HiJackThis

HiJackThis

by Trend Micro Inc.

What is HiJackThis?

HiJackThis is software application developed by Trend Micro Inc.. It is most commonly found on computers running Windows 7 with nearly 62.34% of installations running this operating system. HiJackThis's installer is typically 1.00 GB in size and installs around 28 files. The most common release is 2.0.2 with 48.88% of all installations currently using this version.

HiJackThis is most popular in the United States with 54.83% of installations residing in this country.

HiJackThis adds 1 scheduled task to the Windows Task Scheduler launching the program at randomly scheduled times. When using a computer that is connected to the internet, HiJackThis is known to create 1 firewall exception to allow inbound and outbound connectivity.

About HiJackThis?

HijackThis is an open source enumeration tool originally created by Merijn Bellekom, and later acquired by Trend Micro. This program is designed to target browser-hijacking methods without relying on a database of known spyware. It quickly scans a user's computer and identifies browser hijacking locations, providing a detailed list of the entries found. HijackThis is primarily used for diagnosing browser hijacking issues, as its removal capabilities, if used without proper knowledge, can potentially cause significant damage to the computer. It is important to note that HijackThis does not remove or detect spyware; instead, it focuses on listing common locations where browser hijacking activity can occur, which can lead to the installation of malware on a computer.

Software Behaviors

Services:
  • steamservice.exe runs as a service named 'Steam Client Service' (SYSTEM\CurrentControlSet\Services\Steam Client Service) "Steam Client Service monitors and updates Steam content".
Firewall:
  • hijackthis.exe is added as a firewall exception for 'C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe'.
Scheduled tasks:
  • steam.exe is scheduled as a task with the class '{F5AD5BE3-8A53-416A-85DF-3F13BD2920A5}' (runs on registration).

Startup Entries

Registry entries:
  • HijackThis.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'HijackThis startup scan' and executes as C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan.
  • hijackthis.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'HijackThis startup scan' and executes as C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan.
  • steam.exe is loaded in the current user (HKCU) registry as an auto-starting executable named 'Steam Client Bootstrapper (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)' and executes as "C:\Program Files\Steam\steam.exe".

Software Details

URL:
https://www.trendmicro.com
Support:
Installation path:
C:\Program Files\trend micro\hijackthis
Uninstaller:
MsiExec.exe /X{45A66726-69BC-466B-A7A4-12FCBA4883D7}
Size:
1.00 GB
Language:
English

HiJackThis Executable Details

Primary executable:
hijackthis.exe
Name:
HiJackThis
Path:
C:\Program Files\trend micro\hijackthis\hijackthis.exe
MD5:
ee86268e59e4b38961e7c40d16be5bb4
SHA-1:
SHA-256:
Files installed by HiJackThis
File Type Filename MD5
DLL
98ac67e24b18c21d3cf15d9fe75e1054
EXE
a7690639d8fc6f297c0406fb8b8d7e21
EXE
e1d0872dcc8e750f67413a49f691160c
EXE
d6a1efc99c7908c1f8092ee5ac8e0b3b
EXE
7d95cbe03ab46e5cef0b3a518b0bc52b
EXE
2007f2fd9a65d62cde7fb3fe39ed51ce
EXE
9b3196aac291b6a55ee7712919ae8981
EXE
65c534d9108d1c491387d56ee780e99f