Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy general
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #51  
Old February 11th, 2005, 12:46 PM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re: HijackThis Auto Analysis

and even worse (in my view) is this one which changes explorer.exe and leaves no signs
http://www.viruslist.com/en/weblog?weblogid=159054634

and it is spreading quite widely at the moment
  #52  
Old February 12th, 2005, 12:22 AM
Marja's Avatar
Marja Marja is offline
Honestly, I'm not a bot!!
 
Join Date: Mar 2004
Location: In the Vast Fields of My Mind
Posts: 4,550
Default Re: HijackThis Auto Analysis

So, if you use Process Guard to protect explorer.exe, you wouldn't know it??

Worried,
Marja
  #53  
Old February 12th, 2005, 02:31 AM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re: HijackThis Auto Analysis

If you use PG then it shouldn't be able to change explorer.exe or any other file on your computer without your knowledge or permission
  #54  
Old February 12th, 2005, 01:03 PM
Me -Marja
 
Posts: n/a
Default Re: HijackThis Auto Analysis

Thanks, Derek, that's what I thought, but things keep getting more complicated everyday, don't they?

Glad you are all here helping!!

Marja
  #55  
Old February 12th, 2005, 09:09 PM
pissedoff
 
Posts: n/a
Default Re: HijackThis Auto Analysis

Removed for Admin review.

Blackspear.

Reviewed - Given the false accusations and trolling comments to insult, and take this thread off-topic; the contents of this post will not be returning - snap

Last edited by snapdragin : February 13th, 2005 at 03:53 AM. Reason: reviewed post
  #56  
Old February 15th, 2005, 01:07 PM
Merijn's Avatar
Merijn Merijn is offline
Spyware Expert
 
Join Date: Mar 2004
Location: NL
Posts: 6
Default Re: HijackThis Auto Analysis

Hey all, spy1 alerted me to this thread and I've read through its key posts.

First off, HijackThis is NOT an antivirus program. Therefore, it cannot prevent, detect or fix malware that modifies system files. This constitutes a PE virus which is beyond my (and Visual Basic's) capabilities. The only thing that would detect a change like this would be an antivirus program.

Secondly, I'm trying to keep HJT as general as possible so it stays small and fast. I'm not going to build a database of specific things to check and identify it as 'Malware #1253' like Spybot S&D does. HijackThis didn't start out as that and never will become that. There are far better programs to use a database-based targeting method.

Finally, if you come across a method that is frequently used by malware that isn't covered by HijackThis (or StartupList for that matter), let me know about it. I do want to stay on top of these things but stuff like this doesn't always reach me. The few examples Derek and Pieter mentioned are mostly PE viruses, but some are completely new to me and seem interesting enough to review further.

Merijn
  #57  
Old February 15th, 2005, 01:13 PM
Infinity Infinity is offline
Very Frequent Poster
 
Join Date: May 2004
Posts: 2,651
Default Re: HijackThis Auto Analysis

Thanx Merijn for your clarification.

keep up the good work
__________________
... hmmmm .. so you're a signature reader ...
 

Wilders Security Forums > Privacy Related Topics > privacy general « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:01 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums