| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
|
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe More info about file aawservice.exe |
Legitimate |
Item found in 2-spyware.com library
|
Change status |
C:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com library This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\LEXPPS.EXE More info about file lexpps.exe |
Legitimate |
Item found in 2-spyware.com library This file is related to Lexmark Printer Port Scanner utility, it is a standard component of the... |
Change status |
| C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgfws8.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\gearsec.exe More info about file gearsec.exe |
Legitimate |
Item found in 2-spyware.com library It is a driver for CD-RW, released by GEAR software and... |
Change status |
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe More info about file mdm.exe |
Legitimate |
Item found in 2-spyware.com library mdm.exe is a system process - Machine Debug Manager. Used by developers. Located in "C:\PROGRAM... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com library NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status |
| C:\Program Files\M-Audio\Ozone\Install\ozinst.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\tcpsvcs.exe More info about file tcpsvcs.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft TCP/IP Services, represented by tcpsvcs.exe file, are included in Windows NT 4/2000/XP... |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgam.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgrsx.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\PROGRA~1\AVG\AVG8\avgnsx.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\PROGRA~1\AVG\AVG8\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com library It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Dell\Support\Alert\bin\DAMon.exe More info about file damon.exe |
Legitimate |
Item found in 2-spyware.com library Dell Alert Monitor, started by damon.exe executable, is a common component of the Dell Support... |
Change status |
| C:\Program Files\Xerox\NWWia\XrxFTPLt.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\WINDOWS\system32\WDBtnMgr.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe More info about file jusched.exe |
Legitimate |
Item found in 2-spyware.com library Checks if there are new versions of Java available. |
Change status |
C:\Program Files\Winamp\Winampa.exe More info about file winampa.exe |
Legitimate |
Item found in 2-spyware.com library winampa.exe is represented by a system tray icon and stands for Winamp player agent. |
Change status |
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe More info about file directcd.exe |
Legitimate |
Item found in 2-spyware.com library directcd.exe is an application process used by Roxio's Easy CD/DVD Creator when burning a CD or a... |
Change status |
| C:\PROGRA~1\AVG\AVG8\avgtray.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe More info about file hpwuschd2.exe |
Legitimate |
Item found in 2-spyware.com library hpwuschd2.exe is a legitimate process related to Hewlett Packard software. |
Change status |
| C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerMonitor.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe More info about file easyshare.exe |
Legitimate |
Item found in 2-spyware.com library easyshare.exe is related to Kodak camera software. |
Change status |
C:\Program Files\QUICKENW\QWDLLS.EXE More info about file qwdlls.exe |
Legitimate |
Item found in 2-spyware.com library This is a part of Intuit Quicken finance suite. Executable qwdlls.exe is used to launch essential... |
Change status |
| C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\MagicDisc\MagicDisc.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Documents and Settings\jakjas\\Desktop\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com |
Not necessary |
http://www.dellnet.com is your Default Page URL. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.daemonsearch.com/ |
Not necessary |
http://google.daemonsearch.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/sbcydsl/defaults /sb/*http://www.yahoo.com/search/ie.html |
Not necessary |
http://rd.yahoo.com/customize/sbcydsl/defaults /sb/*http://www.yahoo.com/search/ie.html is your Search Bar. If you do not like this fact, fix this item. |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl |
Not necessary |
http://yahoo.sbc.com/dsl is your start page. If you do not like this fact, fix this item. |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = |
Not necessary |
Fix this item because it points to nowhere |
Change status |
| R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dellnet.com/ |
Not necessary |
http://www.dellnet.com/ is related to your Internet Connection Wizard. If you do not like this fact, fix this item. |
Change status |
| O1 - Hosts: 85.17.40.71 |
Questionable |
Do you want an URL address "" to be redirected to "85.17.40.71" when you type it? If not, then fix this |
|
| O1 - Hosts: 85.17.40.69 |
Questionable |
Do you want an URL address "" to be redirected to "85.17.40.69" when you type it? If not, then fix this |
|
| O1 - Hosts: 85.17.40.70 |
Questionable |
Do you want an URL address "" to be redirected to "85.17.40.70" when you type it? If not, then fix this |
|
| O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll |
Unknown |
No exact entries found |
Insert file into database
|
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll More info about file acroiehelper.dll |
Legitimate |
Application program item according to inner database File related to Adobe Acrobat Reader program. |
Change status
|
| O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerIE.dll |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: (no name) - {562BA4FA-FB03-4954-9E78-6EB0D3304724} - (no file) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll More info about file ssv.dll |
Legitimate |
System item according to inner database Related to Java Virtual Machine software, which is legitimate. |
Change status
|
| O2 - BHO: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL |
Unknown |
No exact entries found |
Insert file into database
|
| O2 - BHO: (no name) - {C88B64DA-A23E-D19E-11E0-AA8F04257BCC} - C:\WINDOWS\system32\cuxadf.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll More info about file iefdmcks.dll |
Legitimate |
Application program item according to inner database free download manager hook to IE, so when downloading in IE, the download will be taken over by FDM |
Change status
|
