| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\csrss.exe More info about file csrss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Windows Defender\MsMpEng.exe More info about file msmpeng.exe |
Legitimate |
Item found in 2-spyware.com library Related to Windows Defender program. |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\wltrysvc.exe More info about file wltrysvc.exe |
Legitimate |
Item found in 2-spyware.com library Installed alongside Broadcom wireless communication software. It is a tool that displays an icon in... |
Change status |
C:\WINDOWS\System32\bcmwltry.exe More info about file bcmwltry.exe |
Legitimate |
Item found in 2-spyware.com library bcmwltry.exe is BroadCom's Wireless Network Tray Applet. It runs if you are on a wireless... |
Change status |
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe More info about file ccproxy.exe |
Legitimate |
Item found in 2-spyware.com library File related to Symantec software |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe More info about file ccsetmgr.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status |
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe More info about file ccevtmgr.exe |
Legitimate |
Item found in 2-spyware.com library ccEvtMgr.exe is an event logging application and runs at startup. It monitors virus alerts, virus... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Digital Media Reader\shwiconem.exe More info about file shwiconem.exe |
Legitimate |
Item found in 2-spyware.com library A part of Digital Media USB Reader software required by some USB devices to work properly. Provides... |
Change status |
C:\WINDOWS\ehome\ehtray.exe More info about file ehtray.exe |
Legitimate |
Item found in 2-spyware.com library Windows Media Center 2005 |
Change status |
C:\WINDOWS\zHotkey.exe More info about file zhotkey.exe |
Legitimate |
Item found in 2-spyware.com library
|
Change status |
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
Item found in 2-spyware.com library ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status |
C:\Program Files\Windows Defender\MSASCui.exe More info about file msascui.exe |
Legitimate |
Item found in 2-spyware.com library The file is component of Microsoft Windows Defender application. |
Change status |
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe More info about file nmbgmonitor.exe |
Legitimate |
Item found in 2-spyware.com library file for nero cd burning |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\eHome\ehRecvr.exe More info about file ehrecvr.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Windows XP Media Center application. |
Change status |
C:\WINDOWS\eHome\ehSched.exe More info about file ehsched.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Windows XP Media Center application. |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\WINDOWS\ehome\mcrdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\dllhost.exe More info about file dllhost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\eHome\ehmsas.exe More info about file ehmsas.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Microsoft Windows Media Center application. |
Change status |
C:\WINDOWS\System32\alg.exe More info about file alg.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com library AntiVir real-time Protection process. |
Change status |
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com library Scheduler for AntiVir Anti Virus program. |
Change status |
C:\Program Files\MSN Messenger\msnmsgr.exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
| c:\program files\warcraft iii\war3.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe More info about file acrord32.exe |
Legitimate |
Item found in 2-spyware.com library File acrord32.exe is an executable of Acrobat Reader program, which is used to view PDF documents.... |
Change status |
C:\WINDOWS\system32\drwtsn32.exe More info about file drwtsn32.exe |
Legitimate |
Item found in 2-spyware.com library This is a debug tool, included in Windows XP operating system. It collects information related to... |
Change status |
C:\WINDOWS\system32\drwtsn32.exe More info about file drwtsn32.exe |
Legitimate |
Item found in 2-spyware.com library This is a debug tool, included in Windows XP operating system. It collects information related to... |
Change status |
C:\Program Files\Mozilla Firefox\firefox.exe More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.250\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ask.com |
Not necessary |
http://www.ask.com is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com |
Not necessary |
http://www.myspace.com is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54729 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID} |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID} is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer |
Not necessary |
Microsoft Internet Explorer is the title in your Internet Explorer window. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac |
Not necessary |
. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Legitimate |
legitimate bho toolbar, related to SpyBot Search&Destroy |
Change status
|
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll More info about file yiesrvc.dll |
