Donation Goal
Donate Now Goal amount for this year: 799 USD, Received: 100 USD (13%)
Please donate to help support this website. The funds will be used to purchase owned license of LiteSpeed Web Server Enterprise (2-CPU). It provides superior performance in terms of raw speed, scalability and anti-DDoS capabilities.

5 Ways to Automatically Analyze HijackThis! Log File

Posted By Raymond In Category: Computer

Feb
25
2008

HijackThis opens you a possibility to find and fix nasty entries on your computer easier. Therefore it will scan special parts in the registry and on your harddisk and compare them with the default settings. If there is some abnormality detected on your computer HijackThis will save them into a logfile. In order to find out what entries are nasty and what are installed by the user, you need some background information.

A HijackThis logfile is not so easy to analyze. Even for an advanced computer user. Previously I’ve shared with you a few websites that is able to help you identify which startup program is good or bad but it’s still a tedious job because you have to analyze line by line. Today I am going to share with you 5 ways to automatically analyze HijackThis! log file. All you need to do is just paste your complete logfile into the textbox, wait for a few seconds and the report will give get recommendations based on that analysis.


Do take note that the results and recommendation generated by these hijackthis log analyzers are not 100% accurate and is to be used for reference purposes only. An automatic analysis should NEVER substitute an expert’s analysis.

1. HijackThis.DE Logfile Analyzer

Analyze Hijackthis log

You can either paste the log file to the text box or upload the log file from your computer to HijackThis.DE Logfile analyzer. This is one of the best automated HijackThis log file analyzer because the report is easy to read and it shows visitors rating. Instead of having the long analysis, you can opt for short analysis at the end of the report. Short analysis will only display the entries that it advice you to remove.
[ Visit HijackThis.de Logfile Analyzer ]

2. HiJackThis! Log Auto Analyzer V2

Networktech Hijackthis log auto analyzer

Everything is color coded to help you determine which category each item falls under. It uses Tony Kleins BHO DB + our its additions to find to help you figure out which items in your log are OK and which ones are bad! To display more information about the entry, just move your mouse over the line. This is also one of my favorite.
[ Visit HijackThis! Log Auto Analyzer V2 ]

3. Help2Go Detective

Help2Go Detective Hijackthis log file

Help2Go Detective is able to detect 11504 malware, including the Peper and CoolWebSearch trojans. It will only let you know the malicious, suspicious and suggestions. The safe ones won’t be displayed.
[ Visit Help2Go Detective ]

4. Prevx HijackThis Log Analyzer

Prevx Hijacthis log analyzer

Prevx HijackThis Log Analyzer is the worst among all. It only scans the filenames and path. I’ve tried analyzing a few log files from computers that is infected by spywares but it couldn’t determine anything bad in the HijackThis Log. Maybe this analyzer is fake, but I’ll include the link if you’d like to check it out.
[ Visit Prevx HijackThis Log Analyzer ]

5. HijackReader v1.03 Beta

Download Hijackreader

The final one is a free tool (not website). HijackReader automatically searches Pacman’s startup list as well as Tony Klein’s Browser Helper Object (BHO) list. After scanning all entries from the HijackThis log that you pasted, it will create a HTML report file.
[ Download HijackReader ]

You can use all 5 methods for better accuracy to determine if an entry is good or bad. Again, I just want to make it clear that the 4 websites and 1 tool is to provide only an analysis on the log file created by HijackThis. If you’re looking for the HijackThis program, you can get it from the link.


Related posts:
  • Trend Micro acquired HiJackThis tool
  • HijackThis Alternative for Manually Detecting and Removing Virus
  • File Automatically Deleted By Windows in WLM File Transfer
  • 8 Ways to Speed Up Your Metabolism
  • Free ways to diagnose your monitor
    • yao90

      great! nice software! thanks a lot! :D

    • krzywomordus

      HJT is not enough. It wont never show u for example bagle infection – so i use combofix to fix this ;>

    • thegoat

      What about HiJackFree. How good is it compared to HJT?

    • Cute Lemon Jokes

      my task manager always show the “conime.exe” , use antivirus also cannot delete it. What is that ? a virus?

