· General · Release Notes
Release Notes – Windows Defender Released and ProcessHawk, HJT Revamped
Hi folks – We’ve got a batch of updates to share. ProcessHawk has been completely rewritten, we’ve shipped a brand new Windows Defender tool, and HijackThis has been modernized with an actively maintained replacement under the hood. Details below.
ProcessHawk — Complete Rewrite
The old version dated back to 2016 — no error handling, no real report output, and a whitelist that hadn’t been touched in seven years. The new version does what it always did (kills unnecessary processes before malware scans), but now gives you a real picture of what was running on the machine and whether any of it looks suspicious.
The biggest addition is suspicious process intelligence. ProcessHawk now flags processes running from locations commonly associated with malware — TEMP folders, Downloads, AppData, the Recycle Bin — and highlights unsigned executables. If a process resists termination, it gets called out prominently in the report. The goal is to give you an instant read on whether a machine is likely infected before the scan even starts.
- Suspicious location flagging (TEMP, Downloads, AppData, Recycle Bin) with per-process badges in the report
- Unsigned process detection — killed processes without a digital signature are highlighted
- Failed-to-kill processes are called out as potential active malware
- Hardcoded critical process protection — csrss, lsass, svchost, explorer, and other system processes can never be killed, even if the whitelist is misconfigured
- Completely updated whitelist with modern RMM tools (AnyDesk, NinjaRMM, Datto, Syncro, ConnectWise), Windows Defender components, Windows Terminal, and dozens of other modern system processes
- New Dry Run mode lets you see exactly what ProcessHawk would kill without actually terminating anything — useful for verifying whitelist coverage on a new machine
- Full parsed report with stats, alerts, and a process table replacing the old raw text dump
Windows Defender — New Tool
Windows Defender is a brand new tool that gives you a complete picture of a machine’s security posture without opening a dozen different windows. Run Diagnostic mode and you get Defender’s protection status, signature age, threat inventory, exclusion audit, competing AV detection, Windows Firewall status, and a security health score — all in one report.
The tool flags the things that actually matter: signatures that haven’t updated in weeks, suspicious exclusions that malware may have added, third-party AV products conflicting with Defender, and ransomware protection (Controlled Folder Access) being disabled. Quick Scan and Full Scan modes let you kick off a Defender scan directly from TechSuite, and Update Signatures pulls fresh definitions without navigating Windows Security.
- Diagnostic mode with full security posture report and health score
- Signature age warnings and threat inventory
- Exclusion audit — flags entries that look like malware-added exceptions
- Competing AV detection and conflict reporting
- Controlled Folder Access (ransomware protection) status
- Windows Firewall status per network profile
- Quick Scan, Full Scan, and Update Signatures modes
- Requires Windows 10 or later
HijackThis — Modernized with HiJackThis+
The old version wrapped the original TrendMicro HiJackThis v2.0.5, which hasn’t been updated since 2013 and doesn’t work properly on Windows 10 or 11. The new version uses HiJackThis+ by Dragokas — an actively maintained fork that supports Windows 7 through 11 and adds detection categories that didn’t exist when the original was abandoned.
The wrapper itself is also brand new. Instead of just launching the executable and dumping raw output, the tool now parses the full scan log, categorizes every entry, and produces a structured report with clear sections for startup items, services, scheduled tasks, browser settings, and more.
- Upgraded from TrendMicro HiJackThis v2.0.5 (2013) to HiJackThis+ v3.4.0.17 (2025)
- Full Windows 10 and 11 support — the old version would frequently fail or produce incomplete scans on modern systems
- New parsed report with collapsible sections for startup items, services, scheduled tasks, hosts file entries, and more
- Services with missing executables are flagged with clear visual indicators
- Structured output with entry counts by category, service counts, and scan duration
- Admin check, VM detection, and OS version reporting in diagnostics
As always, if you have requests or notice anything unexpected, just send us an email at support@repairtechsolutions.com.
Ian & Garrett