GithubHelp home page GithubHelp logo

dragokas / hijackthis Goto Github PK

View Code? Open in Web Editor NEW
664.0 48.0 106.0 171.73 MB

A free utility that finds malware, adware and other security threats

Home Page: http://hjt.sf.net

License: GNU General Public License v2.0

Batchfile 0.48% PowerShell 0.01% VBA 3.51% VBScript 0.22% Visual Basic 6.0 95.69% C++ 0.09%
malware hijacking-methods expert adware security scanner tuneup cleanup toolbars unwanted

hijackthis's Introduction

Download

Latest build [v3.x Alpha] - test version

Stable build [v2 outdated] - not updated anymore

(this is alpha-version - major changes are in progress; although it is definitely safe to use)

HiJackThis+

HiJackThis+ (Plus) (previously called: HiJackThis Fork v3) is a fork and a continuation of the original Trend Micro HiJackThis by Merijn Bellekom development, once a well-known tool.

At the moment, it is a step-by-step 100% rewritten source code of the original engine, aimed to provide a full compatiblity with the most recent Windows OS and a balance beetween compiling very fast results in logfile and combatting with the most popular malware, inluding the one not known to other antiviruses.

It is made by Alex Dragokas - a lawyer, security observer and malware researcher.

Overview

HiJackThis+ is a free utility for Microsoft Windows that scans your computer for settings changed by adware, spyware, malware and other unwanted programs. Shortly, consider it like Sysinternals Autoruns.

The difference from classical antiviruses is the ability to function without constant database updates, because HiJackThis+ primarily detects hijacking methods rather than comparing items against a pre-built database (signatures). This allows it to detect new or previously unknown malware - but it also makes no distinction between safe and unsafe items. Users are expected to research all scanned items manually, and only remove items from their PC when absolutely appropriate.

Therefore, FALSE POSITIVES ARE LIKELY. If you are ever unsure, you should consult with a knowledgeable expert BEFORE deleting anything.

HiJackThis+ is not a replacement of a classical antivirus. It doesn't provide a real-time protection, because it is a passive scanner only. Consider it as an addition. However, you can use it in form of boot-up automatical scanner in the following way:

  • Run the scanning by clicking "Do a system scan only"
  • Add all items in the ignore-list
  • Set up boot-up scan in menu "File" - "Settings" - "Add HiJackThis to startup"
  • Next time when user logged in, HiJackThis will silently scan your OS and display UI if only new records in your system were found.

Tutorial

Features

  • Lists non-default settings in the registry, hard drive and memory related to autostart
  • Generates organized, easily readable reports
  • Does not use a database of specific malware, adware, etc
  • Detects potential methods used by hijackers
  • Can be configured to automatically scan at system boot up

Advantages

  • Short logs
  • Fast scans
  • Not necessarily to create fixing scripts manually
  • No need for internet access or recurring database updates
  • Already familiar to many people
  • Portable

New in version 2.6+

  • Detects several new hijacking methods
  • Fully supports new versions of OS Windows
  • New and updated supplementary tools
  • Improved interface, security and backups

HiJackThis+ also comes with several modules useful for specific analysis and removing malware from a computer:

  • StartupList 2 (*new*)
  • Process Manager
  • Uninstall Manager
  • Hosts File Manager
  • Alternative Data Spy
  • Services Removing Tool
  • Batch Digital Signature Checker (*new*)
  • Registry Key Type Analyzer (*new*)
  • Registry Key Unlocker (*new*)
  • Files DACL Unlocker (*new*)
  • Check Browsers' LNK & ClearLNK (as downloadable components) (*new*)

Log analysis

IMPORTANT: HiJackThis+ does not make value-based calls on what is considered good or bad. You must exercise caution when using this tool. Avoid making changes to your computer settings without thoroughly studying the consequences of each change.

If you are not already an expert, we recommend submitting your case to an online help forum. Here are some suggestions:

Note: currently, only VIRUSNET association can provide direct analysis of HiJackThis+ logs in our github 'Issues' section. Please feel free to ask help there (English/Russian only).

Technical support

System requirements & Compatibility

  • Microsoft™ Windows™ 11 / 10 / 8.1 / 8 / 7 / Vista / XP (32/64-bit desktop and server)
  • WinRE & LiveCD are NOT supported

Copyrights

Thanks to:

  • regist (VIRUSNET) { @regist } - for the valuable tips and ideas, user's manual, database updates, closed and beta-testing
  • Sandor (VIRUSNET) { @Sandor-Helper } - for the beta-testing, lot of reports, PC treatment on GitHub and forums of association
  • akok (VIRUSNET) { @akokSZ } - for product promotion, providing a platform for tests and discussion, help with resolving conflicts with antiviruses
  • SafeZone.cc team (general VIRUSNET community) - for promotion and support, feedback and bug reports, PC treatment on forums of association
  • Fernando Mercês { @merces } (Trend Micro) - coordinator of original HJT, for the tips, suggestions and promotion
  • Loucif Kharouni { @loucifkharouni } (Trend Micro) - coordinator of original HJT, for the tips & suggestions

HiJackThis+ by Alex Dragokas is a continuation of Trend Micro HiJackThis development, based on v.2.0.6 branch and 100% rewritten at the moment. HiJackThis+ was initially supported by Trend Micro, but they have since refused support and closed its GitHub repository. HiJackThis+ is distributed under the initial GPLv2 license. It also includes several tools and plugins available as freeware.

Reviews & Mirrors

(clickable)

Note: These mirrors belong to other companies. They are non-official.

More references:

Other projects

You may also find my other programs useful:

hijackthis's People

Contributors

dragokas avatar loucifkharouni avatar merces avatar tannerhelland avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

hijackthis's Issues

Option run at startup doesn't work if hijackthis.exe is already in Fork directory

Hi,

When I check : Option run at startup it ok if hijackthis.exe is not already in Fork directory. If file is already in fork directory (and run from or not), hijack rename existing hijackthis.exe to xxxx.bak, doesn't create the schedule task and generate an error message.

ps : I just discover the additional tools in Tools menu... that's great!

best...

Suspected malware. Need PC cure help with HijackThis log

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs:
    On 20181031, had a spyware attack (see attached file spyware_attack_2018.10.31.pdf) and have since had intermittent problems accessing the internet with Chrome and Firefox, 'DNS server not found' for all websites I try to access. Other PC's on my home network are able to access the internet with no problems. On 2018.11.01 my DSL broadband provider spent 2 hours debugging my network connectivity and found no broadband issues on their end.

  2. What programs (browsers) affected by the problem:
    Chrome and Firefox

CollectionLog-2018.11.02-17.28.zip
spyware_attack_20181031.pdf

  1. Steps to reproduce:
    Try to access any website with Chrome or Firefox and occasionally, intermittently DNS server is not found.

Browser Hijack Software Scanner

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

CreateFile: Access denied (code 5)

On Vista,
when trying to open some task scheduler xml files, CreateFile returns code 5.
Code is:
retHandle = CreateFile(StrPtr(FileName), GENERIC_READ, FILE_SHARE_READ Or FILE_SHARE_WRITE, ByVal 0&, OPEN_EXISTING, ByVal 0&, ByVal 0&)

Windows Defender is turned off. And there no AV software installed.

Icacls show nothing unspecific for these 4 files:

C:\Windows\system32>icacls C:\Windows\system32\Tasks\Microsoft\Windows\CertificateServicesClient\SystemTask
C:\Windows\system32\Tasks\Microsoft\Windows\CertificateServicesClient\SystemTask BUILTIN\Administrators:(F)
                                                                                 NT AUTHORITY\SYSTEM:(F)

Successfully processed 1 files; Failed processing 0 files

C:\Windows\system32>icacls C:\Windows\system32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries
C:\Windows\system32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries BUILTIN\Administrators:(F)
                                                                         NT AUTHORITY\SYSTEM:(F)

Successfully processed 1 files; Failed processing 0 files

C:\Windows\system32>icacls C:\Windows\system32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
C:\Windows\system32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask BUILTIN\Administrators:(F)
                                                                                  NT AUTHORITY\SYSTEM:(F)

Successfully processed 1 files; Failed processing 0 files

C:\Windows\system32>icacls C:\Windows\system32\Tasks\Microsoft\Windows\Tcpip\WSHReset
C:\Windows\system32\Tasks\Microsoft\Windows\Tcpip\WSHReset BUILTIN\Administrators:(F)
                                                           NT AUTHORITY\SYSTEM:(F)
                                                           NT AUTHORITY\LOCAL SERVICE:(Rc,S,X,RA)
                                                           NT AUTHORITY\LOCAL SERVICE:(R)

Successfully processed 1 files; Failed processing 0 files

Elevated notepad can open these 4 files normally.
At the same time all another xml files in the SAME directories can be opened normally with CreateFile.
Currently, it happens only in IDE.
However, some time ago I saw the same behavior in release.

Log of HJT:

Logfile of HiJackThis Fork (Beta) by Alex Dragokas v.2.8.0.2

Platform: x64 Windows Vista (Business), 6.0.6002.0, Service Pack: 2
Time: 02.02.2018 - 01:18 (UTC+02:00)
Language: OS: English (0x409). Display: English (0x409). Non-Unicode: English (0x409)
Elevated: No
Ran by: Alex (group: Administrator) on WIN-DGRPVC84P0L, FirstRun: no

Internet Explorer: 7.0.6002.18005
Default: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Internet Explorer)

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.EXE
1 C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
1 C:\Windows\System32\Wbem\WmiPrvSE.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\dwm.exe
1 C:\Windows\System32\taskeng.exe
1 C:\Windows\system32\SearchIndexer.exe
2 C:\Windows\system32\csrss.exe
1 C:\Windows\system32\lsass.exe
1 C:\Windows\system32\lsm.exe
1 C:\Windows\system32\msdtc.exe
1 C:\Windows\system32\services.exe
1 C:\Windows\system32\smss.exe
10 C:\Windows\system32\svchost.exe
1 C:\Windows\system32\wininit.exe
1 C:\Windows\system32\winlogon.exe
1 VGAuthService.exe
1 vmacthlp.exe
1 vmtoolsd.exe

O4 - HKLM..\Run: [VMware User Process] = C:\Program Files\VMware\VMware Tools\vmtoolsd.exe -n vmusr
O4 - HKLM..\Run: [Windows Defender] = C:\Program Files\Windows Defender\MSASCui.exe -hide
O10 - Broken Internet access because of LSP chain gap (#1 in chain of 6 missing)
O17 - DHCP DNS 1: 192.168.132.2
O22 - Task: Run HJT Project - C:\Program Files (x86)\Microsoft Visual Studio\VB98\vb6.exe "C:\Users\Alex\Desktop_HJT_src_HijackThis.vbp"
O23 - Service R2: VMware Alias Manager and Ticket Service - (VGAuthService) - C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe
O23 - Service R2: VMware Physical Disk Helper Service - C:\Program Files\VMware\VMware Tools\vmacthlp.exe
O23 - Service R2: VMware Tools - (VMTools) - C:\Program Files\VMware\VMware Tools\vmtoolsd.exe
O23 - Service S2: Windows Defender - (WinDefend) - C:\Windows\System32\svchost.exe; "ServiceDll" = C:\Program Files\Windows Defender\mpsvc.dll
O23 - Service S3: TP AutoConnect Service - (TPAutoConnSvc) - C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe
O23 - Service S3: TP VC Gateway Service - (TPVCGateway) - C:\Program Files\VMware\VMware Tools\TPVCGateway.exe

Debug information:

  • 02.02.2018 01:18:20 - modFile.OpenW - #0 LastDllError = 5 (Access is denied.) Cannot open file: C:\Windows\system32\Tasks\Microsoft\Windows\CertificateServicesClient\SystemTask
  • 02.02.2018 01:18:21 - modFile.OpenW - #0 LastDllError = 5 (Access is denied.) Cannot open file: C:\Windows\system32\Tasks\Microsoft\Windows\PLA\System\ConvertLogEntries
  • 02.02.2018 01:18:21 - modFile.OpenW - #0 LastDllError = 5 (Access is denied.) Cannot open file: C:\Windows\system32\Tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
  • 02.02.2018 01:18:21 - modFile.OpenW - #0 LastDllError = 5 (Access is denied.) Cannot open file: C:\Windows\system32\Tasks\Microsoft\Windows\Tcpip\WSHReset

--
End of file - Time spent: 2 sec. - 6502 bytes, CRC32: FFFFFFFF. Sign: 숧偁

Could not figure out why that happens.

Reporting one issue in StartupList, and another potential issue in AVZ Antivirus Toolkit as well

Hello,

I would like to report two bugs/errors I encountered in the latest versions of HiJackThis and AVZ Antivirus Toolkit. Before running a full system scan (and saving a log file) within HiJackThis, I decided to run the StartUp List v2.12 Fork. Please refer to the attached screenshot titled "StartupList_Err.png" and you will see that almost halfway through the process, the program throws a Run-time error '5': Invalid procedure call or argument error.

Considering I used to write programs in VB6 a long, long time ago, I'm quite familiar with this error (and I remember it being one of the more common ones, in fact). I'd like to point out that StartupList was in the process of loading my Winlogons Autostarts, as you can clearly see in my screenshot. As instructed, I made sure to generate a debug log file (which is attached as "HiJackThis_debug.log"), although I must admit I only glanced over it for all of about five seconds.

Furthermore, when I was generating the debug log file information using the latest version of the AVZ Antivirus Toolkit, you will see in the attached "RSITx64.exe_Err.png" image that upon AVZ trying to load RSITx64.exe, it was unable to do so. I am not sure if this was due to an issue on my end or otherwise. However, I simply clicked 'OK' and the Toolkit kept humming along as if nothing had ever happened until it finished. Consequently, if this error WAS in fact due to an issue on my end, I'd very much like to know if it would have had anything to do with a potential virus/infection? I am fixing to post my scan log file shortly as I believe it contains quite a few abnormalities.

In conclusion, it would be very simple (for me, at least) to reproduce the two errors I described and displayed above. I would simply run StartupList again (I've run it more than once and the same error occured each time), and the same goes for the AVZ Antivirus Toolkit. I ran it at least twice and the error occurred each time as well. I am assuming the Toolkit error is due to something on my end, although I am unsure about the StartupList error.

Thank you for your time.

rsitx64 exe_err

startuplist_err

HiJackThis_debug.log

malware

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: browser open inaspectately pages
  2. What programs (browsers) affected by the problem: chrome - edge
    HiJackThis.log

Chrome LAG on text fields

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: Click on any text entry field in Chrome
  2. What programs (browsers) affected by the problem: Chrome
  3. Steps to reproduce: Click on a text entry field, there will be clocking for about 3 seconds then text can be entered.
    CollectionLog-2018.08.10-09.55.zip

Virus From Persistent Hacker

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?
    HiJackThis2.log

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _______Nothing: Unable to view content on webpages and experiencing rogue access points affecting my internet connection at home, also from infiltrating code running on iPhone and work Android phone, and when using Verizon Jetpack. Network showing NetBotx , someone monitoring Iot items in home and multiple rogue access points using Linux Ubantu, Citrix, and multiple Raspberry PIs, etc.
  2. What programs (browsers) affected by the problem: Every browser I use: Edge, Internet Explorer, Firefox, K-Melon. Multiple .exe files and new users created impersonating my user id and Microsoft Apps being downloaded by Remote Computer with forced sharing.________
  3. Steps to reproduce: Monitoring source code on every web page in every browser and using SysAdmin apps to monitor daily changes on PC including configuration changes and changes made to Registry Editor to deny access to information. I am not an IT Professional or a developer. I am learning on my own.__

Endless "The shell stopped unexpectedly and explorer.exe was restarted."

Welcome !
Thank you for joining the section of VIRUSNET association support.

  • Describe your problem in details:
  1. What did you done before the problem occurs:
    Beginning two days ago, beginning with system boot and as long as the Windows (Explorer) Shell is active, it repeatedly continually fails and restarts every few seconds to minutes (just happened now as I was typing this). It's apparently freezing or hanging, and certain actions like right-clicking on the Desktop will elicit an immediate crash and restart, but otherwise some watchdog eventually kicks in and does the deed.

After one of these events, the Shell will be momentarily functional - e.g. Desktop right-click context menu works - but only briefly. (Another restart just happened.) The restarts grab focus away from every other process and that primary Shell instance of explorer.exe also seems to permanently hog one CPU core as long as it is active (25% utilization of a 4-core Core i5-3570K CPU), making the system largely unusable as long as the Shell is active. Killing the primary explorer.exe process provides some relief, AND Explorer then continues to function normally as a file manager.

