dragokas / hijackthis

A free utility that finds malware, adware and other security threats
http://hjt.sf.net
GNU General Public License v2.0
703 stars 112 forks source link
adware cleanup expert hijacking-methods malware portable pup scanner security toolbars tuneup unwanted

Download

Latest build [v3.x Alpha] - test version

Stable build [v2 outdated] - not updated anymore

(this is alpha-version - major changes are in progress; although it is definitely safe to use)

HiJackThis+

HiJackThis+ (Plus) (previously called: HiJackThis Fork v3) is a fork and a continuation of the original Trend Micro HiJackThis by Merijn Bellekom development, once a well-known tool.

At the moment, it is a step-by-step 100% rewritten source code of the original engine, aimed to provide a full compatiblity with the most recent Windows OS and a balance beetween compiling very fast results in logfile and combatting with the most popular malware, inluding the one not known to other antiviruses.

It is made by Alex Dragokas - a lawyer, security observer and malware researcher.

Overview

HiJackThis+ is a free utility for Microsoft Windows that scans your computer for settings changed by adware, spyware, malware and other unwanted programs. Shortly, consider it like Sysinternals Autoruns.

The difference from classical antiviruses is the ability to function without constant database updates, because HiJackThis+ primarily detects hijacking methods rather than comparing items against a pre-built database (signatures). This allows it to detect new or previously unknown malware - but it also makes no distinction between safe and unsafe items. Users are expected to research all scanned items manually, and only remove items from their PC when absolutely appropriate.

Therefore, FALSE POSITIVES ARE LIKELY. If you are ever unsure, you should consult with a knowledgeable expert BEFORE deleting anything.

HiJackThis+ is not a replacement of a classical antivirus. It doesn't provide a real-time protection, because it is a passive scanner only. Consider it as an addition. However, you can use it in form of boot-up automatical scanner in the following way:

Tutorial

Features

Advantages

New in version 2.6+

HiJackThis+ also comes with several modules useful for specific analysis and removing malware from a computer:

Log analysis

IMPORTANT: HiJackThis+ does not make value-based calls on what is considered good or bad. You must exercise caution when using this tool. Avoid making changes to your computer settings without thoroughly studying the consequences of each change.

If you are not already an expert, we recommend submitting your case to an online help forum. Here are some suggestions:

Note: currently, only VIRUSNET association can provide direct analysis of HiJackThis+ logs in our github 'Issues' section. Please feel free to ask help there (English/Russian only).

Technical support

System requirements & Compatibility

Copyrights

HiJackThis+ by Alex Dragokas is a continuation of Trend Micro HiJackThis development, based on v.2.0.6 branch and 100% rewritten at the moment. HiJackThis+ was initially supported by Trend Micro, but they have since refused support and closed its GitHub repository. HiJackThis+ is distributed under the initial GPLv2 license. It also includes several tools and plugins available as freeware.

Reviews & Mirrors

(clickable)

Note: These mirrors belong to other companies. They are non-official.

More references:

Other projects

You may also find my other programs useful: