Understanding HijackThis

thathagat

Devil's advocate
Guru
Local time
8:07 AM
Messages
268

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
All of the public HJT tutorials are based on the original Bleeping Computer tutorial and have been around for many years. That said, HijackThis is no longer relied on by security experts as providing much more than a general overview. It just doesn't provide enough information to fully analyze the extent of a malware infection.

Warning: Online HijackThis analysis tools should be used with extreme caution as f/p's are very common.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
All of the public HJT tutorials are based on the original Bleeping Computer tutorial and have been around for many years. That said, HijackThis is no longer relied on by security experts as providing much more than a general overview. It just doesn't provide enough information to fully analyze the extent of a malware infection.

Warning: Online HijackThis analysis tools should be used with extreme caution as f/p's are very common.
.
Is there anything better at the moment?
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Hi, Victek. I'm not sure if you mean better than HijackThis or better than the tutorials.

As to the tutorials, as far as they go, they explain what the results of the log are showing. The thing is that it requires experience and research to know if what is in the log is safe or malicious. There is something that is in the final stages of review prior to posting that may be helpful in that regard. However, until it is public, I cannot say anything more about it.

As to the logs, due to the current state of malware/rootkits, most security forums request an ARK (anti-rootkit) log and, depending on their preference, a DDS, OTL or RSIT log. As an example, Unknown Infection, Possibly Malware/Worm shows both DDS and OTL logs, although the supplemental logs are attachments to the thread. You can see how much more in-depth those logs are.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Corrine said:
HijackThis is no longer relied on by security experts as providing much more than a general overview. It just doesn't provide enough information to fully analyze the extent of a malware infection.
its still a key tool in forums dealing in helping people with manual malware removal :p

Corrine said:
Online HijackThis analysis tools should be used with extreme caution as f/p's are very common.
well it is all about an analysis.....pointing to what could be unsafe/bad/unknown ....that's it....and i've seen fps at expert malware removal forums leave aside online hjt analysis:p

one more online hjt analysis site is of emsisoft creators of A2
http:///www.hijackfree.com/en/upload/

Victek said:
Is there anything better at the moment?
ummm......there were/are of the likes of RunScanner,AutoRuns,X-RayPc Spyware Process Analyzer but HJT still rules
 

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
Hi, Victek. I'm not sure if you mean better than HijackThis or better than the tutorials.

As to the tutorials, as far as they go, they explain what the results of the log are showing. The thing is that it requires experience and research to know if what is in the log is safe or malicious. There is something that is in the final stages of review prior to posting that may be helpful in that regard. However, until it is public, I cannot say anything more about it.

As to the logs, due to the current state of malware/rootkits, most security forums request an ARK (anti-rootkit) log and, depending on their preference, a DDS, OTL or RSIT log. As an example, Unknown Infection, Possibly Malware/Worm shows both DDS and OTL logs, although the supplemental logs are attachments to the thread. You can see how much more in-depth those logs are.
.
Thanks for the additional information. Re my comment, I meant is there anything better then HiJackThis at the moment. Usually if a system is bootable a combination of on-demand scanners, e.g. MBAM, Hitman Pro, etc, will clean it up without needing to get into a detailed analysis. Occasionally though these programs aren't sufficient and something like HiJackThis is necessary. Being able to use HJT in combination with online analysis tools might result in a successful cleanup without having to submit logs to a security forum and wait for feedback.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
If you don't know how to do an in depth analyzing and cleaning, then it is best to ask in a forum where security advisor's have been trained. This is voluntary, free help. Or you could pay a couple hundred dollars to a PC shop.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Here's a fairly comprehensive list of sites providing help by trained analysts:

ASAP Member Forums Providing Log Analysis

Dansk - Danish
Spywarefri

Deutsch - German Spezifisch deutschsprachige Computerhilfe-Foren (german-language sites to get help from):
a-squared Anti-Malware Sie haben Probleme mit a-squared Anti-Malware? Fragen Sie hier unsere Experten!

English
247Fixes
5 Star Support
a-squared Anti-Malware If you have problems with a-squared Anti-Malware?
Amazingtechs
Atribune.org
BestTechie
Bluetack Internet Security Solutions
CyberAnswers.org
D-A-L Computer Help
Freedomlist
Gladiator Security
LandzDown
Lockergnome
Log'N'Rock
MalwareBytes
MalWare Removal
NutnWorks
Security Cadets
Security Central
Smokey's Security Forums
SpyWare BeWare!
SpywareInfoForum
Techmonkeys
Tech Support Forum
Tech Support Guy
TeMerc Internet Countermeasures
The Spykiller
TnT - Tips 'n' Tricks
WhatTheTech
Windows Forum