Legitimate |
Application program item according to inner database The file is related to Yahoo! software. |
Change status
|
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll More info about file ssv.dll |
Legitimate |
System item according to inner database Related to Java Virtual Machine software, which is legitimate. |
Change status
|
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll More info about file nisshext.dll |
Legitimate |
Application program item according to inner database A web browser toolbar belonging to Symantec AdBlocker, which is integrated into a variety of... |
Change status
|
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll More info about file navshext.dll |
Legitimate |
Application program item according to inner database Component of Norton Anti-virus. Located in "C:\Program Files\Norton AntiVirus\". Uses... |
Change status
|
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll More info about file nisshext.dll |
Legitimate |
Application program item according to inner database A web browser toolbar belonging to Symantec AdBlocker, which is integrated into a variety of... |
Change status
|
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll More info about file navshext.dll |
Legitimate |
Application program item according to inner database Component of Norton Anti-virus. Located in "C:\Program Files\Norton AntiVirus\". Uses... |
Change status
|
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O4 - HKLM\..\Run: [SunKistEM] "C:\Program Files\Digital Media Reader\shwiconem.exe" More info about file shwiconem.exe |
Legitimate |
Application program item according to inner database A part of Digital Media USB Reader software required by some USB devices to work properly. Provides... |
Change status
|
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe More info about file ehtray.exe |
Legitimate |
System item according to inner database Windows Media Center 2005 |
Change status
|
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe More info about file zhotkey.exe |
Legitimate |
System item according to inner database
|
Change status
|
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" More info about file atiptaxx.exe |
Legitimate |
System item according to inner database ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status
|
| O4 - HKLM\..\Run: [LXCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCFtime.dll,_RunDLLEntry@16 |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide More info about file msascui.exe |
Legitimate |
Application program item according to inner database The file is component of Microsoft Windows Defender application. |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min More info about file avgnt.exe |
Legitimate |
Application program item according to inner database Used by AntiVir Anti Virus. |
Change status
|
O4 - HKLM\..\RunOnce: [IERESETICONS] %SystemRoot%\system32\cmd.exe /d /q /c %SystemRoot%\iereseticons.exe More info about file cmd.exe |
Legitimate |
System item according to inner database Command prompt tool that comes with Windows NT/2000/XP. Located in "C:\WINNT\SYSTEM32" on Windows... |
Change status
|
| O4 - HKLM\..\RunOnce: [Installing-ie7] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IE7-WindowsXP-x86-enu[1].exe /passive |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" More info about file nmbgmonitor.exe |
Legitimate |
Application program item according to inner database file for nero cd burning |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - Startup: BHODemon 2.0.lnk = C:\Program Files\BHODemon 2\BHODemon.exe More info about file bhodemon.exe |
Legitimate |
Runs a main component of the BHODemon program on Windows startup. BHODemon manages Internet Explorer plug-ins and protects the web browser from unsolicited add-ons. |
Change status
|
| O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present |
Questionable |
This item can be set only by administrator or by Spybot software. If you are administrator and you do not know anything about it, then fix this item. |
Change status
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll |
Legitimate |
Legitimate extra button in your browser - related to Yahoo! Services. |
Change status
|
| O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Real.com' and points to file 'C:\WINDOWS\system32\Shdocvw.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) |
Not necessary |
Fix this item because it points to a file that cannot be found |
Change status
|
| O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) |
Not necessary |
Fix this item because it points to a file that cannot be found |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O11 - Options group: [INTERNATIONAL] International* |
Questionable |
This item represents a group added to Advanced Options tab in IE Tools > Internet Options menu. Should the item called "INTERNATIONAL" be there? If not, fix it. |
Change status
|
| O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab |
Questionable |
Are you using an ActiveX object with a name 'Support.com Configuration Class' located in 'http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab'? If not, fix this item. |
Change status
|
