| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\ewido\security suite\ewidoctrl.exe More info about file ewidoctrl.exe |
Legitimate |
Item found in 2-spyware.com library This is a vital component of ewido security suite, a popular anti-spyware and anti-malware program. |
Change status |
C:\Program Files\ewido\security suite\ewidoguard.exe More info about file ewidoguard.exe |
Legitimate |
Item found in 2-spyware.com library This is a vital component of ewido security suite, which is a popular anti-spyware and anti-malware... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\WINDOWS\System32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com library NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status |
C:\WINDOWS\System32\HPZipm12.exe More info about file hpzipm12.exe |
Legitimate |
Item found in 2-spyware.com library This is a standard component of Hewlett-Packard device drivers. The presence of this file means,... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Documents and Settings\Dale\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html |
Not necessary |
c:\secure32.html is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html |
Not necessary |
c:\secure32.html is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html |
Not necessary |
c:\secure32.html is your local page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html |
Not necessary |
c:\secure32.html is your local page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by CenturyTel |
Not necessary |
Microsoft Internet Explorer provided by CenturyTel is the title in your Internet Explorer window. If you do not like this fact, fix this item. |
Change status |
| R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) |
Not necessary |
Fix this item because it points to a file that cannot be found |
Change status |
| O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx |
Legitimate |
legitimate bho toolbar, related to Adobe Acrobat reader |
Change status
|
| O2 - BHO: (no name) - {41F328E2-5E46-F5B8-0160-020188931F32} - C:\WINDOWS\System32\imtqodk.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup More info about file nvcpl.dll |
Legitimate |
System item according to inner database Related to nVidia cards. NvCpl.dll is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,... |
Change status
|
| O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto More info about file msconfig.exe |
Legitimate |
System item according to inner database Microsoft System Configuration Utility. Located in "C:\Windows\System" on Windows 98/ME and... |
Change status
|
| O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\System32\autosys.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
| O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present |
Questionable |
This item can be set only by administrator or by Spybot software. If you are administrator and you do not know anything about it, then fix this item. |
Change status
|
| O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll |
Legitimate |
This item represents a plugin added to Internet Explorer to work with '.spop' files. Seems to be safe, unless you know that it is malicious. |
Change status
|
| O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll |
Unknown |
No exact entries found |
Change status
|
| O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe More info about file ewidoctrl.exe |
Legitimate |
Item found in 2-spyware.com database. This is a vital component of ewido security suite, a popular anti-spyware and anti-malware... |
Change status
|
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe More info about file ewidoguard.exe |
Legitimate |
Item found in 2-spyware.com database. This is a vital component of ewido security suite, which is a popular anti-spyware and anti-malware... |
Change status
|
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com database. NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status
|
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe More info about file hpzipm12.exe |
Legitimate |
Item found in 2-spyware.com database. This is a standard component of Hewlett-Packard device drivers. The presence of this file means,... |
Change status
|