| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
D:\Ahead\InCD\InCDsrv.exe More info about file incdsrv.exe |
Legitimate |
Item found in 2-spyware.com library Ahead Nero InCD Service. Allows to format writeable CDs and DVDs and use them as regular hard... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\system32\cisvc.exe More info about file cisvc.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe More info about file mdm.exe |
Legitimate |
Item found in 2-spyware.com library mdm.exe is a system process - Machine Debug Manager. Used by developers. Located in "C:\PROGRAM... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe More info about file ulcdrsvr.exe |
Legitimate |
Item found in 2-spyware.com library Legitimate file ulcdrsvr.exe is an essential component of Ulead DVD Workshop video editing... |
Change status |
C:\WINDOWS\system32\cidaemon.exe More info about file cidaemon.exe |
Legitimate |
Item found in 2-spyware.com library This file is related to Microsoft Indexing Service - it is a complex system utility, which indexes... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
Item found in 2-spyware.com library ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
| D:\Program Files\WinFast\WFTVFM\WFWIZ.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe More info about file hpgs2wnd.exe |
Legitimate |
Item found in 2-spyware.com library Hewlett Packard Share-to-Web utility built into thier products. |
Change status |
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Item found in 2-spyware.com library File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status |
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe More info about file hpgs2wnf.exe |
Legitimate |
Item found in 2-spyware.com library Related to software from HP. Located in "C:\Program Files\Hewlett-Packard\HP Share-to-Web\". |
Change status |
C:\Program Files\Yahoo!\Messenger\YPager.exe More info about file ypager.exe |
Legitimate |
Item found in 2-spyware.com library Related to Yahoo Messenger. Located in "C:\PROGRA~1\Yahoo!\MESSEN~1\". File ypager.exe is related... |
Change status |
E:\Collaterals\Hi Jack This\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults /sb/*http://www.yahoo.com/search/ie.html |
Not necessary |
http://red.clientapps.yahoo.com/customize/ycomp/defaults /sb/*http://www.yahoo.com/search/ie.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp /defaults/sp/*http://www.yahoo.com |
Not necessary |
http://red.clientapps.yahoo.com/customize/ycomp /defaults/sp/*http://www.yahoo.com is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ |
Not necessary |
http://www.yahoo.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp /defaults/su/*http://www.yahoo.com |
Not necessary |
http://red.clientapps.yahoo.com/customize/ycomp /defaults/su/*http://www.yahoo.com is your default SearchURL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 66.250.69.1:8080 |
Not necessary |
66.250.69.1:8080 is your Proxy Server. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = |
Not necessary |
This is your folder of IE toolbar links, but it points to nowhere. If you do not like this fact, fix this item. |
Change status |
| R3 - URLSearchHook: (no name) - <default> - (no file) |
Not necessary |
Fix this item because it has no name and no file to point to |
Change status |
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
| O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: (no name) - {0d2def3a-f4f1-42ec-ac4f-132e7ba6e292} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - D:\Program Files\GetRight\xx2gr.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: Nothing - {7a932ed2-1737-4ab8-b84d-c71779958551} - C:\WINDOWS\system32\hpE60B.tmp (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: (no name) - {944864A5-3916-46E2-96A9-A2E84F3F1208} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
System item according to inner database ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status
|
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe More info about file hpztsb04.exe |
Legitimate |
Application program item according to inner database File hpztsb04.exe is an essential component of Hewlett-Packard printer drivers. It is responsible... |
Change status
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
| O4 - HKLM\..\Run: [drwtsn64] C:\WINDOWS\system32\drwtsn64.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O4 - HKLM\..\Run: [WinFast Schedule] D:\Program Files\WinFast\WFTVFM\WFWIZ.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe More info about file hpgs2wnd.exe |
Legitimate |
System item according to inner database Hewlett Packard Share-to-Web utility built into thier products. |
Change status
|
| O4 - HKLM\..\RunServices: [drwtsn64] C:\WINDOWS\system32\drwtsn64.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Application program item according to inner database File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status
|
| O4 - HKCU\..\Run: [drwtsn64] C:\WINDOWS\system32\drwtsn64.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
Application program item according to inner database Related to Adobe Acrobat Reader. |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE More info about file osa.exe |
Legitimate |
Application program item according to inner database The Office Startup Assistant (Osa.exe or OSA) is a program that improves the performance of Office... |
Change status
|
| O8 - Extra context menu item: Download with GetRight - D:\Program Files\GetRight\GRdownload.htm |
Not necessary |
Do you want item 'Download with GetRight' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Open with GetRight Browser - D:\Program Files\GetRight\GRbrowse.htm |
Not necessary |
Do you want item 'Open with GetRight Browser' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O15 - Trusted Zone: http://*.windowsupdate.com |
Questionable |
Do you want URL pattern "http://*.windowsupdate.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 |
Questionable |
Are you using an ActiveX object with a name 'Windows Genuine Advantage Validation Tool' located in 'http://go.microsoft.com/fwlink/?linkid=39204'? If not, fix this item. |
Change status
|
| O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab |
Questionable |
Are you using an ActiveX object with a name 'VerifyGMN Class' located in 'http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} - |
Questionable |
Are you using an ActiveX object with no name located in ''? If not, fix this item. |
Change status
|
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls /en/x86/client/wuweb_site.cab?1118712154592 |
Questionable |
Are you using an ActiveX object with a name 'WUWebControl Class' located in 'http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls /en/x86/client/wuweb_site.cab?1118712154592'? If not, fix this item. |
Change status
|
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1144828047968 |
Questionable |
Are you using an ActiveX object with a name 'MUWebControl Class' located in 'http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1144828047968'? If not, fix this item. |
Change status
|
| O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx |
Questionable |
Are you using an ActiveX object with a name 'Get_ActiveX Control' located in 'https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx'? If not, fix this item. |
Change status
|
| O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - https://my.levelupgames.ph/KeyCrypt/npkcx.cab |
Questionable |
Are you using an ActiveX object with no name located in 'https://my.levelupgames.ph/KeyCrypt/npkcx.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - |
Questionable |
Are you using an ActiveX object with no name located in ''? If not, fix this item. |
Change status
|
| O16 - DPF: {E20352D0-48EF-49E6-A042-981AA9958EE2} (Launcher Control) - http://www.hyperrelay.ph/activex/v1.1.0.1/TWOLauncher.cab |
Questionable |
Are you using an ActiveX object with a name 'Launcher Control' located in 'http://www.hyperrelay.ph/activex/v1.1.0.1/TWOLauncher.cab'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{091C0B2D-AAE2-4F9B-B4FC-1521EAB26CD8}: NameServer = 203.87.128.3,203.87.128.4 |
Questionable |
Do you recognize these IP addresses '203.87.128.3,203.87.128.4' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS1\Services\Tcpip\..\{091C0B2D-AAE2-4F9B-B4FC-1521EAB26CD8}: NameServer = 203.87.128.3,203.87.128.4 |
Questionable |
Do you recognize these IP addresses '203.87.128.3,203.87.128.4' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS2\Services\Tcpip\..\{091C0B2D-AAE2-4F9B-B4FC-1521EAB26CD8}: NameServer = 203.87.128.3,203.87.128.4 |
Questionable |
Do you recognize these IP addresses '203.87.128.3,203.87.128.4' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O20 - Winlogon Notify: winhab32 - winhab32.dll (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
| O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe |
Legitimate |
Required for PhotoshopCS |
Change status
|
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe |
Legitimate |
ATI Video Card Control Panel |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: InCD Helper (InCDsrv) - Nero AG - D:\Ahead\InCD\InCDsrv.exe More info about file incdsrv.exe |
Legitimate |
Item found in 2-spyware.com database. Ahead Nero InCD Service. Allows to format writeable CDs and DVDs and use them as regular hard... |
Change status
|
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe More info about file ulcdrsvr.exe |
Legitimate |
Item found in 2-spyware.com database. Legitimate file ulcdrsvr.exe is an essential component of Ulead DVD Workshop video editing... |
Change status
|