| Line: |
Status: |
Comments: |
Actions: |
D:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\system32\services.exe More info about file services.exe |
Questionable |
This item can be legitimate or spyware related, depending on its location and other factors. Make some further research on it. |
Change status |
D:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com library This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status |
D:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\system32\LEXPPS.EXE More info about file lexpps.exe |
Legitimate |
Item found in 2-spyware.com library This file is related to Lexmark Printer Port Scanner utility, it is a standard component of the... |
Change status |
D:\WINDOWS\System32\CTsvcCDA.exe More info about file ctsvccda.exe |
Legitimate |
Item found in 2-spyware.com library Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some... |
Change status |
D:\Program Files\ewido anti-malware\ewidoctrl.exe More info about file ewidoctrl.exe |
Legitimate |
Item found in 2-spyware.com library This is a vital component of ewido security suite, a popular anti-spyware and anti-malware program. |
Change status |
D:\WINDOWS\System32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com library NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status |
D:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
| D:\WINDOWS\System32\PnkBstrA.exe |
Unknown |
No exact entries found |
Insert file into database
|
| D:\WINDOWS\System32\PnkBstrB.exe |
Unknown |
No exact entries found |
Insert file into database
|
| D:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe More info about file smagent.exe |
Legitimate |
Item found in 2-spyware.com library SoundMAX Agent. Related to drivers for various sound cards and similar devices. |
Change status |
D:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
D:\WINDOWS\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com library Related to the ZoneAlarm firewall from ZoneLabs. Located in "C:\WINDOWS\SYSTEM\ZONELABS\". |
Change status |
| D:\Program Files\Pure Networks\Network Magic\nmsrvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe More info about file smax4pnp.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to SoundMax software. |
Change status |
| D:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe More info about file wkufind.exe |
Legitimate |
Item found in 2-spyware.com library Wkufind is a standard component of PictureIt! application, which is included in Microsoft Works... |
Change status |
| D:\Program Files\IMT Labs Messenger Plugin\Cloud.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe More info about file pdvdserv.exe |
Legitimate |
Item found in 2-spyware.com library Related to some DVD playing programs like CyberLink PowerDVD. Provides support for the DVD drive's... |
Change status |
D:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe More info about file datalayer.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Nokia PC Suite. |
Change status |
D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe More info about file launchapplication.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Nokia PC Suite. |
Change status |
| D:\PROGRA~1\Sony\SONICS~1\SsAAD.exe |
Unknown |
No exact entries found |
Insert file into database
|
| D:\Program Files\Athan\Athan.exe |
Unknown |
No exact entries found |
Insert file into database
|
| D:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
| D:\Program Files\Lexmark 2200 Series\lxbvbmon.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\WINDOWS\System32\RUNDLL32.EXE More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe More info about file zlclient.exe |
Legitimate |
Item found in 2-spyware.com library ZoneAlarm Firewall http://www.zonelabs.com |
Change status |
D:\Program Files\MSN Messenger\msnmsgr.exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe More info about file ctdetect.exe |
Legitimate |
Item found in 2-spyware.com library
|
Change status |
D:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe More info about file ssscsisv.exe |
Legitimate |
Item found in 2-spyware.com library SonicStage SCSI Service (SSScsiSV) - Sony Corporation |
Change status |
| D:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE |
Unknown |
No exact entries found |
Insert file into database
|
D:\WINDOWS\System32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
| D:\Program Files\MSN Messenger\usnsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
D:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
D:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
D:\Program Files\Mozilla Firefox\firefox.exe More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
D:\Documents and Settings\Ours\Desktop\Salman\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank |
Not necessary |
about:blank is your start page. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll More info about file ssv.dll |
Legitimate |
System item according to inner database Related to Java Virtual Machine software, which is legitimate. |
Change status
|
| O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - d:\program files\google\googletoolbar4.dll |
Legitimate |
legitimate bho toolbar, related to Google Toolbar |
Change status
|
| O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar4.dll |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SoundMAXPnP] D:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe More info about file smax4pnp.exe |
Legitimate |
Application program item according to inner database The file is related to SoundMax software. |
Change status
|
| O4 - HKLM\..\Run: [Lexmark 2200 Series] "D:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe" |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [FaxCenterServer] "D:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Microsoft Works Update Detection] D:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe More info about file wkufind.exe |
Legitimate |
Application program item according to inner database Wkufind is a standard component of PictureIt! application, which is included in Microsoft Works... |
Change status
|
| O4 - HKLM\..\Run: [CloudPlugin] "D:\Program Files\IMT Labs Messenger Plugin\Cloud.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [RemoteControl] "D:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" More info about file pdvdserv.exe |
Legitimate |
Application program item according to inner database Related to some DVD playing programs like CyberLink PowerDVD. Provides support for the DVD drive's... |
Change status
|
O4 - HKLM\..\Run: [DataLayer] D:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe More info about file datalayer.exe |
Legitimate |
