| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Avira\AntiVir Desktop\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com library Scheduler for AntiVir Anti Virus program. |
Change status |
C:\Program Files\Avira\AntiVir Desktop\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com library avguard.exe stands for AntiVir real-time protection process. Do not terminate it. |
Change status |
C:\WINDOWS\system32\Atievxx.exe More info about file atievxx.exe |
Legitimate |
Item found in 2-spyware.com library This is a standard component of ATI video card drivers. File atievxx.exe is responsible for... |
Change status |
C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com library The file belongs to Bonjour for Windows application. |
Change status |
| C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Maxtor\Sync\SyncServices.exe More info about file syncservices.exe |
Legitimate |
Item found in 2-spyware.com library SyncServices.exe is related to the SyncServices application. Do not terminate this process. |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\WINDOWS\system32\SearchIndexer.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Java\jre6\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe More info about file avgnt.exe |
Legitimate |
Item found in 2-spyware.com library avgnt.exe is a security process that is associated with the Avira Internet Security Suite, which... |
Change status |
| C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\Documents and Settings\dolphin\Application Data\Google\Update\GoogleUpdate.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe More info about file hpotdd01.exe |
Legitimate |
Item found in 2-spyware.com library This file is a standard part of Hewlett-Packard software, which is used to manipulate digital... |
Change status |
| C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Sprint\Sprint SmartView\bmctl.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dogpile.com/info.dogpl.toolbar/dog/forms/search.htm |
Not necessary |
http://www.dogpile.com/info.dogpl.toolbar/dog/forms/search.htm is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.dogpile.com/info.dogpl/ |
Not necessary |
http://www.dogpile.com/info.dogpl/ is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dogpile.com/info.dogpl.toolbar/dog/forms/search.htm |
Not necessary |
http://www.dogpile.com/info.dogpl.toolbar/dog/forms/search.htm is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.dogpile.com/info.dogpl.toolbar/dog/forms/search.htm |
Not necessary |
http://www.dogpile.com/info.dogpl.toolbar/dog/forms/search.htm is your Search Assistant. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.dogpile.com/info.dogpl.toolbar/ |
Not necessary |
http://www.dogpile.com/info.dogpl.toolbar/ is your default SearchURL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.dogpile.com/info.dogpl.toolbar/ |
Not necessary |
. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>;*.local |
Not necessary |
127.0.0.1;<local>;*.local overrides your Proxy Server. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll More info about file jp2ssv.dll |
Legitimate |
System item according to inner database
|
Change status
|
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll More info about file jqs_plugin.dll |
Legitimate |
System item according to inner database
|
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min More info about file avgnt.exe |
Legitimate |
Application program item according to inner database avgnt.exe is a security process that is associated with the Avira Internet Security Suite, which... |
Change status
|
O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe More info about file conime.exe |
Dangerous |
Spyware related item according to inner database File conime.exe is a part of BFGhost backdoor. It can steal your personal documents, account... |
Change status
|
| O4 - HKLM\..\Run: [EKIJ5000StatusMonitor] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Sprint SmartView] "C:\Program Files\Sprint\Sprint SmartView\SprintSV.exe" -a |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [RDVCHG] "C:\Program Files\Sprint\Sprint SmartView\RDVCHG.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\dolphin\Application Data\Google\Update\GoogleUpdate.exe" /c |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKUS\S-1-5-18\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User ''SYSTEM'') |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User ''SYSTEM'') |
Unknown |
No exact entries found |
Change status
|
| O4 - HKUS\.DEFAULT\..\RunOnce: [Printing Migration] rundll32.exe C:\WINDOWS\System32\spool\migrate.dll,ProcessWin9xNetworkPrinters (User ''Default user'') |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - Startup: AutorunsDisabled |
Questionable |
Startup - link: 'AutorunsDisabled', file: '' |
Change status
|
| O4 - Global Startup: hpoddt01.exe.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
| O9 - Extra button: (no name) - AutorunsDisabled - (no file) |
Not necessary |
Fix this item. It represents extra button in your IE toolbar and points to file that doesn't exist. |
Change status
|
| O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Bonjour' and points to file 'C:\Program Files\Bonjour\ExplorerPlugin.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name '@xpsp3res.dll,-20001' and points to file 'C:\WINDOWS\Network Diagnostic\xpnetdiag.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O9 - Extra button: (no name) - AutorunsDisabled - (no file) (HKCU) |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file '(no file) (HKCU)'. If you do not want it to be there, fix this item. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: bmnet.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: bmnet.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: bmnet.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1235169715668 |
Legitimate |
Legitimate ActiveX item from site http://update.microsoft.com/ |
Change status
|
| O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab'? If not, fix this item. |
Change status
|
| O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll |
Unknown |
No exact entries found |
Change status
|
| O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll |
Unknown |
No exact entries found |
Change status
|
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe More info about file sched.exe |
Legitimate |
Item found in 2-spyware.com database. Scheduler for AntiVir Anti Virus... |
Change status
|
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe More info about file avguard.exe |
Legitimate |
Item found in 2-spyware.com database. avguard.exe stands for AntiVir real-time protection process. Do not terminate it.... |
Change status
|
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe More info about file mdnsresponder.exe |
Legitimate |
Item found in 2-spyware.com database. The file belongs to Bonjour for Windows... |
Change status
|
| O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe |
Legitimate |
Related to Macrovision Corporation. |
Change status
|
| O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: Kodak AiO Network Discovery Service - Eastman Kodak Company - C:\Program Files\Kodak\AiO\Center\ekdiscovery.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe More info about file syncservices.exe |
Legitimate |
Item found in 2-spyware.com database. SyncServices.exe is related to the SyncServices application. Do not terminate this process.... |
Change status
|
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe More info about file hpzipm12.exe |
Legitimate |
Item found in 2-spyware.com database. This is a standard component of Hewlett-Packard device drivers. The presence of this file means,... |
Change status
|
| O23 - Service: Sprint RcAppSvc (SprintRcAppSvc) - SmithMicro Inc. - C:\Program Files\Sprint\Sprint SmartView\RcAppSvc.exe |
Unknown |
No exact entries found |
Insert file into database
|