| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Programmer\Windows Defender\MsMpEng.exe More info about file msmpeng.exe |
Legitimate |
Item found in 2-spyware.com library Related to Windows Defender program. |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Mixer.exe More info about file mixer.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to change audio settings. |
Change status |
C:\Programmer\ahead\InCD\InCD.exe More info about file incd.exe |
Legitimate |
Item found in 2-spyware.com library InCD.exe is part of Nero CD Burning Software.
"Write to CDs and DVDs as if they were... |
Change status |
C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe More info about file ccapp.exe |
Legitimate |
Item found in 2-spyware.com library From Symantec: "ccApp.exe is the common hosting application that is used for both NAV and NIS.... |
Change status |
| C:\Programmer\Windows Defender\MSASCui.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Programmer\MSN Messenger\MsnMsgr.Exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe More info about file aluschedulersvc.exe |
Legitimate |
Item found in 2-spyware.com library Related to Symantec anti-virus software. |
Change status |
C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe More info about file ccsetmgr.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status |
C:\Programmer\Norton AntiVirus\navapsvc.exe More info about file navapsvc.exe |
Legitimate |
Item found in 2-spyware.com library Norton AntiVirus application that provides auto-protection of the system. NAVAPSVC.EXE runs on... |
Change status |
C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE More info about file nprotect.exe |
Legitimate |
Item found in 2-spyware.com library NPROTECT.EXE is part of Norton Antivirus. NPROTECT.EXE is located in "C:\PROGRAM FILES\NORTON... |
Change status |
C:\Programmer\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com library NVIDIA related software. |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status |
C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe More info about file ccevtmgr.exe |
Legitimate |
Item found in 2-spyware.com library ccEvtMgr.exe is an event logging application and runs at startup. It monitors virus alerts, virus... |
Change status |
C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe More info about file symwsc.exe |
Legitimate |
Item found in 2-spyware.com library File symwsc.exe is included in Norton Antivirus program. It runs background process, which... |
Change status |
C:\Programmer\Norton AntiVirus\SAVScan.exe More info about file savscan.exe |
Legitimate |
Item found in 2-spyware.com library This executable file is a standard part of antivirus and security-related software, published by... |
Change status |
C:\Programmer\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Documents and Settings\Ella\Skrivebord\Spyware - removal\hijackthis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| O2 - BHO: Nothing - {8d83b16e-0de1-452b-ac52-96ec0b34aa4b} - C:\WINDOWS\system32\hp6CF2.tmp (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup More info about file mixer.exe |
Legitimate |
System item according to inner database Provides system tray access to change audio settings. |
Change status
|
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
O4 - HKLM\..\Run: [InCD] C:\Programmer\ahead\InCD\InCD.exe More info about file incd.exe |
Legitimate |
Application program item according to inner database InCD.exe is part of Nero CD Burning Software.
<i>"Write to CDs and DVDs as if they were... |
Change status
|
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize More info about file rundll32.exe |
Legitimate |
System item according to inner database Rundll32.exe loads and runs 32-bit DLLs. Rundll32.exe comes with all versions of Microsoft Windows.... |
Change status
|
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install More info about file nwiz.exe |
Legitimate |
System item according to inner database Nwiz.exe is Related to nVidia graphic cards drivers.
