| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe More info about file aswupdsv.exe |
Legitimate |
Item found in 2-spyware.com library Related to Avast anti-virus software. |
Change status |
C:\Program Files\Alwil Software\Avast4\ashServ.exe More info about file ashserv.exe |
Legitimate |
Item found in 2-spyware.com library ashServ.exe is a process related to Avast anti-virus software. It should not be disabled to ensure... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe More info about file aolacsd.exe |
Legitimate |
Item found in 2-spyware.com library This is a standard component of AOL 9.0 Internet connection software. File aolacsd.exe is required... |
Change status |
C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe More info about file btwdins.exe |
Legitimate |
Item found in 2-spyware.com library btwdins.exe is used when bluetooth device is installed. |
Change status |
C:\WINDOWS\system32\CTsvcCDA.exe More info about file ctsvccda.exe |
Legitimate |
Item found in 2-spyware.com library Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some... |
Change status |
| C:\Program Files\Creative\Shared Files\CTDevSrv.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\slserv.exe More info about file slserv.exe |
Legitimate |
Item found in 2-spyware.com library Installed alongside Smartlink communication software for modems. It is a tool that displays the... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\WINDOWS\system32\keyhook.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe More info about file ashmaisv.exe |
Legitimate |
Item found in 2-spyware.com library Related to Avast anti-virus software. |
Change status |
C:\Apps\Powercinema\PCMService.exe More info about file pcmservice.exe |
Legitimate |
Item found in 2-spyware.com library From Dell: "The Dell Media Experience (DME) will ship on selected Dimension and Inspiron systems... |
Change status |
| C:\apps\ABoard\ABoard.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe More info about file ashdisp.exe |
Legitimate |
Item found in 2-spyware.com library Avast Anti virus |
Change status |
| C:\apps\ABoard\AOSD.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe More info about file hpwuschd2.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Hewlett Packard software. |
Change status |
| C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe More info about file ashwebsv.exe |
Legitimate |
Item found in 2-spyware.com library Related to Avast anti-virus software. |
Change status |
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Belkin\Bluetooth Software\BTTray.exe More info about file bttray.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to Widcomm‘s bluetooth software. |
Change status |
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe More info about file hpqtra08.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of Hewlett-Packard device drivers. It is also included in other HP... |
Change status |
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe More info about file hpqste08.exe |
Legitimate |
Item found in 2-spyware.com library The file is related to HP software. |
Change status |
| C:\Program Files\MSN Messenger\usnsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\WISPTIS.EXE More info about file wisptis.exe |
Legitimate |
Item found in 2-spyware.com library The Microsoft Tablet PC component providing support for a pen input device for the Microsoft Tablet... |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\MSN Messenger\msnmsgr.exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe More info about file mwsoemon.exe |
Dangerous |
Item found in 2-spyware.com library This is a part of an adware application, published by WebSearch. This program displays commercial... |
Change status |
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\HijackThis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ |
Legitimate |
http://www.google.co.uk/ is your start page. This is a legitimate page. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=54896 is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 |
Not necessary |
http://go.microsoft.com/fwlink/?LinkId=69157 is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.aol.co.uk/web?isinit=true&query=%s |
Not necessary |
http://search.aol.co.uk/web?isinit=true&query=%s is your default SearchURL. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell |
Not necessary |
Packard Bell is the title in your Internet Explorer window. If you do not like this fact, fix this item. |
Change status |
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll More info about file ssv.dll |
Legitimate |
System item according to inner database Related to Java Virtual Machine software, which is legitimate. |
Change status
|
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 More info about file imjpmig.exe |
Legitimate |
System item according to inner database Related to Windows East Asian language support (Japanese keyboard entry). Located in... |
Change status
|
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
| O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" More info about file pcmservice.exe |
Legitimate |
System item according to inner database From Dell: "The Dell Media Experience (DME) will ship on selected Dimension and Inspiron systems... |
Change status
|
| O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe More info about file ashdisp.exe |
Legitimate |
Related to Avast anti-virus software. |
Change status
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe More info about file hpwuschd2.exe |
