| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\csrss.exe More info about file csrss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Windows Defender\MsMpEng.exe More info about file msmpeng.exe |
Legitimate |
Item found in 2-spyware.com library Related to Windows Defender program. |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\WINDOWS\system32\acs.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com library File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status |
| C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe More info about file defwatch.exe |
Legitimate |
Item found in 2-spyware.com library This file is a standard component of Norton AntiVirus Corporate Edition application. Process... |
Change status |
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe More info about file rtvscan.exe |
Legitimate |
Item found in 2-spyware.com library File rtvscan.exe is an essential component of Norton AntiVirus application, published by Symantec... |
Change status |
| C:\WINDOWS\system32\ssoftsrv.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\alg.exe More info about file alg.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\wscntfy.exe More info about file wscntfy.exe |
Questionable |
Item found in 2-spyware.com library wscntfy.exe is an executable file that starts a malicious process, launches certain parasite... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\pctspk.exe More info about file pctspk.exe |
Legitimate |
Item found in 2-spyware.com library File pctspk.exe, started by an executable with the same name, is a part of the drivers for PCTEL... |
Change status |
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe More info about file syntplpr.exe |
Legitimate |
Item found in 2-spyware.com library Related to Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
created by:... |
Change status |
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe More info about file syntpenh.exe |
Legitimate |
Item found in 2-spyware.com library System tray access for Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
Change status |
|
| C:\Program Files\Panasonic\HotKey Appendix\HKEYAPP.EXE |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
Item found in 2-spyware.com library ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status |
C:\Program Files\Winamp\winampa.exe More info about file winampa.exe |
Legitimate |
Item found in 2-spyware.com library System tray icon for Winamp. |
Change status |
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe More info about file vptray.exe |
Legitimate |
Item found in 2-spyware.com library System tray icon for Norton Anti-Virus. Located in "C:\Program Files\NavNT\" |
Change status |
C:\Program Files\Common Files\Real\Update_OB\realsched.exe More info about file realsched.exe |
Legitimate |
Item found in 2-spyware.com library Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status |
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe More info about file issch.exe |
Legitimate |
Item found in 2-spyware.com library Executable issch.exe is a standard component of InstallShield software. It is used to connect to... |
Change status |
C:\Program Files\Windows Defender\MSASCui.exe More info about file msascui.exe |
Legitimate |
Item found in 2-spyware.com library
|
Change status |
C:\Program Files\Eraser1\eraser.exe More info about file eraser.exe |
Dangerous |
Item found in 2-spyware.com library eraser.exe is an executable file that is responsible for launching parasites, loading main... |
Change status |
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Item found in 2-spyware.com library File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status |
| C:\Program Files\ZyXEL\G-102v2\G-102v2.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\wuauclt.exe More info about file wuauclt.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Mozilla Firefox\firefox.exe More info about file firefox.exe |
Legitimate |
Item found in 2-spyware.com library File firefox.exe launches Mozilla Firefox web browser, implements user interface and controls all... |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe More info about file spysweeper.exe |
Legitimate |
Item found in 2-spyware.com library An executable file of SpySweeper anti-spyware program. |
Change status |
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe More info about file wrsssdk.exe |
Legitimate |
Item found in 2-spyware.com library Related to Spy Sweeper anti-spyware program. |
Change status |
C:\DOCUME~1\Delete\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3 /*http://www.yahoo.com/ext/search/search.html |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3 /*http://www.yahoo.com/ext/search/search.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com |
Not necessary |
yahoo.com is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com is your Default Search URL. If you do not like this fact, fix this item. |
Change status |
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3 /*http://www.yahoo.com/ext/search/search.html |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/sb/wdgt3 /*http://www.yahoo.com/ext/search/search.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/wdgt3/*http://www.yahoo.com |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/sp/wdgt3/*http://www.yahoo.com is your Search Page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com |
Not necessary |
yahoo.com is your start page. If you do not like this fact, fix this item. |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com |
Not necessary |
http://us.rd.yahoo.com/customize/ie/defaults/su/wdgt3/*http://www.yahoo.com is your default SearchURL. If you do not like this fact, fix this item. |
Change status |
| O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll |
Legitimate |
legitimate bho toolbar, related to SpyBot Search&Destroy |
Change status
|
O3 - Toolbar: Proxy - {98A7C97A-4FFF-4f6e-A313-D21BC759DD99} - C:\WINDOWS\tproxy.dll More info about file tproxy.dll |
Dangerous |
Spyware related item according to inner database tproxy.dll is a dynamically linked library. In simple phrase, it is an essential component of a... |
Change status
|
| O4 - HKLM\..\Run: [Hotkey] C:\WINDOWS\System32\hkeyman.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe More info about file pctspk.exe |
Legitimate |
System item according to inner database File pctspk.exe, started by an executable with the same name, is a part of the drivers for PCTEL... |
Change status
|
| O4 - HKLM\..\Run: [PCinfo] C:\Program Files\Panasonic\PCINFO\SetDiag.exe /FirstLogin |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe More info about file syntplpr.exe |
Legitimate |
System item according to inner database Related to Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
created by:... |
Change status
|
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe More info about file syntpenh.exe |
Legitimate |
System item according to inner database System tray access for Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".<br... |
Change status
|
| O4 - HKLM\..\Run: [Panasonic HotKey Manager] "C:\Program Files\Panasonic\HotKey Appendix\HKEYAPP.EXE" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe More info about file ati2mdxx.exe |
Legitimate |
System item according to inner database ATI 2D Mode component from ATI Technologies, Inc. Related to your graphics card. Located in... |
Change status
|
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe More info about file atiptaxx.exe |
Legitimate |
System item according to inner database ATI Desktop Control Panel from ATI Technologies, Inc. Located in "C:\Program Files\ATI... |
Change status
|
| O4 - HKLM\..\Run: [IP Changer 2.0] "C:\Program Files\Plustech Inc\IP Changer 2.0\IPChanger.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe More info about file winampa.exe |
Legitimate |
Application program item according to inner database System tray icon for Winamp. |
Change status
|
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe More info about file vptray.exe |
Legitimate |
Application program item according to inner database System tray icon for Norton Anti-Virus. Located in "C:\Program Files\NavNT\" |
Change status
|
| O4 - HKLM\..\Run: [SystemLock] C:\Program Files\r2 Studios\System Lock\SysLock.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot More info about file realsched.exe |
Legitimate |
Application program item according to inner database Related to Real-One player. Located in "C:\Program Files\Common Files\Real\Update_OB\". |
Change status
|
| O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup |
Legitimate |
InstallShield Automatic Updater |
Change status
|
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start More info about file issch.exe |
Legitimate |
Application program item according to inner database Executable issch.exe is a standard component of InstallShield software. It is used to connect to... |
Change status
|
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide More info about file msascui.exe |
Legitimate |
System item according to inner database
|
Change status
|
| O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser1\eraser.exe -hide More info about file eraser.exe |
Dangerous |
Spyware related item according to inner database eraser.exe is an executable file that is responsible for launching parasites, loading main... |
Change status
|
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe More info about file teatimer.exe |
Legitimate |
Application program item according to inner database File teatimer.exe is related to Spybot Search & Destroy spyware removal program. It runs background... |
Change status
|
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q More info about file swdoctor.exe |
Legitimate |
Application program item according to inner database Main component of Spyware Doctor, a popular anti-spyware program. |
Change status
|
| O4 - Global Startup: ZyXEL G-102v2 Utility.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
| O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present |
Questionable |
This item can be set only by administrator or by Spybot software. If you are administrator and you do not know anything about it, then fix this item. |
Change status
|
| O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present |
Questionable |
This item can be set only by administrator or by Spybot software. If you are administrator and you do not know anything about it, then fix this item. |
Change status
|
| O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html |
Not necessary |
Do you want item 'Backward Links' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html |
Not necessary |
Do you want item 'Cached Snapshot of Page' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm |
Not necessary |
Do you want item 'Download all by Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm |
Not necessary |
Do you want item 'Download by Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm |
Not necessary |
Do you want item 'Download selected by Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm |
Not necessary |
Do you want item 'Download web site by Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Liatro SWF Decoder Catch - C:\Program Files\Liatro\Liatro SWF Tools 5.0\swfcatch.htm |
Not necessary |
Do you want item 'Liatro SWF Decoder Catch' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html |
Not necessary |
Do you want item 'Similar Pages' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html |
Not necessary |
Do you want item 'Translate Page into English' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'ieSpell' and points to file 'C:\Program Files\ieSpell\iespell.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'ieSpell' and points to file 'C:\Program Files\ieSpell\iespell.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\ieSpell\iespell.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'ieSpell Options' and points to file 'C:\Program Files\ieSpell\iespell.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Windows Messenger' and points to file 'C:\Program Files\Messenger\msmsgs.exe'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://www.virtualapple.org/activegs.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: Yahoo! Graffiti - http://download.games.yahoo.com/games/clients/y/grt5_x.cab |
Questionable |
Are you using an ActiveX object with no name located in 'http://download.games.yahoo.com/games/clients/y/grt5_x.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab |
Questionable |
Are you using an ActiveX object with a name 'System Requirements Lab' located in 'http://www.systemrequirementslab.com/sysreqlab.cab'? If not, fix this item. |
Change status
|
| O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll |
Legitimate |
Related to Norton AntiVirus |
Change status
|
| O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll |
Legitimate |
Related to SpySweeper v 4.5 by Webroot |
Change status
|
| O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe |
Legitimate |
related to Atheros Wireless LAN |
Change status
|
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe More info about file ati2evxx.exe |
Legitimate |
Item found in 2-spyware.com database. File ati2evxx.exe, which starts a process with the same name, is the standard component of video... |
Change status
|
| O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe |
Legitimate |
Related to Autodesk, Inc. |
Change status
|
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe More info about file defwatch.exe |
Legitimate |
Item found in 2-spyware.com database. This file is a standard component of Norton AntiVirus Corporate Edition application. Process... |
Change status
|
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe More info about file rtvscan.exe |
Legitimate |
Item found in 2-spyware.com database. File rtvscan.exe is an essential component of Norton AntiVirus application, published by Symantec... |
Change status
|
| O23 - Service: Cryptainer service (ssoftservice) - Cypherix - C:\WINDOWS\SYSTEM32\ssoftsrv.exe |
Legitimate |
Owner:Cypherix Cypherix Encryption Software |
Change status
|
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe More info about file wrsssdk.exe |
Legitimate |
Item found in 2-spyware.com database. Related to Spy Sweeper anti-spyware... |
Change status
|