| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Ahead\InCD\InCDsrv.exe More info about file incdsrv.exe |
Legitimate |
Item found in 2-spyware.com library Ahead Nero InCD Service. Allows to format writeable CDs and DVDs and use them as regular hard... |
Change status |
C:\WINDOWS\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com library Related to the ZoneAlarm firewall from ZoneLabs. Located in "C:\WINDOWS\SYSTEM\ZONELABS\". |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com library This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\AskBarDis\bar\bin\AskService.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\RunDll32.exe More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe More info about file googledesktop.exe |
Legitimate |
Item found in 2-spyware.com library GoogleDesktop.exe is the main component of Google Desktop, an application that improves you... |
Change status |
C:\Program Files\Ahead\InCD\InCD.exe More info about file incd.exe |
Legitimate |
Item found in 2-spyware.com library InCD.exe is an application process that is part of Nero CD Burning Software. "Write to CDs and... |
Change status |
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe More info about file opware32.exe |
Legitimate |
Item found in 2-spyware.com library opware32.exe is part of ScanSoft OmniPage suite. This software was designed to scan static paper... |
Change status |
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe More info about file googledesktop.exe |
Legitimate |
Item found in 2-spyware.com library GoogleDesktop.exe is the main component of Google Desktop, an application that improves you... |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgtray.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe More info about file zlclient.exe |
Legitimate |
Item found in 2-spyware.com library ZoneAlarm Firewall http://www.zonelabs.com |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Item found in 2-spyware.com library File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status |
C:\Program Files\Windows Live\Messenger\msnmsgr.exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
| C:\Program Files\Windows Live\Contacts\wlcomm.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgrsx.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgnsx.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\rundll32.exe More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Bonjour for Windows application. |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\iTunes\iTunes.exe More info about file itunes.exe |
Legitimate |
Item found in 2-spyware.com library iTunes from apple computers for Windows.
Seems good. |
Change status |
| C:\Program Files\AVG\AVG8\avgscanx.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\AVG\AVG8\avgcsrvx.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\AVG\AVG8\avgui.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| C:\Program Files\AVG\AVG8\avgscanx.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\AVG\AVG8\avgcsrvx.exe |
Unknown |
No exact entries found |
Insert file into database
|
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/ |
Unknown |
No exact entries found |
Insert file into database
|
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Unknown |
No exact entries found |
Insert file into database
|
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Unknown |
No exact entries found |
Insert file into database
|
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Unknown |
No exact entries found |
Insert file into database
|
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 |
Unknown |
No exact entries found |
Insert file into database
|
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = |
Unknown |
No exact entries found |
Insert file into database
|
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local |
Unknown |
No exact entries found |
Insert file into database
|
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll More info about file ietoolbar.dll |
Dangerous |
Item found in 2-spyware.com library ietoolbar.dll is a library file that is responsible for implementing main parasite functions and... |
Change status |
| O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll More info about file windowslivelogin.dll |
Legitimate |
Item found in 2-spyware.com library The file belongs to Microsoft Windows Live application. |
Change status |
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll More info about file ietoolbar.dll |
Dangerous |
Item found in 2-spyware.com library ietoolbar.dll is a library file that is responsible for implementing main parasite functions and... |
Change status |
| O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Movie_Edit_Pro_14_PLUS\TrayServer.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Item found in 2-spyware.com library Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status |
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe More info about file incd.exe |
Legitimate |
Item found in 2-spyware.com library InCD.exe is an application process that is part of Nero CD Burning Software. "Write to CDs and... |
Change status |
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe More info about file opware32.exe |
Legitimate |
Item found in 2-spyware.com library opware32.exe is part of ScanSoft OmniPage suite. This software was designed to scan static paper... |
Change status |
| O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
| O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Item found in 2-spyware.com library File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status |
| O4 - HKCU\..\Run: [AdobeUpdater6] "C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe" |
Unknown |
No exact entries found |
Insert file into database
|
| O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra ''Tools'' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Unknown |
No exact entries found |
Insert file into database
|
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
| O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab |
Unknown |
No exact entries found |
Insert file into database
|
| O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab |
Unknown |
No exact entries found |
Insert file into database
|
| O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL |
Legitimate |
The file is related to Google Desktop software. |
Insert file into database
|
| O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Bonjour for Windows application. |
Change status |
| O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe More info about file googledesktop.exe |
Legitimate |
