Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

June 12th, 2009, 10:00 GMT · By

HijackThis Hijacked by Trojan Remover

SHARE:

Adjust text size:


HijackThis illegally packaged with Loaris Trojan Remover
Enlarge picture
Trend Micro malware analysts warn that the company's popular HijackThis utility is being abused by authors of a trojan remover, who pack it within their program. The system analysis tool is being used to lure users into acquiring a license.

HijackThis (HJT) is a program that scans and lists potentially malicious startup entries, registry keys, browser helper object (BHO) files, etc. Originally developed by Merijn Bellekom, the free application, which is mainly used for diagnosis, was acquired by Trend Micro after it achieved a significant level of popularity.

"By itself, it does not determine what is good or bad, but it lists registry keys and files system of the scanned system where unwanted programs potentially could reside," Det Caraig, technical communication specialist at Trend, explains. Because of this, its output can generally only be understood by computer experts or experienced users.

While analyzing an application called Loaris Trojan Remover, Edgardo Diaz, Jr., escalation engineer at TrendLabs, found that it "contained the HijackThis program repackaged using Delphi-based packager InnoSetup." The program then provides an option in its interface to launch and use HJT.

"Users who are really interested in using HijackThis, may thus be tricked into buying the antivirus," Mr. Diaz says. "Beware, Trend Micro does NOT sell nor intend to sell HijackThis," he stresses. It seems that, in this case, Loaris Inc., the company developing the trojan remover, failed to ask Trend Micro for permission to bundle its tool, which is free, but not open source, with its software.

Following the Trend article, Loaris has stopped illegally distributing and deploying HijackThis with its own security software. "Loaris Trojan Remover version 1.1.6.8 no longer carries HJT in its UI," Mr. Det Caraig announces.

Trend Micro advises users to "download software only from the official vendor sites or highly trusted communities." The latest version of HijackThis is available for download here.

TELL US WHAT YOU THINK:

2,752 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Ransomware Becoming the Next Step in Scareware Evolution

Major U.S. Retailer Settles FTC Spyware Charges

Scareware Turns Ransomware

L0phtCrack Version 6 – Restoring a Piece of Hacking History

AVG Tags Adobe Flash Player as Malware

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM