Avast WEBforum

Other => General Topics => Topic started by: avatar2005 on March 25, 2007, 09:26:20 PM

Title: hijackthis log analyzer
Post by: avatar2005 on March 25, 2007, 09:26:20 PM
Hi friends!
I need a good online hijackthis log analyzer.
What can you suggest to me?
Title: Re: hijackthis log analyzer
Post by: Spyros on March 25, 2007, 09:40:42 PM
http://hijackthis.de/
But double-check everything on google before you do anything drastic.
Title: Re: hijackthis log analyzer
Post by: polonus on March 25, 2007, 09:48:24 PM
Halio avatar2005,

Tools like FreeFixer, and the one that validates online like there is X-RayPC have all come along in the slipstream of HijackThis, and I consider them programs to be able to work better cleansing routines.
There are online sources to evaluate the outcome of FreeFixer or its reports rather, and they have a very interesting forum to discuss the findings of FreeFixer. You also have to note that FreeFixer is still in beta. But I have installed it, and it seems a valuable addition in finding things that should not be on a malware-free computer. It is nice that you can work the logs of X-RayPC to cleanse in a similar way as you handle the HJT-logs. These aren't programs for the meek, and certainly not to be used without help of an expert.
You can search the file database here: http://www.kephyr.com/filedb/

polonus
Title: Re: hijackthis log analyzer
Post by: Spiritsongs on March 25, 2007, 09:50:20 PM
 :) Hi :

    As far as I am concerned, they do NOT exist ; much more trustworthy
    is the EXPERIENCE of 2 Malware Experts and what they shared at
    www.landzdown.com/index.php?topic=438.0  .
Title: Re: hijackthis log analyzer
Post by: polonus on March 25, 2007, 09:58:48 PM
Hi Spiritsongs,

We have experts here as well. I know essexboy has the same qualifications as the people you advertise for. And then we have noadfear among the members of our webforum, developer of may special cleansing tools himself.. Why should not avatar2005 not learn to work these specific tools himself as well, He can go to sites and analyse particular cleansing routines at majorgeeks, analyse cleansing routines we have solved here etc. He can ask essexboy how he did it, and essexboy will be too glad to instruct him how it is done.
I cannot see why the folks at landzdown should have the exclusivety, while we have competent people here as well, and like essexboy got the training, why avatar2005 couldn't is beyond me.
I'd like to say to avatar2005: "Naboj!",

Also consider this nice program Brute Force Uninstaller: http://metallica.geekstogo.com/BFUinstructions.html

polonus
Title: Re: hijackthis log analyzer
Post by: DavidR on March 25, 2007, 10:11:44 PM
There really is nothing wrong with using an on-line analyser, provided you don't take what it says as gospel and check those that are indicated as nasty, potentially nasty and unknown. Using google on the file names to see if that confirms the analysis.

Also at hijackthis.de you can even upload the suspect file for scanning not to mention the suspect files can be uploaded to virustotal and or jotti for scanning.

With the best will in the world not everyone who needs to use HJT and as you keep saying go to landzdown.com they couldn't possibly cope with the load. So using an on-line analysis tool as outlined above will break the back of the task and any further questions, etc. can be asked here, 'avast users helping avast users.'
Title: Re: hijackthis log analyzer
Post by: polonus on March 25, 2007, 10:23:14 PM
Hi DavidR,

I fully agree here with you. We like to share our expertise amongst ourselves, and help our fellow forum members as best as we can. This is a good information database to evaluate the hijackthis logs:
http://www.short-media.com/forum/showthread.php?t=35982

You can view and search the database here:
http://spywareshooter.com/search/search.php

Or the quick URL:
http://spywareshooter.com/entrylist.html


polonus
Title: Re: hijackthis log analyzer
Post by: mauserme on March 25, 2007, 10:34:28 PM
As far as I am concerned, they do NOT exist ...
You must have missed Spyros' post.  Its just a couple above yours.

Use it as part of a learning process and it will show you much.  Temper it with good sense and it will help you out of some difficulties and save you a little time.

Or do you mean to imply that the experts never, ever have occasion to double check themselves?
Title: Re: hijackthis log analyzer
Post by: polonus on March 25, 2007, 10:42:34 PM
Hi mauserme,

Especially when the malware does not seem to come out of the book, it is an evolving process. Also hijackthis is an ever changing tool, well anyway it better stays that way. You have various online databases for executables, processes, dll's etc. etc. to check and re-check. What I like especially and always renders best results is co-operation in a cleansing procedure. You would not believe how much I learned from simple being into it. The so-called experts had to go through the very same routines, and if they can almost "sniff out" the baddies only comes with time and experience. You must be very accurate, and keep to the prescribed routines,

polonus
Title: Re: hijackthis log analyzer
Post by: essexboy on March 25, 2007, 10:44:09 PM
Quote
Or do you mean to imply that the experts never, ever have occasion to double check themselves?
No I never double check, triple or quadruple yes, but never double  ;D

But as the links say many types of malware now have protection routines built in along with morphing dll/exe files.  All the tools out there are only as good as the mind wielding them, which is where the analysis tools like silent runners, DSS and Winpfind come in
Title: Re: hijackthis log analyzer
Post by: avatar2005 on March 25, 2007, 10:46:46 PM
After some searching & looking to provided links I'm wondering why HiJackThis  shows PC Tools firewall plus service as " Possible nasty" ??? ::)
Title: Re: hijackthis log analyzer
Post by: mauserme on March 25, 2007, 11:30:45 PM
Was it an unknown process?  It is kind of new so if that's all it said don't read too much into it.

If there's more to it than simply an unknown process post what it did say about it.
Title: Re: hijackthis log analyzer
Post by: DavidR on March 25, 2007, 11:40:30 PM
Quote from: avatar2005
After some searching & looking to provided links I'm wondering why HiJackThis  shows PC Tools firewall plus service as " Possible nasty"

Because it is possible that you are running it from a different location, hence reference to where it might normally be installed. It is also saying 'do you know this process' if so and you installed it then there is less likelihood of it being nasty. That is what we mean by checking and don't take everything as gospel, they to advise scanning with and AV if you are suspicious, etc.

There is also a means of adding user input to state that it is a safe program, etc.
Title: Re: hijackthis log analyzer
Post by: Lisandro on March 26, 2007, 12:43:09 AM
Strange that the HiJackThis does not 'discover' the path by the Registry and not only the 'default' location: this way you does not the freedom to install an application in any other path than the dafault one... am I wrong?
Title: Re: hijackthis log analyzer
Post by: mauserme on March 26, 2007, 01:25:24 AM
HijackThis does show the actual path.  But if the installation path is not the default, or at least not something the online analyzer expects, it gets reported as possibly nasty or unknown or whatever.  That's one reason human input is so important.

It makes more sense if you think of in terms of something like lsass.exe.  If the path is c:\windows\system32 its normally ok and the analyzer will report it as such.  If its c:\program files\temp its reported as possibly nasty because lsass.exe is a name known to be used by malware and its not the right path for the lsass.exe that's known to be good.  Doesn't mean its absolutely bad, but it needs closer scrutiny.
Title: Re: hijackthis log analyzer
Post by: Lisandro on March 26, 2007, 02:46:23 AM
But if the installation path is not the default
The default will be only in English... the default could be changed... the online analyzer should be improved...

Doesn't mean its absolutely bad, but it needs closer scrutiny.
This should be done by the antivirus signatures... I suppose.

Ok, I'm not bashing HJT, just thinking loudly about its behavior...
Title: Re: hijackthis log analyzer
Post by: mauserme on March 26, 2007, 03:46:08 AM
The default will be only in English... the default could be changed... the online analyzer should be improved...
I don't know what languages it can handle other than English.  I was involved with a log recently where the paths had both English and Spanish and I think the combination threw things off a bit.

Doesn't mean its absolutely bad, but it needs closer scrutiny.
This should be done by the antivirus signatures... I suppose.
The online scanners for sure.  I mean, if its on the computer already the resident scanner may not help.

Also some of the specialized tools like FindAwf that provide more information while doing nothing destructive.  Google and sometimes other threads where a similar entry has been analyzed also comes into play.  Sometimes its not only the location but also how it loads.  Its uncommon to be able to make a decision based upon a single line in a hjt log.  Not with the really nasty stuff, anyway.
Title: Re: hijackthis log analyzer
Post by: Hard_ROCKER on March 26, 2007, 12:07:45 PM
Sites to check out:


HijackThis log analysis :

http://www.hijackthis.de/ (http://www.hijackthis.de/) (this one is the best IMHO)

http://www.prevx.com/hijackthis.asp (http://www.prevx.com/hijackthis.asp)

http://exelib.com/hijack (http://exelib.com/hijack)

http://www.spyandseek.com/ (http://www.spyandseek.com/)

http://hjt.networktechs.com/ (http://hjt.networktechs.com/)


HijackThis tutorials and help :

http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php (http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php)

http://www.spywareinfo.com/~merijn/htlogtutorial.php (http://www.spywareinfo.com/~merijn/htlogtutorial.php)

http://www.castlecops.com/HijackThis.html (http://www.castlecops.com/HijackThis.html)

http://www.malwarehelp.org/understanding-and-interpreting-hjt1.html (http://www.malwarehelp.org/understanding-and-interpreting-hjt1.html)

http://netsecurity.about.com/od/popupsandspyware/a/aahijackthis.htm (http://netsecurity.about.com/od/popupsandspyware/a/aahijackthis.htm)

http://forums.majorgeeks.com/showthread.php?t=38752 (http://forums.majorgeeks.com/showthread.php?t=38752)


I'm sure there are plenty more helpful websites out there but these should be enough i believe .



Browse safely !