Item found in 2-spyware.com library GoogleDesktop.exe is the main component of Google Desktop, an application that improves you... |
Change status |
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe More info about file incdsrv.exe |
Legitimate |
Item found in 2-spyware.com library Ahead Nero InCD Service. Allows to format writeable CDs and DVDs and use them as regular hard... |
Change status |
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com library This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status |
| O23 - Service: Seekeen Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Seekeen\seekeen140.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com library Related to the ZoneAlarm firewall from ZoneLabs. Located in "C:\WINDOWS\SYSTEM\ZONELABS\". |
Change status |
| -- |
Unknown |
No exact entries found |
Insert file into database
|
| End of file - 8258 bytes |
Unknown |
No exact entries found |
Insert file into database
|
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/ |
Not necessary |
http://sympatico.msn.ca/ is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local |
Not necessary |
*.local overrides your Proxy Server. If you do not like this fact, fix this item. |
Change status |
| R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll |
Questionable |
If you do not recognize this entry name "AVG Security Toolbar BHO" and this path "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll", then fix this item |
Change status |
| O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll More info about file acroiehelpershim.dll |
Legitimate |
Application program item according to inner database adobe acrobat activex |
Change status
|
| O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll More info about file avgssie.dll |
Legitimate |
Application program item according to inner database Related to AVG Antivirus 8.0 |
Change status
|
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll More info about file windowslivelogin.dll |
Legitimate |
Application program item according to inner database The file belongs to Microsoft Windows Live application. |
Change status
|
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll More info about file ietoolbar.dll |
Dangerous |
Spyware related item according to inner database ietoolbar.dll is a library file that is responsible for implementing main parasite functions and... |
Change status
|
| O3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar1.dll |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd More info about file cmicnfg.cpl |
Legitimate |
System item according to inner database system tray access for C-Media sound cards. |
Change status
|
| O4 - HKLM\..\Run: [TrayServer] C:\Program Files\MAGIX\Movie_Edit_Pro_14_PLUS\TrayServer.exe |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup More info about file googledesktop.exe |
Legitimate |
Application program item according to inner database GoogleDesktop.exe is the main component of Google Desktop, an application that improves you... |
Change status
|
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe More info about file incd.exe |
Legitimate |
Application program item according to inner database InCD.exe is an application process that is part of Nero CD Burning Software. <i>"Write to CDs and... |
Change status
|
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe More info about file opware32.exe |
Legitimate |
Application program item according to inner database opware32.exe is part of ScanSoft OmniPage suite. This software was designed to scan static paper... |
Change status
|
| O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" More info about file zlclient.exe |
Legitimate |
System item according to inner database ZoneAlarm Firewall http://www.zonelabs.com |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" More info about file reader_sl.exe |
Legitimate |
Application program item according to inner database reader_sl.exe is Related to Adobe Acrobat Reader. |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Admin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Application program item according to inner database File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status
|
| O4 - HKCU\..\Run: [AdobeUpdater6] "C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe" |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Research' and points to file 'C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\PROGRA~1\SPYBOT~1\SDHelper.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Spybot' and points to file '{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name '@xpsp3res.dll,-20001' and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab |
Questionable |
Are you using an ActiveX object with a name 'DivXBrowserPlugin Object' located in 'http://download.divx.com/player/DivXBrowserPlugin.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab |
Questionable |
Are you using an ActiveX object with a name 'Shockwave Flash Object' located in 'http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab'? If not, fix this item. |
Change status
|
| O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "linkscanner" and file "C:\Program Files\AVG\AVG8\avgpp.dll". |
Change status
|
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL More info about file |
Legitimate |
The file is related to Google Desktop software. |
Change status
|
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll More info about file |
Unknown |
No exact entries found |
Change status
|
| O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com database. The file belongs to Bonjour for Windows... |
Change status
|
| O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe |
Legitimate |
Firebird Database Server |
Change status
|
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe More info about file googledesktop.exe |
Legitimate |
Item found in 2-spyware.com database. GoogleDesktop.exe is the main component of Google Desktop, an application that improves you... |
Change status
|
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe More info about file incdsrv.exe |
Legitimate |
Item found in 2-spyware.com database. Ahead Nero InCD Service. Allows to format writeable CDs and DVDs and use them as regular hard... |
Change status
|
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com database. This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status
|
| O23 - Service: Seekeen Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Seekeen\seekeen140.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe More info about file vsmon.exe |
Legitimate |
Item found in 2-spyware.com database. Related to the ZoneAlarm firewall from ZoneLabs. Located in... |
Change status
|