| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe More info about file spysweeper.exe |
Legitimate |
Item found in 2-spyware.com library An executable file of SpySweeper anti-spyware program. |
Change status |
C:\Program Files\Mozilla Firefox\firefox.exe More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE More info about file winword.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Word, which is started by winword.exe file, is a text processing program, included in... |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
| E:\Program Files\uTorrent\uTorrent.exe |
Unknown |
No exact entries found |
Insert file into database
|
E:\Program Files\Trend Micro\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/ |
Not necessary |
http://google.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank |
Not necessary |
about:blank is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - E:\Program Files\Orbitdownloader\orbitcth.dll More info about file orbitcth.dll |
Legitimate |
Application program item according to inner database Orbit Downloader
|
Change status
|
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
| O2 - BHO: AdblockIE - {90EFF544-3981-4d46-85C9-C0361D0931D6} - mscoree.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll |
Legitimate |
legitimate bho toolbar, related to Google Toolbar |
Change status
|
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll More info about file swg.dll |
Legitimate |
System item according to inner database google toolbar notifier |
Change status
|
| O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll More info about file jp2ssv.dll |
Legitimate |
System item according to inner database
|
Change status
|
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll More info about file jqs_plugin.dll |
Legitimate |
System item according to inner database
|
Change status
|
| O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - E:\Program Files\Orbitdownloader\GrabPro.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll |
Legitimate |
legitimate bho toolbar, related to Google Toolbar |
Change status
|
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll More info about file yt.dll |
Legitimate |
Application program item according to inner database Yahoo! Toolbar |
Change status
|
O3 - Toolbar: (no name) - {C46CED39-05C9-40C3-88D1-E07AB8128E02} - (no file) More info about file yt.dll |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe More info about file ashdisp.exe |
Questionable |
HKLM - Run: [avast!], file: E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (params - '') (short filename - ashDisp.exe) |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKLM\..\Policies\Explorer\Run: [] |
Questionable |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKUS\S-1-5-19\..\RunOnce: [] (User ''LOCAL SERVICE'') |
Questionable |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKUS\S-1-5-20\..\RunOnce: [] (User ''NETWORK SERVICE'') |
Questionable |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User ''SYSTEM'') |
Questionable |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User ''Default user'') |
Questionable |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase1140.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - http://www.superadblocker.com/activex/sabspx.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://www.superadblocker.com/activex/sabspx.cab'? If not, fix this item. |
Change status
|
| O18 - Protocol: skyline - {3A4F9195-65A8-11D5-85C1-0001023952C1} - C:\Program Files\Bhuvan\TerraExplorerX.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "skyline" and file "C:\Program Files\Bhuvan\TerraExplorerX.dll". |
Change status
|
| O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "x-sdch" and file "C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll". |
Change status
|
| O23 - Service: Vipre Trial Reset (.vipre_reset) - Unknown owner - C:\Program Files\Vipre_Reset.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe More info about file aswupdsv.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Avast anti-virus... |
Change status
|
O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashServ.exe More info about file ashserv.exe |
Legitimate |
Item found in 2-spyware.com database. ashServ.exe is a process related to Avast anti-virus software. It should not be disabled to ensure... |
Change status
|
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe More info about file ashmaisv.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Avast anti-virus... |
Change status
|
O23 - Service: avast! Web Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe More info about file ashwebsv.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Avast anti-virus... |
Change status
|
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe More info about file googleupdaterservice.exe |
Legitimate |
Item found in 2-spyware.com database. Service for Google... |
Change status
|
| O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe More info about file nbservice.exe |
Legitimate |
Item found in 2-spyware.com database. ... |
Change status
|
| O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
| O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - E:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe More info about file spysweeper.exe |
Legitimate |
Item found in 2-spyware.com database. An executable file of SpySweeper anti-spyware... |
Change status
|