    • bala

      Dear Raymond Sir,

      I used the 3 of the analysers you stated above. One said that there is no error. one said i should remove ctfmon. and another one said that ctfmon is good. What should i do?

      From: A puzzled person…

    • durutti

      very helpful!

    • http://Sedebeeliminar? JR

      El HijackThis log file analysis en dos entradas me indica \”Fuzzy Algorithmcheck (x.xx / x.xx) Nasty\” , las x representan unos valores que pone.

      Es correcto darle fix a estas entradas?

    • Vladusik

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:32:09, on 21.11.2010
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
      C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
      C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
      C:\Program Files\Trident Software\Pragma6\pkernel.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\uTorrent\uTorrent.exe
      D:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
      C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Trident Software\Pragma6\pservice.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtblfs.exe
      C:\Program Files\Mozilla Firefox\plugin-container.exe
      D:\Program Files\Download Master\Download Master\dmaster.exe
      C:\WINDOWS\system32\msiexec.exe
      D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 – HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
      R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yandex.ru/
      R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 – HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R0 – HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
      R0 – HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\pchealth\helpctr\System\panels\blank.htm
      R1 – HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 – HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
      O2 – BHO: IEVkbdBHO Class – {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll
      O2 – BHO: EWPBrowseObject Class – {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} – C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll
      O2 – BHO: Groove GFS Browser Helper – {72853161-30C5-4D22-B7F9-0BBC1D38A37E} – C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 – BHO: IE 4.x-6.x BHO for Download Master – {9961627E-4059-41B4-8E0E-A7D6B3854ADF} – D:\PROGRA~1\DOWNLO~2\DOWNLO~1\dmiehlp.dll
      O2 – BHO: Google Toolbar Notifier BHO – {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} – C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
      O2 – BHO: Java(tm) Plug-In 2 SSV Helper – {DBC80044-A445-435b-BC74-9C25C1C588A9} – C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 – BHO: FilterBHO Class – {E33CF602-D945-461A-83F0-819F76A199F8} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
      O2 – BHO: JQSIEStartDetectorImpl – {E7E6F031-17CE-4C07-BC86-EABFE594F69C} – C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 – Toolbar: DM Bar – {0E1230F8-EA50-42A9-983C-D22ABC2EED3C} – D:\Program Files\Download Master\Download Master\dmbar.dll
      O3 – Toolbar: Easy-WebPrint – {327C2873-E90D-4c37-AA9D-10AC9BABA46C} – C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
      O4 – HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 – HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 – HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 – HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 – HKLM\..\Run: [Pragma6] C:\Program Files\Trident Software\Pragma6\pkernel.exe
      O4 – HKLM\..\Run: [SunJavaUpdateSched] “C:\Program Files\Common Files\Java\Java Update\jusched.exe”
      O4 – HKLM\..\Run: [AVP] “C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe”
      O4 – HKCU\..\Run: [Hotmail] C:\WINDOWS\system32\rundll32.exe
      O4 – HKCU\..\Run: [swg] “C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe”
      O4 – HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 – HKCU\..\Run: [uTorrent] “C:\Program Files\uTorrent\uTorrent.exe”
      O4 – HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘LOCAL SERVICE’)
      O4 – HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘NETWORK SERVICE’)
      O4 – HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘SYSTEM’)
      O4 – HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User ‘Default user’)
      O4 – Startup: HDDlife.lnk = D:\Program Files\BinarySense\HDDlife\HDDlifePro.exe
      O8 – Extra context menu item: Translate with Lingvo – res://D:\Program Files\Lingvo.exe/3000
      O8 – Extra context menu item: Высокоскоростная печать Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