  1. What programs (browsers) affected by the problem:
    Everything is affected, obviously.

  2. Steps to reproduce:
    Boot the system and wait....

In addition to attaching the requested Autologger log file, I am attaching a Zip file containing an .evtx Event Viewer file containing a filtered view of some of the recorded APPCRASH and BEX64 Application log events.

CollectionLog-2018.08.22-18.34.zip
BEX64 explorer.exe crashes.evtx.zip

Mark everything found for fixing after check doesn't work

Hi,

Everything is in the title!!
Mark everything found for fixing after check doesn't work in admin exe launch or not.

Windows 10 Pro 10 build 16299

Thanks a lot for your work dragokas.

ps : I use Hijackthis only to check new entry at computer startup and detect normal/abnormal setup since last session. This software do the job very well.

Best regards,

Log file, could someone scan it for me please

Hi

I have been having a problem with overheating cpu that is working hard even when there is limited work being done.
Olpair seems to have invaded Chrome and is popping up ads even sometimes when Chrome has been closed.
Many thanks

Logfile of HiJackThis Fork (Beta) by Alex Dragokas v.2.8.0.4

Platform: x64 Windows 10 (Pro), 10.0.17134.345 (ReleaseId: 1803), Service Pack: 0
Time: 11.10.2018 - 18:10 (UTC+01:00)
Language: OS: English (0x409). Display: English (0x809). Non-Unicode: English (0x809)
Elevated: Yes
Ran by: Think (group: Administrator) on THINK-PC, FirstRun: yes

Chrome: 69.0.3497.100
Edge: 11.0.17134.345
Internet Explorer: 11.0.17134.1
Default: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Chrome)

Boot mode: Normal

Running processes:
Number | Path
13 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
1 C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
1 C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
1 C:\Program Files (x86)\Windscribe\WindscribeService.exe
1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1 C:\Program Files\AVAST Software\Avast\AvastUI.exe
1 C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
2 C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
1 C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
1 C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
1 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1 C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
1 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
1 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
1 C:\Program Files\Windows Defender\MSASCuiL.exe
1 C:\Program Files\WindowsApps\Microsoft.BingNews_4.27.2643.0_x64__8wekyb3d8bbwe\Microsoft.Msn.News.exe
1 C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.210.0_x64__kzf8qxf38zg5c\SkypeHost.exe
1 C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18081.14710.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
1 C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1808.2461.0_x64__8wekyb3d8bbwe\Calculator.exe
1 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.10827.20137.0_x64__8wekyb3d8bbwe\HxOutlook.exe
1 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.10827.20137.0_x64__8wekyb3d8bbwe\HxTsr.exe
1 C:\Users\Think\AppData\Local\Apps\2.0\6G6P2LDL.JXQ\NG54Y1LD.2VW\lsb...tion_2d7b41b05b24775e_0001.0006_3b0a905c8de4f74a\LSB.exe
1 C:\Users\Think\AppData\Roaming\Dashlane\Dashlane.exe
1 C:\Users\Think\AppData\Roaming\Dashlane\DashlanePlugin.exe
1 C:\Users\Think\Desktop\HiJackThis\HiJackThis.exe
1 C:\Users\Think\Desktop\HiJackThis\MemCompression
1 C:\Users\Think\Desktop\HiJackThis\Registry
1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
2 C:\Windows\System32\LPlatSvc.exe
9 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
2 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SettingSyncHost.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\SystemSettingsBroker.exe
1 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\browser_broker.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
2 C:\Windows\System32\dasHost.exe
3 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\hkcmd.exe
1 C:\Windows\System32\ibmpmsvc.exe
1 C:\Windows\System32\igfxpers.exe
1 C:\Windows\System32\igfxtray.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\rundll32.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
80 C:\Windows\System32\svchost.exe
2 C:\Windows\System32\taskhostw.exe
2 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wbem\unsecapp.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
1 C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
12 C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\explorer.exe

O2-32 - HKLM..\BHO: Dashlane BHO - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Think\AppData\Roaming\Dashlane\ie\Dashlanei.dll
O3-32 - HKLM..\Toolbar: Dashlane Toolbar - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Think\AppData\Roaming\Dashlane\ie\KWIEBar.dll
O4 - HKCU..\Run: [DashlanePlugin] = C:\Users\Think\AppData\Roaming\Dashlane\DashlanePlugin.exe ws
O4 - HKCU..\Run: [Dashlane] = C:\Users\Think\AppData\Roaming\Dashlane\Dashlane.exe autoLaunchAtStartup
O4 - HKCU..\Run: [Windscribe] = C:\Program Files (x86)\Windscribe\Windscribe.exe -os_restart
O4 - HKCU..\StartupApproved\Run: [GoogleChromeAutoLaunch_E88856B6B5DF275909287BC7482DE870] (2018/09/07) = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5
O4 - HKCU..\StartupApproved\Run: [OneDrive] (2018/09/07) = C:\Users\Think\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background
O4 - HKCU..\StartupApproved\StartupFolder: C:\Users\Think\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\adu213uasdk123jim12.vbs (2018/09/07)
O4 - HKCU..\StartupApproved\StartupFolder: C:\Users\Think\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\asdu123jnjasodi9i13.vbs (2018/09/07)
O4 - HKCU..\StartupApproved\StartupFolder: C:\Users\Think\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\asdzu1762z3hnsajmd.vbs (2018/09/07)
O4 - HKLM..\Run: [AvastUI.exe] = C:\Program Files\AVAST Software\Avast\AvLaunch.exe /gui
O4 - HKLM..\StartupApproved\Run: [HotKeysCmds] = C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM..\StartupApproved\Run: [IgfxTray] = C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM..\StartupApproved\Run: [Persistence] = C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM..\StartupApproved\Run: [SecurityHealth] = C:\Program Files\Windows Defender\MSASCuiL.exe
O4 - HKU\S-1-5-19..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4 - HKU\S-1-5-20..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4 - User Startup: C:\Users\Think\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\laskdadn81237sausinadsh.vbs
O4-32 - HKLM..\Run: [HP Software Update] = C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O9 - Button: HKLM..{22CC3EBD-C286-43aa-B8E6-06B115F74162} - HP Smart Print - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9 - Tools menu item: HKLM..{22CC3EBD-C286-43aa-B8E6-06B115F74162} - HP Smart Print - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9-32 - Button: HKLM..{22CC3EBD-C286-43aa-B8E6-06B115F74162} - HP Smart Print - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O9-32 - Tools menu item: HKLM..{22CC3EBD-C286-43aa-B8E6-06B115F74162} - HP Smart Print - C:\Program Files (x86)\Hewlett-Packard\Smart Print\SmartPrintSetup.exe
O17 - DHCP DNS 1: 194.168.4.100
O17 - DHCP DNS 2: 194.168.8.100
O21 - HKLM..\ShellIconOverlayIdentifiers: avast - {472083B0-C522-11CF-8763-00608CC02F24} - C:\Program Files\AVAST Software\Avast\ashShA64.dll
O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndContinueUpdates - {0DC331EE-8438-49D5-A721-E10B937CE459} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndScanForUpdates - {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: HPCustParticipation HP ENVY 4500 series - C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe /UA 12.5 /DDV 0x0b00
O22 - Task: WpsExternal_Think_20180806190351 - C:\Users\Think\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe /wpscloudlaunch /run_plugin /plugin_name=ktaskschdtool /plugin_entry=ktaskschdtool.dll /task=wpsexternal /launchtask /ver=1.0 /start_from=task_external
O22 - Task: WpsUpdateTask_Think - C:\Users\Think\AppData\Local\Kingsoft\WPS Office\10.2.0.7456\wtoolex\wpsupdate.exe -from=task
O22 - Task: \Avast Software\Overseer - C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe /from_scheduler:1
O22 - Task: \Lenovo\ImController\Lenovo iM Controller Monitor - C:\WINDOWS\system32\ImController.InfInstaller.exe -checkremoval
O22 - Task: \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance - C:\WINDOWS\system32\sc.exe START ImControllerService
O22 - Task: \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask - C:\WINDOWS\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
O22 - Task: \Lenovo\ImController\TimeBasedEvents\8ed7f941-e68a-4863-8b4e-c5f9a9ebb713 - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger 8ed7f941-e68a-4863-8b4e-c5f9a9ebb713
O22 - Task: \Lenovo\ImController\TimeBasedEvents\d7d5a0a3-f422-4c51-bf57-a00bcf54fb91 - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger d7d5a0a3-f422-4c51-bf57-a00bcf54fb91
O22 - Task: \Lenovo\ImController\TimeBasedEvents\ec23bdf7-269a-45af-b41a-15f2453ca479 - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger ec23bdf7-269a-45af-b41a-15f2453ca479
O22 - Task: \Lenovo\Lenovo Hardware Settings - C:\WINDOWS\system32\rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
O22 - Task: \Lenovo\Lenovo Service Bridge\S-1-5-21-1371865374-2896238855-448623355-1000 - C:\WINDOWS\system32\rundll32.exe dfshim.dll,ShOpenVerbShortcut C:\Users\Think\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo\Lenovo Service Bridge.appref-ms
O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -SettingChange - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -SettingChange - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -ProtectionStateChanged -FreeNetworkOnly - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceWnsFallback - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -Periodic - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: \Microsoft\Windows\DirectX\DXGIAdapterCache - C:\WINDOWS\system32\dxgiadaptercache.exe (Microsoft)
O22 - Task: \Microsoft\Windows\HelloFace\FODCleanupTask - C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe (Microsoft)
O22 - Task: \Microsoft\Windows\InstallService\ScanForUpdates - {A558C6A5-B42B-4C98-B610-BF9559143139} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: \Microsoft\Windows\InstallService\ScanForUpdatesAsUser - {DDAFAEA2-8842-4E96-BADE-D44A8D676FDB} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: \Microsoft\Windows\InstallService\SmartRetry - {F3A219C3-2698-4CBF-9C07-037EDB8E72E6} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: \Microsoft\Windows\LanguageComponentsInstaller\ReconcileLanguageResources - {D0582E3B-3126-4CAA-9155-AC37C912A489} - C:\WINDOWS\System32\LanguageOverlayServer.dll (Microsoft)
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"
O22 - Task: \Microsoft\Windows\Setup\Notifier - C:\WINDOWS\system32\Notifier.exe (file missing)
O22 - Task: \Microsoft\Windows\Speech\HeadsetButtonPress - C:\WINDOWS\system32\speech_onecore\common\SpeechRuntime.exe StartedFromTask (Microsoft)
O22 - Task: \Microsoft\Windows\WaaSMedic\PerformRemediation - {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32},None - C:\WINDOWS\System32\WaaSMedicSvc.dll (Microsoft)
O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service R2: Lenovo PM Service - (IBMPMSVC) - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service R2: Lenovo Platform Service - (LPlatSvc) - C:\WINDOWS\system32\LPlatSvc.exe
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service R2: SynTPEnh Caller Service - (SynTPEnhService) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service R2: System Interface Foundation Service - (ImControllerService) - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service R2: WindscribeService - C:\Program Files (x86)\Windscribe\WindscribeService.exe
O23 - Service R3: aswbIDSAgent - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service S2: Google Update Service (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: AvastWscReporter - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe /runassvc
O23 - Service S3: Google Update Service (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
O23 - Service S3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service S3: Windows Defender Advanced Threat Protection Service - (Sense) - C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe
O23 - Service S3: Windows Defender Antivirus Network Inspection Service - (WdNisSvc) - C:\ProgramData\Microsoft\Windows Defender\platform\4.14.17639.18041-0\NisSrv.exe
O23 - Service S3: Windows Defender Antivirus Service - (WinDefend) - C:\ProgramData\Microsoft\Windows Defender\platform\4.14.17639.18041-0\MsMpEng.exe

