maybe this is where i should ask...?

Discussion in 'The Lounge' started by SomeCrazyStuff, Sep 12, 2008.

  1. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    hey i was just curious what all is being looked for in the removing malware logs.. i mean all the ccleaner superantispyware combofix mbam and mgtools logs.. i realize when certain things like java and windows messenger etc show up in them they are an instant flag.. but how do yall know about which certain options to choose in the different scans(HJT) or what the custom scripts to use with combofix and others should contain?

    is this just experience? or is there something else that says hey this computer needs to run this scan with these options and this other scan with these other options...

    mostly im just curious so i can be more effective at debugging and cleaning computer at work and whereever else might need it.. for example right now i am trying to run those tools on all my computer at the house including my brothers and dads(mom is on a mac g5.. xP) and they get kinda annoyed when i wont tell them what the logs mean.. whether it be cuz i dont know or just dont want to tell them..

    also.. what would it take to be more of a moderator type person on here.. i would love doing that... i mean i have from like 5:30 til 8am to do support postings... lol once i know what i am looking for i could possibly give the other foum admins a lil bit of a break... xD

    oh and by the way.. if you have never heard metallica and the trans siberian orchestra play carol of the bells you need to go find that.. it is LOVELY.. it was just playing in the background.. random thought.. xP
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Malware logs, well yes you are correct it really does need a trained eye to be able to work out what is legitimate and what is not in a HJT log, however HJT is overused for the wrong reasons, it is not a cleaning tool, does not show all malware that will be on a PC, its great for finding BHOs and some malware that could be inthe startup hive, but not much else.

    Some info to read
    http://forums.majorgeeks.com/showthread.php?t=38752
    http://www.bleepingcomputer.com/tutorials/tutorial42.html

    HJT will only be good in debugging if you have malware issues, if you have a slow PC and other issues its pretty useless.

    As for moderator, well whats needed is a track record of great advice and for the admin team to notice this and think that you could be a valuable member of the team, sadly on many forums its not easy to become a moderator as forums have many great members who are worthy of job, its not actually easy to moderate a site of this volume and also answer tech questions, so while some like the kudos of being a moderator on a busy and well known forum its not all its cracked upto be, its hard work at times.... like having a second job.

    Having said that its rewarding at times to meet and help many folk, so knuckle down and who knows :)

    trans siberian orchestra, yes friend of mine from Estonia mentioned this a whiles back... great sound.


    Good to have you onboard Majorgeeks and jump in answer tech questions and have fun.
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Plus it can seriously impact your nap time.....
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Agreed.... ah clock has just hit naptime for me, ding!
     
  5. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ha ok thats what i figured for the moderator part.. is anyone who is a moderator/admin souly employed in the site? or is the entire site upheld just on the side of other jobs? just curious.. i wouldnt mind settin up a site like this..

    yea im sure it can cut into nap time.. but looking at several of the mod's post logs averaging about 31 posts a day i think i could handle that.. like i said i have the entire afternoon almost everyday to do whatever.. right now all i do in the afternoon is either mess around on one of my computers or play xbox... i try to stay away from the tv.. the shows are all the same anyways...


    but yea glad to see that not eveyone on here are complete geeks... lol we all need our sleep.. xD
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Employed?......roflmao
     
  7. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member


    Wha??? You don't get paid for your exterminator job, Tim?

    :-D
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I get to keep all the virus's I find.....roflmao
     
  9. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    ha.. you joke but some people really do do that... look at the people with their virus zoos.. lol thats a disaster waiting to happen.. (oops i think i connect my zoo to the mainframe control our part of the internet backbone.. o_O)
     
  10. Wenchie

    Wenchie I R teh brat

    I found a unit with 4000 different infections on it. One that was sophisticated enough to sense a virus scan running and TURN OFF THE PC.

    It was at the LITERACY volunteers... guess they weren't COMPUTER literate, eh?
     
  11. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    wow 4000 different infections... not any repeats or some of them being different parts of the same infection?

    would definitely say they were computer illiterate...

    4000 seperate infections.. i cant even comprehend it.. only thing ive seen anywhere near that is a couple of system that had xp antivirus 2005/2006/2007/2008/2009 that declared between 10k and 30k infections.. but they were almost all fake so... yea...
     
  12. Wenchie

    Wenchie I R teh brat

    Well, there were probably actually more. like I said after it sensed the virus scan running it started a count down to shut off and locked the computer. After that I told her I couldn't do this for her (it was just a favor) she needed to call a tech. Probably move her data to a disk and wipe the drive.
     
  13. SomeCrazyStuff

    SomeCrazyStuff Private E-2


    ok correct me if im wrong but by moving files to another hard drive to restore them later.. wouldnt that provide means for the malware to spread from one computer to the next.. i mean i know we all hate having to format and start all over... but unless the files were critical to human life i dont think i would risk moving them...
     
  14. Wenchie

    Wenchie I R teh brat

    you'd have to scan the individual files prior to movin them. IF unchecked then yes, it would.
     
  15. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    yea good point.. i guess you could move all the files into a single folder and then have something run through that folder looking for malware.. but that would be a pain in the rear to go through each file individually.. but necessary i suppose..

    which brings to mind another question.. would an malware scans run go through each file and see if anything is different about it or if there are viral code attatched to the file? or do malware scans just look for certain instances of viral code/files.. for example say i got a trojan that downloaded a couple of files including a virus that attached code to the end of a word document.. or even just a txt file... would the malware scan pick up just the couple of files the trojan downloaded or would it look into the files for that bit of code that the virus planted?

    just curious.. even though curiosity killed the cat im still alive so...
     
  16. Wenchie

    Wenchie I R teh brat

    I believe they're pre programed to search for known viruses and file types. They don't scan a file and if anything has changed about it flag it, it has to have been specifically infected. Thats why keeping updates and databases up to date is so important, it tells the scanner what to look for
     
  17. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    that makes perfect sense.. kudos to the company thatll make a malware scan that looks for code instead of certain signatures... xD
     
  18. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Not employed by the site at all, you'll find many of the admins/moderators have been members of the site for many years, so its a combination for me of wanting to try and help PC users that get stuck with the issues I may have faced in the past years of using PCs or just know about how to fix, to liking the forum setup, other admins and mix of membership that keeps me around.

    Being a moderator or a member of many forums is voluntary and we all answer whatever questions in our free time, while many of us may work in the tech industry many dont they just love computing and as I mentioned earlier just wish to give something back to help others. For me I have a hybrid job which is a mix of tech and medicine, but my background has been predominantly tech and computing.

    I am a moderator on another forum, and member of a few others, so I'm or anyone else is not tied exclusively to this site, we come and go, but the admin/mod team's on forums tend to have the site they mod on as their main home base.


    That would be great if they could think for themselves and hunt out virii, however some virus scanners use heuristics which is supposed to find unknown malware, which tries to help the signature based virus scanner part, in some cases this heuristic approach works but as we all know malware is still rife so this type of malware scan needs more work.

    Just treat malware/virii as you would think of a human virus, they are similar, both mutate and create new strains that are immune to previous vaccines( until developed as Wenchine mentions earlier on new definition signature files for AV apps ), all spread like wildfire, can go un-noticed for a long time, PC virii need signatures which are in some way parts of the virus themselves like a human virus vaccine.
     
  19. SomeCrazyStuff

    SomeCrazyStuff Private E-2

    heuristics.. yea.. forgot about that.. especially for rootkits and stuff.. lol im an idiot... go ahead laugh.. i laugh at myself.. xP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds