HiJackThis

HiJackThis

by Trend Micro Inc.

What is HiJackThis?

HiJackThis is software application developed by Trend Micro Inc.. It is most commonly found on computers running Windows 7 with nearly 62.34% of installations running this operating system. HiJackThis's installer is typically 1.00 GB in size and installs around 28 files. The most common release is 2.0.2 with 48.88% of all installations currently using this version.

HiJackThis is most popular in the United States with 54.83% of installations residing in this country.

HiJackThis adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, HiJackThis is known to create 1 firewall exception to allow inbound and outbound connectivity.

About HiJackThis?

HijackThis is an open source enumeration tool originally created by Merijn Bellekom, and later acquired by Trend Micro. This program is designed to target browser-hijacking methods without relying on a database of known spyware. It quickly scans a user's computer and identifies browser hijacking locations, providing a detailed list of the entries found. HijackThis is primarily used for diagnosing browser hijacking issues, as its removal capabilities, if used without proper knowledge, can potentially cause significant damage to the computer. It is important to note that HijackThis does not remove or detect spyware; instead, it focuses on listing common locations where browser hijacking activity can occur, which can lead to the installation of malware on a computer.

Software Behaviors

Services:
  • steamservice.exe runs as a service named 'Steam Client Service' (SYSTEM\CurrentControlSet\Services\Steam Client Service) "Steam Client Service monitors and updates Steam content".
Firewall:
  • hijackthis.exe is added as a firewall exception for 'C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe'.
Scheduled tasks:
  • steam.exe is scheduled as a task with the class '{F5AD5BE3-8A53-416A-85DF-3F13BD2920A5}' (runs on registration).

Startup Entries

Registry entries:
  • HijackThis.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'HijackThis startup scan' and executes as C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan.
  • hijackthis.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'HijackThis startup scan' and executes as C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan.
  • steam.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)' and executes as "C:\Program Files\Steam\steam.exe".

Software Details

URL:
https://www.trendmicro.com
Support:
Installation path:
C:\Program Files\trend micro\hijackthis
Uninstaller:
MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
Size:
1.00 GB
Language:
English

HiJackThis Executable Details

Primary executable:
hijackthis.exe
Name:
HiJackThis
Path:
C:\Program Files\trend micro\hijackthis\hijackthis.exe
MD5:
ee86268e59e4b38961e7c40d16be5bb4
SHA-1:
SHA-256:
Files installed by HiJackThis
File Type Filename MD5
DLL
9c002ba83a1099fc46c8c8699ebb17d3
DLL
0170a5acb0693735a8f113659bb4709f
DLL
6adf54561bc2a9354ca9f353d778d389
DLL
e949eee7d1be07e32267fe10d9992c38
EXE
ee86268e59e4b38961e7c40d16be5bb4
DLL
80f3a2ed2a2ffaacbdf51f80b991b275
EXE
11dd6e8ab9759d1ac91ffe0d0e4949cb
DLL
4d48dbe4d3a06c497435014e5c583f34
DLL
7c7cc9feb1026678c48bbabe84ea57c2
DLL
da204a2bab5780a0df37eb5be58fca57