| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Windows Defender\MsMpEng.exe More info about file msmpeng.exe |
Legitimate |
Item found in 2-spyware.com library Related to Windows Defender program. |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe More info about file wkufind.exe |
Legitimate |
Item found in 2-spyware.com library Wkufind is a standard component of PictureIt! application, which is included in Microsoft Works... |
Change status |
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
| C:\Program Files\Windows Defender\MSASCui.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe More info about file spysweeper.exe |
Legitimate |
Item found in 2-spyware.com library An executable file of SpySweeper anti-spyware program. |
Change status |
| C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Xfire\Xfire.exe More info about file xfire.exe |
Legitimate |
Item found in 2-spyware.com library xfire [ http://www.xfire.com ] gamer instant messenger |
Change status |
C:\WINDOWS\system32\cisvc.exe More info about file cisvc.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\tcpsvcs.exe More info about file tcpsvcs.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft TCP/IP Services, represented by tcpsvcs.exe file, are included in Windows NT 4/2000/XP... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe More info about file wrsssdk.exe |
Legitimate |
Item found in 2-spyware.com library Related to Spy Sweeper anti-spyware program. |
Change status |
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\WINDOWS\system32\cidaemon.exe More info about file cidaemon.exe |
Legitimate |
Item found in 2-spyware.com library This file is related to Microsoft Indexing Service - it is a complex system utility, which indexes... |
Change status |
C:\WINDOWS\system32\cidaemon.exe More info about file cidaemon.exe |
Legitimate |
Item found in 2-spyware.com library This file is related to Microsoft Indexing Service - it is a complex system utility, which indexes... |
Change status |
| C:\PROGRA~1\iolo\SYSTEM~1\SysMech6.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\WinRAR\WinRAR.exe More info about file winrar.exe |
Questionable |
Item found in 2-spyware.com library winrar.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
C:\DOCUME~1\JAYFRE~1\LOCALS~1\Temp\Rar$EX00.969\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
C:\DOCUME~1\JAYFRE~1\LOCALS~1\Temp\Rar$EX00.813\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb /ymsgr6/*http://www.yahoo.com/ext/search/search.html |
Not necessary |
http://red.clientapps.yahoo.com/customize/ie/defaults/sb /ymsgr6/*http://www.yahoo.com/ext/search/search.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie /defaults/sp/ymsgr6/*http://www.yahoo.com |
Not necessary |
http://red.clientapps.yahoo.com/customize/ie /defaults/sp/ymsgr6/*http://www.yahoo.com is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com |
Legitimate |
http://www.yahoo.com is your start page. This is a legitimate page. |
Change status |
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie /defaults/su/ymsgr6/*http://www.yahoo.com |
Not necessary |
http://red.clientapps.yahoo.com/customize/ie /defaults/su/ymsgr6/*http://www.yahoo.com is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb /ymsgr6/*http://www.yahoo.com/ext/search/search.html |
Not necessary |
http://red.clientapps.yahoo.com/customize/ie/defaults/sb /ymsgr6/*http://www.yahoo.com/ext/search/search.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie /defaults/sp/ymsgr6/*http://www.yahoo.com |
Not necessary |
http://red.clientapps.yahoo.com/customize/ie /defaults/sp/ymsgr6/*http://www.yahoo.com is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com |
Legitimate |
http://www.yahoo.com is your start page. This is a legitimate page. |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie /defaults/su/ymsgr6/*http://www.yahoo.com |
Not necessary |
http://red.clientapps.yahoo.com/customize/ie /defaults/su/ymsgr6/*http://www.yahoo.com is your default SearchURL. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R3 - Default URLSearchHook is missing |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx |
Legitimate |
legitimate bho toolbar, related to Adobe Acrobat reader |
Change status
|
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Legitimate |
legitimate bho toolbar, related to SpyBot Search&Destroy |
Change status
|
| O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll |
Legitimate |
legitimate bho toolbar, related to SBC Yahoo! Browser related |
Change status
|
| O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll |
Legitimate |
legitimate bho toolbar, related to SBC Yahoo! Browser related |
Change status
|
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll More info about file googletoolbar2.dll |
Legitimate |
Application program item according to inner database Google Toolbar for Internet Explorer. |
Change status
|
| O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll |
Legitimate |
legitimate bho toolbar, related to Microsoft Money |
Change status
|
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe More info about file wkufind.exe |
Legitimate |
Application program item according to inner database Wkufind is a standard component of PictureIt! application, which is included in Microsoft Works... |
Change status
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe More info about file zlclient.exe |
Legitimate |
System item according to inner database ZoneAlarm Firewall http://www.zonelabs.com |
Change status
|
| O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray More info about file spysweeper.exe |
Legitimate |
Application program item according to inner database An executable file of SpySweeper anti-spyware program. |
Change status
|
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot More info about file realplay.exe |
Legitimate |
Application program item according to inner database File realplay.exe, which starts a process with the same name, is the main executive component of... |
Change status
|
| O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic Professional 6\SMSystemAnalyzer.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe More info about file xfire.exe |
Legitimate |
Application program item according to inner database xfire [ http://www.xfire.com ] gamer instant messenger |
Change status
|
| O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html |
Not necessary |
Do you want item 'Backward Links' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html |
Not necessary |
Do you want item 'Cached Snapshot of Page' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html |
Not necessary |
Do you want item 'Similar Pages' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html |
Not necessary |
Do you want item 'Translate into English' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Yahoo! Services' and points to file 'C:\Program Files\Yahoo!\Common\yiesrvc.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Real.com' and points to file 'C:\WINDOWS\System32\Shdocvw.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'MoneySide' and points to file 'C:\Program Files\Microsoft Money\System\mnyviewer.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O12 - Plugin for .UVR: C:\Program Files\Internet Explorer\Plugins\NPUPano.dll |
Legitimate |
This item represents a plugin added to Internet Explorer to work with '.UVR' files. Seems to be safe, unless you know that it is malicious. |
Change status
|
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409 |
Questionable |
Are you using an ActiveX object with a name 'Windows Genuine Advantage Validation Tool' located in 'http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409'? If not, fix this item. |
Change status
|
| O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab |
Questionable |
Are you using an ActiveX object with a name 'FilePlanet Download Control Class' located in 'http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {640B39C1-D713-464F-92C3-75BD972B95EE} - http://download.sidestep.com/get/k00719/sb028.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://download.sidestep.com/get/k00719/sb028.cab'? If not, fix this item. |
Change status
|
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1144930452843 |
Questionable |
Are you using an ActiveX object with a name 'MUWebControl Class' located in 'http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1144930452843'? If not, fix this item. |
Change status
|
| O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab |
Questionable |
Are you using an ActiveX object with a name 'GSDACtl Class' located in 'http://launch.gamespyarcade.com/software/launch/alaunch.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) - http://webcamnow.com/broadcast/ActiveXWebCam.cab |
Questionable |
Are you using an ActiveX object with a name 'WebCam Control' located in 'http://webcamnow.com/broadcast/ActiveXWebCam.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll |
Questionable |
Are you using an ActiveX object with a name 'YahooYMailTo Class' located in 'http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yse/ymmapi_416.dll'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{651013F1-8A71-4935-B3CB-6830BD5B5F53}: NameServer = 85.255.114.53,85.255.112.16 |
Questionable |
Do you recognize these IP addresses '85.255.114.53,85.255.112.16' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{65D32D75-5C88-4931-8467-7BBCCAE7C1DC}: NameServer = 85.255.114.53,85.255.112.16 |
Questionable |
Do you recognize these IP addresses '85.255.114.53,85.255.112.16' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll |
Legitimate |
Related to SpySweeper v 4.5 by Webroot |
Change status
|
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe |
Legitimate |
ATI Video Card Control Panel |
Change status
|
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe More info about file isafe.exe |
Legitimate |
Item found in 2-spyware.com database. This file is related to eTrust Antivirus. This program protects your computer from various viruses,... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe More info about file nmssvc.exe |
Legitimate |
Item found in 2-spyware.com database. This is a part of Intel network card drivers. It enables support for SNMP network protocol, which... |
Change status
|
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe More info about file wrsssdk.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Spy Sweeper anti-spyware... |
Change status
|
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com database. Related to the ZoneAlarm firewall from ZoneLabs. Located in... |
Change status
|