A couple of quick questions

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rearden, Sep 21, 2004.

  1. Rearden

    Rearden Private E-2

    Hi there. I've been learning how to analyze Hijack This logs for a bit now and I have a few questions that I didn't see covered in the tutorials i've read (including the one on this site). The biggest thing I don't undersand is what to do about something like this. . .

    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM (file missing)

    The reason I don't understand is because of this entry:

    O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM

    that doesn't have the missing file thing.

    I've attached the original log and what it looked like after I was done with it. I left all of those(missing file) things alone because I don't understand. Can anyone explain it to me? I'd sure appreciate it.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not save your log files properly as text files. They appear to be missing the carriage return/line feed pairs. How exactly did you do this?
     
  3. Rearden

    Rearden Private E-2

    Sorry about that, might have been just the way my linux box saved it. I took the original and put it in notepad and deleted lines that I knew were good and left was I was unsure about. These should work.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't you have the ability to save the log file from HijackThis (but save it to a .txt file) and post it unmodified. Your original log is annoying to look at because things are wrapped to second lines when they should be on one line. This makes a lot more work for us. Logs are hard enough to read. You need to save them properly as a .txt file and then upload it here with no modifications and that includes not allowing the Linux system to modify it.

    These lines:
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} -
    res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM (file missing)

    should show as:
    O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM (file missing)

    Also, it appears you did some kind of cut and paste because some lines do not contain complete info. Like:
    O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/gam...nts/y/ct1_x.cab

    see how part of the link is missing. Do not cut & paste. Just save the log with HJT but instead of saving it to a .log file save it to a .txt file by changing the save as type.

    Are you telling me you do not know what Iespell is and did not install it? It is some sort of spell checker addon for Internet Explorer. If you do not want it, first check in Add/Remove programs for an uninstall routine.

    Can I assume you install all this UnH Solutions stuff?
    And what about these? Did you install them?
    C:\PROGRA~1\NEOTRA~1\
    C:\Program Files\Maxthon\
    C:\Program Files\Desktop Sidebar\
     
    Last edited: Sep 22, 2004
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normally it is safe to have HJT fix lines that say (no file) or (file missing). The question is why are your file missing for Iespell?

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
    O2 - BHO: (no name) - SOFTWARE - (no file)
    O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
    O2 - BHO: (no name) - {9C691A33-7DDA-4C2F-BE4C-C176083F35CF} - (no file)
    O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll (file missing)
    O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll (file missing)
    O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - (no file) (HKCU)

    How are things working now?
     
  6. Rearden

    Rearden Private E-2

    I'm sorry. I think you misunderstood what I am trying to do. I've been doing a lot of research, learning how to read and interpret Hijack This logs. I am trying to learn so that I can help other people interpret their logs. To help me learn, I will sometimes interpret a log, and then check back later to see if what I came up with matches what others came up with. The log that I posted here was on an internet forum and nobody ever replied. I didn't know what to do with the (no file) lines so I asked here. I apologize if I caused anyone to waste their time. :\
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it did waste some time. But did you learn what to do now?
     
  8. Rearden

    Rearden Private E-2

    Yes, thanks. Again, sorry if I caused any problems.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds