| Line: |
Status: |
Comments: |
Actions: |
| C:\Windows\system32\Dwm.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Windows\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Windows\system32\taskeng.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe More info about file bdagent.exe |
Legitimate |
Item found in 2-spyware.com library Legitimate file, related to BitDefender. |
Change status |
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe More info about file trueimagemonitor.exe |
Legitimate |
Item found in 2-spyware.com library Related to Acronis True Image |
Change status |
| C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe More info about file schedhlp.exe |
Legitimate |
Item found in 2-spyware.com library Related to Acronis True Image |
Change status |
C:\Program Files\Windows Sidebar\sidebar.exe More info about file sidebar.exe |
Dangerous |
Item found in 2-spyware.com library sidebar.exe is an executable file which primary purpose is to start a parasite or launch some of... |
Change status |
C:\Program Files\Free Download Manager\fdm.exe More info about file fdm.exe |
Legitimate |
Item found in 2-spyware.com library fdm.exe is the main component of Free Download Manager. It is not an essential system process and... |
Change status |
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe More info about file superantispyware.exe |
Legitimate |
Item found in 2-spyware.com library SAS is one of the best as-programs |
Change status |
C:\Windows\System32\mobsync.exe More info about file mobsync.exe |
Legitimate |
Item found in 2-spyware.com library "With Internet Explorer, you can make pages available offline. You can use Synchronization Manager... |
Change status |
C:\Program Files\Windows Media Player\wmplayer.exe More info about file wmplayer.exe |
Legitimate |
Item found in 2-spyware.com library This file represents Windows Media Player - it is a versatile multimedia player, published by... |
Change status |
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Windows\system32\Taskmgr.exe More info about file taskmgr.exe |
Legitimate |
Windows Task Manager |
Change status |
| C:\Users\shaun\Desktop\new antispy\RSIT.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Windows\system32\SearchFilterHost.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\trend micro\shaun.exe |
Unknown |
No exact entries found |
Insert file into database
|
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ |
Legitimate |
http://www.google.co.uk/ is your start page. This is a legitimate page. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = |
Not necessary |
This is your folder of IE toolbar links, but it points to nowhere. If you do not like this fact, fix this item. |
Change status |
| O1 - Hosts: ::1 localhost |
Questionable |
Do you want an URL address "localhost" to be redirected to "::1" when you type it? If not, then fix this |
|
| O2 - BHO: UrlHelper Class - {474597C5-AB09-49d6-A4D5-2E8D7341384E} - C:\Program Files\iMesh Applications\iMesh\iMeshIEHelper.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll More info about file iefdm2.dll |
Legitimate |
Application program item according to inner database The process belongs to the software Free Download Manager. |
Change status
|
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll More info about file ietoolbar.dll |
Dangerous |
Spyware related item according to inner database ietoolbar.dll is a library file that is responsible for implementing main parasite functions and... |
Change status
|
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide More info about file msascui.exe |
Legitimate |
Application program item according to inner database The file is component of Microsoft Windows Defender application. |
Change status
|
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" More info about file bdagent.exe |
Legitimate |
Application program item according to inner database Legitimate file, related to BitDefender. |
Change status
|
| O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe More info about file trueimagemonitor.exe |
Legitimate |
Application program item according to inner database Related to Acronis True Image |
Change status
|
| O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" More info about file schedhlp.exe |
Legitimate |
Application program item according to inner database Related to Acronis True Image |
Change status
|
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun More info about file sidebar.exe |
Dangerous |
Spyware related item according to inner database sidebar.exe is an executable file which primary purpose is to start a parasite or launch some of... |
Change status
|
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun More info about file fdm.exe |
Legitimate |
Application program item according to inner database fdm.exe is the main component of Free Download Manager. It is not an essential system process and... |
Change status
|
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe More info about file superantispyware.exe |
Legitimate |
System item according to inner database SAS is one of the best as-programs |
Change status
|
| O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ''LOCAL SERVICE'') |
Questionable |
System item according to inner database SAS is one of the best as-programs |
Change status
|
| O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User ''LOCAL SERVICE'') |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User ''NETWORK SERVICE'') |
Unknown |
No exact entries found |
Change status
|
| O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm |
Not necessary |
Do you want item 'Download all with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm |
Not necessary |
Do you want item 'Download selected with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm |
Not necessary |
Do you want item 'Download video with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm |
Not necessary |
Do you want item 'Download with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\PROGRA~1\SPYBOT~1\SDHelper.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Spybot' and points to file '{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}'. If you do not want it to be there, fix this item. |
Change status
|
| O13 - Gopher Prefix: |
Dangerous |
This item adds a prefix "Gopher Prefix: " for every URL address you enter in the IE and redirects you to wrong address. Fix this item. |
Change status
|
| O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab |
Questionable |
Are you using an ActiveX object with a name 'OnlineScanner Control' located in 'http://download.eset.com/special/eos/OnlineScanner.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab |
Questionable |
Are you using an ActiveX object with a name 'Shockwave Flash Object' located in 'http://fpdownload2.macromedia.com/get/s ... wflash.cab'? If not, fix this item. |
Change status
|
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll More info about file |
Unknown |
No exact entries found |
Change status
|
| O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll |
Unknown |
No exact entries found |
Change status
|
| O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Acronis OS Selector Reinstall Service AcronisOSSReinstallSvcAcronisOSSReinstallSvcAcronisOSSReinstallSvcAcrSch2Svc (AcronisOSSReinstallSvcAcronisOSSReinstallSvcAcronisOSSReinstallSvcAcrSch2Svc) - Unknown owner - C:\Windows\System32\wxpepoqxxd.exe (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe More info about file schedul2.exe |
Legitimate |
Item found in 2-spyware.com database. schedul2.exe is related to Acronis True Image Scheduler. It is not a harmful process, and shouldn't... |
Change status
|
| O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe More info about file livesrv.exe |
Legitimate |
Item found in 2-spyware.com database. livesrv.exe is the BitDefender Security Update Service. It updates BitDefender antivirus software.... |
Change status
|
| O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes'' Anti-Malware\mbamservice.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe More info about file vsserv.exe |
Legitimate |
Item found in 2-spyware.com database. Legitimate file, related to... |
Change status
|
| O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe |
Legitimate |
The RealVNC 4 server for VNC usage over a LAN/WAN. |
Change status
|
| R1 bdftdif;bdftdif; \??\C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys [2009-06-24 137224] |
Not necessary |
. If you do not like this fact, fix this item. |
Change status |
| R1 CSC;Offline Files Driver; C:\Windows\system32\drivers\csc.sys [2008-01-21 350720] |
Not necessary |
. If you do not like this fact, fix this item. |
Change status |
| R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-06-23 9968] |
Not necessary |
. If you do not like this fact, fix this item. |
Change status |
| R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-06-23 72944] |
Not necessary |
. If you do not like this fact, fix this item. |
Change status |
| R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2008-08-30 3929600] |
Questionable |
If you do not recognize this entry name " C:\Windows\system32\DRIVERS\atikmdag.sys [2008-08-30 3929600]" and this path " C:\Windows\system32\DRIVERS\atikmdag.sys [2008-08-30 3929600]", then fix this item |
Change status |
| R3 bdfm;BDFM; C:\Windows\system32\drivers\bdfm.sys [2009-06-24 111112] |
Questionable |
If you do not recognize this entry name "dows\system32\drivers\bdfm.sys [2009-06-24 111112]" and this path "dows\system32\drivers\bdfm.sys [2009-06-24 111112]", then fix this item |
Change status |
| R3 Bdfndisf;BitDefender Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\bdfndisf.sys [2009-06-24 104328] |
Questionable |
If you do not recognize this entry name "der Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\bdfndisf.sys [2009-06-24 104328]" and this path "der Firewall NDIS Filter Service; C:\Windows\system32\DRIVERS\bdfndisf.sys [2009-06-24 104328]", then fix this item |
Change status |
| R3 bdfsfltr;bdfsfltr; C:\Windows\system32\DRIVERS\bdfsfltr.sys [2009-06-24 242184] |
Questionable |
If you do not recognize this entry name " C:\Windows\system32\DRIVERS\bdfsfltr.sys [2009-06-24 242184]" and this path " C:\Windows\system32\DRIVERS\bdfsfltr.sys [2009-06-24 242184]", then fix this item |
Change status |
| R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys [2009-06-24 8832] |
Questionable |
If you do not recognize this entry name " \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys [2009-06-24 8832]" and this path " \??\C:\Program Files\BitDefender\BitDefender 2009\bdselfpr.sys [2009-06-24 8832]", then fix this item |
Change status |
| R3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520] |
Questionable |
If you do not recognize this entry name "icrosoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]" and this path "icrosoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]", then fix this item |
Change status |
| R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2009-06-17 19096] |
Questionable |
If you do not recognize this entry name "MProtector; \??\C:\Windows\system32\drivers\mbam.sys [2009-06-17 19096]" and this path "MProtector; \??\C:\Windows\system32\drivers\mbam.sys [2009-06-17 19096]", then fix this item |
Change status |
| R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-06-23 7408] |
Questionable |
If you do not recognize this entry name "\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-06-23 7408]" and this path "\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-06-23 7408]", then fix this item |
Change status |
| R3 vncmirror;vncmirror; C:\Windows\system32\DRIVERS\vncmirror.sys [2008-06-12 4608] |
Questionable |
If you do not recognize this entry name "or; C:\Windows\system32\DRIVERS\vncmirror.sys [2008-06-12 4608]" and this path "or; C:\Windows\system32\DRIVERS\vncmirror.sys [2008-06-12 4608]", then fix this item |
Change status |
| R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328] |
Questionable |
If you do not recognize this entry name "\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]" and this path "\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]", then fix this item |
Change status |
| R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 298496] |
Questionable |
If you do not recognize this entry name "Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 298496]" and this path "Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-06 298496]", then fix this item |
Change status |