| Line: |
Status: |
Comments: |
Actions: |
C:\WINNT\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\services.exe More info about file services.exe |
Questionable |
This item can be legitimate or spyware related, depending on its location and other factors. Make some further research on it. |
Change status |
C:\WINNT\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com library Related to the ZoneAlarm firewall from ZoneLabs. Located in "C:\WINDOWS\SYSTEM\ZONELABS\". |
Change status |
C:\WINNT\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\AVGANT~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\AVGANT~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINNT\system32\regsvc.exe More info about file regsvc.exe |
Legitimate |
Item found in 2-spyware.com library File is related to Remote Registry Service - it is a system component, which exists in Microsoft... |
Change status |
C:\WINNT\system32\MSTask.exe More info about file mstask.exe |
Legitimate |
Item found in 2-spyware.com library Mstask.exe is the task scheduler service, responsible for running tasks at a time predetermined by... |
Change status |
C:\WINNT\System32\WBEM\WinMgmt.exe More info about file winmgmt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\dcomcfg.exe More info about file dcomcfg.exe |
Dangerous |
Item found in 2-spyware.com library dcomcfg.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
C:\WINNT\system32\atmclk.exe More info about file atmclk.exe |
Dangerous |
Item found in 2-spyware.com library atmclk.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe More info about file viewmgr.exe |
Legitimate |
Item found in 2-spyware.com library This is a part of media player, which can act as an adware program. This player appears to be a... |
Change status |
C:\PROGRA~1\AVGANT~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
| C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe More info about file directcd.exe |
Legitimate |
Item found in 2-spyware.com library Related to CD burning software from Roxio. Located in "C:\Program Files\Roxio\Easy CD Creator... |
Change status |
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe More info about file zlclient.exe |
Legitimate |
Item found in 2-spyware.com library ZoneAlarm Firewall http://www.zonelabs.com |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
| C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtWLan.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINNT\system32\notepad.exe More info about file notepad.exe |
Questionable |
Item found in 2-spyware.com library The RapidBlaster spyware has been reported to masquerade as Notepad.exe, using the same filename as... |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINNT\system32\NOTEPAD.EXE More info about file notepad.exe |
Questionable |
Item found in 2-spyware.com library The RapidBlaster spyware has been reported to masquerade as Notepad.exe, using the same filename as... |
Change status |
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://topics.nytimes.com/top/news/international/countriesandterritories /northkorea/index.html?8qa |
Not necessary |
http://topics.nytimes.com/top/news/international/countriesandterritories /northkorea/index.html?8qa is your start page. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll More info about file googletoolbar1.dll |
Legitimate |
Application program item according to inner database An essential component of Google Toolbar. |
Change status
|
| O2 - BHO: (no name) - {f7d40011-29bb-43eb-9c97-875ce89e9e36} - C:\WINNT\system32\hp100.tmp |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon More info about file mobsync.exe |
Legitimate |
System item according to inner database "With Internet Explorer, you can make pages available offline. You can use Synchronization Manager... |
Change status
|
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe More info about file viewmgr.exe |
Legitimate |
Application program item according to inner database This is a part of media player, which can act as an adware program. This player appears to be a... |
Change status
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\AVGANT~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
| O4 - HKLM\..\Run: [CreateCD50] "C:\Program Files\Common Files\Adaptec Shared\CreateCD\CreateCD50.exe" -r |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" More info about file directcd.exe |
Legitimate |
Application program item according to inner database Related to CD burning software from Roxio. Located in "C:\Program Files\Roxio\Easy CD Creator... |
Change status
|
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" More info about file zlclient.exe |
Legitimate |
System item according to inner database ZoneAlarm Firewall http://www.zonelabs.com |
Change status
|
| O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html |
Not necessary |
Do you want item 'Backward Links' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html |
Not necessary |
Do you want item 'Cached Snapshot of Page' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html |
Not necessary |
Do you want item 'Similar Pages' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html |
Not necessary |
Do you want item 'Translate Page into English' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Research' and points to file 'C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'AIM' and points to file 'C:\Program Files\AIM\aim.exe'. If you do not want it to be there, fix this item. |
Change status
|
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls /en/x86/client/wuweb_site.cab?1146057031691 |
Questionable |
Are you using an ActiveX object with a name 'WUWebControl Class' located in 'http://update.microsoft.com/windowsupdate/v6/V5Controls /en/x86/client/wuweb_site.cab?1146057031691'? If not, fix this item. |
Change status
|
| O21 - SSODL: cholecyst - {ee2975b6-e8d5-405e-8448-8fe9590f6cfb} - C:\WINNT\system32\mzoeut.dll (file missing) |
Unknown |
No exact entries found |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\AVGANT~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\AVGANT~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe More info about file dmadmin.exe |
Legitimate |
Item found in 2-spyware.com database. File dmadmin.exe is a standard component of Microsoft Windows operating system. It is included in... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com database. Related to the ZoneAlarm firewall from ZoneLabs. Located in... |
Change status
|