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - http://a516.g.akamai.net/f/516/25175/7d/runaware.download .akamai.com/25175/citrix/wficat-no-eula.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://a516.g.akamai.net/f/516/25175/7d/runaware.download .akamai.com/25175/citrix/wficat-no-eula.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {2396F475-3C4C-4028-AD17-FAF37352EE82} (Activex Control) - http://www.poolgameonline.com/loadgame_et.cab |
Questionable |
Are you using an ActiveX object with a name 'Activex Control' located in 'http://www.poolgameonline.com/loadgame_et.cab'? If not, fix this item. |
Change status
|
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls /en/x86/client/wuweb_site.cab?1135649640794 |
Legitimate |
Legitimate ActiveX item from site http://update.microsoft.com/ |
Change status
|
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1139802177656 |
Legitimate |
Legitimate ActiveX item from site http://update.microsoft.com/ |
Change status
|
| O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by111fd.bay111.hotmail.msn.com/activex/HMAtchmt.ocx |
Questionable |
Are you using an ActiveX object with a name 'Hotmail Attachments Control' located in 'http://by111fd.bay111.hotmail.msn.com/activex/HMAtchmt.ocx'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{25F3C646-17BC-40E8-9638-A57028872BB7}: NameServer = 85.255.116.149,85.255.112.60 |
Questionable |
Do you recognize these IP addresses '85.255.116.149,85.255.112.60' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{371BDE93-341C-492E-B63D-653331EE7DC1}: NameServer = 85.255.116.149,85.255.112.60 |
Questionable |
Do you recognize these IP addresses '85.255.116.149,85.255.112.60' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{F32BADEE-6407-4D41-B3B2-AC97E6939A5B}: NameServer = 85.255.116.149,85.255.112.60 |
Questionable |
Do you recognize these IP addresses '85.255.116.149,85.255.112.60' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{FDB3C652-2498-4386-AE22-98A58815F792}: NameServer = 85.255.116.149,85.255.112.60 |
Questionable |
Do you recognize these IP addresses '85.255.116.149,85.255.112.60' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "livecall" and file "C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll". |
Change status
|
| O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "msnim" and file "C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll". |
Change status
|
| O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "talkto" and file "C:\PROGRA~1\MSNMES~1\msgrapp.8.0.0812.00.dll". |
Change status
|
| O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll |
Legitimate |
windows check |
Change status
|
| O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
| O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll |
Legitimate |
The file belongs to WMP11 Beta application. |
Change status
|
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com database. Scheduler for AntiVir Anti Virus... |
Change status
|
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com database. AntiVir real-time Protection... |
Change status
|
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe More info about file ccevtmgr.exe |
Legitimate |
Item found in 2-spyware.com database. ccEvtMgr.exe is an event logging application and runs at startup. It monitors virus alerts, virus... |
Change status
|
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe More info about file ccproxy.exe |
Legitimate |
Item found in 2-spyware.com database. File related to Symantec... |
Change status
|
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe More info about file ccpwdsvc.exe |
Legitimate |
Item found in 2-spyware.com database. guess this has to do with teh entry of the password for norton, is it corrupt or what, did someone... |
Change status
|
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe More info about file ccsetmgr.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
| O23 - Service: lxcf_device - - C:\WINDOWS\system32\lxcfcoms.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS More info about file prismxl.sys |
Legitimate |
Item found in 2-spyware.com database. A part of some IT management products and remote administration software made by New Boundary... |
Change status
|
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe More info about file sbserv.exe |
Legitimate |
Item found in 2-spyware.com database. Part of Norton Anti-virus. SBServ.exe is located in "C:\Program Files\Common Files\Symantec... |
Change status
|
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe More info about file sndsrvc.exe |
Legitimate |
Item found in 2-spyware.com database. This is a part of Norton Internet Security and Norton Personal Firewall applications. It runs... |
Change status
|
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe More info about file spbbcsvc.exe |
Legitimate |
Item found in 2-spyware.com database. Essential component of Symantec's Norton Internet Security... |
Change status
|
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe More info about file wltrysvc.exe |
Legitimate |
Item found in 2-spyware.com database. Installed alongside Broadcom wireless communication software. It is a tool that displays an icon in... |
Change status
|