Jump to content


Spyware Mods/Analysts


6 replies to this topic

#1 OFFLINE   Stryker

    Member

  • Members
  • PipPip
  • 30 posts
  • Gender:Male
  • Location:Edinburgh, UK

Posted 10 April 2008 - 08:50 PM

This is just a question but how do the people like __RiP_ChAiN_ , TwistedMetal, rridgely etc know what it is to look for when someone posts a Hijack This log for analysis.

I have sat looking through many posts trying to identify patterns, however the logs don't really mean terribly much to me at a glance. It's an area that has interested me for a little while, but I'm not quite sure how to go about acquiring the necessary knowledge!

Have you had an interest/been involved in this area for so long that you recognise patterns, or does your knowledge come from attending a College or University?

Any tips or directions to learning materials would be great!

Cheers

Stryker
Sucess is a journey, not a destination...

#2 OFFLINE   1984

    CCleaner Lover

  • Members
  • PipPipPipPip
  • 1,605 posts
  • Gender:Male
  • Location:Canada

Posted 11 April 2008 - 01:09 AM

They have a free online "university" to learn how to read hijack this logs here:

http://forums.spywareinfo.com/

#3 OFFLINE   davey

    Keep it simple !

  • Members
  • PipPipPipPipPip
  • 2,235 posts
  • Gender:Male
  • Location:Maryland U.S.A.

Posted 11 April 2008 - 06:48 AM

View PostStryker, on Apr 10 2008, 04:50 PM, said:

Any tips or directions to learning materials would be great!

Cheers

Stryker
Hi Stryker,
If you haven't already heard from him,just PM RipChain with a link to your post.He is so busy he may not see it in the Lounge.
:) davey

#4 OFFLINE   Stryker

    Member

  • Members
  • PipPip
  • 30 posts
  • Gender:Male
  • Location:Edinburgh, UK

Posted 11 April 2008 - 12:31 PM

Thanks Davey. I wasn't sure where the best place to post that question was.

I'll give him a PM.
Sucess is a journey, not a destination...

#5 OFFLINE   YoKenny

    Super Power User

  • Members
  • PipPipPipPipPip
  • 2,874 posts
  • Gender:Male
  • Location:Oshawa, Ont. Canada
  • Interests:Helping people get rid of malware on their systems then showing them how not to get re-infected again

Posted 11 April 2008 - 09:34 PM

HijackThis Tutorial & Guide
A guide and tutorial on using HijackThis to remove Browser Hijackers & Spyware

http://www.bleepingc...tutorial42.html

It does not explain what is good nor bad but using the two tutorials and Google searches you will soon find out how to read the HijackThis logs.
"Education is what remains after one has forgotten everything he learned in school." - Albert Einstein
IE7Pro user

#6 OFFLINE   __RiP_ChAiN_

    Advanced Member

  • Members
  • PipPipPip
  • 476 posts
  • Gender:Male
  • Location:U.S.A
  • Interests:Take a guess...

Posted 12 April 2008 - 05:57 AM

Sorry for being late to this thread, I rarely deviate from the HijackThis forums..

Quote

I have sat looking through many posts trying to identify patterns, however the logs don't really mean terribly much to me at a glance. It's an area that has interested me for a little while, but I'm not quite sure how to go about acquiring the necessary knowledge!

Have you had an interest/been involved in this area for so long that you recognise patterns, or does your knowledge come from attending a College or University?
Although it is possible to learn how HijackThis works in detail by reading tutorials on the subject, including the one available from Bleeping Computer, you will still need to go through some sort of training in order to recognize the infections in such logs. I, myself, went through the training course available on GeeksToGo, which is now one of the places I help teach how to work HIjackThis logs at. For more information on training there, you can take a look here.

There are also other schools that will teach you about HijackThis, such as CastleCops, MRU, and Bleeping Computer.
It is really interesting to get such a unique perspective on the way malware infects computers, and the ways used to get rid of such crap.
In addition, the reason people like me just seem to show up from nowhere, is because most of us regularly do work at half a dozen forums, or more. Usually at one of the main fourms, where you can also learn how to read HJT logs from.

#7 OFFLINE   Stryker

    Member

  • Members
  • PipPip
  • 30 posts
  • Gender:Male
  • Location:Edinburgh, UK

Posted 15 April 2008 - 12:31 PM

Thanks for all the advice. I'll give them a look and let you know how I get on!

Stryker
Sucess is a journey, not a destination...