SpywareInfo Forum: Analyze your own HijackThis log - SpywareInfo Forum

Jump to content

Posting Guidelines



Before posting, please make sure you have read the forum FAQ. It's there for a reason.


If you do not have spyware or another parasite and just want a check for anything suspicious, do not post that here. Click here for that.


Please do not post your email address or other personal information. Spammers do lurk here and they also operate email harvester bots to scan for email addresses. If a moderator sees that you have posted an email address, it will be removed.



DO NOT POST YOUR LOG FILE INTO SOMEONE ELSE'S TOPIC!

START YOUR OWN TOPIC.



Please stay with your original topic when posting follow up log files.

  • (9 Pages)
  • +
  • « First
  • 7
  • 8
  • 9
  • You cannot start a new topic
  • You cannot reply to this topic

Analyze your own HijackThis log here's how

#121 User is offline   Budfred Icon

  • Malware Hound
  • PipPipPipPipPip
  • Group: Administrators
  • Posts: 15,885
  • Joined: 15-May 04

Posted 11 September 2008 - 05:53 AM

View Postfoolofthehill, on Sep 10 2008, 11:49 PM, said:

Well, I just thought I'd mention it since I haven't seen anyone else mention it in their replies.

The efforts of yours (you and all the members) are much appreciated !

Greetz
FOTH
Posted Image

Your comment is appreciated since it gives us a chance to check into it... It is possible that it just recently happened, so no one else reported it because there was nothing evident... Whatever the situation is though, we can address it now that we know about it... :thumbup:
Budfred

Helpful links: SpywareBlaster... HijackThis... Sunbelt Kerio firewall...

MS MVP 2006 and ASAP Member since 2004

Please read the FAQ and the article "So how did I get infected in the first place?"

#122 User is offline   Beta-Carrot! Icon

  • Member
  • Pip
  • Group: Full Member
  • Posts: 12
  • Joined: 07-July 07

Posted 08 November 2008 - 09:05 PM

A small update, AOL Hometown appears to have been shut down.

"Important information regarding the shutdown of AOL Hometown, Journals (blogs) and KW FTP.

We regret to inform you that AOL Hometown, AOL Journals (blogs) and KW FTP has been shut down.

Sincerely,
The AOL Team



AOL (UK) Limited. Registered in England and Wales under number 03462696 with its registered office at 68 Hammersmith Road, London W14 8YW. VAT Registration Number: 766 45 16 05."

The mirror at spywarewarrior is working.

#123 User is offline   oceanediam Icon

  • Member
  • Pip
  • Group: Full Member
  • Posts: 2
  • Joined: 30-December 08

Posted 30 December 2008 - 07:56 AM

Hi! Just find this tutorial, and it is fantastic for a housewife-computer-user like me!! :p
Anyway, i am trying really hard and you are a great help.
but I am stuck not far from the beginning!!!:


http://www.allsecpros.com/bholist.txt (right click> save target as)

Open the text file and go to edit>find then copy the CLSID (e.g. {00000762-3965-4A1A-98CE-3D4BF457D4C8}) or file name e.g. ddm3dia.dll into the search box that appears. Click "Find next". If the BHO name is found then you will notice a letter at the start of the line. This letter will be one of the following-



When I open that link and go to edit and find, all I get is the line at the buttom left of the page. and it doesnīt find anything.
If I go to edit and find in my hijackthis notepad, I have got your little window with the find stuff, but it doesnīt find anything and doesnīt give me the letters X,L,O... either!
:techsupport:

So I am stuck there!! and donīt know what to do anymore!
Thanks for your help, and I will " see" you soon!! :wave:


Just find something : if I go to the other link you gave: http://www.allsecpros.com/toolbarlist.
it takes me to the same place that the link which ends with "bholist"

This post has been edited by oceanediam: 30 December 2008 - 08:01 AM


#124 User is offline   jedi Icon

  • Canis meus id comedit
  • PipPipPipPipPip
  • Group: Administrators
  • Posts: 13,443
  • Joined: 16-June 04

Posted 30 December 2008 - 09:00 AM

The lists have moved to here:
http://www.systemlookup.com/
Thank you for bringing it to our attention.
jedi
Member of ASAP since 2005


My help is free, but if you wish to help keep these forums running please consider a donation, see this topic for details.

#125 User is offline   oceanediam Icon

  • Member
  • Pip
  • Group: Full Member
  • Posts: 2
  • Joined: 30-December 08

Posted 01 January 2009 - 02:26 AM

Thanks Jedi! ;)

#126 User is offline   Juliosgirl Icon

  • Member
  • Pip
  • Group: Helper Trainee
  • Posts: 3
  • Joined: 18-January 09

Posted 19 January 2009 - 05:10 PM

I have no words to thank you, I have just started to learn and you are making it a lot easier.

#127 User is offline   Beta-Carrot! Icon

  • Member
  • Pip
  • Group: Full Member
  • Posts: 12
  • Joined: 07-July 07

Posted 17 August 2009 - 08:04 PM

I really love this tutorial, but it's starting to show its age.

Dead sites linked to in the tutorial
-------------
hometown.aol.co.uk/jrmc137/hjttutorial/tutorial.htm -- The link to the tutorial (the mirror is still up).
allsecpros (compromised, according to the first post) -- The only BHO list, the CWS domain list, the IE toolbar list.
computercops.biz -- The only CLSID list and the startup list.
www.fbeej.dk -- The "Extra protocols and protocol hijackers" ("O18s") list.
www.spywareinfo.com -- Information about The O20, O21, and O22 entries.
www.antispyware.nextdesigns.net -- For research on NT Services.

Most of the dead sites have replacements listed either in this thread or in the tutorial itself. Will anyone ever update the tutorial?

#128 User is offline   Budfred Icon

  • Malware Hound
  • PipPipPipPipPip
  • Group: Administrators
  • Posts: 15,885
  • Joined: 15-May 04

Posted 17 August 2009 - 09:57 PM

No, that isn't likely... Ascell is not really around anymore, so someone else would need to do it and then it would be an entirely different tutorial... It may be worthwhile to unpin it since it is so outdated however...
Budfred

Helpful links: SpywareBlaster... HijackThis... Sunbelt Kerio firewall...

MS MVP 2006 and ASAP Member since 2004

Please read the FAQ and the article "So how did I get infected in the first place?"

#129 User is offline   Beta-Carrot! Icon

  • Member
  • Pip
  • Group: Full Member
  • Posts: 12
  • Joined: 07-July 07

Posted 29 September 2009 - 10:24 PM

That's a shame, anyway, all of the dead sites I listed seem to be well replaced by http://sysinfo.org/ and http://www.systemlookup.com/. The only exception to that mostly good news is that I see no replacement for the CWS domain list, but if your possibly dealing with cool web shredder, you can just ask on the forums I guess.

  • (9 Pages)
  • +
  • « First
  • 7
  • 8
  • 9
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users


Support the forum!