| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com library Scheduler for AntiVir Anti Virus program. |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\igfxtray.exe More info about file igfxtray.exe |
Legitimate |
Item found in 2-spyware.com library From a user: I just(hours ago) installed some newer Intel graphics drivers in my system(82810E),... |
Change status |
C:\WINDOWS\system32\hkcmd.exe More info about file hkcmd.exe |
Legitimate |
Item found in 2-spyware.com library hkcmd.exe is a system process related to the Hotkey Command Module for Intel Graphics Contollers.... |
Change status |
C:\WINDOWS\system32\igfxpers.exe More info about file igfxpers.exe |
Legitimate |
Item found in 2-spyware.com library Related to the integrated intel graphics adapter driver. |
Change status |
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe More info about file avgnt.exe |
Legitimate |
Item found in 2-spyware.com library avgnt.exe is a security process that is associated with the Avira Internet Security Suite, which... |
Change status |
C:\WINDOWS\RTHDCPL.EXE More info about file rthdcpl.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Realtek HD Audio software. |
Change status |
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe More info about file launchapplication.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Nokia PC Suite. |
Change status |
| C:\Documents and Settings\seasoft\Desktop\UniKey4.0\UniKey.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe More info about file yahoomessenger.exe |
Legitimate |
Item found in 2-spyware.com library An executable file of Yahoo! Messenger. |
Change status |
C:\Program Files\Free Download Manager\fdm.exe More info about file fdm.exe |
Legitimate |
Item found in 2-spyware.com library fdm.exe is the main component of Free Download Manager. It is not an essential system process and... |
Change status |
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com library avguard.exe stands for AntiVir real-time protection process. Do not terminate it. |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe More info about file ulcdrsvr.exe |
Legitimate |
Item found in 2-spyware.com library Legitimate file ulcdrsvr.exe is an essential component of Ulead DVD Workshop video editing... |
Change status |
| C:\WINDOWS\system32\UTSCSI.EXE |
Unknown |
No exact entries found |
Insert file into database
|
| C:\WINDOWS\system32\CAP2RSK.EXE |
Unknown |
No exact entries found |
Insert file into database
|
| C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP2SWK.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe More info about file servicelayer.exe |
Legitimate |
Item found in 2-spyware.com library servicelayer.exe is part of the Nokia Connectivity Library. It is required by the Nokia Connection... |
Change status |
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com |
Legitimate |
http://www.yahoo.com is your start page. This is a legitimate page. |
Change status |
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll More info about file yiesrvc.dll |
Legitimate |
Application program item according to inner database The file is related to Yahoo! software. |
Change status
|
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll More info about file iefdm2.dll |
Legitimate |
Application program item according to inner database The process belongs to the software Free Download Manager. |
Change status
|
O3 - Toolbar: Yahoo! Barre d''outils - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe More info about file igfxtray.exe |
Legitimate |
System item according to inner database From a user: I just(hours ago) installed some newer Intel graphics drivers in my system(82810E),... |
Change status
|
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe More info about file hkcmd.exe |
Legitimate |
System item according to inner database hkcmd.exe is a system process related to the Hotkey Command Module for Intel Graphics Contollers.... |
Change status
|
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe More info about file igfxpers.exe |
Legitimate |
Application program item according to inner database Related to the integrated intel graphics adapter driver. |
Change status
|
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE More info about file skytel.exe |
Legitimate |
Application program item according to inner database skytel.exe stands for the Realtek Voice Manager, which is part of Realtek devices. |
Change status
|
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 More info about file imjpmig.exe |
Legitimate |
System item according to inner database Related to Windows East Asian language support (Japanese keyboard entry). Located in... |
Change status
|
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC More info about file imscinst.exe |
Legitimate |
Application program item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\PINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min More info about file avgnt.exe |
Legitimate |
Application program item according to inner database avgnt.exe is a security process that is associated with the Avira Internet Security Suite, which... |
Change status
|
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE More info about file rthdcpl.exe |
Legitimate |
Application program item according to inner database The file is related to Realtek HD Audio software. |
Change status
|
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE More info about file alcmtr.exe |
Legitimate |
Runs a tool related to RealTek sound card drivers on Windows startup. |
Change status
|
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup More info about file launchapplication.exe |
Legitimate |
Application program item according to inner database The file belongs to Nokia PC Suite. |
Change status
|
| O4 - HKCU\..\Run: [UniKey] C:\Documents and Settings\seasoft\Desktop\UniKey4.0\UniKey.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet More info about file yahoomessenger.exe |
Legitimate |
Application program item according to inner database An executable file of Yahoo! Messenger. |
Change status
|
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun More info about file fdm.exe |
Legitimate |
Application program item according to inner database fdm.exe is the main component of Free Download Manager. It is not an essential system process and... |
Change status
|
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
| O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User ''SYSTEM'') |
Questionable |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
| O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User ''Default user'') |
Questionable |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
| O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll |
Legitimate |
Legitimate extra button in your browser - related to Yahoo! Services. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com database. Scheduler for AntiVir Anti Virus... |
Change status
|
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com database. avguard.exe stands for AntiVir real-time protection process. Do not terminate it.... |
Change status
|
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe More info about file servicelayer.exe |
Legitimate |
Item found in 2-spyware.com database. servicelayer.exe is part of the Nokia Connectivity Library. It is required by the Nokia Connection... |
Change status
|
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe More info about file ulcdrsvr.exe |
Legitimate |
Item found in 2-spyware.com database. Legitimate file ulcdrsvr.exe is an essential component of Ulead DVD Workshop video editing... |
Change status
|
| O23 - Service: USBest Service Zero (UTSCSI) - USBest - C:\WINDOWS\system32\UTSCSI.EXE |
Unknown |
No exact entries found |
Insert file into database
|