Results of analyzing your log


The HijackThis log analyzer beta 2 is a brand new service, so it is natural that it may have a few issues with entry descriptions and status. You can help us to improve the analyzer! If you have some information on unknown items, please share it with us and thousands of 2-Spyware.com visitors. We will carefully check your submission and approve it, if it is correct. You can also change status of entries that do not look identified correctly to you. Also feel free to post your description for existing items. We will review and add it to the analyzer's database.
Thank you!

Files and registry entries considered to be safe
Legitimate items6083%
Not necessary items710%
 6793%

File and registry entries that can be both dangerous or safe
Questionable items00%
Unknown items46%
 46%

Files and registry entries considered to be DANGEROUS. Fix immediately!
Dangerous items11%


Line: Status: Comments: Actions:
C:\WINDOWS\System32\smss.exe
More info about file smss.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\system32\csrss.exe
More info about file csrss.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\system32\winlogon.exe
More info about file winlogon.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\system32\services.exe
More info about file services.exe
Legitimate In most of cases it is legitimate system process, only sometimes can be used by malicious software Change status
C:\WINDOWS\system32\lsass.exe
More info about file lsass.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\system32\svchost.exe
More info about file svchost.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\System32\svchost.exe
More info about file svchost.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\System32\svchost.exe
More info about file svchost.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\System32\svchost.exe
More info about file svchost.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\system32\spoolsv.exe
More info about file spoolsv.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\Explorer.EXE
More info about file explorer.exe
Legitimate Process found in system process library Change status
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
More info about file smax4pnp.exe
Legitimate Item found in 2-spyware.com library
The file is related to SoundMax software.
Change status
C:\Program Files\Logitech\iTouch\iTouch.exe
More info about file itouch.exe
Legitimate Item found in 2-spyware.com library
A legitimate component of the Logitech iTouch keybord driver.
Change status
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
More info about file avgcc.exe
Legitimate Item found in 2-spyware.com library
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe
More info about file fpdisp5a.exe
Legitimate Item found in 2-spyware.com library
An essential component of the FinePrint utility, which acts as a printer driver that controls and...
Change status
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
More info about file ewido.exe
Legitimate Item found in 2-spyware.com library
ewido anti-malware component.
Change status
C:\WINDOWS\System32\ctfmon.exe
More info about file ctfmon.exe
Legitimate Process found in system process library Change status
C:\Program Files\MSN Messenger\msnmsgr.exe
More info about file msnmsgr.exe
Legitimate Item found in 2-spyware.com library
Microsoft Windows Messenger chat client.
Change status
C:\Program Files\Spyware Doctor\swdoctor.exe
More info about file swdoctor.exe
Legitimate Item found in 2-spyware.com library
Main component of Spyware Doctor, a popular anti-spyware program.
Change status
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
More info about file avgamsvr.exe
Legitimate It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. Change status
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
More info about file avgupsvc.exe
Legitimate Item found in 2-spyware.com library
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
More info about file avgemc.exe
Legitimate Item found in 2-spyware.com library
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
C:\WINDOWS\System32\CTsvcCDA.EXE
More info about file ctsvccda.exe
Legitimate Item found in 2-spyware.com library
Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some...
Change status
C:\Program Files\ewido anti-spyware 4.0\guard.exe
More info about file guard.exe
Legitimate Item found in 2-spyware.com library
ewido Anti-malware real-time guard
Change status
C:\WINDOWS\System32\nvsvc32.exe
More info about file nvsvc32.exe
Legitimate Item found in 2-spyware.com library
NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching...
Change status
C:\Program Files\Spyware Doctor\sdhelp.exe
More info about file sdhelp.exe
Legitimate Item found in 2-spyware.com library
A part of Spyware Doctor, a popular legitimate anti-spyware program.
Change status
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
More info about file smagent.exe
Legitimate Item found in 2-spyware.com library
SoundMAX Agent. Related to drivers for various sound cards and similar devices.
Change status
C:\WINDOWS\System32\svchost.exe
More info about file svchost.exe
Legitimate Process found in system process library Change status
C:\WINDOWS\System32\wdfmgr.exe
More info about file wdfmgr.exe
Legitimate Item found in 2-spyware.com library
A part of Microsoft Windows Media Player 10. It is used to eliminate software compatibility...
Change status
C:\Program Files\BitComet\BitComet.exe Unknown No exact entries found Insert file into database
C:\WINDOWS\System32\Msn32e.exe Unknown No exact entries found Insert file into database
C:\Program Files\Mozilla Firefox\firefox.exe
More info about file firefox.exe
Legitimate Item found in 2-spyware.com library
File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all...
Change status
C:\Documents and Settings\tan\Desktop\HijackThis.exe
More info about file hijackthis.exe
Legitimate Item found in 2-spyware.com library
This is the main component of HijackThis security application, designed to perform system scans and...
Change status
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx Legitimate legitimate bho toolbar, related to Adobe Acrobat reader Change status
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll Legitimate legitimate bho toolbar, related to PCTools Spyware Doctor Change status
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
More info about file ssv.dll
Legitimate System item according to inner database
Related to Java Virtual Machine software, which is legitimate.
Change status
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll Legitimate legitimate bho toolbar, related to PCTools Spyware Doctor Change status
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
More info about file toolband.dll
Dangerous Spyware related item according to inner database
toolband.dll is a library file that contains malicious code, which implements main parasite...
Change status
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
More info about file imjpmig.exe
Legitimate System item according to inner database
Related to Windows East Asian language support (Japanese keyboard entry). Located in...
Change status
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
More info about file imscinst.exe
Legitimate Application program item according to inner database
Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\PINTLGNT\".
Change status
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
More info about file tintsetp.exe
Legitimate System item according to inner database
Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\".
Change status
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
More info about file tintsetp.exe
Legitimate System item according to inner database
Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\".
Change status
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
More info about file smax4pnp.exe
Legitimate Application program item according to inner database
The file is related to SoundMax software.
Change status
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
More info about file smax4.exe
Legitimate Application program item according to inner database
The file belongs to SoundMAX Control Center.
Change status
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
More info about file nvcpl.dll
Legitimate System item according to inner database
Related to nVidia cards. NvCpl.dll is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,...
Change status
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
More info about file nwiz.exe
Legitimate System item according to inner database
Nwiz.exe is Related to nVidia graphic cards drivers.
Long name - NVIDIA nView Wizard.<br...
Change status
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
More info about file nvmctray.dll
Legitimate System item according to inner database
nVidia graphics cards related. NVMCTRAY.DLL is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,...
Change status
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
More info about file itouch.exe
Legitimate Driver related item according to inner database.
A legitimate component of the Logitech iTouch keybord driver.
Change status
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
More info about file avgcc.exe
Legitimate System item according to inner database
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
O4 - HKLM\..\Run: [FinePrint Dispatcher v5] "C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp5a.exe" /source=HKLM
More info about file fpdisp5a.exe
Legitimate Driver related item according to inner database.
An essential component of the FinePrint utility, which acts as a printer driver that controls and...
Change status
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
More info about file ewido.exe
Legitimate Application program item according to inner database
ewido anti-malware component.
Change status
O4 - HKLM\..\Run: [Microsoft Layer Services] Msn32e.exe Unknown No exact entries found Insert file into database
O4 - HKLM\..\RunServices: [Microsoft Layer Services] Msn32e.exe Unknown No exact entries found Insert file into database
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
More info about file ctfmon.exe
Legitimate Application program item according to inner database
When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)...
Change status
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
More info about file msnmsgr.exe
Legitimate System item according to inner database
Microsoft Windows Messenger chat client.
Change status
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
More info about file swdoctor.exe
Legitimate Application program item according to inner database
Main component of Spyware Doctor, a popular anti-spyware program.
Change status
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html Not necessary Do you want item 'Easy-WebPrint Add To Print List' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. Change status
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html Not necessary Do you want item 'Easy-WebPrint High Speed Print' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. Change status
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html Not necessary Do you want item 'Easy-WebPrint Preview' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. Change status
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html Not necessary Do you want item 'Easy-WebPrint Print' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. Change status
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll Not necessary This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll'. If you do not want it to be there, fix this item. Change status
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll Not necessary This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll'. If you do not want it to be there, fix this item. Change status
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll Legitimate This item represents a plugin added to Internet Explorer to work with '.spop' files. Seems to be safe, unless you know that it is malicious. Change status
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) Not necessary It is a protocol hijacker that points to nowhere. Fix this item. Change status
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
More info about file avgamsvr.exe
Legitimate Item found in 2-spyware.com database.
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
More info about file avgupsvc.exe
Legitimate Item found in 2-spyware.com database.
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
More info about file avgemc.exe
Legitimate Item found in 2-spyware.com database.
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft...
Change status
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
More info about file ctsvccda.exe
Legitimate Item found in 2-spyware.com database.
Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some...
Change status
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
More info about file guard.exe
Legitimate Item found in 2-spyware.com database.
ewido Anti-malware real-time...
Change status
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
More info about file nvsvc32.exe
Legitimate Item found in 2-spyware.com database.
NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching...
Change status
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
More info about file sdhelp.exe
Legitimate Item found in 2-spyware.com database.
A part of Spyware Doctor, a popular legitimate anti-spyware...
Change status
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
More info about file smagent.exe
Legitimate Item found in 2-spyware.com database.
SoundMAX Agent. Related to drivers for various sound cards and similar...
Change status


