2003
Location: Toronto
Posts: 894
Send a message via MSN to mikezel
Quote:
Originally posted by Panama Red
Steve1 and Lobos, Thank you very much. Those are all going to be bookmarked in a "spyware" folder!
Ditto here Steve1 and Lobos, except I bookmarked the thread under "The best of PCMech"

Those resources will be extremely valuble to me in the future.

Mike
mikezel is offline   Reply With Quote
Old 07-08-2004, 06:56 PM   #10
Member (7 bit)
 
CarlS's Avatar
 
Join Date: Mar 2003
Location: Altamonte Springs, FL
Posts: 108
Thumbs up

Thank you, Statica, for posting this as a sticky and thank you, Steve1 and Lobos, for the excellent references. I am going to send this link to someone and I hope she will join PCMechanic as a result - after she gets her computer working well enough to go online.
__________________
Carl S
CarlS is offline   Reply With Quote
Old 07-08-2004, 07:43 PM   #11
Shiro Usagi
Premium Member
 
Cricket's Avatar
 
Join Date: Sep 1999
Location: Kaneohe, Hawaii
Posts: 34,002
Great info in this thread, keep it coming.

With the increase in hijack activity lately, it's good to have a thread like this that we can all reference back to.

One thing, the creator of CoolWebShredder won't be updating it anymore (or not as often) since he's busy with school. So watch out for newer CoolWebSearch hijacks...they're said to be harder to deal with and remove. Hopefully, something else will come along to help with this problem.

Cricket
Cricket is offline   Reply With Quote
Old 07-08-2004, 08:34 PM   #12
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
oops I forgot to put the best resource of them all

http://www.google.com/

Lobos
Lobos is offline   Reply With Quote
Old 07-16-2004, 11:17 PM   #13
brewer, mostly...
 
kev7555's Avatar
 
Join Date: Jun 2004
Location: Laying on the floor, in the brewery
Posts: 1,315
efficiency

MAN!

Every day I become more impressed with the efficiency with which this forum is administrated. Thanks guys for all of the very useful links.

I was a bit stumped as to what to make of all the data in a HijackThis log.


-Kev
kev7555 is offline   Reply With Quote
Old 07-20-2004, 09:28 AM   #14
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
Please read this thread, folks.

http://forum.pcmech.com/showthread.php?t=104450
glc is offline   Reply With Quote
Old 07-20-2004, 02:58 PM   #15
SGS
Member (8 bit)
 
Join Date: Jul 2004
Posts: 160
I'd just like to add:

FBJ's List for checking those new 020, 021 and 022 entries.
SGS is offline   Reply With Quote
Old 07-25-2004, 03:26 PM   #16
Lest we forget
 
ghost2003's Avatar
 
Join Date: Jun 2003
Location: Ontario, Canada
Posts: 1,870
posted a thread for this a while ago but im gonna add it here.
http://majorgeeks.com/download4265.html
Its a very nice little program to help with looking through HJT logs.
__________________
redqueen: Antec Sonata, Pentium-D 2.5GHz, MSI G31M3-L, 2GB ram, 320 GB HDD, OpenBSD
hal9000: Lenovo T61, 2GB ram, 120 GB HDD, FreeBSD
ghost2003 is offline   Reply With Quote
Old 07-28-2004, 05:33 AM   #17
Member (10 bit)
 
Join Date: Mar 2004
Location: California
Posts: 936
Tutorials

Understanding Spyware, Browser Hijackers, and Dialers

tutorial Using Ad-aware

Tutorial Using Spybot S/D

Tutorial Using SpywareBlaster


I put these in here because it is a safer browser if anyone has a question on how to set it up Here are some tutorials

Howto Switch from Internet Explorer to Firefox

Enhancing Firefox with Browser Extensions
Lobos is offline   Reply With Quote
Old 07-31-2004, 11:09 AM   #18
Member (11 bit)
 
toomyg's Avatar
 
Join Date: Sep 2001
Location: Western New York
Posts: 1,178
Send a message via AIM to toomyg Send a message via Yahoo to toomyg
You should make a special section in the forum just for HiJack logs
toomyg is offline   Reply With Quote
Old 08-30-2004, 09:42 PM   #19
brewer, mostly...
 
kev7555's Avatar
 
Join Date: Jun 2004
Location: Laying on the floor, in the brewery
Posts: 1,315
Thanks, Statica and all else who have posted links here. I have taken Panama Red's suggestion and created a folder on spyware info.