--
End of file - Time spent: 13 sec. - 31766 bytes, CRC32: FFFFFFFF. Sign: 篕૸

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

Suspicious HiJackThis entries

Hi everybody,
First off, I'm running an older Windows 7 machine (purchased over 5 years ago). As expected, it's slowed down over time. Recently, it's moving at a snails pace. I decided to run a quick HiJackThis scan just to see if anything fishy was going on and found at least one entry that seemed a little off. Any help would be much appreciated.

CollectionLog-2018.01.23-05.41.zip

issue win7 starting fortnite

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

Logfile of HiJackThis Fork (Beta) by Alex Dragokas v.2.8.0.4

Platform: x64 Windows 7 (Home Premium), 6.1.7601.24263, Service Pack: 1
Time: 10.11.2018 - 05:02 (UTC+01:00)
Language: OS: German (0x407). Display: German (0x407). Non-Unicode: German (0x407)
Elevated: Yes

Default: "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Firefox)

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
29 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\HiJackThis Fork\HiJackThis.exe
1 C:\Program Files (x86)\RocketDock\RocketDock.exe
1 C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
1 C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
1 C:\Program Files\AMD\CNext\CNext\amddvr.exe
1 C:\Program Files\AMD\CNext\CNext\amdow.exe
1 C:\Program Files\CCleaner\CCUpdate.exe
1 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
1 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
1 C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
1 C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
7 C:\Program Files\Mozilla Firefox\firefox.exe
1 C:\Program Files\Mozilla Firefox\plugin-container.exe
1 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
1 C:\Program Files\Windows Media Player\wmpnetwk.exe
1 C:\Users\worthtoot\Downloads\FRST64.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\alg.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\dwm.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\lsm.exe
1 C:\Windows\System32\notepad.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
14 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskeng.exe
1 C:\Windows\System32\taskhost.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\explorer.exe

O2 - HKLM..\BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - HKLM..\BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common

Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2-32 - HKLM..\BHO: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files

(x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKCU..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU..\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries

\Win64\EpicGamesLauncher.exe -silent
O4 - HKCU..\Run: [RocketDock] = C:\Program Files (x86)\RocketDock\RocketDock.exe
O4 - HKLM..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
O4 - MSConfig\startupreg: AdobeBridge [command] = (no file) (HKCU) (2018/11/05)
O4 - MSConfig\startupreg: AwesomeMiner [command] = C:\Program Files (x86)\Awesome Miner\AwesomeMiner.exe /minimized

(file missing) (HKCU) (2018/08/04)
O4 - MSConfig\startupreg: DAEMON Tools Lite Automount [command] = C:\Program Files\DAEMON Tools Lite\DTAgent.exe -

autorun (HKCU) (2018/11/05)
O4 - MSConfig\startupreg: Steam [command] = C:\Program Files (x86)\Steam\steam.exe -silent (HKCU) (2018/08/13)
O4 - MSConfig\startupreg: uTorrent [command] = C:\Users\worthtoot\AppData\Roaming\uTorrent\uTorrent.exe /MINIMIZED

(HKCU) (2018/11/05)
O9-32 - Button: HKLM..{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - In Blog veröffentlichen - C:\Program Files

(x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9-32 - Tools menu item: HKLM..{219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - In &Blog in Windows Live Writer

veröffentlichen - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: C:\Windows\system32\PrxerDrv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\prxernsp.dll
O15 - Trusted Zone: HKCU - *.localhost
O17 - DHCP DNS 1: 192.168.43.1
O22 - Task: (disabled) {FCAB38F3-AC64-483D-8256-9C9755D41B97} - C:\Windows\system32\pcalua.exe -a C:\Users\worthtoot

\Downloads\setup.exe -d C:\Users\worthtoot\Downloads
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - C:\Windows

\system32\CompatTelRunner.exe (Microsoft)
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - C:\Windows

\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly (Microsoft)
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\ProgramDataUpdater - C:\Windows

\system32\compattelrunner.exe -maintenance (Microsoft)
O22 - Task: Adobe Flash Player NPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_122_Plugin.exe -

check plugin
O22 - Task: Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: CCleanerSkipUAC - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource

scheduler
O22 - Task: MSIAfterburner - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s (file missing)
O22 - Task: StartCN - C:\Program Files\AMD\CNext\CNext\cncmd.exe startwithdelay
O22 - Task: StartDVR - C:\Program Files\AMD\CNext\CNext\dvrcmd.exe
O22 - Task: \Microsoft\Windows Live\SOXE\Extractor Definitions Update Task - {3519154C-227E-47F3-9CC9-12C3F05817F1} -

(no file)
O22 - Task: {9008A083-84D4-48B7-B059-F89CF679428E} - C:\Windows\system32\pcalua.exe -a C:\Users\worthtoot\Downloads