Application program item according to inner database The file belongs to Nokia PC Suite. |
Change status
|
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray More info about file launchapplication.exe |
Legitimate |
Application program item according to inner database The file belongs to Nokia PC Suite. |
Change status
|
| O4 - HKLM\..\Run: [SsAAD.exe] D:\PROGRA~1\Sony\SONICS~1\SsAAD.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Athan] D:\Program Files\Athan\Athan.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [SBCSTray] D:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\System32\NvCpl.dll,NvStartup More info about file nvcpl.dll |
Legitimate |
System item according to inner database Related to nVidia cards. NvCpl.dll is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,... |
Change status
|
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install More info about file nwiz.exe |
Legitimate |
System item according to inner database Nwiz.exe is Related to nVidia graphic cards drivers. Full name - NVIDIA nView Wizard.<br... |
Change status
|
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit More info about file nvmctray.dll |
Legitimate |
System item according to inner database nVidia graphics cards related. NVMCTRAY.DLL is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,... |
Change status
|
| O4 - HKLM\..\Run: [nmapp] "D:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" More info about file zlclient.exe |
Legitimate |
System item according to inner database ZoneAlarm Firewall http://www.zonelabs.com |
Change status
|
| O4 - HKLM\..\RunOnce: [symPCCheckup] "D:\WINDOWS\System32\Adobe\Shockwave 11\symcheckupstub.exe" /task /reboot |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - HKCU\..\Run: [Creative Detector] "D:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R More info about file ctdetect.exe |
Legitimate |
System item according to inner database
|
Change status
|
| O4 - HKCU\..\Run: [system34] D:\WINDOWS\SoftwareProtection\Windows External Security Update.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE More info about file osa9.exe |
Legitimate |
Application program item according to inner database Loads Microsoft Office components at reboot, to improve the startup time of the Office programs.... |
Change status
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - D:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing) |
Not necessary |
Fix this item because it points to a file that cannot be found |
Change status
|
| O9 - Extra ''Tools'' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - D:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing) |
Not necessary |
Fix this item because it points to a file that cannot be found |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'D:\Program Files\Messenger\MSMSGS.EXE'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\MSMSGS.EXE |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Messenger' and points to file 'D:\Program Files\Messenger\MSMSGS.EXE'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab |
Questionable |
Are you using an ActiveX object with a name 'Facebook Photo Uploader 5 Control' located in 'http://upload.facebook.com/controls/2008.10 .10_v5.5.8/FacebookPhotoUploader5.cab'? If not, fix this item. |
Change status
|
| O23 - Service: Adobe LM Service - Unknown owner - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe |
Legitimate |
Required for PhotoshopCS |
Change status
|
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - D:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: ATI Smart - Unknown owner - D:\WINDOWS\system32\ati2sgag.exe |
Legitimate |
ATI Video Card Control Panel |
Change status
|
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - D:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe More info about file adskscsrv.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate file related to Autodesk licensing... |
Change status
|
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\System32\CTsvcCDA.exe More info about file ctsvccda.exe |
Legitimate |
Item found in 2-spyware.com database. Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some... |
Change status
|
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido anti-malware\ewidoctrl.exe More info about file ewidoctrl.exe |
Legitimate |
Item found in 2-spyware.com database. This is a vital component of ewido security suite, a popular anti-spyware and anti-malware... |
Change status
|
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe More info about file googleupdaterservice.exe |
Legitimate |
Item found in 2-spyware.com database. Service for Google... |
Change status
|
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - D:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com database. This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status
|
O23 - Service: MSCSPTISRV - Sony Corporation - D:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe More info about file mscsptisrv.exe |
Legitimate |
Item found in 2-spyware.com database. Sony Sonicstage mpe... |
Change status
|
| O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - D:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Pure Networks Network Magic Service (nmservice) - Pure Networks, Inc. - D:\Program Files\Pure Networks\Network Magic\nmsrvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\System32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com database. NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status
|
| O23 - Service: PACSPTISVR - Sony Corporation - D:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe |
Legitimate |
Sony computers
|
Change status
|
| O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\System32\PnkBstrA.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: PnkBstrB - Unknown owner - D:\WINDOWS\System32\PnkBstrB.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - D:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe More info about file smagent.exe |
Legitimate |
Item found in 2-spyware.com database. SoundMAX Agent. Related to drivers for various sound cards and similar... |
Change status
|
| O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - D:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe |
Legitimate |
Sony computers |
Change status
|
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - D:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe More info about file ssscsisv.exe |
Legitimate |
Item found in 2-spyware.com database. SonicStage SCSI Service (SSScsiSV) - Sony Corporation... |
Change status
|
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com database. Related to the ZoneAlarm firewall from ZoneLabs. Located in... |
Change status
|