| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe More info about file aluschedulersvc.exe |
Legitimate |
Item found in 2-spyware.com library Related to Symantec anti-virus software. |
Change status |
| C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe More info about file reader_sl.exe |
Legitimate |
Item found in 2-spyware.com library reader_sl.exe is Related to Adobe Acrobat Reader. |
Change status |
| C:\Program Files\SelectRebates\SelectRebates.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe More info about file registrybooster.exe |
Legitimate |
Item found in 2-spyware.com library Part of Uniblue's "Registry Booster" |
Change status |
| C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll More info about file acroiehelpershim.dll |
Legitimate |
Application program item according to inner database adobe acrobat activex |
Change status
|
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll More info about file coieplg.dll |
Legitimate |
System item according to inner database symantec shared file |
Change status
|
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll More info about file ipsbho.dll |
Legitimate |
System item according to inner database Description
ipsbho.dll is a IPS Browser Helper DLL belonging to Symantec Intrusion Detection from... |
Change status
|
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll More info about file sepsearchhelperie.dll |
Legitimate |
System item according to inner database
|
Change status
|
| O2 - BHO: ParentalControl Bar - {A057A204-BACC-4D26-908B-27FCD4A32E85} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll More info about file swg.dll |
Legitimate |
System item according to inner database google toolbar notifier |
Change status
|
| O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll More info about file jp2ssv.dll |
Legitimate |
System item according to inner database
|
Change status
|
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll More info about file jqs_plugin.dll |
Legitimate |
System item according to inner database
|
Change status
|
| O2 - BHO: ShopAtHomeIEHelper - {E8DAAA30-6CAA-4b58-9603-8E54238219E2} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll |
Unknown |
No exact entries found |
Insert file into database
|
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll More info about file coieplg.dll |
Legitimate |
System item according to inner database symantec shared file |
Change status
|
O3 - Toolbar: ParentalControl Bar - {A057A204-BACC-4D26-908B-27FCD4A32E85} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL More info about file coieplg.dll |
Unknown |
No exact entries found |
Insert file into database
|
O3 - Toolbar: ShopAtHome Toolbar - {98279C38-DE4B-4bcf-93C9-8EC26069D6F4} - C:\Program Files\SelectRebates\Toolbar\ShopAtHomeToolbar.dll More info about file coieplg.dll |
Unknown |
No exact entries found |
Insert file into database
|
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll More info about file coieplg.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" More info about file ccapp.exe |
Legitimate |
System item according to inner database From Symantec: <i>"ccApp.exe is the common hosting application that is used for both NAV and NIS.... |
Change status
|
| O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360 Premier Edition\osCheck.exe" |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [IDTSysTrayApp] sttray.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" More info about file reader_sl.exe |
Legitimate |
Application program item according to inner database reader_sl.exe is Related to Adobe Acrobat Reader. |
Change status
|
| O4 - HKLM\..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S More info about file registrybooster.exe |
Legitimate |
System item according to inner database Part of Uniblue's "Registry Booster" |
Change status
|
| O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Thomas\Start Menu\Programs\IMVU\Run IMVU.lnk |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Run IMVU' and points to file 'C:\Documents and Settings\Thomas\Start Menu\Programs\IMVU\Run IMVU.lnk'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab |
Questionable |
Are you using an ActiveX object with a name 'Windows Live Safety Center Base Module' located in 'http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab |
Questionable |
Are you using an ActiveX object with a name 'Symantec Download Manager' located in 'https://webdl.symantec.com/activex/symdlmgr.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab |
Questionable |
Are you using an ActiveX object with a name 'Groove Control' located in 'http://www.nick.com/common/groove/gx/GrooveAX27.cab'? If not, fix this item. |
Change status
|
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe More info about file aluschedulersvc.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Symantec anti-virus... |
Change status
|
| O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe |
Legitimate |
Related to Norton/Symantec AntiVirus |
Change status
|
| O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe |
Legitimate |
Related to Norton/Symantec AntiVirus. |
Change status
|
| O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe More info about file googleupdaterservice.exe |
Legitimate |
Item found in 2-spyware.com database. Service for Google... |
Change status
|
| O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\WINDOWS\system32\STacSV.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe More info about file symlcsvc.exe |
Legitimate |
Item found in 2-spyware.com database. An essential component of security-related Symantec software such as Norton AntiVirus and Norton... |
Change status
|