Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

does anyone know how to analyze "hijack this" logs?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 07:45 PM
Original message
does anyone know how to analyze "hijack this" logs?
i posted in the computer group forum, but it is a little slower moving there, and i am at my wits end with @#$%^&*(*^&%!@&^* smartsearch!

http://www.democraticunderground.com/discuss/duboard.php?az=view_all&address=242x4379

if anyone knows how to analyze or a site where an analysis can be doner fairly quickly, i will be forever in your debt.
Printer Friendly | Permalink |  | Top
Rufus T. Firefly Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 07:46 PM
Response to Original message
1. Hijackers are pure evil.
I've had to deal with that myself. I've got quite a bit of troubleshooting experience, so I might be able to help.
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 07:58 PM
Response to Reply #1
4. have you worked with hijack this before?
Edited on Tue Aug-02-05 08:38 PM by shugah
it seems to be the most thorough search for finding possible hijack registry keys. the problem is that it has returned things like .dlls and what not.

edited to add: pure evil is right!
Printer Friendly | Permalink |  | Top
 
ET Awful Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 07:48 PM
Response to Original message
2. Post your log
Edited on Tue Aug-02-05 07:57 PM by ET Awful
I'll take a look at it.

I'm not an "expert" but I've never broken a computer by using Hijack This :)

Edit: I won't be able to look at it tonight. IF you post it, I'll get back to you in the morning.
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:18 PM
Response to Reply #2
5. i'm afraid a thread about someone's hijacked browser
in the lounge won't take long to hit the archives! ;-)

i'll bookmark this thread and PM you tomorrow if that's okay. thanks!
Printer Friendly | Permalink |  | Top
 
greyl Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 07:48 PM
Response to Original message
3. annoyances.org may help
Or just post the log here, since you've achieved some attention. :)
Printer Friendly | Permalink |  | Top
 
I Know How To Do it Donating Member (499 posts) Send PM | Profile | Ignore Tue Aug-02-05 08:27 PM
Response to Original message
6. One little trick that I use once in a while on XP is to do a system
restore to the day before the spyware installed itself.
Works like a charm for certain spyware that's really difficult to manually get rid of like that istsvc crap.
Another thing to do is open up msconfig to see what's going to be started and disable spyware from auto executing.
I only really use Adaware from Lavasoft. Between that and my general knowledge, I wipe them all out.
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:37 PM
Response to Reply #6
7. i wish i had restored!
if i had realized how insidious this was, i would have restored for sure! unfortunately, i reset my homepage, and blocked the url, and thought i was good to go - smugly, i might add ;-)

i rarely restart my computer, so it was days, possibly weeks, before i realized that i had a real problem. and it seems to be getting more aggressive - randomly resets my homepage even without restart - plus i am getting numerous errors and program shut downs...

noAdware (same as adaware by lavasoft) is very good, by the way. even with all the nasty **it i have in my registry, i don't get pop-ups!

i've been fighting this for awhile now - i'm most often able to troubleshoot whatever is wrong with my computer, but this time i am just at my wits end!

thanks for the suggestion - how i wish i had restored when i first noticed the problem! next time... ;-)
Printer Friendly | Permalink |  | Top
 
I Know How To Do it Donating Member (499 posts) Send PM | Profile | Ignore Tue Aug-02-05 08:52 PM
Response to Reply #7
11. You have to catch them early otherwise you get so many that
they conflict with each other and really mess stuff up.
I had a room mate that kept going to Porn Sites that were linked from spam. He had so much freakin' spyware that once you got rid of one, you discovered a new layer of spyware. I spent a whole day getting his computer back to working only to learn that two weeks later he was doing the same thing and wanted me to fix it again.

A lot of Song Lyrics websites throw crap all over your computer as well as Cheat sites for games.
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 09:10 PM
Response to Reply #11
15. bizarre, but true:
i think this hijack ocurred when i was researching genealogy! i went to a site hosted in another country and got a rash of pop-ups. that is very unusual because i always have anti-virus, spyware, and pop-up protection running. i properly closed them all, but it was quite a flurry and perhaps i made an inadvertant mistake.

and, of course, since i am so careful as a rule, i never get a simple run of the mill fix. no fair! ;-)

p.s. i'd tell your porn surfing friend that plenty of spyware will help lead him to even more porn! oh yeah, and that he's on his own ;-)
Printer Friendly | Permalink |  | Top
 
miss_kitty Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:43 PM
Response to Original message
8. you could try this
http://hijackthis.de/index.php?langselect=english

back up your registry before you take action. a semi-broken one is better than a really fucked up one
Printer Friendly | Permalink |  | Top
 
miss_kitty Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:46 PM
Response to Reply #8
10. or this
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:56 PM
Response to Reply #8
13. thank you miss_kitty
that is a site i have bookmarked! i couldn't find much else about that site - how long it's been around, who does the analysis, how long it might take someone to respond, etc. i have learned that there are a lot of people online who do want to help with this problem - probably because they hate this hijacking crap as much as everyone else ;-)

thanks!
Printer Friendly | Permalink |  | Top
 
LynzM Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:45 PM
Response to Original message
9. I might be able to find you a resource or three...
Give me a bit, I'll get back to you. I know someone who used to work on them a lot, and if she's busy, I'm sure she knows other people..
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 08:52 PM
Response to Reply #9
12. okay LynzM
you may be my new hero then! ;-)

thank you!
Printer Friendly | Permalink |  | Top
 
Bossy Monkey Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 09:05 PM
Response to Original message
14. There are a gazillion computer help desks online, and nearly every
browser hijack has happened to somebody already. Therefore, what I normally do is google "HijackThis log" and the filename from any HijackThis result that doesn't look familiar to me. You should get any number of helpdesk threads where people are asking about their logs and being told that the item in question is either harmful or innocuous. Follow their advice.

Regarding smartsearch, here's a helpdesk thread about that. The instructions are in the next to last post, almost at the bottom: http://www.askmarvin.ca/forums/index.php?showtopic=2309

Good luck with it!
Printer Friendly | Permalink |  | Top
 
shugah Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Aug-02-05 09:13 PM
Response to Reply #14
16. that's a good idea!
i have been thinking that if all else fails - which it has so far ;-) - that i would cut and paste every single item that hijack this has found. i even got started on it - but it never ocurred to me to search with "hijackthis log."

thanks undisclosed!
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu Apr 25th 2024, 01:25 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC