| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe More info about file mmtask.exe |
Legitimate |
Item found in 2-spyware.com library Part of the Music Match Jukebox. Located in "C:\Program Files\MusicMatch\MusicMatch Jukebox\". A... |
Change status |
C:\Program Files\QuickTime\qttask.exe More info about file qttask.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status |
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe More info about file wkufind.exe |
Legitimate |
Item found in 2-spyware.com library Wkufind is a standard component of PictureIt! application, which is included in Microsoft Works... |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\WINDOWS\system32\RUNDLL32.EXE More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Spyware Doctor\swdoctor.exe More info about file swdoctor.exe |
Legitimate |
Item found in 2-spyware.com library Main component of Spyware Doctor, a popular anti-spyware program. |
Change status |
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe More info about file acsd.exe |
Legitimate |
Item found in 2-spyware.com library File acsd.exe is an essential component of AOL 9.0 software, which is used to connect your computer... |
Change status |
C:\Program Files\Spyware Doctor\sdhelp.exe More info about file sdhelp.exe |
Legitimate |
Item found in 2-spyware.com library A part of Spyware Doctor, a popular legitimate anti-spyware program. |
Change status |
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status |
C:\WINDOWS\wanmpsvc.exe More info about file wanmpsvc.exe |
Legitimate |
Item found in 2-spyware.com library File wanmpsvc.exe is a standard component of AOL 7.0 software and its later versions. It runs... |
Change status |
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe More info about file symwsc.exe |
Legitimate |
Item found in 2-spyware.com library File symwsc.exe is included in Norton Antivirus program. It runs background process, which... |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\Documents and Settings\Sarah Bell\Desktop\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ |
Not necessary |
http://www.yahoo.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome |
Not necessary |
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch |
Not necessary |
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch |
Not necessary |
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome |
Not necessary |
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/en-us/srchasst/srchasst.htm |
Not necessary |
http://ie.search.msn.com/en-us/srchasst/srchasst.htm is your search assistant. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = |
Not necessary |
This is your folder of IE toolbar links, but it points to nowhere. If you do not like this fact, fix this item. |
Change status |
| O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll |
Legitimate |
legitimate bho toolbar, related to PCTools Spyware Doctor |
Change status
|
| O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll |
Legitimate |
legitimate bho toolbar, related to PCTools Spyware Doctor |
Change status
|
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
System item according to inner database ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status
|
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe More info about file urllstck.exe |
Legitimate |
Application program item according to inner database Norton Internet Security related. Located in "C:\Program Files\Norton Internet Security... |
Change status
|
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r More info about file sgtray.exe |
Legitimate |
Application program item according to inner database Part of the Veritas Storage Guard. Located in "C:\Program Files\VERITAS Software\Update Manager\". |
Change status
|
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe More info about file tfswctrl.exe |
Legitimate |
System item according to inner database tfswctrl.exe fullname DLA Packet Writing Software
tfswctrl.exe Related to CD burning... |
Change status
|
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe More info about file mmtask.exe |
Legitimate |
Application program item according to inner database Part of the Music Match Jukebox. Located in "C:\Program Files\MusicMatch\MusicMatch Jukebox\". A... |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe More info about file wkufind.exe |
Legitimate |
Application program item according to inner database Wkufind is a standard component of PictureIt! application, which is included in Microsoft Works... |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe More info about file sndmon.exe |
Legitimate |
Application program item according to inner database This is the main part of LiveUpdate tool, published by Symantec. It is required to update all... |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [w0eae647.dll] RUNDLL32.EXE w0eae647.dll,I2 0009075600eae647 More info about file rundll32.exe |
Legitimate |
System item according to inner database Rundll32.exe loads and runs 32-bit DLLs. Rundll32.exe comes with all versions of Microsoft Windows.... |
Change status
|
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe More info about file sndmon.exe |
Legitimate |
Application program item according to inner database This is the main part of LiveUpdate tool, published by Symantec. It is required to update all... |
Change status
|
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q More info about file swdoctor.exe |
Legitimate |
Application program item according to inner database Main component of Spyware Doctor, a popular anti-spyware program. |
Change status
|
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe More info about file adobe gamma loader.exe |
Legitimate |
Application program item according to inner database From adobe: "The Adobe Gamma Control Panel is used to eliminate color casts in a monitor's display.... |
Change status
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
A part of Adobe Acrobat Reader. Used to speed up the program's launch time. |
Change status
|
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe More info about file aoltray.exe |
Legitimate |
Application program item according to inner database Related to AOL Internet software. |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE More info about file osa.exe |
Legitimate |
Application program item according to inner database The Office Startup Assistant (Osa.exe or OSA) is a program that improves the performance of Office... |
Change status
|
| O4 - Global Startup: wupdmgr.exe |
Questionable |
Global Startup - link: 'wupdmgr.exe', file: '' |
Change status
|
| O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Spyware Doctor' and points to file 'C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe |
Legitimate |
Required for PhotoshopCS |
Change status
|
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe More info about file acsd.exe |
Legitimate |
Item found in 2-spyware.com database. File acsd.exe is an essential component of AOL 9.0 software, which is used to connect your computer... |
Change status
|
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe More info about file ccevtmgr.exe |
Legitimate |
Item found in 2-spyware.com database. ccEvtMgr.exe is an event logging application and runs at startup. It monitors virus alerts, virus... |
Change status
|
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe More info about file ccproxy.exe |
Legitimate |
Item found in 2-spyware.com database. File related to Symantec... |
Change status
|
| O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe |
Legitimate |
Related to Norton/Symantec AntiVirus. |
Change status
|
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe More info about file ccsetmgr.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe More info about file savscan.exe |
Legitimate |
Item found in 2-spyware.com database. This executable file is a standard part of antivirus and security-related software, published by... |
Change status
|
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe More info about file sdhelp.exe |
Legitimate |
Item found in 2-spyware.com database. A part of Spyware Doctor, a popular legitimate anti-spyware... |
Change status
|
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe More info about file sndsrvc.exe |
Legitimate |
Item found in 2-spyware.com database. This is a part of Norton Internet Security and Norton Personal Firewall applications. It runs... |
Change status
|
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe More info about file symwsc.exe |
Legitimate |
Item found in 2-spyware.com database. File symwsc.exe is included in Norton Antivirus program. It runs background process, which... |
Change status
|
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe More info about file wanmpsvc.exe |
Legitimate |
Item found in 2-spyware.com database. File wanmpsvc.exe is a standard component of AOL 7.0 software and its later versions. It runs... |
Change status
|