headleft
     
HijackThis.de Security
Direct download
To the authors homepage
Database
Deutsch English Français Italian Czech
     
headright
 
HijackThis log file analysis
HijackThis opens you a possibility to find and fix nasty entries on your computer easier.
Therefore it will scan special parts in the registry and on your harddisk and compare them with the default settings. If there is some abnormality detected on your computer HijackThis will save them into a logfile. In order to find out what entries are nasty and what are installed by the user, you need some background information.
A logfile is not so easy to analyze. Even for an advanced computer user. With the help of this automatic analyzer you are able to get some additional support. Just paste your complete logfile into the textbox at the bottom of this page.
Due to a few misunderstandings, I just want to make it clear that this site provides only an online analysis, and not HijackThis the program.
Service & Support
HijackThis.de Supportforum Deutsch | English
Forospyware.com (Spanish) www.forospyware.com
Pchelpforum.com www.pchelpforum.com
Computerhilfen www.computerhilfen.com

Current information
Information - If you send us unknown or incorrect rated entries please fill out all the fields in english or german language. We will ignore it otherwise. We also ignore everything which doesn't contain reliable information to this entry.
Furthermore the contact forms on this page are not intended to help with your computer problems. Please use our forum if you have problems with your computer.
   
Log file
You can paste a logfile in this textbox

or you can choose a logfile from your computer


The following analyses has been stored temporarily
Logfile of Hijac...[Remove Logfile] 14.10.2007, 10:41:26
Show the visitors ratings
   
Help us to keep this free service online! Please give us a small donation via PayPal.
We didn't detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don't use any firewall at all.
We recommend you to use a firewall. Download and install one or activate windows xp´s own one. In case you got questions or you want us to add the firewall you use to our database, contact us at our forum.
Actions
Entry
Kind
Visitor's assessment
Information
Analyzerdetails 
Logfile of HijackThis v1.99.1
Kind

This should be the newest version.
 
Platform: Windows XP SP2 (WinNT 5.01.2600)
Kind

Analyzerdetails 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Kind

This should be the newest version.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\System32\smss.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\system32\winlogon.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\system32\services.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\system32\lsass.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\system32\svchost.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\System32\svchost.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\system32\spoolsv.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\Program Files\Eset\nod32krn.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\WINDOWS\Explorer.EXE
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\Program Files\Eset\nod32kui.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Kind
Not dangerous, but unnecessary.
This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\Fraps\fraps.exe
Kind

Visitor's assessment Analyzerdetails 
C:\WINDOWS\system32\svchost.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\Program Files\Mozilla Firefox\firefox.exe
Kind

This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
Kind

Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups! Tool, mit dem sie dieses Logfile erzeugt haben. Das Programm sollte so angelegt sein ! C:\Programme\HijackThis\HijackThis.exe
Visitor's assessment Analyzerdetails 
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Kind

SDhelper.dll - Spybot - Search & Destroy, http://spybot.eon.net.au/
Visitor's assessment Analyzerdetails 
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
Kind
This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
Kind
SoundMax integrated sound. Required if you have custom settings for your sound, such as effects and environments
Visitor's assessment Analyzerdetails 
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
Kind
This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Kind
This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
O4 - HKCU\..\Run: [Primedius Firewall] C:\Program Files\Primedius\Firewall\Prifw.exe
Kind

Fuzzy Algorithmcheck (4.44 / 5.00), Safe
Visitor's assessment Analyzerdetails Unknown
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk.disabled
Kind

Unknown application.
Visitor's assessment Analyzerdetails 
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
Kind
To be fixed if not done intentionally. This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
Kind
To be fixed if not done intentionally. This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Kind

Fuzzy Algorithmcheck (4.42 / 5.00), Safe
Visitor's assessment Analyzerdetails 
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
Kind

Fuzzy Algorithmcheck (4.42 / 5.00), Safe
Visitor's assessment Analyzerdetails 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
Kind
The entry Messenger has been identified as safe.
Visitor's assessment Analyzerdetails 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
Kind
The entry Windows Messenger has been identified as safe.
Visitor's assessment Analyzerdetails 
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
Kind
This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails Unknown
O20 - Winlogon Notify: PRISMAPI.DLL - C:\WINDOWS\SYSTEM32\PRISMAPI.DLL
Kind

Visitor's assessment Analyzerdetails 
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
Kind

This service (NetSvc.exe) was identified as a good one.
Visitor's assessment Analyzerdetails 
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
Kind
This service (nod32krn.exe) was identified as a good one. This entry was classified from our visitors as good.
Visitor's assessment Analyzerdetails 
O23 - Service: PRISMSVC - Conexant Systems, Inc. - C:\WINDOWS\system32\PRISMSVC.EXE
Kind

This service (PRISMSVC.EXE) was identified as a good one.
Short analysis
Use these tips at your own risk!
   
© 2004 - 2007 Mathias Mattner | Contact
 
bottomleft
     
bottomright