| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe More info about file mdm.exe |
Legitimate |
Item found in 2-spyware.com library mdm.exe is a system process - Machine Debug Manager. Used by developers. Located in "C:\PROGRAM... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\dcomcfg.exe More info about file dcomcfg.exe |
Dangerous |
Item found in 2-spyware.com library dcomcfg.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
| C:\Program Files\Creative\Shared Files\CAMTRAY.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe More info about file ymsgr_tray.exe |
Legitimate |
Item found in 2-spyware.com library A part of Yahoo! Instant Messenger.
|
Change status |
C:\Program Files\Eraser\eraser.exe More info about file eraser.exe |
Dangerous |
Item found in 2-spyware.com library eraser.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Documents and Settings\Simon\Local Settings\Temporary Internet Files\Content.IE5\Q3IZ2XAZ\HijackThis[1].exe |
Unknown |
No exact entries found |
Insert file into database
|
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR |
Not necessary |
http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR |
Not necessary |
http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7 /*http://www.yahoo.com/ext/search/search.html |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7 /*http://www.yahoo.com/ext/search/search.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*http://www.yahoo.com is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR |
Not necessary |
http://g.ninemsn.com.au/0SEENAU/SAOS01?FORM=TOOLBR is your default SearchURL. If you do not like this fact, fix this item. |
Change status |
| O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hp1631.tmp |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
| O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCAN |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet More info about file ypager.exe |
Legitimate |
Application program item according to inner database Related to Yahoo Messenger. Located in "C:\PROGRA~1\Yahoo!\MESSEN~1\". File ypager.exe is related... |
Change status
|
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Application program item according to inner database File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status
|
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide More info about file eraser.exe |
Dangerous |
Spyware related item according to inner database eraser.exe is an executable file that is responsible for launching parasites, loading main... |
Change status
|
| O4 - Startup: LimeWire On Startup.lnk = C:\Documents and Settings\Simon\Desktop\LimeWire\LimeWire.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
A part of Adobe Acrobat Reader. Used to speed up the program's launch time. |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE More info about file osa.exe |
Legitimate |
Application program item according to inner database The Office Startup Assistant (Osa.exe or OSA) is a program that improves the performance of Office... |
Change status
|
| O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html |
Not necessary |
Do you want item 'Backward Links' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html |
Not necessary |
Do you want item 'Cached Snapshot of Page' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html |
Not necessary |
Do you want item 'Similar Pages' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html |
Not necessary |
Do you want item 'Translate Page into English' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) |
Not necessary |
This item represents extra button in your IE toolbar with a name 'PartyPoker.com' and points to file 'C:\Program Files\PartyPoker\PartyPoker.exe (file missing)'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing) |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'PartyPoker.com' and points to file 'C:\Program Files\PartyPoker\PartyPoker.exe (file missing)'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab |
Questionable |
Are you using an ActiveX object with a name 'Creative Software AutoUpdate' located in 'http://www.creative.com/su/ocx/15015/CTSUEng.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab |
Questionable |
Are you using an ActiveX object with a name 'MsnMessengerSetupDownloadControl Class' located in 'http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15021/CTPID.cab |
Questionable |
Are you using an ActiveX object with a name 'Creative Software AutoUpdate Support Package' located in 'http://www.creative.com/su/ocx/15021/CTPID.cab'? If not, fix this item. |
Change status
|
| O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) |
Not necessary |
It is a protocol hijacker that points to nowhere. Fix this item. |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|