\avm_fritz_wlan_usb_stick_x64_05.04.31.exe -d C:\Users\worthtoot\Downloads
O23 - Service R2: Apple Mobile Device Service - C:\Program Files\Common Files\Apple\Mobile Device Support

\AppleMobileDeviceService.exe
O23 - Service R2: Diagnostics Tracking Service - (DiagTrack) - C:\Windows\System32\svchost.exe -k utcsvc; "ServiceDll" =

C:\Windows\system32\diagtrack.dll
O23 - Service R2: TeamViewer 13 - (TeamViewer) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service R2: Windows Defender - (WinDefend) - C:\Windows\System32\svchost.exe -k secsvcs; "ServiceDll" = C:\Program

Files\Windows Defender\mpsvc.dll
O23 - Service R2: Windows Live ID Sign-in Assistant - (wlidsvc) - C:\Program Files\Common Files\Microsoft Shared\Windows

Live\WLIDSVC.EXE
O23 - Service R3: Disc Soft Lite Bus Service - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service S2: Google Update-Dienst (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

/svc
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\Windows\SysWOW64\Macromed\Flash

\FlashPlayerUpdateService.exe
O23 - Service S3: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service S3: Google Update-Dienst (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

/medsvc
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance

Service\maintenanceservice.exe
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService

--
End of file - Time spent: 4 sec. - 16210 bytes, CRC32: FFFFFFFF. Sign: �
HiJackThis.log

*BUG REPORT* Run-time error while verifying process signature after running a StartUpList scan

Hello,

I noticed an Email earlier today notifying me that there had been a new version of HijackThis uploaded to the GitHub repo. I immediately downloaded it and decided (for whatever reason) to run a StartUpList scan.

As you can see from the screenshot of the Run-time error I have inserted below, I had been right-clicking on each of the running processes at the time the error actually occurred. I want to say I was able to successfully verify at least a minimum of 15 processes successfully without any issues before I tried to verify the process that actually threw the error ("armsvc.exe").

I just ran another StartUpList scan and I was able to verify the "armsvc.exe" process without any issues at all. Considering the error occurred because HijackThis was having trouble opening my clipboard, I'm thinking it's possible the reason behind me receiving the error may not be related to HijackThis at all, but instead my computer and/or its clipboard at the time. With that said, if Dragokas would like, he can add specific error handling for this type of particular error and (assuming my theory is correct) that is one of the reasons why I decided to go ahead and post this as a bug report.

hijackthis_bug

Crash at hijackthis close

I've tested all the tools and close them. When I close hijackthis I've error starting with double frame... and hijackthis.exe remain running without UI...

That's all folks for today :-)

Analisi 6 settembre

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

Plan on future versions

Plan, before v3.0 Final Release:

  • finish backup module for remaining sections (O23, O25). (finished)
  • remove MSCOMCTL, replace all controls by Unicode version.
  • finish updating of Russian user's manual. (finished)
  • revision of internal manual (EN/RU/UA). (finished)
  • finish GitHub wiki page templates. (finished)
  • fully portable version. (canceled)
  • read-only media support (requested by NickM).

Plan, after v3.0 Final Release:

  • Win98 SE+ support. (canceled)
  • checking hijackers in another browser (in progress)
  • default service settings restore tool (in progress)
  • fast registry search tool.
  • Security Fixes & Protection tool. (canceled)
  • multi-threading (in progress)

Uninstall manager: new UI & features

Just reworked UI:

rs

Also, log format is changed into:
ProgramName (Hive-xBit\...\Subkey) (Version: xxx - Publisher) (Special marks)

++ added "hidden" and "No uninstall string" entries
++ items with HKU (other users' software), marked as (User: Username) in log

Any else suggestions you would like to see in release?

HJT: Main discussion thread - improvement & development & news

Hi, everyone !!!

Welcome to the HJT development thread.

Here you can ask fast basic questions about HiJackThis Fork.
However, for our convenience, it's better that you create new issue for your case, especially for bug reports.

Don't forget to read HJT tutorial and Wiki-pages before asking questions.
Do not post HJT logs here for analyzing. Instead, create a new thread (issue).

Most of the news is published most quickly on general forum in our Russian-speaking community.
This topic will be updated with news as far as possible.

To post here you need to process a simple registration on GitHub.

Sometimes, new version of binary coming before pushing the source code. If you want you can test actual alpha/beta-version by this link: https://dragokas.com/tools/HiJackThis_test.zip

I wish you nice day and no viruses,
Stanislav.

Security Fixes & Protection Center

Welcome, contributors!

Here is new "work in progress" module (see comments in frmSecurity.frm file).

security

Purpose of the center:

  • increase system security by individual user wish;
  • optimization for the best performance.

You can:

  • Help with writing the code and pull request;
  • Suggest something new, suitable for this center.
  • Say some objections and wishes about already planned features.

Thanks,
Stanislav.

Peppe

Welcome !Logfile of HiJackThis Fork (Alpha) by Alex Dragokas v.2.7.0.20

Platform: x64 Windows 10 (Pro), 10.0.16299.64 (ReleaseId: 1709), Service Pack: 0
Time: 13.12.2017 - 07:01, Uptime: 21:48 min.
Language: OS: Italian (0x410). Display: Italian (0x410). Non-Unicode: Italian (0x410)
Elevated: Yes
Ran by: Peppe (group: Administrator) on DESKTOP-NVQH03Q, FirstRun: no

Opera: 49.0.2725.47
Chrome: 63.0.3239.84
Firefox: 57.0.2.6549
Edge: 11.0.16299.15
Internet Explorer: 11.0.16299.15
Default: "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Firefox)

