| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\acs.exe More info about file acs.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Atheros Wireless LAN application. |
Change status |
C:\WINDOWS\System32\brsvc01a.exe More info about file brsvc01a.exe |
Legitimate |
Item found in 2-spyware.com library This is an essential component of Brother printer drivers. File brsvc01a.exe.exe is used to control... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\brss01a.exe More info about file brss01a.exe |
Legitimate |
Item found in 2-spyware.com library This is an essential component of Brother printer drivers. File brss01a.exe is used to control a... |
Change status |
C:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\Brmfrmps.exe More info about file brmfrmps.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Brother printer/scanner application. |
Change status |
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe More info about file isafe.exe |
Legitimate |
Item found in 2-spyware.com library This file is related to eTrust Antivirus. This program protects your computer from various viruses,... |
Change status |
C:\WINDOWS\System32\svchosts.exe More info about file svchosts.exe |
Dangerous |
Item found in 2-spyware.com library svchosts.exe is related to the Online Trojan, which changes your Internet Explorer settings. This... |
Change status |
C:\WINDOWS\System32\CTsvcCDA.EXE More info about file ctsvccda.exe |
Legitimate |
Item found in 2-spyware.com library Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe More info about file vetmsg.exe |
Legitimate |
Item found in 2-spyware.com library A vital component of Computer Associates eTrust EZ Antivirus. |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
Item found in 2-spyware.com library ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status |
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe More info about file syntplpr.exe |
Legitimate |
Item found in 2-spyware.com library Related to Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
created by:... |
Change status |
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe More info about file syntpenh.exe |
Legitimate |
Item found in 2-spyware.com library System tray access for Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
Change status |
|
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe More info about file hpcmpmgr.exe |
Legitimate |
Item found in 2-spyware.com library File hpcmpmgr.exe is a part of Hewlett-Packard Component Manager tool, which comes preinstalled on... |
Change status |
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe More info about file hpwuschd2.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Hewlett Packard software. |
Change status |
C:\WINDOWS\System32\hphmon05.exe More info about file hphmon05.exe |
Legitimate |
Item found in 2-spyware.com library Executable hphmon05.exe is a part of HP printer drivers. It is required to enable support for the... |
Change status |
| C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\pctspk.exe More info about file pctspk.exe |
Legitimate |
Item found in 2-spyware.com library File pctspk.exe, started by an executable with the same name, is a part of the drivers for PCTEL... |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\Program Files\QuickTime\qttask.exe More info about file qttask.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status |
| C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe More info about file pptd40nt.exe |
Legitimate |
Item found in 2-spyware.com library Part of Scansoft's PaperPort scanner application. Usually located in "C:\Program... |
Change status |
| C:\Program Files\Brother\ControlCenter2\brctrcen.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe More info about file vettray.exe |
Legitimate |
Item found in 2-spyware.com library Part of Computer Associates EZ Anti-virus program |
Change status |
C:\Program Files\Messenger\MSMSGS.EXE More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
| C:\Program Files\D-Link\AirPlus G Wireless Adapter Utility\AirPlus.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\NOTEPAD.EXE More info about file notepad.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe More info about file spybotsd.exe |
Legitimate |
Item found in 2-spyware.com library Main component of Spybot - Search & Destroy, a popular anti-spyware program |
Change status |
| C:\Documents and Settings\Martin\My Documents\Drivers\HijackThis1991.exe |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
| O2 - BHO: (no name) - {f4d74aaa-a178-4463-846b-b4bc87a024e0} - C:\WINDOWS\System32\ixt0.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll More info about file toolband.dll |
Legitimate |
Canon printer kit toolbar in ie7 |
Change status
|
O3 - Toolbar: Safety Bar - {18668683-731c-48fa-b1b9-ad013748fb00} - C:\Program Files\Safety Bar\SafetyBar.dll More info about file toolband.dll |
Unknown |
No exact entries found |
Insert file into database
|
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
System item according to inner database ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status
|
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe More info about file ati2mdxx.exe |
Legitimate |
System item according to inner database ATI 2D Mode component from ATI Technologies, Inc. Related to your graphics card. Located in... |
Change status
|
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe More info about file syntplpr.exe |
Legitimate |
System item according to inner database Related to Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
created by:... |
Change status
|
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe More info about file syntpenh.exe |
Legitimate |
System item according to inner database System tray access for Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".<br... |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
| O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" More info about file hpcmpmgr.exe |
Legitimate |
Application program item according to inner database File hpcmpmgr.exe is a part of Hewlett-Packard Component Manager tool, which comes preinstalled on... |
Change status
|
O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\HP\HP Software Update\HPWuSchd2.exe" More info about file hpwuschd2.exe |
Legitimate |
Application program item according to inner database The file is related to Hewlett Packard software. |
Change status
|
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe More info about file hphmon05.exe |
Legitimate |
Application program item according to inner database Executable hphmon05.exe is a part of HP printer drivers. It is required to enable support for the... |
Change status
|
| O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe More info about file pctspk.exe |
Legitimate |
System item according to inner database File pctspk.exe, started by an executable with the same name, is a part of the drivers for PCTEL... |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
| O4 - HKLM\..\Run: [PDUiP6600DMon] C:\Program Files\Canon\Memory Card Utility\iP6600D\PDUiP6600DMon.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe More info about file pptd40nt.exe |
Legitimate |
System item according to inner database Part of Scansoft's PaperPort scanner application. Usually located in "C:\Program... |
Change status
|
| O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe |
Legitimate |
Related to ScanSoft PaperPort, legitimate scanner software |
Change status
|
| O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04b\BrStDvPt.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe More info about file vettray.exe |
Legitimate |
System item according to inner database Part of Computer Associates EZ Anti-virus program |
Change status
|
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck More info about file spybotsd.exe |
Legitimate |
Application program item according to inner database Main component of Spybot - Search & Destroy, a popular anti-spyware program |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
| O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
A part of Adobe Acrobat Reader. Used to speed up the program's launch time. |
Change status
|
| O4 - Global Startup: D-Link AirPlus G Wireless Utility.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
| O4 - Global Startup: D-Link REG Utility.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE More info about file osa.exe |
Legitimate |
Application program item according to inner database The Office Startup Assistant (Osa.exe or OSA) is a program that improves the performance of Office... |
Change status
|
| O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll |
Legitimate |
This item represents a plugin added to Internet Explorer to work with '.pdf' files. Seems to be safe, unless you know that it is malicious. |
Change status
|
| O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll |
Questionable |
Are you using an ActiveX object with a name 'YInstStarter Class' located in 'C:\Program Files\Yahoo!\Common\yinsthelper.dll'? If not, fix this item. |
Change status
|
| O21 - SSODL: eupeptic - {8670ee50-01f9-47da-ac1e-cf8549e9e521} - (no file) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe More info about file acs.exe |
Legitimate |
Item found in 2-spyware.com database. The file is related to Atheros Wireless LAN... |
Change status
|
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe More info about file brsvc01a.exe |
Legitimate |
Item found in 2-spyware.com database. This is an essential component of Brother printer drivers. File brsvc01a.exe.exe is used to control... |
Change status
|
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\isafe.exe More info about file isafe.exe |
Legitimate |
Item found in 2-spyware.com database. This file is related to eTrust Antivirus. This program protects your computer from various viruses,... |
Change status
|
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE More info about file ctsvccda.exe |
Legitimate |
Item found in 2-spyware.com database. Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe More info about file vetmsg.exe |
Legitimate |
Item found in 2-spyware.com database. A vital component of Computer Associates eTrust EZ... |
Change status
|