MalwareTeks Blog » Blog Archive » HijackThis is now spyware?


 30 Jul 2007 @ 8:08 PM 
 

HijackThis is now spyware?

 

Straight from TomCoyote.org

Merijn, the creator of HijackThis ™ recently sold the popular application used to remove malware to Trend Micro™. In addition to improvements like support for Windows Vista™, they’ve added a deceptively titled “AnalyzeThis” button. While the average user likely thinks the AnalyzeThis button provides helpful information for diagnosing their log.

That is certainly interesting.

MalwareTeks is still considering the use of HijackThis v2 from Trend Micro. As Blair points out in his article it is somewhat necessary for Vista users as HijackThis v1.99.1 doesn’t support Vista.

Yes, there are alternatives to HijackThis and we are consider these programs in lieu of HijackThis.

Share our articles with others by publishing them to:
  • Digg
  • Reddit
  • del.icio.us
  • Slashdot
  • StumbleUpon
  • Technorati
  • blogmarks
  • Furl
  • YahooMyWeb
  • Fark
Tags Tags:
Categories: Uncategorized
Posted By: ShadowPuterDude
Last Edit: 30 Jul 2007 @ 08 08 PM
359 views
E-mailPermalink
 

Responses to this post » (2 Total)

 
  1. JeanInMontana said...
    12:33 pm - July 31st, 2007

    IMO calling it spyware is stretching the definition of what that word means to most of the community. There are several other reputable programs that have some sort of upload function. Some are for false positive reporting, others for submitting possible malicious files. What Trend Micro has done is really no different.

    The thing doesn’t work or didn’t when I tried it. It did nothing. I could get behind addressing that issue.

    I think it could be detrimental in the hands of a inexperienced person, but so can the older versions. HiJack This! has always been a tool if used improperly there is/was chance of disaster.

    I have actually used it since it was still in beta at Malwarebytes. Marcin instructs users to install and scan with it to remove the 022 lines not shown in older versions. I found no problems.

    There is a ruckus amongst the forums and most comments I’ve seen are opposing Blair’s opinion.

    http://www.castlecops.com/postlite196457-.html

    http://www.dslreports.com/foru.....ould-it-be

  2. ShadowPuterDude said...
    7:17 pm - July 31st, 2007

    I didn’t spend a lot of time analyzing what Blair had to say about the matter, last night; but, ….

    Yes, labeling HijackThis as Spyware, because of the submission of a HJT log to TrendSecure, is a bit of a stretch. Many different respected tools submit data for analysis to a web site, in one form or fashion, already. It’s what they do with that data is of concern. As near as I can tell only the log is uploaded and no other data, other than that necessary to make the connection and transfer, are sent to TrendSecure.

    As, pointed out in the links you provided, this isn’t much different than people publicly posting their logs on helper forums.

    The only way personally identifiable information will be visible to a third-party is when HijackThis is not installed in it’s default location and installed some place like My Documents, the Desktop or within the Documents and Settings folder of the logged on user; or an instance of a piece of software or malware that autoruns from within the Documents and Settings folder of the logged on user.

    I looked at the stats page, and agree with Blair that it is pretty useless. By pressing the Analyze This button, I would expect that the log was being uploaded to some type of online analysis tool. Which, IMO anyone other than an expert viewing the results and actioning items based on the scan is playing Russian Roulette.

 

Leave A Comment ...

 

 XHTML:
You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>
\/ More Options ...
Change Theme...
  • Users » 9
  • Posts/Pages » 187
  • Comments » 116
Change Theme...
  • VoidVoid « Default
  • LifeLife
  • EarthEarth
  • WindWind
  • WaterWater
  • FireFire
  • LiteLight
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.
  • No Child Pages.