Author Topic: Farbar (frst), OTL, HijackThis log analyzing  (Read 31464 times)

0 Members and 1 Guest are viewing this topic.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #15 on: March 27, 2015, 08:52:49 AM »
I already was informed by my host that they are installing PHP 5.4 next month.
It is supposed to have all things needed to smoothly update to the upcoming PHP 7 version.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #16 on: March 27, 2015, 01:33:09 PM »
Dropped a line on Milos.
Could take a while till it is fixed.
I dropped a heavy anchor chain on him to make sure he noticed the line  ;D

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #17 on: March 30, 2015, 09:11:23 PM »
Reply from avast about the false positive:
Quote
The problem is, what we detect is this string: "AUTOIT3EXECUTESCRIPT C:\\GOOGLE\\GOOGLEUPDATE". That is in all the infected lnk files, but unfortunatelly in your .dat file as well. I suppose you are changing the file quite often, so whitelisting (which is hash-based) would not help much, right? (I whitelisted it now anyway.) I will try to change the detection so it does not flag your file...

New test version is now online:
Added detection for items in the farbar log
Added detection for things in addition.txt
Added the first (small) things to support checking the Hijackthis log
Added colors

http://www.ache.nl/cgi-bin/download.pl?file=MFLA

I could use some HJT logs from people who are running Windows 7, 8.1 and the preview of version 10.
All updates must be installed, not only for Windows but also for IE and such.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #18 on: March 31, 2015, 09:50:01 PM »
Windows 10 build 10049
Using Spartan as my browser


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #19 on: March 31, 2015, 09:53:38 PM »
Thank you essexboy,
I see your system is really badly infected with the Essexboy virus  ;D

I was asking for HijackThis logs ;)

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48552
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #20 on: March 31, 2015, 10:26:58 PM »
Thank you essexboy,
I see your system is really badly infected with the Essexboy virus  ;D

I was asking for HijackThis logs ;)
Since HijackThis isn't used any more, why spend time on outdated software analysis ?
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #21 on: March 31, 2015, 11:14:55 PM »
Ooops wrong log.. Here is the proper one :)


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #22 on: March 31, 2015, 11:18:21 PM »
Hi bob3160,

Just like Freefixer HJT can still be used for a wide range of particular malware cleansing, especially so-called browser related malware. The code has been left to "rot" by those that acquired Merijn's original HJT, but Eddy's creation has nothing to do with that.
Quote
The problem with HijackThis has always been that it’s not a tool for the inexperienced user because it doesn’t differentiate between malicious entries and those legitimately put there by software, so users have to rely on expert advice or risk making the computer worse by trying themselves. If you are the impatient type and want to quickly get some results about your log file without waiting for someone else to reply to you, here are 5 ways to automatically analyze the HiJackThis log file and quickly receive recommendations on what to fix.
Quote from Trend Micro's. And even going here to have the HJT results analyzed: http://www.hijackthis.de/index.php?langselect=english   will mean that you need expertise from a qualified removal expert to go over the analysis results and to know what exactly  to tick and what to leave unticked for cleansing.

I think Eddy knows perfectly well what he is doing, and he is very well aware of some of the HJT tool's obsolete state and limitations and he wants to overcome that with his new tool. I for instance have never understood why a well kept tool like Freefixer never got off the ground and why it never got any interest from malware removers, neither has Autoruns that could be used where HJT felt it's limits. So Eddy should also offer Autoruns next to his new tool.

The natural successor for HJT is RSIT: http://www.malwareinfo.nl/rsit-randoms-system-information-tool/

Damian


« Last Edit: March 31, 2015, 11:48:33 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #23 on: April 01, 2015, 04:22:21 AM »
Essexboy,

it is really time to remove that virus.
I am asking for Hijackthis logs, not Farbar logs.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #24 on: April 18, 2015, 04:56:57 PM »
Latest version:
http://www.ache.nl/cgi-bin/download.pl?file=ALA-B12

Added: detection for things in addition.txt
Added: detection for items in the Farbar logfile
Added: progress status while checking Adition.txt
Added: checking for pcalua.exe entries in Addition.txt
Bug fix: Addition.txt wasn't sometimes checked

If you get a message that a old version of Farbar is used, change the first line in FRST.txt to :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #25 on: April 18, 2015, 05:11:32 PM »
Eddy HJT is no longer valid as with 64bit systems it can not correctly report file paths etc..

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #26 on: April 18, 2015, 07:28:37 PM »
And the problem is... ?
Over 18.000 people are downloading it from SourceForge.
I don't know how many people are downloading it from other sites.
Just a (very?) low estimated guess....
Over 50.000 users are downloading and using it each week.

And so what if HJT doesn't support 64 bit systems?
There are millions of user who don't have a 64 bit system.
And for them HijackThis is still working fine.
Besides that, it is not hard for me to add a check what OS (bits) they are using and tell them the log is "not reliable" if they are using a 64 bit system.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #27 on: April 20, 2015, 12:10:53 AM »
And the problem is... ?
Over 18.000 people are downloading it from SourceForge.
I don't know how many people are downloading it from other sites.
Just a (very?) low estimated guess....
Over 50.000 users are downloading and using it each week.

And so what if HJT doesn't support 64 bit systems?
There are millions of user who don't have a 64 bit system.
And for them HijackThis is still working fine.
Besides that, it is not hard for me to add a check what OS (bits) they are using and tell them the log is "not reliable" if they are using a 64 bit system.

There is no issue. Martin was simply pointing out that HJT is no longer in common use for malware removal.

Looks like an interesting program. Might give it a shot one day. Load up a massively infected system and see what it catches, if I understood what it does correctly.

VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #28 on: April 20, 2015, 01:16:40 AM »
Bit of a Bug for you!

I JUST downloaded Farbar (FRST) from the website. Ran it, then Save As > C:\Program Files (x86)\ALA\FRST.txt.

Why am I being told it isn't the correct version?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Farbar (frst), OTL, HijackThis log analyzing
« Reply #29 on: April 20, 2015, 01:23:26 AM »
See reply #24:
Quote
If you get a message that a old version of Farbar is used, change the first line in FRST.txt to :
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015