| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe More info about file evteng.exe |
Legitimate |
Item found in 2-spyware.com library EvtEng.exe is an application process related to Intel EvtEng Module. It provides additional support... |
Change status |
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe More info about file s24evmon.exe |
Legitimate |
Item found in 2-spyware.com library Related to special software required by Intel wireless hardware. It allows to configure and... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Bonjour for Windows application. |
Change status |
C:\WINDOWS\system32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com library NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status |
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe More info about file oprotsvc.exe |
Legitimate |
Item found in 2-spyware.com library OProtSvc.exe is an application process that is related to PROSet Wireless software. You should not... |
Change status |
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe More info about file regsrvc.exe |
Legitimate |
Item found in 2-spyware.com library regsrvc.exe is an essential part of Intel wireless hardware drivers. Do not terminate or delete it... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgam.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgrsx.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe More info about file zcfgsvc.exe |
Legitimate |
Item found in 2-spyware.com library ZcfgSvc.exe is a part of Intel wireless hardware drivers. Allows to monitor and configure the... |
Change status |
C:\PROGRA~1\AVG\AVG8\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe More info about file 1xconfig.exe |
Legitimate |
Item found in 2-spyware.com library This is a part of the drivers for USB devices. It also is related to special monitoring and... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe More info about file acrotray.exe |
Legitimate |
Item found in 2-spyware.com library Related to Adobe Acrobat Reader program. |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Logitech\SetPoint\SetPoint.exe More info about file setpoint.exe |
Legitimate |
Item found in 2-spyware.com library The file is associated with Logitech Mouse/Keyboard application. |
Change status |
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE More info about file khalmnpr.exe |
Legitimate |
Item found in 2-spyware.com library khalmnpr.exe is associated with Logitech Mouse/Keyboard application. |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe More info about file fnplicensingservice.exe |
Legitimate |
Item found in 2-spyware.com library fnplicensingservice.exe is the Activation Licensing Service for the Macrovision FLEXnet Publisher... |
Change status |
C:\Program Files\Mozilla Firefox\firefox.exe More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgnsx.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://customer.voodoopc.com |
Not necessary |
http://customer.voodoopc.com is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your start page. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll More info about file avgssie.dll |
Legitimate |
Application program item according to inner database Related to AVG Antivirus 8.0 |
Change status
|
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll More info about file acroiefavclient.dll |
Legitimate |
System item according to inner database The file belongs to Adobe Acrobat to display .pdf files in Internet Explorer. |
Change status
|
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll More info about file acroiefavclient.dll |
Legitimate |
System item according to inner database The file belongs to Adobe Acrobat to display .pdf files in Internet Explorer. |
Change status
|
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup More info about file nvcpl.dll |
Legitimate |
System item according to inner database Related to nVidia cards. NvCpl.dll is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,... |
Change status
|
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" More info about file acrotray.exe |
Legitimate |
Application program item according to inner database Related to Adobe Acrobat Reader program. |
Change status
|
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE More info about file khalmnpr.exe |
Legitimate |
Application program item according to inner database khalmnpr.exe is associated with Logitech Mouse/Keyboard application. |
Change status
|
| O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install More info about file nwiz.exe |
Legitimate |
System item according to inner database Nwiz.exe is Related to nVidia graphic cards drivers. Full name - NVIDIA nView Wizard.<br... |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe More info about file adobe gamma loader.exe |
Legitimate |
Application program item according to inner database From adobe: "The Adobe Gamma Control Panel is used to eliminate color casts in a monitor's display.... |
Change status
|
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe More info about file setpoint.exe |
Legitimate |
Application program item according to inner database The file is associated with Logitech Mouse/Keyboard application. |
Change status
|
| O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html |
Not necessary |
Do you want item 'Append to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html |
Not necessary |
Do you want item 'Convert link target to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html |
Not necessary |
Do you want item 'Convert link target to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html |
Not necessary |
Do you want item 'Convert selected links to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html |
Not necessary |
Do you want item 'Convert selected links to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html |
Not necessary |
Do you want item 'Convert selection to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html |
Not necessary |
Do you want item 'Convert selection to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html |
Not necessary |
Do you want item 'Convert to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Research' and points to file 'C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name '@xpsp3res.dll,-20001' and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O14 - IERESET.INF: START_PAGE_URL=http://customer.voodoopc.com |
Questionable |
This item changes your "default" Start page in IE. It will appear if you Restore default web settings. If you are an administrator and you do not recognize address "", fix this item. |
Change status
|
| O15 - Trusted IP range: 10.210.1.6 |
Questionable |
Do you want URL pattern "10.210.1.6" to be in your trusted IP addresses range of IE? If not, fix this item. |
Change status
|
| O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab |
Questionable |
Are you using an ActiveX object with a name 'Shockwave Flash Object' located in 'http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {D9EF4DC2-D250-486F-88A0-516DC35AB59E} (JJang File Share Control) - http://app.gridcdn.com/control/JJangFile/JJangFile.CAB |
Questionable |
Are you using an ActiveX object with a name 'JJang File Share Control' located in 'http://app.gridcdn.com/control/JJangFile/JJangFile.CAB'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = BEARUSA.local |
Questionable |
Do you recognize these IP addresses 'BEARUSA.local' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\Software\..\Telephony: DomainName = BEARUSA.local |
Questionable |
Do you recognize these IP addresses 'BEARUSA.local' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{CBCCDFFE-2DA3-4485-9FCF-E2D962FBA2A8}: NameServer = 208.67.222.222,208.67.220.220 |
Questionable |
Do you recognize these IP addresses '208.67.222.222,208.67.220.220' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = BEARUSA.local |
Questionable |
Do you recognize these IP addresses 'BEARUSA.local' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = BEARUSA.local |
Questionable |
Do you recognize these IP addresses 'BEARUSA.local' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "linkscanner" and file "C:\Program Files\AVG\AVG8\avgpp.dll". |
Change status
|
| O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "skype4com" and file "C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL". |
Change status
|
| O20 - AppInit_DLLs: avgrsstx.dll |
Unknown |
No exact entries found |
Change status
|
| O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe |
Legitimate |
Required for PhotoshopCS |
Change status
|
| O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com database. The file belongs to Bonjour for Windows... |
Change status
|
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe More info about file evteng.exe |
Legitimate |
Item found in 2-spyware.com database. EvtEng.exe is an application process related to Intel EvtEng Module. It provides additional support... |
Change status
|
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe More info about file fnplicensingservice.exe |
Legitimate |
Item found in 2-spyware.com database. fnplicensingservice.exe is the Activation Licensing Service for the Macrovision FLEXnet Publisher... |
Change status
|
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe More info about file lbtserv.exe |
Legitimate |
Item found in 2-spyware.com database. lbtserv.exe is an application process that is responsible for setting up and maintaining Bluetooth... |
Change status
|
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com database. NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status
|
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe More info about file oprotsvc.exe |
Legitimate |
Item found in 2-spyware.com database. OProtSvc.exe is an application process that is related to PROSet Wireless software. You should not... |
Change status
|
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe More info about file regsrvc.exe |
Legitimate |
Item found in 2-spyware.com database. regsrvc.exe is an essential part of Intel wireless hardware drivers. Do not terminate or delete it... |
Change status
|
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe More info about file s24evmon.exe |
Legitimate |
Item found in 2-spyware.com database. Related to special software required by Intel wireless hardware. It allows to configure and... |
Change status
|
| O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ahong/LOCALS~1/Temp/msohtmlclip1/01/clip_image002.gif |
Unknown |
No exact entries found |
Insert file into database
|