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe
1 C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
2 C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe
1 C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe
1 C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe
1 C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe
1 C:\Program Files (x86)\Wise\Wise Memory Optimizer\WiseMemoryOptimzer.exe
1 C:\Program Files\CCleaner\CCleaner64.exe
1 C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
1 C:\Program Files\COMODO\COMODO Internet Security\cis.exe
1 C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
1 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
1 C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
1 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
1 C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\browsernativehost.exe
1 C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe
4 C:\Program Files\Mozilla Firefox\firefox.exe
1 C:\Users\Peppe\Desktop\Attività quotidiane\Pulizia\HiJackThis.exe
1 C:\Windows\SysWOW64\ANIWConnService.exe
1 C:\Windows\System32\DbxSvc.exe
2 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\System32\cmd.exe
3 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
70 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\timeout.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wbem\unsecapp.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\explorer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://it.yahoo.com/?fr=fp-comodo&type=42_33090001005_1.14.433704.601_i_hp_sp
R0 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes: DefaultScope = {0AA24E16-07B3-4694-8357-3C21ACC5F516} - Yahoo! - https://it.search.yahoo.com/yhs/search?hspart=comodo&hsimp=yhs-com_chrome&type=42_33090001005_1.14.433704.601_i_ds_sp&p={searchTerms}
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: TopResultURL = http://www.bing.com/search?pc=COSP&ptag=D120517-A915F698E57&form=CONBDF&conlogo=CT3335818&q={searchTerms}
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: URL = http://www.bing.com/search?pc=COSP&ptag=D120517-A915F698E57&form=CONBDF&conlogo=CT3335818&q={searchTerms}
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{0AA24E16-07B3-4694-8357-3C21ACC5F516} - Yahoo! - HTTP://IE.SEARCH.YAHOO.COM/OS?APPID=CHRIE&COMMAND= (SuggestionsURL)
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{0AA24E16-07B3-4694-8357-3C21ACC5F516} - Yahoo! - https://it.search.yahoo.com/yhs/search?hspart=comodo&hsimp=yhs-com_chrome&type=42_33090001005_1.14.433704.601_i_ds_sp&p={searchTerms} (URL)
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{88B41F8C-9689-4393-8FCB-2EB521E53390} - Yahoo Search - https://it.search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default (URL)
R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{88B41F8C-9689-4393-8FCB-2EB521E53390} - Yahoo Search - https://it.search.yahoo.com/sugg/ie?command={SearchTerms}&appid=i&output=osxml&appid=chrie (SuggestionsURL)
O2 - HKLM..\BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2015\x64\AcroIEFavStub.dll
O2 - HKLM..\BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll
O2 - HKLM..\BHO: Free Download Manager - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\iebho.dll
O2 - HKLM..\BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll
O2 - HKLM..\BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL
O2 - HKLM..\BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2015\x64\AcroIEFavStub.dll
O2-32 - HKLM..\BHO: Free Download Manager - {13D67BB7-DB5F-48AA-884D-7A5D94168509} - C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\x86\iebho.dll
O2-32 - HKLM..\BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2-32 - HKLM..\BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O3 - HKLM..\Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\2015\x64\AcroIEFavStub.dll
O4 - HKCU..\Run: [GUDelayStartup] C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun
O4 - HKCU..\StartupApproved\Run: [CCleaner Monitoring] (2017/11/18) C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU..\StartupApproved\Run: [Free Download Manager] (2017/11/18) C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\fdm.exe --minimized
O4 - HKCU..\StartupApproved\Run: [OffCAT] (2017/11/18) C:\Users\Peppe\AppData\Local\Microsoft\OffCAT\OffCAT_RTS.exe -startup
O4 - HKLM..\BootExecute: autocheck autochk * (file missing)
O4 - HKLM..\FileRenameOperations: C:\Users\Peppe\AppData\Local\Temp\adobegc.log -> DELETE
O4 - HKLM..\FileRenameOperations: C:\WINDOWS\SoftwareDistribution\ReportingEvents.log -> DELETE
O4 - HKLM..\FileRenameOperations: C:\WINDOWS\debug\PASSWD.LOG -> DELETE
O4 - HKLM..\FileRenameOperations: C:\WINDOWS\debug\WIA\wiatrace.log -> DELETE
O4 - HKLM..\FileRenameOperations: C:\WINDOWS\temp\DESKTOP-NVQH03Q-20171212-0913.log -> DELETE
O4 - HKLM..\FileRenameOperations: C:\WINDOWS\temp\officeclicktorun.exe_streamserver(20171212091310D3C).log -> DELETE
O4 - HKLM..\Policies\Explorer\Run: [Chrome] C:\WINDOWS\servicecrsssr.vbs
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
O4 - HKLM..\Run: [COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10}] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O4 - HKLM..\StartupApproved\Run32: [D-Link D-Link Wireless G DWL-G122_DWA-110] (2017/11/18) C:\Program Files (x86)\D-Link\DWL-G122_DWA-110\AirGCFG.exe
O4 - HKLM..\StartupApproved\Run32: [IseUI] (1601/01/01) C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe
O4 - HKLM..\StartupApproved\Run: [SecurityHealth] (2017/11/18) C:\Program Files\Windows Defender\MSASCuiL.exe
O4 - HKU\S-1-5-19..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
O4 - HKU\S-1-5-20..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
O8 - HKCU..\Extra context menu item: Download selected with FDM - C:/Program Files/FreeDownloadManager.ORG/Free Download Manager (file missing)
O8 - HKCU..\Extra context menu item: Download with FDM - C:/Program Files/FreeDownloadManager.ORG/Free Download Manager (file missing)
O8 - HKCU..\Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE
O8 - HKCU..\Extra context menu item: Scarica con Mipony - (no file)
O8 - HKCU..\Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - HKLM..{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - HKLM..{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - HKLM..{2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - HKLM..{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - HKLM..{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Send to OneNote - HKLM..{2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll
O9-32 - Extra 'Tools' menuitem: Lync Click to Call - HKLM..{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9-32 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - HKLM..{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9-32 - Extra 'Tools' menuitem: Se&nd to OneNote - HKLM..{2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9-32 - Extra button: Lync Click to Call - HKLM..{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9-32 - Extra button: OneNote Lin&ked Notes - HKLM..{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9-32 - Extra button: Send to OneNote - HKLM..{2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O15 - Trusted Zone: HKCU - *.localhost
O15 - Trusted Zone: HKCU - http://webcompanion.com
O15 - Trusted Zone: HKU.DEFAULT - *.localhost
O15 - Trusted Zone: HKU.DEFAULT - http://webcompanion.com
O17 - HKLM\System\CSS\Services\Tcpip..{1fc485fa-68d6-4b0b-8033-0fdbb8f21a8d}: NameServer = 156.154.70.25
O17 - HKLM\System\CSS\Services\Tcpip..{1fc485fa-68d6-4b0b-8033-0fdbb8f21a8d}: NameServer = 156.154.71.25
O17 - HKLM\System\CSS\Services\Tcpip..{d9ae8ad7-69f2-47c1-8e6a-0e9b6692da2b}: NameServer = 156.154.70.25
O17 - HKLM\System\CSS\Services\Tcpip..{d9ae8ad7-69f2-47c1-8e6a-0e9b6692da2b}: NameServer = 156.154.71.25
O17 - HKLM\System\ControlSet001\Services\Tcpip..{1fc485fa-68d6-4b0b-8033-0fdbb8f21a8d}: NameServer = 156.154.70.25
O17 - HKLM\System\ControlSet001\Services\Tcpip..{1fc485fa-68d6-4b0b-8033-0fdbb8f21a8d}: NameServer = 156.154.71.25
O17 - HKLM\System\ControlSet001\Services\Tcpip..{d9ae8ad7-69f2-47c1-8e6a-0e9b6692da2b}: NameServer = 156.154.70.25
O17 - HKLM\System\ControlSet001\Services\Tcpip..{d9ae8ad7-69f2-47c1-8e6a-0e9b6692da2b}: NameServer = 156.154.71.25
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O21 - ShellIconOverlayIdentifiers: (no name) - {472083B0-C522-11CF-8763-00608CC02F24} - (no file) (file missing)
O21 - ShellIconOverlayIdentifiers: DropboxExt1 Class - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt10 Class - {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt2 Class - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt3 Class - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt4 Class - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt5 Class - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt6 Class - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt7 Class - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt8 Class - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: DropboxExt9 Class - {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
O21 - ShellIconOverlayIdentifiers: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) - {8BA85C75-763B-4103-94EB-9470F12FE0F7} - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL
O21 - ShellIconOverlayIdentifiers: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) - {CD55129A-B1A1-438E-A425-CEBC7DC684EE} - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL
O21 - ShellIconOverlayIdentifiers: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} - C:\Program Files\Microsoft Office\root\Office16\GROOVEEX.DLL
O21-32 - ShellIconOverlayIdentifiers: DropboxExt1 Class - {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt10 Class - {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt2 Class - {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt3 Class - {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt4 Class - {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt5 Class - {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt6 Class - {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt7 Class - {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt8 Class - {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: DropboxExt9 Class - {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} - C:\Program Files (x86)\Dropbox\Client\DropboxExt.19.0.dll
O21-32 - ShellIconOverlayIdentifiers: Microsoft SkyDrive Pro Icon Overlay 1 (ErrorConflict) - {8BA85C75-763B-4103-94EB-9470F12FE0F7} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O21-32 - ShellIconOverlayIdentifiers: Microsoft SkyDrive Pro Icon Overlay 2 (SyncInProgress) - {CD55129A-B1A1-438E-A425-CEBC7DC684EE} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O21-32 - ShellIconOverlayIdentifiers: Microsoft SkyDrive Pro Icon Overlay 3 (InSync) - {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O22 - Task: (disabled) Adobe Flash Player Updater - C:\WINDOWS\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe
O22 - Task: (disabled) CCleanerSkipUAC - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: (disabled) DropboxUpdateTaskMachineUA - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
O22 - Task: (disabled) FreeDownloadManagerNetworkMonitor - C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\winwfpmonitor.exe
O22 - Task: (disabled) HPCustParticipation HP ENVY 4520 series - C:\Program Files\HP\HP ENVY 4520 series\Bin\HPCustPartic.exe /UA 15.5
O22 - Task: (disabled) Maxthon5 Update - E:\Program Files (x86)\Maxthon5\Bin\Maxthon.exe -RunScheduledUpdate
O22 - Task: (disabled) Uninstaller_SkipUac_Peppe - C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe /UninstallExplorer
O22 - Task: (disabled) \S-1-5-21-1676732629-4264307262-1539213425-1002\DataSenseLiveTileTask - C:\WINDOWS\System32\DataUsageLiveTileTask.exe
O22 - Task: Application Starter - f1375f225883e83d52e8db9690775c3c - C:\Program Files (x86)\Innovative Solutions\DriverMax\innostp.exe -install
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: DriverMax Notification - C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe -NOT
O22 - Task: DriverMaxAgent - C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe -AGENT
O22 - Task: DriverMaxWelcome - C:\Program Files (x86)\Innovative Solutions\DriverMax\drivermax.exe -BKSCAN
O22 - Task: GU5SkipUAC - C:\Program Files (x86)\Glary Utilities 5\Integrator.exe $(Arg0)
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: Opera scheduled Autoupdate 1492409753 - C:\Program Files (x86)\Opera\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: PerfectRegistry_DEFAULT - C:\Program Files (x86)\Raxco\PerfectRegistry\PerfectRegistry.exe -default
O22 - Task: PerfectRegistry_UPDATES - C:\Program Files (x86)\Raxco\PerfectRegistry\PerfectRegistry.exe -updatecheck
O22 - Task: PrivaZer_SkipUAC - C:\Program Files (x86)\PrivaZer\PrivaZer.exe $(Arg0)
O22 - Task: Wise Care 365.job - C:\Program Files (x86)\Wise\Wise Care 365\WiseTray.exe -StartTray
O22 - Task: Wise Turbo Checker.job - C:\Program Files (x86)\Wise\Wise Care 365\WiseTurbo.exe
O22 - Task: \COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O22 - Task: \COMODO\COMODO CMC {06A09C0F-DD9C-4191-A670-71115CD78627} - C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe --launchSchedule {06A09C0F-DD9C-4191-A670-71115CD78627}
O22 - Task: \COMODO\COMODO Maintenance {947247B5-026A-4437-9371-770782BE839D} - C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe --launchSchedule {947247B5-026A-4437-9371-770782BE839D}
O22 - Task: \COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} - C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe --launchSchedule {F140D794-60B6-4F00-9235-D6457AA25B22}
O22 - Task: \COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} - C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe --launchSchedule {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59}
O22 - Task: \COMODO\COMODO Telemetry {18AD3DFA-30C0-4B5F-84F7-F1870B1A4921} - C:\Program Files\COMODO\COMODO Internet Security\cis.exe --telemetry
O22 - Task: \COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} - C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe --launchSchedule {A6D52E4F-569B-4756-B3D8-DF217313DA85}
O22 - Task: \DelayedItemsByChemtableSoftware\AdobeAAMUpdater-1.0 - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
O22 - Task: \DelayedItemsByChemtableSoftware\CCleaner Monitoring (3) - C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O22 - Task: \DelayedItemsByChemtableSoftware\CCleaner Monitoring - C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O22 - Task: \DelayedItemsByChemtableSoftware\GUDelayStartup - C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun
O22 - Task: \Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False (Microsoft)
O22 - Task: \Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService (Microsoft)
O22 - Task: \Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft)
O22 - Task: \Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft)
O22 - Task: \Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880 (Microsoft)
O22 - Task: \Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files\Microsoft Office\root\Office16\msoia.exe scan upload (Microsoft)
O22 - Task: {31DDBD37-5DB7-4030-8064-10B0CAA806C3} - C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
O23 - Service R2: ANIWConn Service - (ANIWConnService) - C:\WINDOWS\SysWow64\ANIWConnService.exe
O23 - Service R2: COMODO Internet Security Helper Service - (CmdAgent) - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service R2: DbxSvc - C:\WINDOWS\system32\DbxSvc.exe
O23 - Service R2: Servizio Windows Defender Security Center - (SecurityHealthService) - C:\WINDOWS\system32\SecurityHealthService.exe
O23 - Service R2: Wise Boot Assistant - (WiseBootAssistant) - C:\Program Files (x86)\Wise\Wise Care 365\BootTime.exe
O23 - Service R2: isesrv - C:\Program Files (x86)\COMODO\Internet Security Essentials\isesrv.exe
O23 - Service R3: COMODO Virtual Service Manager - (cmdvirth) - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service S2: MxService - E:\Program Files (x86)\Maxthon5\Bin\MxService.exe
O23 - Service S3: AOMEI Backupper Scheduler Service - (Backupper Service) - C:\Program Files (x86)\AOMEI Backupper\ABService.exe
O23 - Service S3: PDF24 - E:\Program Files (x86)\PDF24\pdf24.exe
O23 - Service S3: Servizio Controllo rete di Windows Defender Antivirus - (WdNisSvc) - C:\Program Files\Windows Defender\NisSrv.exe
O23 - Service S3: Servizio Windows Defender Advanced Threat Protection - (Sense) - C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe
O23 - Service S3: Servizio Windows Defender Antivirus - (WinDefend) - C:\Program Files\Windows Defender\MsMpEng.exe

