| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe More info about file smagent.exe |
Legitimate |
Item found in 2-spyware.com library SoundMAX Agent. Related to drivers for various sound cards and similar devices. |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\AGRSMMSG.exe More info about file agrsmmsg.exe |
Legitimate |
Item found in 2-spyware.com library Modem software from Agere.com. AGRSMMSG.exe is located in "C:\WINDOWS\" on Windows 95/98/ME/XP and... |
Change status |
C:\Program Files\Apoint2K\Apoint.exe More info about file apoint.exe |
Legitimate |
Item found in 2-spyware.com library Alps Pointing-device Driver. Touch-pad related. Located in "C:\Program Files\Apoint\apoint.exe". |
Change status |
C:\WINDOWS\system32\igfxtray.exe More info about file igfxtray.exe |
Legitimate |
Item found in 2-spyware.com library From a user: I just(hours ago) installed some newer Intel graphics drivers in my system(82810E),... |
Change status |
C:\WINDOWS\system32\hkcmd.exe More info about file hkcmd.exe |
Legitimate |
Item found in 2-spyware.com library Hotkey Command Module for Intel Graphics Contollers. Located in "C:\WINNT\System32\" on Windows... |
Change status |
| C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\Program Files\QuickTime\qttask.exe More info about file qttask.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status |
| C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
| C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\Common Files\AOL\1146292273\ee\AOLSoftware.exe More info about file aolsoftware.exe |
Legitimate |
Item found in 2-spyware.com library Related to legitimate America Online software |
Change status |
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe More info about file viewmgr.exe |
Legitimate |
Item found in 2-spyware.com library This is a part of media player, which can act as an adware program. This player appears to be a... |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
C:\Program Files\Apoint2K\Apntex.exe More info about file apntex.exe |
Legitimate |
Item found in 2-spyware.com library Alps Pointing-device Driver. Touch-pad related. Located in "C:\Program Files\Apoint\". |
Change status |
| C:\Program Files\HPQ\shared\hpqwmi.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Internet Explorer\IEXPLORE.EXE More info about file iexplore.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\DOCUME~1\Ryan\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/ |
Not necessary |
http://yahoo.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.hp.com |
Not necessary |
http://www.hp.com is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/ |
Not necessary |
http://yahoo.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.hp.com/ |
Not necessary |
http://www.hp.com/ is related to your Internet Connection Wizard. If you do not like this fact, fix this item. |
Change status |
| O1 - Hosts: localhost 127.0.0.1 |
Questionable |
Do you want an URL address "127.0.0.1" to be redirected to "localhost" when you type it? If not, then fix this |
|
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 More info about file imjpmig.exe |
Legitimate |
System item according to inner database Related to Windows East Asian language support (Japanese keyboard entry). Located in... |
Change status
|
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
| O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe |
Questionable |
questionable item according to our database |
Change status
|
| O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe More info about file agrsmmsg.exe |
Legitimate |
System item according to inner database Modem software from Agere.com. AGRSMMSG.exe is located in "C:\WINDOWS\" on Windows 95/98/ME/XP and... |
Change status
|
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe More info about file apoint.exe |
Legitimate |
Driver related item according to inner database. Alps Pointing-device Driver. Touch-pad related. Located in "C:\Program Files\Apoint\apoint.exe". |
Change status
|
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe More info about file igfxtray.exe |
Legitimate |
System item according to inner database From a user: I just(hours ago) installed some newer Intel graphics drivers in my system(82810E),... |
Change status
|
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe More info about file hkcmd.exe |
Legitimate |
System item according to inner database Hotkey Command Module for Intel Graphics Contollers. Located in "C:\WINNT\System32\" on Windows... |
Change status
|
| O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe |
Questionable |
questionable item according to our database |
Change status
|
| O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
| O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
| O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1146292273\ee\AOLSoftware.exe More info about file aolsoftware.exe |
Legitimate |
Application program item according to inner database Related to legitimate America Online software |
Change status
|
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe More info about file viewmgr.exe |
Legitimate |
Application program item according to inner database This is a part of media player, which can act as an adware program. This player appears to be a... |
Change status
|
| O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com |
Questionable |
This item changes your "default" Start page in IE. It will appear if you Restore default web settings. If you are an administrator and you do not recognize address "", fix this item. |
Change status
|
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls /en/x86/client/wuweb_site.cab?1147362023000 |
Questionable |
Are you using an ActiveX object with a name 'WUWebControl Class' located in 'http://update.microsoft.com/windowsupdate/v6/V5Controls /en/x86/client/wuweb_site.cab?1147362023000'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{2A3B871F-9523-4AF3-96D3-F9DE2B0C7353}: NameServer = 85.255.114.23,85.255.112.220 |
Questionable |
Do you recognize these IP addresses '85.255.114.23,85.255.112.220' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{F0B8AEDF-EFD2-43E6-897D-22C4E69E5ED3}: NameServer = 85.255.114.23,85.255.112.220 |
Questionable |
Do you recognize these IP addresses '85.255.114.23,85.255.112.220' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll |
Legitimate |
Related to Intel(R) integrated graphics controller |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe |
Legitimate |
Related to Hewlett-Packard |
Change status
|
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe More info about file smagent.exe |
Legitimate |
Item found in 2-spyware.com database. SoundMAX Agent. Related to drivers for various sound cards and similar... |
Change status
|