| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\csrss.exe More info about file csrss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\alg.exe More info about file alg.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft products. avgamsvr.exe is legitimate. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\Spyware Doctor\sdhelp.exe More info about file sdhelp.exe |
Legitimate |
Item found in 2-spyware.com library A part of Spyware Doctor, a popular legitimate anti-spyware program. |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe More info about file avgcc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\Yahoo!\Messenger\ypager.exe More info about file ypager.exe |
Legitimate |
Item found in 2-spyware.com library Related to Yahoo Messenger. Located in "C:\PROGRA~1\Yahoo!\MESSEN~1\". File ypager.exe is related... |
Change status |
C:\Program Files\AIM\aim.exe More info about file aim.exe |
Legitimate |
Item found in 2-spyware.com library AOL Instant Messenger. Located in "C:Program FilesAIM95". File aim.exe is related to trojan AIM... |
Change status |
C:\Program Files\Spyware Doctor\swdoctor.exe More info about file swdoctor.exe |
Legitimate |
Item found in 2-spyware.com library Main component of Spyware Doctor, a popular anti-spyware program. |
Change status |
| C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Documents and Settings\baddgirl\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll |
Legitimate |
legitimate bho toolbar, related to PCTools Spyware Doctor |
Change status
|
| O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll |
Legitimate |
legitimate bho toolbar, related to PCTools Spyware Doctor |
Change status
|
| O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\System32\hp27AD.tmp |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP More info about file avgcc.exe |
Legitimate |
System item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe More info about file avgemc.exe |
Legitimate |
Application program item according to inner database It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe More info about file nerocheck.exe |
Legitimate |
Application program item according to inner database Related to Nero CD/DVD Burning software. From the publisher: "This program constantly checks for... |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet More info about file ypager.exe |
Legitimate |
Application program item according to inner database Related to Yahoo Messenger. Located in "C:\PROGRA~1\Yahoo!\MESSEN~1\". File ypager.exe is related... |
Change status
|
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl More info about file aim.exe |
Legitimate |
Application program item according to inner database AOL Instant Messenger. Located in "C:Program FilesAIM95". File aim.exe is related to trojan AIM... |
Change status
|
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q More info about file swdoctor.exe |
Legitimate |
Application program item according to inner database Main component of Spyware Doctor, a popular anti-spyware program. |
Change status
|
| O4 - Startup: PowerReg Scheduler V3.exe |
Questionable |
Startup - link: 'PowerReg Scheduler V3.exe', file: '' |
Change status
|
| O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe |
Questionable |
questionable item according to our database |
Change status
|
| O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Spyware Doctor' and points to file 'C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'AIM' and points to file 'C:\Program Files\AIM\aim.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing) |
Not necessary |
This item represents extra button in your IE toolbar with a name 'PartyCasino.com' and points to file 'C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing) |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'PartyCasino.com' and points to file 'C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'PartyPoker.com' and points to file 'C:\Program Files\PartyGaming\PartyPoker\RunApp.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'PartyPoker.com' and points to file 'C:\Program Files\PartyGaming\PartyPoker\RunApp.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Yahoo! Messenger' and points to file 'C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Yahoo! Messenger' and points to file 'C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.bigfishgames.com/online/chainz2/mjolauncher.cab |
Questionable |
Are you using an ActiveX object with a name 'MJLauncherCtrl Class' located in 'http://www.bigfishgames.com/online/chainz2/mjolauncher.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {87056D28-9730-4A47-B9F9-7E890B62C58A} (WildfireActiveXHost Class) - http://www.iwin.com/global/premium/gamehouse/tumblebugs/axhost.cab |
Questionable |
Are you using an ActiveX object with a name 'WildfireActiveXHost Class' located in 'http://www.iwin.com/global/premium/gamehouse/tumblebugs/axhost.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab |
Questionable |
Are you using an ActiveX object with a name 'ZoneIntro Class' located in 'http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://www.iwin.com/global/premium/zylom/caramba/zylomgamesplayer.cab |
Questionable |
Are you using an ActiveX object with a name 'Zylom Games Player' located in 'http://www.iwin.com/global/premium/zylom/caramba/zylomgamesplayer.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.iwin.com/global/premium/popcap/popcaploader_v6.cab |
Questionable |
Are you using an ActiveX object with a name 'PopCapLoader Object' located in 'http://download.iwin.com/global/premium/popcap/popcaploader_v6.cab'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{232F0683-47C9-41C5-AE47-B8D91FA2D32B}: NameServer = 205.208.227.13 205.208.227.14 |
Questionable |
Do you recognize these IP addresses '205.208.227.13 205.208.227.14' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CS1\Services\Tcpip\..\{232F0683-47C9-41C5-AE47-B8D91FA2D32B}: NameServer = 205.208.227.13 205.208.227.14 |
Questionable |
Do you recognize these IP addresses '205.208.227.13 205.208.227.14' as your internet provider DNS servers? If not, fix this item. |
Change status
|
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe More info about file avgamsvr.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe More info about file avgupsvc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe |
Legitimate |
Kodak Software to connect digital cameras |
Change status
|
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe More info about file sdhelp.exe |
Legitimate |
Item found in 2-spyware.com database. A part of Spyware Doctor, a popular legitimate anti-spyware... |
Change status
|