| O2 - BHO: (no name) - {ED1B0922-BCED-4BED-B42F-2D87F350DBC3} - C:\WINDOWS\system32\ddccbbyy.dll (file missing) |
Not necessary |
Fix this item, because it points to file that cannot be found |
Change status
|
| O3 - Toolbar: AVGTOOLBAR - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup More info about file nvcpl.dll |
Legitimate |
System item according to inner database Related to nVidia cards. NvCpl.dll is located in "C:\WINDOWS\SYSTEM\" on Windows 95/98/ME,... |
Change status
|
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe More info about file cfd.exe |
Legitimate |
Application program item according to inner database Related to BroadJump Client Foundation - broadband troubleshooting software installed by some ISPs. |
Change status
|
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe More info about file damon.exe |
Legitimate |
Application program item according to inner database Dell Alert Monitor, started by damon.exe executable, is a common component of the Dell Support... |
Change status
|
| O4 - HKLM\..\Run: [XeroxScannerDaemon] C:\Program Files\Xerox\NWWia\XrxFTPLt.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install More info about file nwiz.exe |
Legitimate |
System item according to inner database Nwiz.exe is Related to nVidia graphic cards drivers. Full name - NVIDIA nView Wizard.<br... |
Change status
|
| O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
| O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" More info about file jusched.exe |
Legitimate |
Application program item according to inner database Checks if there are new versions of Java available. |
Change status
|
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe" More info about file winampa.exe |
Legitimate |
Application program item according to inner database winampa.exe is represented by a system tray icon and stands for Winamp player agent. |
Change status
|
| O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" More info about file directcd.exe |
Legitimate |
Application program item according to inner database directcd.exe is an application process used by Roxio's Easy CD/DVD Creator when burning a CD or a... |
Change status
|
| O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe More info about file hpwuschd2.exe |
Legitimate |
Application program item according to inner database hpwuschd2.exe is a legitimate process related to Hewlett Packard software. |
Change status
|
| O4 - HKLM\..\Run: [LinkScanner Monitor] C:\Program Files\ExPLabs.com\LinkScanner\LinkScannerMonitor.exe /auto |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
| O4 - Startup: Anapod Manager.lnk = C:\Program Files\Red Chair Software\Anapod Explorer\anamgr.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe More info about file adobe gamma loader.exe |
Legitimate |
Application program item according to inner database From adobe: "The Adobe Gamma Control Panel is used to eliminate color casts in a monitor's display.... |
Change status
|
| O4 - Global Startup: Adobe Gamma Loader.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe More info about file reader_sl.exe |
Legitimate |
A part of Adobe Acrobat Reader. Used to speed up the program's launch time. |
Change status
|
| O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE |
Questionable |
questionable item according to our database |
Change status
|
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe More info about file easyshare.exe |
Legitimate |
Application program item according to inner database easyshare.exe is related to Kodak camera software. |
Change status
|
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE More info about file qwdlls.exe |
Legitimate |
Application program item according to inner database This is a part of Intuit Quicken finance suite. Executable qwdlls.exe is used to launch essential... |
Change status
|
| O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm |
Not necessary |
Do you want item 'Download all with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm |
Not necessary |
Do you want item 'Download selected with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm |
Not necessary |
Do you want item 'Download with Free Download Manager' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Sun Java Console' and points to file 'C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Yahoo! Login' and points to file 'C:\Program Files\Yahoo!\common\ylogin.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\common\ylogin.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Yahoo! Login' and points to file 'C:\Program Files\Yahoo!\common\ylogin.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'HP Clipbook' and points to file 'C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll |
Not necessary |
This item represents extra button in your IE toolbar with a name 'HP Smart Select' and points to file 'C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) |
Not necessary |
Fix this item. It represents extra button in your IE toolbar and points to file that doesn't exist. |
Change status
|
| O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll |
Not necessary |
This item represents extra button in your IE toolbar without name and points to file 'C:\Program Files\Spybot'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Spybot' and points to file '{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra button in your browser - related to windows messenger. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe |
Legitimate |
Legitimate extra tools menu item - related to Windows Messenger. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\program files\explabs.com\linkscanner\wrnetdrv.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\program files\explabs.com\linkscanner\wrnetdrv.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\program files\explabs.com\linkscanner\wrnetdrv.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\program files\explabs.com\linkscanner\wrnetdrv.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\program files\explabs.com\linkscanner\wrnetdrv.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O10 - Unknown file in Winsock LSP: c:\program files\explabs.com\linkscanner\wrnetdrv.dll |
Questionable |
This item represents actions of so-called Layered Service Provider. It can be legitimate item or spyware. Be careful fixing it, because you can lose your internet connection. Find more information in Google or use a program called LSPFix. |
Change status
|
| O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll |
Legitimate |
This item represents a plugin added to Internet Explorer to work with '.spop' files. Seems to be safe, unless you know that it is malicious. |
