PDA

View Full Version : HiJackThis! Log Checker Site



tesco
03-02-2005, 02:25 AM
Has anyone seen this website: http://www.hijackthis.de

You run HiJackThis! then paste the log and it analyzes it for you. Then it reports back any nastys, unknowns, or unneccessaries that you have running. :)

It reported some things that I never noticed. :)

peat moss
03-02-2005, 03:07 AM
Ross, I mentioned in another thread about how easy computers are getting. You like some others , know I was kidding . All the same processes exe. names that spyware and trojan's use to hide them selves, can be pretting confusing. Nice to have the tools ! :)

zedaxax
03-02-2005, 05:44 AM
Finally!

RealitY
03-02-2005, 07:42 AM
Only Two...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://filesharingtalk.com/vb3/index.php?
Nasty This entry should be fixed by HijackThis! This entry should be fixed by HijackThis!
:eek: :eek:

O1 - Hosts: 64.91 www.dcsresearch.com
Nasty This entry should be fixed immediately! Must be fixed!
(fkin silly app)
:blink: :blink:

100%
03-02-2005, 01:37 PM
Only Two...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://filesharingtalk.com/vb3/index.php?
Nasty This entry should be fixed by HijackThis! This entry should be fixed by HijackThis!
:eek: :eek:

O1 - Hosts: 64.91 www.dcsresearch.com
Nasty This entry should be fixed immediately! Must be fixed!
(fkin silly app)
:blink: :blink:

:lol:
ok so its got some errors, but its probably the first version and will improve.
None the less it is a real time saver for all those "hijack this" threads. It did spot one i didn't notice.

peat moss
03-08-2005, 03:31 AM
I had to come back to this thread . This is neat, fixed my startup problem ( over two minuet's ) and a pause when you open a folder. And I do mean a pause! I tryed everything ,cleaners out the yahoo , virus scan's ,spyware you name it. But the site helped fix it. It was a trojan active x dialer. Kool mabye it should be pinned or linked ? I know I should of tryed a trojan scanner but what the hey ! :D Thanx Ross .

tesco
03-08-2005, 03:38 AM
actually i was just gonna post that it wasn't that accurate.

Yesterday someone sent me a link on msn saying to look at this thing it's funny so i clicked it and ended up getting spyware and viruses (it was dumb of me to open the file :lol:).
Anyway that checker didnt find anything but i clearly had things in my log that needed removing.

peat moss
03-08-2005, 03:43 AM
Hey I'm not being funny ! I 'm too proud to ask for help ,so when a program helps me fix something I like to share ;) I rarely get problems, but I have three little ones on my computer , so was happy to sort it out . :)




Actualy my wife Sabine was complaining her MSN was slow. I did n't notice till I starting giving a closer look . I rarely shutdown my computer anymore , thats when I noticed it.

tesco
03-08-2005, 03:45 AM
Hey I'm not being funny ! I 'm too proud to ask for help ,so when a program helps me fix something I like to share ;) I rarely get problems, but I have three little ones on my computer , so was happy to sort it out . :)
ya I know, i'm usually really careful.
I guess yesterday was just bad luck. :(

fkdup74
03-08-2005, 03:47 AM
haha, no nasties for me :P
but of course i already knew this :music:

it is kinda silly like RealitY said though...
it knew sygate and symantec was legit, but....
the ccApp.exe & smc.exe -startgui entries it couldnt decide on :lol:

peat moss
03-08-2005, 03:48 AM
haha, no nasties for me :P
but of course i already knew this :music:

it is kinda silly like RealitY said though...
it knew sygate and symantec was legit, but....
the ccApp.exe & smc.exe -startgui entries it couldnt decide on :lol:



FKDUP74, I did n't get that tho, just three nasties that were related . :)


Mabye the site has been updated ? ;) All I can say is from my own experience it help'd me . Take it or leave it ! :)

fkdup74
03-08-2005, 03:54 AM
FKDUP74, I did n't get that tho, just three nasties that were related . :)
Mabye the site has been updated ? ;)

cool :)
(not that you had nasties, but that it caught em)
it could be a very helpful resource, just needs some fine tuning

and remember kiddies...
delete that filesharingtalk shit from your start page!!!!!
:P :lol:

zapjb
03-08-2005, 03:56 AM
Excellent! All green & safe here except 3 yellows which I know are OK. Thanks a bunch rossco.

peat moss
03-08-2005, 04:02 AM
In hindsite it's not really for rookies , but I 'd like to think I know somewhat about my process exe.'s but must admit still gave me pause . :lol: Like what the hell is O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll . I'm thinking norton ,but it does n't know either so I don't feel so bad ! :lol:

fkdup74
03-08-2005, 11:44 PM
O20 - Winlogon Notify: NavLogon -C:\WINDOWS\system32\NavLogon.dll .

argh! delete that shit dude!
its not NAV....
http://computercops.biz/postt59456.html
i just found out myself :lol:
setting up this other pc and saw that shit in the hijackthis log
got curious, did some searching ;)

from what it seems, the .dll is legit, but the call to it (the reg entry) isnt
deleting the dll will make symantec want you to reinstall...
so i just restored it from the junk bin and the reg entry wasnt repeated
so everything looks ok, symantec's running fine
maybe try just removing the reg entry in hijackthis, then reboot

-edit- i'm gonna get a trojan scan goin on that pc...
see if the dll is infected or not

{I}{K}{E}
03-08-2005, 11:51 PM
Has anyone seen this website: http://www.hijackthis.de

