| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Avira\AntiVir Desktop\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com library Scheduler for AntiVir Anti Virus program. |
Change status |
C:\Program Files\Avira\AntiVir Desktop\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com library avguard.exe stands for AntiVir real-time protection process. Do not terminate it. |
Change status |
| C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe More info about file avgnt.exe |
Legitimate |
Item found in 2-spyware.com library avgnt.exe is a security process that is associated with the Avira Internet Security Suite, which... |
Change status |
C:\Program Files\Java\jre6\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\Java\jre6\bin\jucheck.exe More info about file jucheck.exe |
Legitimate |
Item found in 2-spyware.com library jucheck.exe belongs to Java Virtual Machine software and may be terminated at will, which might... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\WINDOWS\msa.exe More info about file msa.exe |
Dangerous |
Item found in 2-spyware.com library
|
Change status |
C:\DOCUME~1\Mike\LOCALS~1\Temp\b.exe More info about file b.exe |
Dangerous |
Item found in 2-spyware.com library b.exe is an executable file which primary purpose is to start a parasite or launch some of its... |
Change status |
C:\WINDOWS\System32\mshta.exe More info about file mshta.exe |
Dangerous |
Item found in 2-spyware.com library mshta.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
| C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Avira\AntiVir Desktop\GUARDGUI.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Mozilla Firefox\firefox.exe More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll More info about file acroiehelpershim.dll |
Legitimate |
Application program item according to inner database adobe acrobat activex |
Change status
|
| O2 - BHO: (no name) - {B8C60D42-9881-11DE-B7C5-CD5255D89593} - C:\DOCUME~1\Mike\LOCALS~1\Temp\~382.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll More info about file jp2ssv.dll |
Legitimate |
System item according to inner database
|
Change status
|
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll More info about file jqs_plugin.dll |
Legitimate |
System item according to inner database
|
Change status
|
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min More info about file avgnt.exe |
Legitimate |
Application program item according to inner database avgnt.exe is a security process that is associated with the Avira Internet Security Suite, which... |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" More info about file reader_sl.exe |
Legitimate |
Application program item according to inner database reader_sl.exe is Related to Adobe Acrobat Reader. |
Change status
|
| O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\RunOnce: [IERESETATTRIB] %SystemRoot%\system32\cmd.exe /d /q /c %SystemRoot%\system32\ieudinit.exe -ResetFileAttributes More info about file cmd.exe |
Legitimate |
System item according to inner database Command prompt tool that comes with Windows NT/2000/XP. Located in "C:\WINNT\SYSTEM32" on Windows... |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
O4 - HKCU\..\Run: [MailBlocker] C:\DOCUME~1\Mike\LOCALS~1\Temp\b.exe More info about file b.exe |
Dangerous |
Spyware related item according to inner database b.exe is an executable file which primary purpose is to start a parasite or launch some of its... |
Change status
|
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe More info about file limewire.exe |
Legitimate |
Application program item according to inner database The file belongs to LimeWire P2P application. |
Change status
|
| O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name '@xpsp3res.dll,-20001' and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab |
Questionable |
Are you using an ActiveX object with a name 'MySpace Uploader Control' located in 'http://lads.myspace.com/upload/MySpaceUploader2.cab'? If not, fix this item. |
Change status
|
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com database. Scheduler for AntiVir Anti Virus... |
Change status
|
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com database. avguard.exe stands for AntiVir real-time protection process. Do not terminate it.... |
Change status
|
| O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|