The links to HiJackthis tutorials and start-up items have been especially helpful.



-Kev






,,
kev7555 is offline   Reply With Quote
Old 09-15-2004, 09:50 AM   #20
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
Current version is 1.99, and is available here:

http://www.spychecker.com/program/hijackthis.html

Please use this version when you post a log.

Last edited by glc; 12-17-2004 at 10:01 PM.
glc is offline   Reply With Quote
Old 11-04-2004, 01:09 PM   #21
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
Updated to show current versions of recommended applications:

HijackThis - see previous post (#20)

Spybot S&D 1.3, http://safer-networking.org/en/download/index.html
Ad-Aware 1.05 SE, http://www.lavasoftusa.com/
CWShredder 2.12, http://cwshredder.net/bin/CWShredder.exe

Update and run your existing antivirus, then follow up with Housecall (http://housecall.trendmicro.com/hous...start_corp.asp) and Panda Active Scan (http://www.pandasoftware.com/actives..._principal.htm) to be totally thorough. IE required as they both require ActiveX.

Last edited by glc; 12-17-2004 at 09:59 PM.
glc is offline   Reply With Quote
Old 01-04-2005, 01:54 PM   #22
Member (7 bit)
 
davsl's Avatar
 
Join Date: Feb 2003
Posts: 114
Please could somebody take a look at my Hijack This Log file and see if anything is wrong. I posted a recent thread about Windows Media player 9 constantly starting evertime I booted up Windows XP and GLC recommended posting my logs up here. Thanks for any help

http://forum.pcmech.com/showthread.php?t=120314
Attached Files
File Type: doc Hijackthis.doc (6.8 KB, 323 views)
davsl is offline   Reply With Quote
Old 01-04-2005, 01:58 PM   #23
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,362
Davsl.
You need to start a new thread in the securities forum, then copy and paste your HJT log into the thread in order for people to see it, it is not going to get picked up tagged on the end of this thread.
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta.

Last edited by rjfvillarosa; 01-04-2005 at 02:00 PM.
rjfvillarosa is offline   Reply With Quote
Old 01-05-2005, 06:08 AM   #24
Member (7 bit)
 
davsl's Avatar
 
Join Date: Feb 2003
Posts: 114
Ok thanks very much will do
davsl is offline   Reply With Quote
Old 01-06-2005, 04:36 AM   #25
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
Not to chew on you, but the second post in this thread says:

Quote:
This thread is open for procedural discussion, but NOT for posting logs or obtaining help. Please open your own threads for obtaining assistance.
In your case, you should have tacked your log (as a copy/paste, not an attachment) onto your existing thread instead of opening a new one, but all is good now.
glc is offline   Reply With Quote
Old 01-24-2005, 05:39 AM   #26
Member (9 bit)
 
Join Date: Jan 2005
Posts: 283
Hotsearchbar.com popup - how do I purge it?

Post removed, please see below.

Last edited by glc; 01-24-2005 at 11:13 AM.
Dazzer is offline   Reply With Quote
Old 01-24-2005, 11:12 AM   #27
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 40,384
Quote:
Originally Posted by glc
This thread is open for procedural discussion, but NOT for posting logs or obtaining help. Please open your own threads for obtaining assistance.
Please review the entire thread. Thank you.
glc is offline   Reply With Quote
Old 02-13-2005, 06:09 PM   #28
Member (10 bit)
 
PMich's Avatar
 
Join Date: Jan 2001
Location: Greenville, MS
Posts: 625
I don't know if this is old news but there is a hijackthis log interpreter from the HijackThis site. I have attached the link below. Just copy and paste your log into the textbox and it tells you a little more about each entry. Good for those of us who aren't experts but are want to work out our own problems.

HijackThis analysis
PMich is offline   Reply With Quote
Old 02-13-2005, 07:12 PM   #29
Served with Pride
Staff
Premium Member
 
Panama Red's Avatar
 
Join Date: Apr 2003
Location: near the left coast of Michigan
Posts: 14,633
Send a message via AIM to Panama Red
Nice linky there, PMich! Think I'll give that a try with the next infestation I'm asked to fix.
Panama Red is offline   Reply With Quote
Old 02-13-2005, 07:17 PM   #30
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,362
Good link Mich.
rjfvillarosa is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 08:56 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1