      O8 – Extra context menu item: Добавление в список для печати Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
      O8 – Extra context menu item: Закачать ВСЕ при помощи Download Master – D:\Program Files\Download Master\Download Master\dmieall.htm
      O8 – Extra context menu item: Закачать при помощи Download Master – D:\Program Files\Download Master\Download Master\dmie.htm
      O8 – Extra context menu item: Передать на удаленную закачку DM – D:\Program Files\Download Master\Download Master\remdown.htm
      O8 – Extra context menu item: Печать Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
      O8 – Extra context menu item: Предварительный просмотр Easy-WebPrint – res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
      O9 – Extra button: Отправить в OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 – Extra ‘Tools’ menuitem: &Отправить в OneNote – {2670000A-7350-4f3c-8081-5663EE0C6C49} – C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 – Extra button: &Виртуальная клавиатура – {4248FE82-7FCB-46AC-B270-339F08212110} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
      O9 – Extra button: Download Master – {8DAE90AD-4583-4977-9DD4-4360F7A45C74} – D:\Program Files\Download Master\Download Master\dmaster.exe
      O9 – Extra ‘Tools’ menuitem: &Download Master – {8DAE90AD-4583-4977-9DD4-4360F7A45C74} – D:\Program Files\Download Master\Download Master\dmaster.exe
      O9 – Extra button: Research – {92780B25-18CC-41C8-B9BE-3C9C571A8263} – C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 – Extra button: Проверка ссы&лок – {CCF151D8-D089-449F-A5A4-D9909053F20F} – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll
      O9 – Extra button: (no name) – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 – Extra ‘Tools’ menuitem: @xpsp3res.dll,-20001 – {e2e2dd38-d088-4134-82b7-f2ba38496583} – C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O16 – DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} – http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      O17 – HKLM\System\CCS\Services\Tcpip\..\{E0346D98-39F7-410D-B76E-73A08B334F55}: NameServer = 192.168.1.1,195.5.21.188
      O18 – Protocol: grooveLocalGWS – {88FED34C-F0CA-4636-A375-3CB6248B04CD} – C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 – Protocol: hddlife – {BD758015-47D9-477A-8873-4B688A2BC0E2} – “C:\Program Files\Common Files\BinarySense\hlAPP.dll” (file missing)
      O20 – AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~3\mzvkbd3.dll
      O23 – Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) – ABBYY (BIT Software) – D:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exe
      O23 – Service: Acronis Scheduler2 Service (AcrSch2Svc) – Acronis – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
      O23 – Service: Ati HotKey Poller – ATI Technologies Inc. – C:\WINDOWS\system32\Ati2evxx.exe
      O23 – Service: Kaspersky Anti-Virus Service (AVP) – Kaspersky Lab ZAO – C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
      O23 – Service: Журнал событий (Eventlog) – Корпорация Майкрософт – C:\WINDOWS\system32\services.exe
      O23 – Service: FLEXnet Licensing Service – Macrovision Europe Ltd. – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 – Service: Google Software Updater (gusvc) – Google – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 – Service: HDDlife HDD Access service – BinarySense, Inc. – C:\Program Files\Common Files\BinarySense\hldasvc.exe
      O23 – Service: Служба COM записи компакт-дисков IMAPI (ImapiService) – Корпорация Майкрософт – C:\WINDOWS\system32\imapi.exe
      O23 – Service: Java Quick Starter (JavaQuickStarterService) – Sun Microsystems, Inc. – C:\Program Files\Java\jre6\bin\jqs.exe
      O23 – Service: NetMeeting Remote Desktop Sharing (mnmsrvc) – Корпорация Майкрософт – C:\WINDOWS\system32\mnmsrvc.exe
      O23 – Service: Plug and Play (PlugPlay) – Корпорация Майкрософт – C:\WINDOWS\system32\services.exe
      O23 – Service: Pragma6Serv – Trident Software, Ltd. – C:\Program Files\Trident Software\Pragma6\pservice.exe
      O23 – Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) – Корпорация Майкрософт – C:\WINDOWS\system32\sessmgr.exe
      O23 – Service: Смарт-карты (SCardSvr) – Корпорация Майкрософт – C:\WINDOWS\System32\SCardSvr.exe
      O23 – Service: Журналы и оповещения производительности (SysmonLog) – Корпорация Майкрософт – C:\WINDOWS\system32\smlogsvc.exe
      O23 – Service: Теневое копирование тома (VSS) – Корпорация Майкрософт – C:\WINDOWS\System32\vssvc.exe
      O23 – Service: Адаптер производительности WMI (WmiApSrv) – Корпорация Майкрософт – C:\WINDOWS\system32\wbem\wmiapsrv.exe


      End of file – 10383 bytes

    Copyright © 2005-2012 - Raymond.CC Blog