Jump to content


HJT Analysis by HJT Programs


  • You cannot reply to this topic
3 replies to this topic

#1 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 15 March 2006 - 07:57 AM

I've been playing around with some HJT analysis programs, and I like them. I was wondering what others think about them. They're not error, or full proof but I find them to be helpful.

HJT Analysis

help2go

HJT NetworkTechs

#2 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,328 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 15 March 2006 - 08:08 AM

Automatted HJT analysis is nice, however the lack of something called Common Sense™ may always hinder them. Such would be the point false postives, the flagging non-malicious entries as malicious.
Complexity of incoherent design.

#3 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 15 March 2006 - 08:22 AM

View PostAndavari, on Mar 15 2006, 02:08 AM, said:

Automatted HJT analysis is nice, however the lack of something called Common Sense™ may always hinder them. Such would be the point false postives, the flagging non-malicious entries as malicious.
Agreed. If you're not sure what something is you shouldn't remove it without getting some opinions first. But for me I like how it breaks it down, and makes it easy to read. Plus, it'll give you tips on how to determine if an entry is okay or not. Example: If this is your IP address leave the entry, but if it isn't remove it immediately. :lol:

It's HJT for Dummies! :D

#4 OFFLINE   AndyManchesta

    Power Member

  • Spyware Moderators
  • 1,821 posts
  • Gender:Male
  • Location:Manchester. UK
  • Interests:Music, Movies, Website Building & Design, Malware Testing/Research and spending time with friends & family.

Posted 15 March 2006 - 10:51 AM

I think the automated Analysis programs are ok to give some indications of whats bad but no one should ever fix what they suggest in my opinion, There is too many malware programs using genuine filenames but in the wrong location so that could easily lead to one of the Automated services flagging the genuine entries as dangerous and recommending it be removed and also missing malware entries and saying its ok.

Hijack This also has some bugs which makes it show certain entries as file missing even though the file does exist. It can easily do that with 09, 010, 018 and 023 entries so some Automated services may show these can be removed as the file isnt there but removing them would cause alot of problems if they do exist and are needed services. There's so many Hijack This forums these days where you can get one on one feedback there really is no excuse to use a quick fix method like the Automated programs. Its ok for advanced users who know whats legit or malware but not recommended for novice users as it could damage the system in a way that cannot be easily repaired. I just tried one of them now and it has all my 04 startup entries showing as 'Probably not needed - Safe to remove' , doesnt really fill me with confidence that it suggests removing all my startup programs which are genuine, Although they are not essential It would be a pain having to start them all manually each time the system reboots :)