| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\runservice.exe More info about file runservice.exe |
Dangerous |
Item found in 2-spyware.com library eLicense, licensing system incorporated with some software... |
Change status |
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe More info about file mdm.exe |
Legitimate |
Item found in 2-spyware.com library mdm.exe is a system process - Machine Debug Manager. Used by developers. Located in "C:\PROGRAM... |
Change status |
| C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com library NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status |
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe More info about file starwindservice.exe |
Legitimate |
Item found in 2-spyware.com library StarWindService.exe is a process which belongs to Alcohol 120% and provides network drive sharing... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\WINDOWS\system32\WgaTray.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\WINDOWS\system32\GSICON.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\dslagent.exe More info about file dslagent.exe |
Dangerous |
Item found in 2-spyware.com library What is this? Please add more information here.
DSLAGENT.EXE is located in... |
Change status |
| C:\Program Files\MSI\Live Update 3\LMonitor.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\SOUNDMAN.EXE More info about file soundman.exe |
Legitimate |
Item found in 2-spyware.com library Related to Realtek Avance Logic soundcards. SOUNDMAN.EXE provides system tray access to a varity of... |
Change status |
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe More info about file dragdiag.exe |
Legitimate |
Item found in 2-spyware.com library System tray icon for Alcatel’s ADSL modems. |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\WINDOWS\system32\RUNDLL32.EXE More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\QuickTime\qttask.exe More info about file qttask.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status |
C:\WINDOWS\system32\rundll32.exe More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe More info about file mm_tray.exe |
Legitimate |
Item found in 2-spyware.com library Music Match Tray icon. Located in "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\". |
Change status |
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe More info about file mmtask.exe |
Legitimate |
Item found in 2-spyware.com library Part of the Music Match Jukebox. Located in "C:\Program Files\MusicMatch\MusicMatch Jukebox\". A... |
Change status |
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\MSN Messenger\MsnMsgr.Exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
C:\Program Files\Steam\Steam.exe More info about file steam.exe |
Legitimate |
Item found in 2-spyware.com library This file is a part of application that comes with most games, published by Valve Corporation. It... |
Change status |
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Item found in 2-spyware.com library File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status |
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
Item found in 2-spyware.com library Related to Adobe Acrobat Reader. |
Change status |
| C:\Program Files\Logitech\SetPoint\SetPoint.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Internet Explorer\iexplore.exe More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Documents and Settings\mike\Desktop\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup More info about file rundll32.exe |
Legitimate |
System item according to inner database Rundll32.exe loads and runs 32-bit DLLs. Rundll32.exe comes with all versions of Microsoft Windows.... |
Change status
|
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install More info about file nwiz.exe |
Legitimate |
System item according to inner database Nwiz.exe is Related to nVidia graphic cards drivers.
Long name - NVIDIA nView Wizard.<br... |
Change status
|
| O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB More info about file dslagent.exe |
Dangerous |
Spyware related item according to inner database What is this? Please add more information here.
DSLAGENT.EXE is located in... |
Change status
|
| O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE More info about file soundman.exe |
Legitimate |
System item according to inner database Related to Realtek Avance Logic soundcards. SOUNDMAN.EXE provides system tray access to a varity of... |
Change status
|
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon More info about file dragdiag.exe |
Legitimate |
System item according to inner database System tray icon for Alcatel’s ADSL modems. |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit More info about file rundll32.exe |
Legitimate |
System item according to inner database Rundll32.exe loads and runs 32-bit DLLs. Rundll32.exe comes with all versions of Microsoft Windows.... |
Change status
|
| O4 - HKLM\..\Run: [EPSON Stylus Photo RX620 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9HE.EXE /P31 "EPSON Stylus Photo RX620 Series" /O6 "USB001" /M "Stylus Photo RX620" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent More info about file rundll32.exe |
Legitimate |
System item according to inner database Rundll32.exe loads and runs 32-bit DLLs. Rundll32.exe comes with all versions of Microsoft Windows.... |
Change status
|
| O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [MMTray] C:\PROGRA~1\MUSICM~1\MUSICM~2\mm_tray.exe More info about file mm_tray.exe |
Legitimate |
Application program item according to inner database Music Match Tray icon. Located in "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\". |
Change status
|
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" More info about file mmtask.exe |
Legitimate |
Application program item according to inner database Part of the Music Match Jukebox. Located in "C:\Program Files\MusicMatch\MusicMatch Jukebox\". A... |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
| O4 - HKLM\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -boot |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent More info about file steam.exe |
Legitimate |
Application program item according to inner database This file is a part of application that comes with most games, published by Valve Corporation. It... |
Change status
|
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Application program item according to inner database File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status
|
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe More info about file adobe gamma loader.exe |
Legitimate |
Application program item according to inner database From adobe: "The Adobe Gamma Control Panel is used to eliminate color casts in a monitor's display.... |
Change status
|
O4 - Startup: Karoo.lnk = E:\Start.exe More info about file start.exe |
Questionable |
Questionable item according to inner database start.exe is an executable file which primary purpose is to start a parasite or launch some of its... |
Change status
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
A part of Adobe Acrobat Reader. Used to speed up the program's launch time. |
Change status
|
| O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE More info about file osa.exe |
Legitimate |
Application program item according to inner database The Office Startup Assistant (Osa.exe or OSA) is a program that improves the performance of Office... |
Change status
|
| O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html |
Not necessary |
Do you want item 'Backward Links' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html |
Not necessary |
Do you want item 'Cached Snapshot of Page' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html |
Not necessary |
Do you want item 'Similar Pages' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html |
Not necessary |
Do you want item 'Translate Page into English' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'Minesweeper Flags Class' located in 'http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {4E330863-6A11-11D0-BFD8-006097237877} (InstallFromTheWeb ActiveX Control) - http://tw.msi.com.tw/autobios/client/iftwclix.cab |
Questionable |
Are you using an ActiveX object with a name 'InstallFromTheWeb ActiveX Control' located in 'http://tw.msi.com.tw/autobios/client/iftwclix.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab |
Questionable |
Are you using an ActiveX object with a name 'MessengerStatsClient Class' located in 'http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://E:\Resources\IntraLaunch.CAB |
Questionable |
Are you using an ActiveX object with a name 'IntraLaunch.MainControl' located in 'file://E:\Resources\IntraLaunch.CAB'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{CF127682-A382-4432-AFD8-96F110C4E3B2}: NameServer = 212.50.160.100 213.249.130.100 |
Questionable |
Do you recognize these IP addresses '212.50.160.100 213.249.130.100' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) |
Not necessary |
It is a protocol hijacker that points to nowhere. Fix this item. |
Change status
|
| O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll |
Unknown |
No exact entries found |
Change status
|
| O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll |
Legitimate |
Related to SpySweeper v 4.5 by Webroot |
Change status
|
| O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe |
Legitimate |
Required for PhotoshopCS |
Change status
|
| O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe |
Legitimate |
Related to Autodesk, Inc. |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe More info about file runservice.exe |
Dangerous |
Item found in 2-spyware.com database. eLicense, licensing system incorporated with some software... |
Change status
|
| O23 - Service: RaySat_3dsmax8 Server (mi-raysat_3dsmax8) - Unknown owner - C:\Program Files\Autodesk\3dsMax8\mentalray\satellite\raysat_3dsmax8server.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com database. NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status
|
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe More info about file starwindservice.exe |
Legitimate |
Item found in 2-spyware.com database. StarWindService.exe is a process which belongs to Alcohol 120% and provides network drive sharing... |
Change status
|