You run HiJackThis! then paste the log and it analyzes it for you. Then it reports back any nastys, unknowns, or unneccessaries that you have running. :)

It reported some things that I never noticed. :)

Nice site :cool:

RealitY
03-09-2005, 12:00 AM
O1 - Hosts: 64.91 www.dcsresearch.com
Nasty This entry should be fixed immediately! Must be fixed!
(fkin silly app)
Actually my comment regarding silly app was geared at the second find which was created by some shit app I had although now I cant remeber what it was although it was a legit nasty that I didnt know about but is now gone. As for the rest of the log it didnt find anything else and as far as the site it seems very useful for the most part and a good find...

fkdup74
03-09-2005, 12:05 AM
Actually my comment regarding silly app was geared at the second find which was created by some shit app I had although now I cant remeber what it was although it was a legit nasty that I didnt know about but is now gone. As for the rest of the log it didnt find anything else and as far as the site it seems very useful for the most part and a good find...

shush already...i said it was useful...just needs some tweaking :P

peat moss
03-09-2005, 01:11 AM
argh! delete that shit dude!
its not NAV....
http://computercops.biz/postt59456.html
i just found out myself :lol:
setting up this other pc and saw that shit in the hijackthis log
got curious, did some searching ;)

from what it seems, the .dll is legit, but the call to it (the reg entry) isnt
deleting the dll will make symantec want you to reinstall...
so i just restored it from the junk bin and the reg entry wasnt repeated
so everything looks ok, symantec's running fine
maybe try just removing the reg entry in hijackthis, then reboot

-edit- i'm gonna get a trojan scan goin on that pc...
see if the dll is infected or not



Much appreciated for the time you took. Deleted with no ill affects. Crap looks like now, I need a dedicated trojan scanner . :dry: Thanks again FKDUP74.


Deleted thru hijackthis .

fkdup74
03-09-2005, 01:38 AM
Much appreciated for the time you took. Deleted with no ill affects. Crap looks like now, I need a dedicated trojan scanner . :dry: Thanks again FKDUP74.


Deleted thru hijackthis .

yeah thats basically all i did,
cause i restored the original from the trash bin
then scanned it, nothin came up
startin to wonder if it was a hoax :dry:
symantec runs w/o the entry, so fk it :P

-edit-
ok, i've scanned that fkr with just about every scanner on earth...
none of em found anything :angry:
-adaware
-ewido security suite
-trojanhunter
-pestpatrol
all passed the file off as good, clean, no prob, etc
i may have jumped the gun peat....

Snee
03-09-2005, 04:12 PM
This will probably come in handy, so thanks for that.

baccyman
03-09-2005, 06:50 PM
i have just run hijackthis and done the log checker which has found 12 bad items where and how do i do the repairs . is it in regedit then try and find the files in the registry and delete them in there.

fkdup74
03-09-2005, 06:53 PM
i have just run hijackthis and done the log checker which has found 12 bad items where and how do i do the repairs . is it in regedit then try and find the files in the registry and delete them in there.

hijackthis will remove the entries for you
just select the bad items and hit "fix checked"
but depending on what they were, you may wanna do some additional checking/scanning

baccyman
03-09-2005, 07:09 PM
thanks for your help

peat moss
03-10-2005, 01:29 AM
yeah thats basically all i did,
cause i restored the original from the trash bin
then scanned it, nothin came up
startin to wonder if it was a hoax :dry:
symantec runs w/o the entry, so fk it :P

-edit-
ok, i've scanned that fkr with just about every scanner on earth...
none of em found anything :angry:
-adaware
-ewido security suite
-trojanhunter
-pestpatrol
all passed the file off as good, clean, no prob, etc
i may have jumped the gun peat....



No you did n't do anything wrong . I read the link aswell. Funny tho I fixed my slow down. I reinstalled Stardock curser XP . Problem fixed , are not computers wierd ? I was prepaired to format and reinstall this weekend ! :blushing:


I did have some nasties tho that hijack fixed . But was concered about the continued slow down , So put my smart hat on ! :)

lanni
03-10-2005, 04:48 AM
thanks for the link rossco_2004 - i found this entry as the only other possible nasty after
I ran "HiJack This" and wanted to know if I can go ahead and fix...or how can I tell if it is legitimate or not
Thanks again
"HKLM\System\CCS\Services\Tcpip\..\{DC6D854C-91D0-442B-9F3C-6F070C328985}: NameServer = 206.47.244.105 206.47.244.87"

peat moss
03-10-2005, 05:16 AM
I think that was the point about this site . Its not for the Noobs, me included ! :) Have you tryed the hijackthis sites?

lanni
03-10-2005, 05:30 AM
no I haven't

peat moss
03-10-2005, 06:29 AM
no I haven't




How can we help you ? If not sure about about the file? leave alone then. Its not going to matter , till you decide . :)

RealitY
03-10-2005, 07:39 AM
"HKLM\System\CCS\Services\Tcpip\..\{DC6D854C-91D0-442B-9F3C-6F070C328985}: NameServer = 206.47.244.105 206.47.244.87"
Just curious if you find anything on your pc when searching for "KALVTMS" by any chance.
I think that this entry is related to Sympatico though somehow...

lanni
03-10-2005, 01:18 PM
thanks for the updates-my isp is with sympatico - i think i will leave it as it is though - besides that entry every other entry is safe ... but i will continue to do some searching if required.....thanks ppl....