| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\csrss.exe More info about file csrss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\Spyware Doctor\sdhelp.exe More info about file sdhelp.exe |
Legitimate |
Item found in 2-spyware.com library A part of Spyware Doctor, a popular legitimate anti-spyware program. |
Change status |
C:\WINDOWS\system32\wdfmgr.exe More info about file wdfmgr.exe |
Legitimate |
Item found in 2-spyware.com library A part of Microsoft Windows Media Player 10. It is used to eliminate software compatibility... |
Change status |
C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\dcomcfg.exe More info about file dcomcfg.exe |
Dangerous |
Item found in 2-spyware.com library dcomcfg.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
Item found in 2-spyware.com library ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status |
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe More info about file pdvdserv.exe |
Legitimate |
Item found in 2-spyware.com library Related to some DVD playing programs like CyberLink PowerDVD. Provides support for the DVD drive's... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\SOUNDMAN.EXE More info about file soundman.exe |
Legitimate |
Item found in 2-spyware.com library Related to Realtek Avance Logic soundcards. SOUNDMAN.EXE provides system tray access to a varity of... |
Change status |
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\Program Files\Winamp\winampa.exe More info about file winampa.exe |
Legitimate |
Item found in 2-spyware.com library System tray icon for Winamp. |
Change status |
C:\Program Files\QuickTime\qttask.exe More info about file qttask.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status |
C:\Program Files\D-Tools\daemon.exe More info about file daemon.exe |
Legitimate |
Item found in 2-spyware.com library CD image manager software. This program is used to run CDs on a computer without the cd in the... |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
| C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\MSN Messenger\MsnMsgr.Exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
C:\Program Files\Spyware Doctor\swdoctor.exe More info about file swdoctor.exe |
Legitimate |
Item found in 2-spyware.com library Main component of Spyware Doctor, a popular anti-spyware program. |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
Item found in 2-spyware.com library Related to Adobe Acrobat Reader. |
Change status |
| C:\Program Files\DLMage\DnloadMage.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe More info about file ymsgr_tray.exe |
Legitimate |
Item found in 2-spyware.com library A part of Yahoo! Instant Messenger.
|
Change status |
C:\Program Files\WinRAR\WinRAR.exe More info about file winrar.exe |
Questionable |
Item found in 2-spyware.com library winrar.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\DOCUME~1\Tristan\LOCALS~1\Temp\Rar$EX00.860\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.monash.edu/ |
Not necessary |
http://my.monash.edu/ is your start page. If you do not like this fact, fix this item. |
Change status |
| O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hp66E7.tmp |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
System item according to inner database ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status
|
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" More info about file pdvdserv.exe |
Legitimate |
Application program item according to inner database Related to some DVD playing programs like CyberLink PowerDVD. Provides support for the DVD drive's... |
Change status
|
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Application program item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE More info about file soundman.exe |
Legitimate |
System item according to inner database Related to Realtek Avance Logic soundcards. SOUNDMAN.EXE provides system tray access to a varity of... |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
| O4 - HKLM\..\Run: [DVD43] "C:\Program Files\DVD Region+CSS Free\DVDRegionFree.exe" /hidden |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe More info about file winampa.exe |
Legitimate |
Application program item according to inner database System tray icon for Winamp. |
Change status
|
| O4 - HKLM\..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 10\LaunchList.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 More info about file daemon.exe |
Legitimate |
Application program item according to inner database CD image manager software. This program is used to run CDs on a computer without the cd in the... |
Change status
|
| O4 - HKLM\..\Run: [SpywareFirewall] C:\Program Files\SpyWall\SpyWall.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
| O4 - HKLM\..\Run: [HPWUTOOLBOX] C:\Program Files\HP\HP Officejet Pro K550 Series\Toolbox\HPWUTBX.exe "-i" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - HKCU\..\Run: [FreshDownload] "C:\Program Files\FreshDevices\FreshDownload\FD.EXE" More info about file fd.exe |
Questionable |
Questionable item according to inner database fd.exe is an executable file that starts a malicious process, launches certain parasite components... |
Change status
|
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet More info about file ypager.exe |
Legitimate |
Application program item according to inner database Related to Yahoo Messenger. Located in "C:\PROGRA~1\Yahoo!\MESSEN~1\". File ypager.exe is related... |
Change status
|
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q More info about file swdoctor.exe |
Legitimate |
Application program item according to inner database Main component of Spyware Doctor, a popular anti-spyware program. |
Change status
|
| O4 - Startup: Download Mage.lnk = C:\Program Files\DLMage\DnloadMage.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
A part of Adobe Acrobat Reader. Used to speed up the program's launch time. |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE More info about file osa9.exe |
Legitimate |
Application program item according to inner database Loads Microsoft Office components at reboot, to improve the startup time of the Office programs.... |
Change status
|
| O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm |
Not necessary |
This item represents extra button in your IE toolbar with a name 'eBay' and points to file '{EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A}'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 |
Questionable |
Are you using an ActiveX object with a name 'Windows Genuine Advantage Validation Tool' located in 'http://go.microsoft.com/fwlink/?linkid=39204'? If not, fix this item. |
Change status
|
| O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'Minesweeper Flags Class' located in 'http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/19aaad10636dd75fcb01/netzip/RdxIE601.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://software-dl.real.com/19aaad10636dd75fcb01/netzip/RdxIE601.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.bigfishgames.com/online/luxor/mjolauncher.cab |
Questionable |
Are you using an ActiveX object with a name 'MJLauncherCtrl Class' located in 'http://www.bigfishgames.com/online/luxor/mjolauncher.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.bigfishgames.com/online/tumblebugs/axhost.cab |
Questionable |
Are you using an ActiveX object with a name 'WildfireActiveXHost Class' located in 'http://www.bigfishgames.com/online/tumblebugs/axhost.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'MessengerStatsClient Class' located in 'http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'Solitaire Showdown Class' located in 'http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab'? If not, fix this item. |
Change status
|
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe |
Legitimate |
ATI Video Card Control Panel |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe More info about file sdhelp.exe |
Legitimate |
Item found in 2-spyware.com database. A part of Spyware Doctor, a popular legitimate anti-spyware... |
Change status
|