OTL Tutorial - How to use OldTimer ListIt - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

OTL Tutorial - How to use OldTimer ListIt

#121 dev00790

  • Group: Member
  • Posts: 5
  • Joined: 02-October 11

Posted 05 May 2012 - 09:19 AM

Hi,

I notice that O38 - SubSystems is not mentioned in the OTL tutorial. Could this be added please?

dev00790

#122 emeraldnzl

  • Group: GeekU Moderator
  • Posts: 14,630
  • Joined: 19-November 07

Posted 05 May 2012 - 03:31 PM

Yes, that together with a number of scan changes and another command are all either already written and in the pipeline (checking by the tool developer) or under preparation.:thumbsup:

#123 dev00790

  • Group: Member
  • Posts: 5
  • Joined: 02-October 11

Posted 05 May 2012 - 03:47 PM

Thanks :)

#124 Wing Man

  • Group: Malware Removal
  • Posts: 5
  • Joined: 11-February 11

Posted 16 May 2012 - 07:41 AM

I have a student asking a question about OTL and a change made to the GUI.

Earler versions of OTL had an option under Modules called "Use Safe List" and at some point this was changed to "No Company Name".
Was this an effort to minimize the amount of "internal" processing as a "safelist" could have grown huge, possibly hindering overall processing time.

I looked at the OTL updates and did not really see anything regarding this change...

Edit:
Should this change be reflected in the tutorial, so the helpers know what the option provides?

#125 emeraldnzl

  • Group: GeekU Moderator
  • Posts: 14,630
  • Joined: 19-November 07

Posted 17 May 2012 - 03:12 PM

Hello Wing Man,

I know you have received a detailed reply from OT at MRU.

For anyone else reading this thread the crux of OT's reply is that improvements/changes are constantly being made to OTL. Not all are commented on. This particular change was made over a year ago to streamline the scan. The form label was made to reflect the change. :)

#126 Wing Man

  • Group: Malware Removal
  • Posts: 5
  • Joined: 11-February 11

Posted 18 May 2012 - 05:42 AM

Yes, OT did reply, thanks. :)

#127 fireblade77

  • Group: Member
  • Posts: 1
  • Joined: 24-May 12

Posted 24 May 2012 - 11:51 AM

Hi there

I am dealing with a little bit of malware and have a random entry in the log which I am going to remove.

mRun: [audiowx] rundll32.exe "23drhl.dll",s


However, before I proceed - Can I ask what the ,s indicates on the end?

Thanks

#128 emeraldnzl

  • Group: GeekU Moderator
  • Posts: 14,630
  • Joined: 19-November 07

Posted 24 May 2012 - 01:12 PM

Hello fireblade77,

Don't know what that is. Might be worth opening a topic in the Malware Forum and have someone there check it out. :)

#129 Wing Man

  • Group: Malware Removal
  • Posts: 5
  • Joined: 11-February 11

Posted 25 May 2012 - 04:57 AM

OTL is just reporting what is found in the registry entry. It's probably a program parameter used to have the file run in "silent" mode or something along those lines.

#130 OldTimer

  • Group: Global Moderator
  • Posts: 3,261
  • Joined: 11-March 05

Posted 25 May 2012 - 06:21 AM

@fireblade77: That is not a line from an OTL log. Questions regarding whatever tool is being used that produced that information will need to be addressed by the associated author. This topic is for OTL related questions.

Cheers.

OT

#131 azarl

  • Group: GeekU Moderator
  • Posts: 15,959
  • Joined: 07-April 08

Posted 25 May 2012 - 06:57 AM

View Postfireblade77, on 24 May 2012 - 11:51 AM, said:

Hi there

I am dealing with a little bit of malware and have a random entry in the log which I am going to remove.

mRun: [audiowx] rundll32.exe "23drhl.dll",s


However, before I proceed - Can I ask what the ,s indicates on the end?

Thanks

That's a DDS entry not OTL. the 's' is the entry point within the module. Basically it means Run 23drhl.dll and start execution at the routine labelled 's'

#132 Wing Man

  • Group: Malware Removal
  • Posts: 5
  • Joined: 11-February 11

Posted 25 May 2012 - 07:08 AM

Duh! :wacko: I wasn't even looking at the mRun: notation... just the file.
Thanks azari, more I thought about it, a parameter would have probably been coded like:
mRun: [audiowx] rundll32.exe "23drhl.dll" /silent

#133 mgrzeg

  • Group: Member
  • Posts: 1
  • Joined: 12-July 12

Posted 13 July 2012 - 08:43 PM

Hi there,
as I couldn't find any other place to post support question regarding OTL, I do it here :)
Some users complain, that OTL can't generate the Extras.txt file because of the "Win32 Error. Code: 23... (CRC)". There's a memory dump file created manually by one of ther users at the moment, when the error message box appears.
I tried to find some information about the reasons, but without .pdbs it's very hard.
Maybe you can help? :)

m.g.

#134 Dakeyras

  • Group: GeekU Moderator
  • Posts: 4,544
  • Joined: 12-January 08

Posted 14 July 2012 - 06:07 AM

Hi and welcome to Geeks to Go. :)

That specific error relates to what is known as a Cyclic Redundancy Check and not something usually associated with malware, though feasible never actually encountered such myself. In some instances it can be caused by a faulting Hard-Drive(be it one in situ and or a network type etc) or a form of CD/DVD removable storage present when OTL is ran that may be damaged for example.

My best advice in this instance would be to seek further assistance in this part of the forum:-

Hardware, Components and Peripherals

Or if you genuinely feel malware may be the culprit:-

Malware and Spyware Cleaning Guide

#135 Valinorum

  • Group: GeekU Junior
  • Posts: 526
  • Joined: 25-July 12

Posted 26 July 2012 - 07:23 AM

Great and informative thread.It really helped me a lot.

Share this topic:


  • 12 Pages +
  • « First
  • 7
  • 8
  • 9
  • 10
  • 11
  • Last »