Español - Spanish Sitios de ayuda contra el spyware en idioma español
a-squared Anti-Malware Tiene problemas con a-squared, con la página de inicio de a-squared o con algún Malware en especial? Siéntase libre de pedir ayuda.
InfoSpyware
ForoSpyware

Finnish Suomalaisia sivuja mistä saada malwaren poisto-apua (Finnish sites to get help from):
Virustorjunta

Français - French Voici des forums français sur lesquels vous trouverez une aide rapide et efficace :
a-squared Anti-Malware Vous avez des problèmes avec a-squared Anti-Malware ou avec certain Malware? Demandez ici à nos experts!
Assiste.com
Zebulon

Italiano - Italian
a-squared Anti-Malware Hai problemi con a-squared Anti-Malware o con malware speciale? Chiedi pure aiuto.
Alground Research Center

Nederlandstalig - Dutch Op deze Nederlandstalige forums wordt U snel en efficiënt geholpen :
Hijackthis.nl
Nucia / Anti Spyware Offensief
PCHelper

Portuguese
Linha Defensiva

Serbian/Croatian
MyCity


non-ASAP Forums Providing Log Analisis

Deutsch - German Spezifisch deutschsprachige Computerhilfe-Foren (German-language sites to get help from):
HijackThis.de Support Board
Protecus
Rokop Security
TrojanBoard

English
Asksomeone.net
Aumha.org
BleepingComputer
Dell Community Forum - HJT room
DSL Reports
Geeks to Go
MajorGeeks
PC Pitstop Forums
Safer-Networking
SpywareHammer
Spyware Warrior

Français - French
IDN - Infos-Du-Net
Vista-XP.fr
FS - Futura-Sciences
PCA - PC-Astuces
Génération Nouvelles Technologies
Telecharger.Com/01net

Nederlandstalig - Dutch
BlueMedicine
Minatica.be
 
Last edited:

My Computer

OS
Windows 7 & Windows Vista Ultimate
Also PC Pitstop Forums?
The question mark is part of the address ... not a question :)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Yup, I missed PCP. Added a link to the Viruses, Spyware, Adware forum.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Hmm, I am so glad I always have yesterdays image and do not have to jump thru all those hoops.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
As you know, whs, most people are not that organized or diligent. At the sites that I administer, I ask that the posted logs include an ARK scan and also t hat ERUNT be installed to ensure there is a valid registry backup.

(Although not active at all of the listed sites, I bet that between Jacee and myself we are most likely a member of most of the listed sites -- at least the English language sites and some of the non-English sites that have private forums for the security community.)
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Corrine, with that being said, I will continue telling people that frequent imaging is their best protection. Apart from a $50 to $70 external disk, it takes so little that everybody should really do it.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
If you don't know how to do an in depth analyzing and cleaning, then it is best to ask in a forum where security adviser's have been trained. This is voluntary, free help. Or you could pay a couple hundred dollars to a PC shop.
.
Free log analysis from pro security advisers is a terrific resource, however sometimes there isn't enough time to make use of it. In the field I often have 3-4 hours max to get a system up. If I can't clean it in an hour I have to move on to data backup and re-installation of the OS. I was thinking that maybe HiJackThis combined with automated log analysis could be "Plan B" when on demand scanners fail, but it sounds like the automated analysis can't be relied on (?)
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Hi, Victek.

Nothing beats a visual inspection and too much can be hidden from HJT -- or just not available for evaluation.
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
If I can't clean it in an hour I have to move on to data backup and re-installation of the OS.
How come you are not using imaging? That would be a lot faster. Or are those customers on which you have no influence on what they are doing.
 

My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
If I can't clean it in an hour I have to move on to data backup and re-installation of the OS.
How come you are not using imaging? That would be a lot faster. Or are those customers on which you have no influence on what they are doing.
.
Unfortunately these are not personal customers that I can educate over time and setup on a proper backup/imaging schedule. They are folks that I help through an "on call" tech service I accept work from. I go to them and can't remove their systems. It's a small time window that limits my cleanup options :geek:
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 x64
CPU
Intel Core2 Extreme Q6850 3.00GHz
Motherboard
EVGA 132-CK-NF79
Memory
8 GB
Graphics Card(s)
Radeon R7 260X
Sound Card
Xonar DS
Hard Drives
Hitachi Deskstar 1 tb
Since you working via a tech service, Victek, perhaps you would find it advantageous to obtain a Malwarebytes' Anti-Malware Technician's License. It is an annually renewable subscription. With that license, you can install MBAM on disk or USB key or both and then update the rules.ref file from your own copy on your own computer to take to your customer's computer. There is a license restriction that you can use it on only one computer at any given time and that it must be uninstalled before using it on another computer.

Inquires can be made about the Technician's License here: Corporate Licensing : Malwarebytes
 

My Computer

OS
Windows 7 & Windows Vista Ultimate
Back
Top