--
End of file - Time spent: 9 sec. - 49944 bytes, CRC32: FFFFFFFF. Sign: 긬
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

task host window stop closing pc

i frstly download pycharm and setup it . the desktop was like picture 1
picture 1
after restating pc , desktop becomes
picture 2
if I rearrange the icons and restart pc the arrangement will change again to be next to some of them like picture 2
then I uninstall pycharm this action doesn't occur again but if i use program on desktop and close the program i find its place changes _ that occurs these days

after some days when shutting down pc i find message " task host window stop closing Pc "

the hijack report ::
hijackthis.log

this installed programs report
InstallList.txt

if you please , i want to what makes programs' places change and stop " task host window stop closing Pc "

Thanks in advance.

Enum modules of 64-bit process under WOW64

ProcMan can't enum modules of 64-bit process,
because under WOW64 EnumProcessModules returns ERROR_PARTIAL_COPY.
The same for CreateToolhelp32Snapshot + TH32CS_SNAPMODULE

Take this project as example: https://github.com/dragokas/Blackbone

See also:
http://www.rohitab.com/discuss/topic/40696-list-loaded-drivers-with-ntquerysysteminformation/
https://doxygen.reactos.org/d7/d55/ldrapi_8c_source.html#l00972
https://stackoverflow.com/questions/3801517/how-to-enum-modules-in-a-64bit-process-from-a-32bit-wow-process

Hi

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

01

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

Commandline /silentautolog

Building hijack this into an Incident Response HTA right now for automation.... one thing I've noticed is that even with the /silentautolog enabled - the following warning will appear and still require interaction from the user:

HijackThis appears to have been started from a temporary folder. Since temp folders tend to be emptied regularly, it's wise to copy HijackThis.exe to a folder of its own, for instance C:\Program Files\HijackThis.
This way, any backups that will be made of fixed items won't be lost.

Please quit HijackThis and copy it to a separate folder first before fixing any items

The obvious work around is to just create a folder which we will do ... but silentautolog as a switch should still not prompt this error.

thanks guys - great work.

Unknown publisher / company (Windows Defender block HJT)

Hi,
That's me again...
When I start hijack THE FIRST TIME Ms Defender don't want to start it (red dialog) because the software has 'no publisher / company'. It is presented like a virus. that's not good, in the doubt, users can stop and forget it.
I've seen this behaviour after starting the beta to test bug correction.

Regards,

Word Document -- End User authorized Macros

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: _________________
  2. What programs (browsers) affected by the problem: ________________
  3. Steps to reproduce: _________________

Hebrew fonts

I just used HijackThis Fork Portable 3 and saw after scanning that Hebrew names are jibrish.
In the log it is OK .
May be using Aerial font will do?
Or add on setup Font manger

About size of the file 'HiJackThis.exe'

I was sometimes asked questions, why HiJackThis.exe is so huge in size ( ~ 5,6 MB ) compairing to original v2.0.5 (380 KB.)

Firstly, you need to understand that this is 100% reworked code with huge additions, see basic changelog under this spoiler or a complete changelog

Next, v2.0.5 is UPX-ed (packed), Fork - is not.

Today, this question is interested for myself too, so I decided to measure all in details.

Here it is.

Total size:

Version Unpacked (no UPX) 7zip (-mx9)
v2.0.5 1276 KB 346 KB.
v2.8.0.4 5683 KB 1843 KB.

Size of separate modules of v2.8.0.4 (in KB.):

Module name Unpacked exe 7zip (-mx9)
Core code and classes* 1344 395
StartupList2 + Microsoft MScomctl.dll 1124 + 1044 230 + 446
Backup & ABR 408 180
Regexp reserve subsystem (PCRE2) 348 179
Translations, ChangeLog, EULA 444 120
Icons, Logo 148 78
WhiteLists 300 66
Main form controls & menu & Other tools 204 50
Digital signature check 104 31
ADS Spy 52 20
ProcMan 52 17
RegKeyUnlocker 44 17
XmlParser 44 15

* Core code and classes includes:

  • New 'File', 'Hash', 'Process', 'Service', 'Task' and other modules.
  • New 'Reg. hive enum', 'Ini file', 'OSInfo', 'Process', 'Registry', 'String Builder' and other classes.
  • Code for detection and curing R, F, O sections.