Hard Rocker
Title: Re: hijackthis log analyzer
Post by: polonus on March 26, 2007, 01:57:23 PM
Hi Hard_ROCKER,

Also check this site for info on processes: http://www.justtext.com/menu-program-list/program-tasks.html
or for instance for info on SisPower.dll:
http://www.file.net/process/sispower.dll.html
or here:
http://www.fbmsoftware.com/spyware-net/SearchComponentResults.aspx?af=2&searchtype=1
or
http://www.spywaredata.com/spyware/malware/rmma.exe.php


polonus

Title: Re: hijackthis log analyzer
Post by: avatar2005 on March 26, 2007, 03:00:38 PM
Thankyou guys for help, & specially for Polonus: dziekuje  za pomoc ;) 8)
Title: Re: hijackthis log analyzer
Post by: polonus on March 26, 2007, 04:05:17 PM
avatar2005,

Nie ma za co!

polonus
Title: Re: hijackthis log analyzer
Post by: Benoit43 on February 17, 2019, 04:13:07 AM
want to know what u guys think of this !

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 21:55:49, on 2019-02-16
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Unable to get Internet Explorer version!


Boot mode: Normal

Running processes:
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\ProgramData\Battle.net\Agent\Agent.6563\Agent.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Users\Mr-Mayem\Downloads\BraveBrowserSetup.exe
C:\Program Files (x86)\GUM7760.tmp\BraveUpdate.exe
C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
C:\Users\Mr-Mayem\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvLaunch.exe" /gui
O4 - HKLM\..\Run: [ZoneAlarm] C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'SERVICE RÉSEAU')
O23 - Service: @%SystemRoot%\system32\aelupsvc.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%systemroot%\system32\appidsvc.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\appinfo.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\audiosrv.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: AMD User Experience Program Launcher (AUEPLauncher) - AMD - C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: @%SystemRoot%\system32\AxInstSV.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bdesvc.dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\bfe.dll,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\qmgr.dll,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Service Brave Update (brave) (brave) - Unknown owner - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
O23 - Service: Service Brave Update (bravem) (bravem) - Unknown owner - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
O23 - Service: @%systemroot%\system32\browser.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\bthserv.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\certprop.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\cryptsvc.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\defragsvc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dhcpcore.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\dnsapi.dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dot3svc.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\dps.dll,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\eapsvc.dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wevtsvc.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdPHost.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\fdrespub.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\FntCache.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\hidserv.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\kmsvc.dll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\ListSvc.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\provsvc.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\ikeext.dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\IPBusEnum.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\iphlpsvc.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lltdres.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\lmhsvc.dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @%SystemRoot%\system32\FirewallAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\iscsidsc.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\msimsg.dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.exe
O23 - Service: @%SystemRoot%\system32\qagentrt.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netman.dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\netprofm.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\nlasvc.dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\nsisvc.dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\p2psvc.dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pcasvc.dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\sysWow64\perfhost.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.exe
O23 - Service: @%systemroot%\system32\pla.dll,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpnpmgr.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpauto.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\pnrpsvc.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\polstore.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\umpo.dll,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\profsvc.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasauto.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%Systemroot%\system32\rasmans.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%windir%\system32\RpcEpMap.dll,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\schedsvc.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sdrsvc.dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\Sens.dll,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\sensrsvc.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\SessEnv.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\shsvcs.dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppuinotify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\ssdpsrv.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sstpsvc.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wiaservc.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\swprv.dll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\sysmain.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\TabSvc.dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\tbssvc.dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\termsrv.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\themeservice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\mmcss.dll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\trkwks.dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\servicing\TrustedInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedInstaller.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%systemroot%\system32\upnphost.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\dwm.exe,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies Ltd. - C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\w32time.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%systemroot%\system32\wbiosrvc.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\WcsPlugInService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%systemroot%\system32\wdi.dll,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wecsvc.dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wercplsupport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wersvc.dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\system32\winhttp.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmisvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wsmsvc.dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wlansvc.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\wpcsvc.dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wpdbusenum.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wscsvc.dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.exe
O23 - Service: Windows Update (wuauserv) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\system32\wudfsvc.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: @%SystemRoot%\System32\wwansvc.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.exe
O23 - Service: ZoneAlarm Privacy Service (ZAPrivacyService) - Check Point Software Technologies, Ltd. - C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZaPrivacyService.exe
Title: Re: hijackthis log analyzer
Post by: DavidR on February 17, 2019, 02:14:29 PM
As you can see from this ancient topic 12 years old. 

HJT hasn't had any update in years, so it really isn't keeping pace with new malware.  So there probably aren't many malware removal specialists who are familiar with it now. 

These malware removal specialists, use more specialist tools as outlined here https://forum.avast.com/index.php?topic=194892.0 (https://forum.avast.com/index.php?topic=194892.0).  If the reason for posting this is you suspect there is malware on your system then you should create your own new topic in the Viruses and Worms sub-forum (https://forum.avast.com/index.php?board=4.0) outlining the problem and attach your logs there.