Skip to content


Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?

Latest commit


Git stats


Failed to load latest commit information.
Latest commit message
Commit time
July 25, 2023 13:29
November 27, 2023 01:06
October 20, 2018 22:06
November 2, 2023 16:04
December 3, 2017 02:12
November 9, 2023 21:29


Latest build [v3.x Alpha] - test version

Stable build [v2 outdated] - not updated anymore

(this is alpha-version - major changes are in progress; some functions may work unstable; the plus+ means smooth introduction of detection of modern malware and step-by-step moving to replace some modules on C++ to access 64-bit processes in normal way and multi-threading; it is also a differentiation among other possible forks around)


HijackThis+ (Plus) (previously called: HiJackThis Fork v3) is a fork and a continuation of the original Trend Micro HijackThis by Merijn Bellekom development, once a well-known tool.

At the moment, it is a step-by-step 100% rewritten source code of the original engine, aimed to provide a full compatiblity with the most recent Windows OS and a balance beetween compiling very fast results in logfile and combatting with the most popular malware, inluding the one not known to other antiviruses.

It is made by Alex Dragokas - a lawyer, security observer and malware researcher from Ukraine (Chernobyl, Na'Vi, Щедрик, Male slavery, nazism, fascism, concentration camp, War of money, authority and blackmail, USA Bio-labs, radioactive contamination from British, Bombs, drones, whores and crazy people, Colony of USA). Yankee go home! F*ck Russia, F*ck Ukraine, F*ck USA, F*ck all the world giving weapon for killing the people, imposing sanctions against Ukrainian people in Crimea. F*cking ukrainophobs, rusophobs and castrated negrophobes, provoking genocide of Ukrainian people with hundred tons of "free" cluster and nuclear weapon, exploding at our land like your own polygon.


HijackThis+ is a free utility for Microsoft Windows that scans your computer for settings changed by adware, spyware, malware and other unwanted programs. Shortly, consider it like Sysinternals Autoruns.

The difference from classical antiviruses is the ability to function without constant database updates, because HijackThis+ primarily detects hijacking methods rather than comparing items against a pre-built database (signatures). This allows it to detect new or previously unknown malware - but it also makes no distinction between safe and unsafe items. Users are expected to research all scanned items manually, and only remove items from their PC when absolutely appropriate.

Therefore, FALSE POSITIVES ARE LIKELY. If you are ever unsure, you should consult with a knowledgeable expert BEFORE deleting anything.

HijackThis+ is not a replacement of a classical antivirus. It doesn't provide a real-time protection, because it is a passive scanner only. Consider it as an addition. However, you can use it in form of boot-up automatical scanner in the following way:

  • Run the scanning by clicking "Do a system scan only"
  • Add all items in the ignore-list
  • Set up boot-up scan in menu "File" - "Settings" - "Add HijackThis to startup"
  • Next time when user logged in, HijackThis will silently scan your OS and display UI if only new records in your system were found.



  • Lists non-default settings in the registry, hard drive and memory related to autostart
  • Generates organized, easily readable reports
  • Does not use a database of specific malware, adware, etc
  • Detects potential methods used by hijackers
  • Can be configured to automatically scan at system boot up


  • Short logs
  • Fast scans
  • Not necessarily to create fixing scripts manually
  • No need for internet access or recurring database updates
  • Already familiar to many people
  • Portable

New in version 2.6+

  • Detects several new hijacking methods
  • Fully supports new versions of OS Windows
  • New and updated supplementary tools
  • Improved interface, security and backups

HijackThis+ also comes with several modules useful for specific analysis and removing malware from a computer:

  • StartupList 2 (*new*)
  • Process Manager
  • Uninstall Manager
  • Hosts File Manager
  • Alternative Data Spy
  • Services Removing Tool
  • Batch Digital Signature Checker (*new*)
  • Registry Key Type Analyzer (*new*)
  • Registry Key Unlocker (*new*)
  • Files DACL Unlocker (*new*)
  • Check Browsers' LNK & ClearLNK (as downloadable components) (*new*)

Log analysis

IMPORTANT: HijackThis+ does not make value-based calls on what is considered good or bad. You must exercise caution when using this tool. Avoid making changes to your computer settings without thoroughly studying the consequences of each change.

If you are not already an expert, we recommend submitting your case to an online help forum. Here are some suggestions:

Note: currently, only VIRUSNET association can provide direct analysis of HijackThis+ logs in our github 'Issues' section. Please feel free to ask help there (English/Russian only).

Technical support

System requirements

Operating system

  • Microsoft™ Windows™ 11 / 10 / 8.1 / 8 / 7 / Vista / XP (32/64-bit desktop and server)


Thanks to:

  • regist (VIRUSNET) { @regist } - for the valuable tips and ideas, user's manual, database updates, closed and beta-testing
  • Sandor (VIRUSNET) { @Sandor-Helper } - for the beta-testing, lot of reports, PC treatment on GitHub and forums of association
  • akok (VIRUSNET) { @akokSZ } - for product promotion, providing a platform for tests and discussion, help with resolving conflicts with antiviruses
  • team (general VIRUSNET community) - for promotion and support, feedback and bug reports, PC treatment on forums of association
  • Fernando Mercês { @merces } (Trend Micro) - coordinator of original HJT, for the tips, suggestions and promotion
  • Loucif Kharouni { @loucifkharouni } (Trend Micro) - coordinator of original HJT, for the tips & suggestions

HijackThis+ by Alex Dragokas is a continuation of Trend Micro HijackThis development, based on v.2.0.6 branch and 100% rewritten at the moment. HijackThis+ was initially supported by Trend Micro, but they have since refused support and closed its GitHub repository. HijackThis+ is distributed under the initial GPLv2 license. It also includes several tools and plugins available as freeware.

Reviews & Mirrors


Note: These mirrors belong to other companies. They are non-official.

More references:

Other projects

You may also find my other programs useful: