// tool · free

Know exactly what's hiding on your PC

Run one forensic, read-only pass over your Windows PC and walk away with a clean 1-page PDF showing every executable, signature, persistence hook, and browser risk — with nothing on your machine touched or changed.

flux@store
$ install pc-hygiene-audit
✓ resolving dependencies
✓ ready — 0 setup, runs on your machine
› launching…
flux@store: ~/run
$ pc-hygiene-audit --run
point it at your input
run the command
it processes locally
get structured output
done — output ready
$ run --pipeline
1
Point it at your input
2
Run the command
3
It processes locally
4
Get structured output
$ explain --how-it-works

How it actually works

Exactly what it does — and when.

1For every .exe, .dll, and .sys across all mounted drives → it computes SHA-256 hashes using Windows CryptoAPI and cross-references them against known-good and known-malicious signature databases.
2For WMI persistence infections → it queries the root\subscription namespace for EventConsumer, EventFilter, and FilterToConsumerBinding entries, flagging malicious persistence payloads without executing or modifying them.
3For browser hijacks → it reads Chrome, Firefox, Edge, and IE preference files to detect unauthorized homepage changes, unwanted extensions, and proxy overrides stored in JSON and SQLite formats.
4For kernel-level rootkit indicators → it enumerates loaded drivers via the Windows DriverStore and cross-checks digital signatures using WinVerifyTrust, flagging unsigned or forged kernel modules.
In practice · Post-Download Security Checkup

After downloading a cracked game from a torrent site, your fan spins up and Chrome redirects to ad sites. You run the PC Hygiene Audit, which hashes all 4,217 executables on your C: drive, flags a malicious WMI EventConsumer tied to a svchost impersonator, and catches a browser proxy override pushing traffic through 91.218.xxx.xxx. You get a 1-page PDF listing every vector — you delete the entries manually, re-scan clean.

$ cat spec.txt
FormatRunnable scripts + docs
DeliveryInstant — no email
LicenseYours forever · use on every project
Works withAny LLM / your own stack
$ benchmark --vs-alternatives
This product
A paid SaaS tool
Monthly cost
$0 — runs on your machine
$80–150/mo, billed forever
Setup
Drop in & run in minutes
Accounts, API keys, rate limits
Your data
Never leaves your computer
Uploaded to their cloud
Ownership
Yours forever — edit the code
Rented; stops when you cancel

Use it to…

Real ways people run PC Hygiene Audit.

Pre-cleanup reconnaissance

Run the audit before deleting or reinstalling anything so the PDF captures every executable hash, signature mismatch, and persistence hook on the machine first.

Secondhand PC handoff check

Hash and signature-scan a used or returned Windows machine across all drives to confirm nothing malicious is lurking before you trust it.

Browser hijack confirmation

When searches redirect or extensions act strange, the read-only browser, WMI, and persistence scan flags the hijack and lands the evidence in your PDF.

What's inside

Flags 25+ malware vectors
Hashes every executable, every drive
Sig-checks + WMI persistence + driver scan
Detects rootkit indicators + browser hijacks
Forensic, read-only — nothing modified
1-page PDF report — free instant download

Questions, answered

Free · no emailYours to ownUse on every projectBuilt to ship results

Ready to put PC Hygiene Audit to work?

Free download · no account needed · yours forever

PC Hygiene Audit