Interpret HJT

Reply

Join Date: May 2004
Posts: 43
Reputation: ajelliott is an unknown quantity at this point 
Solved Threads: 0
ajelliott's Avatar
ajelliott ajelliott is offline Offline
Light Poster

Interpret HJT

 
0
  #1
Jun 6th, 2004
I was wondering if you would be willing to share the tools you use to interpret the HijackThis logs? I have the Task List from www.answeresthatwork.com and it great to see what’s running, but how is it that you know the names of all the processes out there and the right ones to delete using the HJT tool? You must have some kind of list that is undated daily.

For Example, I was advised to remove this line using the HJT tool:
O2 - BHO: (no name) - {221E8D90-C439-4297-B84A-EA3291D7CB1A} - C:\WINNT\system32\ebnel.dll (file missing)

What about this line gives you the clues? No name, ebnel.dll, or “file missing�?
Thank you,
:lol: AJE
________________________________________________________________
" Persistence can change failure into extraordinary achievement."
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 9,809
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 515
Team Colleague
caperjack's Avatar
caperjack caperjack is online now Online
Posting Prodigy

Re: Interpret HJT

 
0
  #2
Jun 6th, 2004
just a couple of things I use or do ,google search for a lot of the bad DLL's
I use BHOList.exe to search this and its also searche for bad Toolbars#221E8D90-C439-4297-B84A-EA3291D7CB1A
you can get it here .http://www.sysinfo.org/bhoinfo.html

If you have CWShredder install on you computer ,create a shortcut to it on you sesktop ,right click it and go to properties.in the target line add this , /debug not there is a space between whats there and the /,
now when you click on the short cut you created you use shredder as a tool to search CWS ,like this .R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_....id=138308.From that line you copy and past this into the shredder tool.
couldnotfind.com ,and it will tell you if is or isn't CWS.

you can also search for the bad 016's ,in SpywareBlaster if you have it installed on you computer .that program can be found in my signature in How i Got Infected In the first place .just open Spywareblaster and click on /internet explorer along the top and then right click on one of the idems in the list and click search .

I use this site for Hijackthis tutoral.
http://www.spywareinfo.com/~merijn/htlogtutorial.html

and this one for good and bad LPS's=010's in the log
http://www.angeltowns.com/members/zupe/lsps.html

and this one to search 017's IP addresses.
http://www.arin.net/whois/

I use canned speaches for my posts with all the links to the programs for the person to use on the affected computer.i got these speaches from the experts at the Spywareinfo.com ,i joined up for the bootcamp to learn how to read logs .I should spend more time there actuall to learn more,so I could be a better help with the hard logs [I leave them to Crunchie ].
Win7 whats it all about .
http://www.microsoft.com/canada/windows/windows-7/
Going with the Flow ,but the water is low and the rocks are big
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 43
Reputation: ajelliott is an unknown quantity at this point 
Solved Threads: 0
ajelliott's Avatar
ajelliott ajelliott is offline Offline
Light Poster

Re: Interpret HJT

 
0
  #3
Jun 6th, 2004
If you have CWShredder install on you computer ,create a shortcut to it on you sesktop ,right click it and go to properties.in the target line add this , /debug not there is a space between whats there and the /,
now when you click on the short cut you created you use shredder as a tool to search CWS ,like this .R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_..._id=138308.From that line you copy and past this into the shredder tool.
couldnotfind.com ,and it will tell you if is or isn't CWS.
Thank you,
:lol: AJE
________________________________________________________________
" Persistence can change failure into extraordinary achievement."
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 43
Reputation: ajelliott is an unknown quantity at this point 
Solved Threads: 0
ajelliott's Avatar
ajelliott ajelliott is offline Offline
Light Poster

Re: Interpret HJT

 
0
  #4
Jun 6th, 2004
I tried this and it worked as far as to bring up a different aspect of CWShreadder. I can see where to past the line but there is no button to execute the search.

It looks like this:
[IMG][IMG]C:\cwshreader.jpg[/img][/IMG]
Thank you,
:lol: AJE
________________________________________________________________
" Persistence can change failure into extraordinary achievement."
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 43
Reputation: ajelliott is an unknown quantity at this point 
Solved Threads: 0
ajelliott's Avatar
ajelliott ajelliott is offline Offline
Light Poster

Re: Interpret HJT

 
0
  #5
Jun 6th, 2004
:o Ok I made a screen shot of the CWShreader using the " ,/debug not " switch, but I don’t know how to imbed it into this reply.

Help.... anyone?
Thank you,
:lol: AJE
________________________________________________________________
" Persistence can change failure into extraordinary achievement."
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 10,126
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 770
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer
Join Date: Aug 2003
Posts: 9,809
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 515
Team Colleague
caperjack's Avatar
caperjack caperjack is online now Online
Posting Prodigy

Re: Interpret HJT

 
0
  #7
Jun 7th, 2004
Originally Posted by ajelliott
I tried this and it worked as far as to bring up a different aspect of CWShreadder. I can see where to past the line but there is no button to execute the search.

It looks like this:
[IMG][IMG]C:\cwshreader.jpg[/img][/IMG]
There is no search button it will just say YES or NO.
when you are checking a CWS,you don't put in the HTTP//www.
just this part .[couldnotfind.com] and the NO will change to a Yes
Win7 whats it all about .
http://www.microsoft.com/canada/windows/windows-7/
Going with the Flow ,but the water is low and the rocks are big
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 43
Reputation: ajelliott is an unknown quantity at this point 
Solved Threads: 0
ajelliott's Avatar
ajelliott ajelliott is offline Offline
Light Poster

Re: Interpret HJT

 
0
  #8
Jun 7th, 2004
Originally Posted by crunchie
You can just go here to access the domains directly too.

http://users.skynet.be/bk136527/CWS/CWSdomains.htm

Hey, thankx for the suggestion...

Is there any tutorials that explains this link and how to use it?
Thank you,
:lol: AJE
________________________________________________________________
" Persistence can change failure into extraordinary achievement."
Reply With Quote Quick reply to this message  
Join Date: May 2004
Posts: 43
Reputation: ajelliott is an unknown quantity at this point 
Solved Threads: 0
ajelliott's Avatar
ajelliott ajelliott is offline Offline
Light Poster

Re: Interpret HJT

 
0
  #9
Jun 7th, 2004
Originally Posted by caperjack
There is no search button it will just say YES or NO.
when you are checking a CWS,you don't put in the HTTP//www.
just this part .[couldnotfind.com] and the NO will change to a Yes

I will try this when I get home. Working at my sister's house today trying to fix her kid's computer....

Yuck what a mess! Even the keys in the keyboard stick together.
Thank you,
:lol: AJE
________________________________________________________________
" Persistence can change failure into extraordinary achievement."
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 9,809
Reputation: caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold caperjack is a splendid one to behold 
Solved Threads: 515
Team Colleague
caperjack's Avatar
caperjack caperjack is online now Online
Posting Prodigy

Re: Interpret HJT

 
0
  #10
Jun 8th, 2004
Originally Posted by ajelliott
Hey, thankx for the suggestion...

Is there any tutorials that explains this link and how to use it?
Just copy paste the suspected CWS into the search ,to check it to see if your suspected is a CWS variant .
Win7 whats it all about .
http://www.microsoft.com/canada/windows/windows-7/
Going with the Flow ,but the water is low and the rocks are big
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 3801 | Replies: 17
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC