Spyware Warrior Spyware Warrior
Help with Spyware, Hijacking & Other Internet Nuisances
 
FAQ :: Search :: Memberlist :: Usergroups :: Register
Profile :: Log in to check your private messages :: Log in

Analyzing HJT logs

 
Post new topic   Reply to topic    Spyware Warrior Forum Index -> General Software Discussion
View previous topic :: View next topic  
Author Message
trickydick
Junior Member


Joined: 25 Nov 2004
Last Visit: 26 May 2006
Posts: 27
Location: montreal, quebec, canada

PostPosted: Tue Nov 30, 2004 9:10 am    Post subject: Analyzing HJT logs Reply with quote

I trust you guys 100% and would rather get your opinion on what to do with it but I was wondering if one of the experts could test an analyzing site and tell me if it is accurate.
the site is
http://hijackthis.de/index.php

Thanks for your help.
tricky
Back to top
View user's profile Send private message
TeMerc
Warrior Obsessed


Joined: 12 Feb 2004
Last Visit: 23 Dec 2009
Posts: 4953
Location: Phx. AZ.

PostPosted: Tue Nov 30, 2004 9:36 am    Post subject: Reply with quote

Hey Tricky, this has come up a few times here, and over at my own site as well.

The only problem with the site, while its OK at what it does, is, more times than not, they don't give you all the info for removal on some items, and then on others it leaves you up in the air, because they cannot telll what something is if its random. By posting your log into a regiular forum, such as this, you get educated experinced analysts, who know what they are looking at. It removes the 'guess work' and will give everyone, including the user who posted a much better all around feeling of something getting done correctly. As opposed to going to that site, and just coming away with a few maybes or could bes.

At least, thats my take anyway.

And on a similar note, I would also shy away from any forums which do not have dedicated HJT log analysis forums, where you can get one on one help, by people who have been deemded qualified by the forum itself. Having a bunch of people dropping in comments, like: "Wel, I think this is bad, but maybe someone else who knows better will know..." Or: "Oh yeah, I saw that once, on my friends machine this is what he did....." And all this is said without taking into account that each OS is slightly different and in some cases must be dealt with differently.

This just came up at another forum, thats why I mentioned it.
_________________

Ultimate Countermeasures Page
Calendar Of Updates
Malware Advisor Blog
Back to top
View user's profile Send private message Visit poster's website
trickydick
Junior Member


Joined: 25 Nov 2004
Last Visit: 26 May 2006
Posts: 27
Location: montreal, quebec, canada

PostPosted: Tue Nov 30, 2004 9:39 am    Post subject: Reply with quote

ok thanks for the input, id rather get an opinion from a real live person and have my log in queue on this site. Thanks for the quick response.
tricky
Back to top
View user's profile Send private message
Nick
Site Admin


Joined: 27 Feb 2004
Last Visit: 28 Aug 2012
Posts: 3913
Location: California

PostPosted: Tue Nov 30, 2004 8:55 pm    Post subject: Reply with quote

That site is ok, but only if you have a good knowledge of this kind of stuff. There were a few legit files it listed as bad in the past, not sure if they are any now. It only tells you what lines to fix, doesn't tell you when you need to manually delete files that HJT doesn't delete. Most important, it tells you nothing about what additional things you may need to do to fix complicated removals like VX2 betterinternet. That one can't be fixed by HJT alone.

In short, not reliable enough to use.
_________________
Nick's Security Ticker

Back to top
View user's profile Send private message Visit poster's website
bem
Warrior


Joined: 10 Dec 2004
Last Visit: 25 Dec 2008
Posts: 75

PostPosted: Mon Jan 03, 2005 11:36 am    Post subject: Reply with quote

Follow up question from the peanut gallery...

Would a good first step be to run the autofix at that site, reboot and THEN post the log here, or would that still be problematical?
_________________
Support the Freeware Revolution!
http://www.freewarearena.com

They'll get my freeware when they pry it from my cold dead hard drive...
Back to top
View user's profile Send private message
TeMerc
Warrior Obsessed


Joined: 12 Feb 2004
Last Visit: 23 Dec 2009
Posts: 4953
Location: Phx. AZ.

PostPosted: Mon Jan 03, 2005 12:44 pm    Post subject: Reply with quote

I would never autofix anything with HJT on any automated site, there are far too many variables to include.

Post here, so a live person can look at your log.

Thats is best.
_________________

Ultimate Countermeasures Page
Calendar Of Updates
Malware Advisor Blog
Back to top
View user's profile Send private message Visit poster's website
bem
Warrior


Joined: 10 Dec 2004
Last Visit: 25 Dec 2008
Posts: 75

PostPosted: Mon Jan 03, 2005 12:58 pm    Post subject: Reply with quote

Already did, I'm clean as a hound's tooth. Very Happy

I'm that nut that sent you the 'tutorial' for your review. This is a step I have been taking. I guess that answers that question. Embarassed

Thanks for the info. Like I've said, I am truly trying to learn to do the job right! ALL imput deeply appreciated...

Buddy
_________________
Support the Freeware Revolution!
http://www.freewarearena.com

They'll get my freeware when they pry it from my cold dead hard drive...
Back to top
View user's profile Send private message
TeMerc
Warrior Obsessed


Joined: 12 Feb 2004
Last Visit: 23 Dec 2009
Posts: 4953
Location: Phx. AZ.

PostPosted: Mon Jan 03, 2005 3:35 pm    Post subject: Reply with quote

BTW, I ahve not forgoten that tutorial, just been busy with lots of other things.

Getting my own site up, am also admin at Calendar of Updates, and holidays as well.

I'll get to it.
_________________

Ultimate Countermeasures Page
Calendar Of Updates
Malware Advisor Blog
Back to top
View user's profile Send private message Visit poster's website
bem
Warrior


Joined: 10 Dec 2004
Last Visit: 25 Dec 2008
Posts: 75

PostPosted: Mon Jan 03, 2005 3:38 pm    Post subject: Reply with quote

I've no doubt. I'm subcribed to your group, a member here, lurking member at the pitstop, and graze freely. You're all OVER this web being darned nice to a lot of different folks. I'm in no danger or hurry.

Thanks...
_________________
Support the Freeware Revolution!
http://www.freewarearena.com

They'll get my freeware when they pry it from my cold dead hard drive...
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Spyware Warrior Forum Index -> General Software Discussion All times are GMT - 8 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group