Long name - NVIDIA nView Wizard.<br... |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmer\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [ccApp] "C:\Programmer\Fælles filer\Symantec Shared\ccApp.exe" More info about file ccapp.exe |
Legitimate |
System item according to inner database From Symantec: <i>"ccApp.exe is the common hosting application that is used for both NAV and NIS.... |
Change status
|
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Programmer\Fælles filer\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT" More info about file cfgwiz.exe |
Legitimate |
System item according to inner database Related to Norton Anti Virus. CfgWiz.exe is located in "C:\Program Files\Common Files\Symantec... |
Change status
|
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE More info about file advchk.exe |
Legitimate |
Application program item according to inner database Warns you when you install a new version of a Norton product and did not uninstall all previous... |
Change status
|
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer More info about file sndmon.exe |
Legitimate |
Application program item according to inner database This is the main part of LiveUpdate tool, published by Symantec. It is required to update all... |
Change status
|
| O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k |
Questionable |
questionable item according to our database |
Change status
|
| O4 - HKLM\..\Run: [Windows Defender] "C:\Programmer\Windows Defender\MSASCui.exe" -hide |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmer\MSN Messenger\MsnMsgr.Exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE More info about file osa.exe |
Legitimate |
Application program item according to inner database The Office Startup Assistant (Osa.exe or OSA) is a program that improves the performance of Office... |
Change status
|
| O8 - Extra context menu item: Backward Links - res://c:\programmer\google\GoogleToolbar2.dll/cmbacklinks.html |
Not necessary |
Do you want item 'Backward Links' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programmer\google\GoogleToolbar2.dll/cmcache.html |
Not necessary |
Do you want item 'Cached Snapshot of Page' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Similar Pages - res://c:\programmer\google\GoogleToolbar2.dll/cmsimilar.html |
Not necessary |
Do you want item 'Similar Pages' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Translate Page into English - res://c:\programmer\google\GoogleToolbar2.dll/cmtrans.html |
Not necessary |
Do you want item 'Translate Page into English' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: Expekt.com Poker - {3852AC86-965F-4abe-A75F-3DCB7E81A4B2} - C:\Programmer\expektMPP\MPPoker.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Expekt.com Poker' and points to file 'C:\Programmer\expektMPP\MPPoker.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Programmer\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Programmer\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'Checkers Class' located in 'http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab |
Questionable |
Are you using an ActiveX object with a name 'SupportSoft SmartIssue' located in 'http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab |
Questionable |
Are you using an ActiveX object with a name 'SupportSoft Script Runner Class' located in 'http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://downol.dr.dk/download/netradio/Rawflow.cab |
Questionable |
Are you using an ActiveX object with a name 'Rawflow ICD Client' located in 'http://downol.dr.dk/download/netradio/Rawflow.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 |
Questionable |
Are you using an ActiveX object with a name 'Windows Genuine Advantage Validation Tool' located in 'http://go.microsoft.com/fwlink/?linkid=39204'? If not, fix this item. |
Change status
|
| O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab |
Questionable |
Are you using an ActiveX object with a name 'LSSupCtl Class' located in 'http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab |
Questionable |
Are you using an ActiveX object with a name 'Symantec RuFSI Utility Class' located in 'http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'MessengerStatsClient Class' located in 'http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab |
Questionable |
Are you using an ActiveX object with a name 'MsnMessengerSetupDownloadControl Class' located in 'http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab |
Questionable |
Are you using an ActiveX object with a name 'ActiveDataInfo Class' located in 'http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab'? If not, fix this item. |
Change status
|
| O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll |
Unknown |
No exact entries found |
Change status
|
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Programmer\Symantec\LiveUpdate\ALUSchedulerSvc.exe More info about file aluschedulersvc.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Symantec anti-virus... |
Change status
|
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccEvtMgr.exe More info about file ccevtmgr.exe |
Legitimate |
Item found in 2-spyware.com database. ccEvtMgr.exe is an event logging application and runs at startup. It monitors virus alerts, virus... |
Change status
|
| O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccPwdSvc.exe |
Legitimate |
Related to Norton/Symantec AntiVirus. |
Change status
|
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\ccSetMgr.exe More info about file ccsetmgr.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|
| O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe More info about file navapsvc.exe |
Legitimate |
Item found in 2-spyware.com database. Norton AntiVirus application that provides auto-protection of the system. NAVAPSVC.EXE runs on... |
Change status
|
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programmer\Norton AntiVirus\AdvTools\NPROTECT.EXE More info about file nprotect.exe |
Legitimate |
Item found in 2-spyware.com database. NPROTECT.EXE is part of Norton Antivirus. NPROTECT.EXE is located in "C:\PROGRAM FILES\NORTON... |
Change status
|
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com database. NVIDIA related... |
Change status
|
O23 - Service: SAVScan - Symantec Corporation - C:\Programmer\Norton AntiVirus\SAVScan.exe More info about file savscan.exe |
Legitimate |
Item found in 2-spyware.com database. This executable file is a standard part of antivirus and security-related software, published by... |
Change status
|
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe More info about file sbserv.exe |
Legitimate |
Item found in 2-spyware.com database. Part of Norton Anti-virus. SBServ.exe is located in "C:\Program Files\Common Files\Symantec... |
Change status
|
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe More info about file sndsrvc.exe |
Legitimate |
Item found in 2-spyware.com database. This is a part of Norton Internet Security and Norton Personal Firewall applications. It runs... |
Change status
|
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\Security Center\SymWSC.exe More info about file symwsc.exe |
Legitimate |
Item found in 2-spyware.com database. File symwsc.exe is included in Norton Antivirus program. It runs background process, which... |
Change status
|