Legitimate |
Application program item according to inner database The file is related to Hewlett Packard software. |
Change status
|
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" More info about file reader_sl.exe |
Legitimate |
Application program item according to inner database Related to Adobe Acrobat Reader. |
Change status
|
| O4 - HKLM\..\RunOnce: [MyWebSearch bar Uninstall] rundll32 C:\PROGRA~1\UNINST~1.DLL,O -3 |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - HKCU\..\Run: [CTZDetec.exe] C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - Global Startup: Bluetooth.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe More info about file hpqtra08.exe |
Legitimate |
Application program item according to inner database This is a legitimate component of Hewlett-Packard device drivers. It is also included in other HP... |
Change status
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Research' and points to file 'C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm |
Not necessary |
This item represents extra button in your IE toolbar with a name '@btrez.dll,-4015' and points to file 'C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name '@btrez.dll,-4017' and points to file 'C:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Real.com' and points to file 'C:\WINDOWS\system32\Shdocvw.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O11 - Options group: [INTERNATIONAL] International* |
Questionable |
This item represents a group added to Advanced Options tab in IE Tools > Internet Options menu. Should the item called "INTERNATIONAL" be there? If not, fix it. |
Change status
|
| O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm |
Questionable |
This item changes your "default" Start page in IE. It will appear if you Restore default web settings. If you are an administrator and you do not recognize address "", fix this item. |
Change status
|
| O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15031/CTSUEng.cab |
Questionable |
Are you using an ActiveX object with a name 'Creative Software AutoUpdate' located in 'http://www.creative.com/su/ocx/15031/CTSUEng.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab |
Questionable |
Are you using an ActiveX object with a name 'Checkers Class' located in 'http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab |
Questionable |
Are you using an ActiveX object with a name 'MessengerStatsClient Class' located in 'http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab |
Questionable |
Are you using an ActiveX object with a name 'Minesweeper Flags Class' located in 'http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15031/CTPID.cab |
Questionable |
Are you using an ActiveX object with a name 'Creative Software AutoUpdate Support Package' located in 'http://www.creative.com/su/ocx/15031/CTPID.cab'? If not, fix this item. |
Change status
|
| O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "livecall" and file "C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL". |
Change status
|
| O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "ms-help" and file "C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll". |
Change status
|
| O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "msnim" and file "C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL". |
Change status
|
| O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "text/xml" and file "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL". |
Change status
|
| O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll |
Legitimate |
windows check |
Change status
|
| O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll |
Legitimate |
The file belongs to WMP11 Beta application. |
Change status
|
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe More info about file aolacsd.exe |
Legitimate |
Item found in 2-spyware.com database. This is a standard component of AOL 9.0 Internet connection software. File aolacsd.exe is required... |
Change status
|
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe More info about file aswupdsv.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Avast anti-virus... |
Change status
|
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe More info about file ashserv.exe |
Legitimate |
Item found in 2-spyware.com database. ashServ.exe is a process related to Avast anti-virus software. It should not be disabled to ensure... |
Change status
|
| O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
| O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe More info about file btwdins.exe |
Legitimate |
Item found in 2-spyware.com database. btwdins.exe is used when bluetooth device is... |
Change status
|
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe More info about file ctsvccda.exe |
Legitimate |
Item found in 2-spyware.com database. Creative CD-ROM Services tool, started by ctsvccda.exe executable, is a common component of some... |
Change status
|
| O23 - Service: CT Device Query service (CTDevice_Srv) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTDevSrv.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe More info about file hpzipm12.exe |
Legitimate |
Item found in 2-spyware.com database. This is a standard component of Hewlett-Packard device drivers. The presence of this file means,... |
Change status
|
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe More info about file slserv.exe |
Legitimate |
Item found in 2-spyware.com database. Installed alongside Smartlink communication software for modems. It is a tool that displays the... |
Change status
|