Recommended software:
Spyware Doctor
(91/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and easy-to-manage...
Malwarebytes Anti Malware
(89/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t have many features. One such...
Spy Sweeper
(85/100)
Spy Sweeper is one of the most powerful and effective spyware removers available today. This Webroot Software's product uses unique, patent-pending parasite detection and removal...
Windows Defender
(80/100)
Windows Defender is a free anti-spyware program made by the leading software company to add native spyware protection to its most popular product - the Microsoft Windows operating...
SUPERAntiSpyware
(75/100)
SUPERAntiSpyware is a powerful, highly effective spyware remover introducing advanced parasite detection and removal features along with reliable real-time protection. The program is not...

Latest Spyware news:
Rogue security applications impersonate leading anti-virus manufacturers
Attack of Waledac Worm is schedulled on July 4
Another Parasite Attack Spreads Via Twitter
Free security product vets Twitter links
Mac trojan targets game sites to infect users
Security Threat at Fanny Mae
Some web sites to avoid for today
British Government will track all e-mail's
YOUR SISTER NAKED LOLZ com
“intervalhehehe” popup

Subscribe to news

Encyclopedia of parasites:
Antivirus 2010 21/11/09
BankerFox.A 21/11/09
Privacy Center 21/11/09
Security Tool 20/11/09
Antivirus System Pro 20/11/09
Advanced Virus Remover 20/11/09
Cyber Security 20/11/09
Win32/Yektel 19/11/09
Fuqer Trojan 19/11/09
SecureKeeper 18/11/09
Sdbot.add 18/11/09
Enterprise Suite 18/11/09
SystemDefender 18/11/09
Trojan.Agent 17/11/09
Alpha Antivirus 17/11/09
Personal Protector 17/11/09
Control Center 16/11/09
LinkSafeness 16/11/09
SiteVillain 16/11/09
System Defender 16/11/09

Library of files:
vbs55.chm 27/10/09
Services.exe 23/10/09
drwtsn32.exe 09/10/09
cvpnd.exe 02/09/09
cftmon.exe 13/08/09
rundll32.exe 24/07/09
tabctl32.ocx 22/07/09
mmc.exe 19/07/09
b.exe 13/07/09
wow.exe 20/06/09

Archive of files
Archive of startup entries