Future updates

Microsoft MScomctl.dll is planned to be replaced by native VB6 code of unicode aware controls.
Replacement weighs ~ + 3992 KB (exe), or + 1049 (7zip),
so HJT size in future builds can be increased up to ~ + 3 MB (exe), or + 0,5 MB (in archive).

Translation into other languages (everybody welcome)

Hi, reader!

If you:

  1. have good knowlegdes of some language and doing little number of spelling mistakes
  2. have good technical skills in PC terminology, especially security topics
  3. ready to help us free of charge 1 or more hours.

You are welcome to make translation of:

  1. Our main program: HiJackThis Fork
  2. One of our closed-source downloadable plugins: ClearLNK, Check Browsers' LNK (1 hour of work maximum)
  3. Basic (short) manual
  4. Or improve existent translation (English, Russian, Ukrainian)

Reward: your nickname in resource page (for plugins) or in programs' About window (for main project).

Please, write down here, if you can and want provide some help, what language do you know, and what translations do you already done before.

Thanks and good luck!

HJT: List of updates

Here we'll public most recent HiJackThis Fork updates list.

If you want to test (experimental) version that is usually coming before actual pushing the source code, you can download nightly build by this link: https://dragokas.com/tools/HiJackThis_test.zip


For the full history (since v.2.6.1.0 Alpha Fork) - Oct 12, 2015 based on official v2.0.6, see: HiJackThis menu "Help" -> "About HJT" -> "History", or ./src/_ChangeLog_en.txt file. Russian version is here.

I suspect I am infected with a nasty Rootkit or a stealthy Trojan Horse

Hello,

Thank you for taking the time to read my post. As the title states, I suspect I am infected with some sort of Rootkit (or possibly a Trojan Horse). Prior to the infection, there was a person skilled in computers and programming that had physical access to my computer. I was informed by others that he had infected my PC. Upon learning this, I did some looking around, but did not find much. However, at this point I didn't know what was true and what wasn't, so I didn't dig very deep.

Approximately a week and a half later, I spoke with this individual and he/she in so many words threatened to "hack" me / do damage to my computer. Approximately 12-16 hours after the threat was made, I was working on my computer when I noticed it started to run hard and fast. My PC fan sped up and I had sensed that various resources on my PC had increased so I opened Task Manager and saw that my Antivirus program was taking up a high percentage of my Disk Usage (I cannot remember the exact percentage/number, but it was high enough to cause concern). I wanted to rule out that it may be my Antivirus simply downloading a definitions update, so I opened the main GUI and saw that it wasn't downloading anything.

I decided to restart my PC to see if any of the issues I've described so far would continue after a reboot, and they did. Therefore, I proceeded to run a netstat command and when I did so I noticed...I would estimate ~250-300 remote ports that were present in some form of state. Most of the ports were random 5-digit ports that were in sets of sequential numbers. For example: 48270, 48271, 48272, 48273, etc. and then they would skip ~50 numbers and pick back up in a sequential format, like so: 48220, 48221, 48222, 48223, etc.

I immediately unplugged my Ethernet cable out from the back of my PC tower and started doing some serious investigating on my PC. I found out that a rule had been added to my Antivirus Firewall that essentially rendered the firewall useless without actually disabling it (considering I would have noticed if it was disabled almost immediately). The rule that was added allowed any network, application, protocol, port, etc. full access to my PC. I also noticed that Developer Options in Windows 10 Pro had been enabled, as well as Microsoft's new implementation of their SSH Server. I now knew that this was very bad, and very serious.

Moving on, this actually happened two or three months ago so I'm not going to go into great detail about all of the symptoms I have experienced since the initial infection unless requested to do so (I'd rather have the logs examined before I list things that may not even be of any relevance or importance). However, I think it's important to note that my primary Email address was compromised about 2 hours after the initial infection. A day or two later I found out that whatever was dropped and executed on my PC had spread throughout my entire LAN, infecting the 4 other PCs that connect to / reside on it because the same symptoms that started appearing on the original computer that was infected also started appearing on my other computers (along with some new / different symptoms).

The AutoLogger log file attached below was generated on a laptop running Windows 7 Pro SP1 (64-bit). The original PC that was infected was running Windows 10 Pro (64-bit). At the moment, the original PC that was initially infected is no longer booting properly. However, I created a WinPE on a USB Stick and I downloaded AVZ v4 directly from the creator's website and was able to configure my own settings and run a full scan. It detected A LOT. I cannot be sure if what it detected is any type of real threat (although it sure appears to be), but I am going to include that log as well due to the fact that I personally feel that the default settings within AVZ (when it is launched by AutoLogger) are nowhere near sufficient enough to detect everything thats on my PCs (namely kernel hooks/intercepts and a whole lot more).

As you will see in the Windows 10 Pro (64-bit) log file, it appears that whatever has apparently infected my computer is residing in my Recycle Bin (I know it sounds weird, I'll let you look at the logs and tell me if its anything malicious or not) as well as my Windows folder (and some of its important subfolders). The last thing I'll say in an attempt not to have this post end up being over 50,000 characters long is that I have ran various programs such as Malwarebytes' AdwCleaner since the initial infection. On another PC running Windows 10 Home (64-bit) AdwCleaner will detect 7 registry keys and one service as being malicious. It will successfully move these item to Quarantine, it'll have me reboot, I'll delete them from the Quarantine section, and then scan again to make sure nothing was missed and the same exact registry keys and the one service are detected all over again. It seems any progress I've been able to make at any given time is quickly erased once the PC in question is rebooted.

Thank you very much for your time and your patience. I have received permission to place the logs in a zip file that is password protected. Whichever helper is assigned to look over this can obtain the password from Mr. Alex.

NOTE: If I was not supposed to include an additional log and/or if the helper assigned to my case is not allowed to view or take it into account, please forgive me and simply ignore it. I just really, really feel it may be of some importance being that it provides so much more than when AVZ is simply launched from AutoLogger.

My_Collection_Logs.zip

[Cure] Guestbook

SafeZone team welcomes HiJackThis users!

We are waiting for your feedback on the received treatment.

Please, leave detailed and correct suggestions and comments on improving the quality of our team service.

If you want to express your wishes for the development of the HiJackThis, welcome to the topic: HJT - improvement & development & news

Using your help, we will be better!
Regards, SafeZone.cc and HiJackThis teams.

PUP.Optional.Softomate detected , but not fixed

Hello,

As my computer is very slow (Windows 10 updated), I made previously :

  • analysis and fixing by Malwarebytes
  • complete analysis by Kaspersky antivirus
  • analysis and cleaning by ZHP Cleaner

This last one (though I followed the indications about navigators) is always detecting PUP.Optional.Softomate, but not fixing it.

That's why I "HijackedThis" and read it, but without detecting (understanding...!) anything ...

CollectionLog-2018.11.05-12.27.zip

HJT log

Welcome !
Thank you for joining the section of VIRUSNET association support.


BEFORE ASKING HELP, READ CAREFULLY THIS INSTRUCTION:


Step 1: Are you in the right place?

  • Do you need assistance in PC cure from viruses?
  • Or would you like to report a bug or propose a feature for HiJackThis?

If yes, see the next step.

Step 2: Show us required logs (for PC cure):

  1. What did you done before the problem occurs: Nothing_________________
  2. What programs (browsers) affected by the problem: Google Chrome
    HiJackThis log.txt

  1. Steps to reproduce: _________________

EDS checking bug on Win7 SP0

On Win 7 (6.1.7600) without service pack WinVerifyTrust returns TRUST_E_NOSIGNATURE.
After removing flag WTD_SAFER_FLAG, WinVerifyTrust returns error "CRYPT_E_BAD_MSG" (Not a cryptographic message or the cryptographic message is not formatted correctly.).

However, Sysinternals SigCheck and Process Hacker works OK.
Don't know how to handle this error.

Possible solutions:

  1. to intercept structures state data with WinDBG or API monitor and compare with own.
  2. extract Process Hacker's source (Verify.c) and test it in Win7 SP0 for several different flags and modes.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.