| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\brsvc01a.exe More info about file brsvc01a.exe |
Legitimate |
Item found in 2-spyware.com library This is an essential component of Brother printer drivers. File brsvc01a.exe.exe is used to control... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\brss01a.exe More info about file brss01a.exe |
Legitimate |
Item found in 2-spyware.com library This is an essential component of Brother printer drivers. File brss01a.exe is used to control a... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\Mixer.exe More info about file mixer.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to change audio settings. |
Change status |
| C:\Program Files\Fitbug Limited\Bug Manager\BugManager.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe More info about file bttray.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Widcomm‘s bluetooth software. |
Change status |
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe More info about file easyshare.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Kodak camera software. |
Change status |
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe More info about file kodak software updater.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Kodak camera software. |
Change status |
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\PocoMail4\Poco.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\MSN Messenger\msnmsgr.exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
C:\Program Files\Trillian\trillian.exe More info about file trillian.exe |
Legitimate |
Item found in 2-spyware.com library Main component of the Trillian instant messenger |
Change status |
| C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\PTC\ProDESKTOP 8.0\Program\ProD.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\notepad.exe More info about file notepad.exe |
Legitimate |
Process found in system process library |
Change status |
C:\DOCUME~1\JANICE~1\LOCALS~1\Temp\Temporary Directory 3 for hijackthis.zip\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/ |
Not necessary |
http://news.bbc.co.uk/ is your start page. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup More info about file mixer.exe |
Legitimate |
System item according to inner database Provides system tray access to change audio settings. |
Change status
|
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
| O4 - HKLM\..\Run: [Bug Manager] C:\Program Files\Fitbug Limited\Bug Manager\BugManager.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [hgqhp.exe] C:\WINDOWS\system32\hgqhp.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
| O4 - Global Startup: BTTray.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe More info about file easyshare.exe |
Legitimate |
Application program item according to inner database The file is related to Kodak camera software. |
Change status
|
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe More info about file kodak software updater.exe |
Legitimate |
Application program item according to inner database The file is related to Kodak camera software. |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE More info about file osa9.exe |
Legitimate |
Application program item according to inner database Loads Microsoft Office components at reboot, to improve the startup time of the Office programs.... |
Change status
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Real.com' and points to file 'C:\WINDOWS\system32\Shdocvw.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O15 - Trusted Zone: *.moove.com |
Questionable |
Do you want URL pattern "*.moove.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O16 - DPF: {131EB16C-BD58-443F-8151-6DFBB0DA1778} (Anark Client 3.0 ActiveX Control) - http://install.anark.com/client/version3/windows-ie/en/AMClient.cab |
Questionable |
Are you using an ActiveX object with a name 'Anark Client 3.0 ActiveX Control' located in 'http://install.anark.com/client/version3/windows-ie/en/AMClient.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 |
Legitimate |
Legitimate ActiveX item from site http://go.microsoft.com/ |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{66F0F21C-2DC9-4F91-A647-F2EAB46046E3}: NameServer = 85.255.113.126,85.255.112.229 |
Questionable |
Do you recognize these IP addresses '85.255.113.126,85.255.112.229' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{71AECD44-D3D0-4560-85AE-F88A5CEE8155}: NameServer = 85.255.113.126,85.255.112.229 |
Questionable |
Do you recognize these IP addresses '85.255.113.126,85.255.112.229' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS1\Services\Tcpip\..\{66F0F21C-2DC9-4F91-A647-F2EAB46046E3}: NameServer = 85.255.113.126,85.255.112.229 |
Questionable |
Do you recognize these IP addresses '85.255.113.126,85.255.112.229' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS2\Services\Tcpip\..\{66F0F21C-2DC9-4F91-A647-F2EAB46046E3}: NameServer = 85.255.113.126,85.255.112.229 |
Questionable |
Do you recognize these IP addresses '85.255.113.126,85.255.112.229' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) |
Not necessary |
It is a protocol hijacker that points to nowhere. Fix this item. |
Change status
|
| O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll |
Legitimate |
windows check |
Change status
|
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe |
Legitimate |
ATI Video Card Control Panel |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe More info about file brsvc01a.exe |
Legitimate |
Item found in 2-spyware.com database. This is an essential component of Brother printer drivers. File brsvc01a.exe.exe is used to control... |
Change status
|
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe More info about file kodakccs.exe |
Legitimate |
Item found in 2-spyware.com database. The file is related to Kodak Camera... |
Change status
|