Change status
|
| O15 - Trusted Zone: *.amaena.com |
Questionable |
Do you want URL pattern "*.amaena.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.avsystemcare.com |
Questionable |
Do you want URL pattern "*.avsystemcare.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.gomyhit.com |
Questionable |
Do you want URL pattern "*.gomyhit.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.imageservr.com |
Questionable |
Do you want URL pattern "*.imageservr.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.imagesrvr.com |
Questionable |
Do you want URL pattern "*.imagesrvr.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.onerateld.com |
Questionable |
Do you want URL pattern "*.onerateld.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.safetydownload.com |
Questionable |
Do you want URL pattern "*.safetydownload.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.storageguardsoft.com |
Questionable |
Do you want URL pattern "*.storageguardsoft.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.trustedantivirus.com |
Questionable |
Do you want URL pattern "*.trustedantivirus.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.virusschlacht.com |
Questionable |
Do you want URL pattern "*.virusschlacht.com" to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.amaena.com (HKLM) |
Questionable |
Do you want URL pattern "*.amaena.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.avsystemcare.com (HKLM) |
Questionable |
Do you want URL pattern "*.avsystemcare.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.gomyhit.com (HKLM) |
Questionable |
Do you want URL pattern "*.gomyhit.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.imageservr.com (HKLM) |
Questionable |
Do you want URL pattern "*.imageservr.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.imagesrvr.com (HKLM) |
Questionable |
Do you want URL pattern "*.imagesrvr.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.onerateld.com (HKLM) |
Questionable |
Do you want URL pattern "*.onerateld.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.safetydownload.com (HKLM) |
Questionable |
Do you want URL pattern "*.safetydownload.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.storageguardsoft.com (HKLM) |
Questionable |
Do you want URL pattern "*.storageguardsoft.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.trustedantivirus.com (HKLM) |
Questionable |
Do you want URL pattern "*.trustedantivirus.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O15 - Trusted Zone: *.virusschlacht.com (HKLM) |
Questionable |
Do you want URL pattern "*.virusschlacht.com " to be in your trusted zone of IE? If not, fix this item. |
Change status
|
| O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\ied_s7m.cab |
Questionable |
Are you using an ActiveX object with no name located in 'file://c:\ied_s7m.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {11111111-1111-1111-1111-511111113457} - file://c:\x.cab |
Questionable |
Are you using an ActiveX object with no name located in 'file://c:\x.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {11111111-1111-1111-1111-511111113458} - file://c:\x.cab |
Questionable |
Are you using an ActiveX object with no name located in 'file://c:\x.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab |
Questionable |
Are you using an ActiveX object with a name 'iPIX ActiveX Control' located in 'http://www.ipix.com/viewers/ipixx.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll |
Questionable |
Are you using an ActiveX object with a name 'yucsetreg Class' located in 'C:\Program Files\Yahoo!\common\yucconfig.dll'? If not, fix this item. |
Change status
|
| O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab |
Legitimate |
Legitimate ActiveX item from site http://security.symantec.com/ |
Change status
|
| O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab |
Questionable |
Are you using an ActiveX object with a name 'Symantec Download Manager' located in 'https://webdl.symantec.com/activex/symdlmgr.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab |
Questionable |
Are you using an ActiveX object with a name 'ImageControl Class' located in 'http://c.ancestry.com/cab/ImageViewer/MFImgVwr.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} (Dell PC Checkup Installer Control) - http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab |
Questionable |
Are you using an ActiveX object with a name 'Dell PC Checkup Installer Control' located in 'http://pccheckup.dellfix.com/rel/35/install/gtdownde.cab'? If not, fix this item. |
Change status
|
| O17 - HKLM\System\CCS\Services\Tcpip\..\{F4E2E3BB-6101-4486-B08A-4689A872E632}: NameServer = 151.164.1.8,206.13.28.12 |
Questionable |
Do you recognize these IP addresses '151.164.1.8,206.13.28.12' as your internet provider DNS servers? If not, fix this item. |
Change status
|
| O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\ExPLabs.com\LinkScanner\XPLPP.dll |
Questionable |
It may be a trace of dangerous protocol hijacker or a legitimate item. Make some research about the name "linkscanner" and file "C:\Program Files\ExPLabs.com\LinkScanner\XPLPP.dll". |
Change status
|
| O20 - AppInit_DLLs: avgrsstx.dll |
Unknown |
No exact entries found |
Change status
|
| O20 - Winlogon Notify: urqrqolj - urqrqolj.dll (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
| O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll |
Legitimate |
windows check |
Change status
|
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe More info about file aawservice.exe |
Legitimate |
Item found in 2-spyware.com database. ... |
Change status
|
| O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe More info about file avgemc.exe |
Legitimate |
Item found in 2-spyware.com database. It is a part of the AVG Anti-Virus program made by Grisoft. It is also related to other Grisoft... |
Change status
|
| O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe |
Unknown |
No exact entries found |
Insert file into database
|
O23 - Service: gearsec - GEAR Software - C:\WINDOWS\system32\gearsec.exe More info about file gearsec.exe |
Legitimate |
Item found in 2-spyware.com database. It is a driver for CD-RW, released by <a href=http://www.gearsoftware.com>GEAR software and... |
Change status
|
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE More info about file lexbces.exe |
Legitimate |
Item found in 2-spyware.com database. This file is a component of MarkVision software, published by Lexmark International. This software... |
Change status
|
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe More info about file nvsvc32.exe |
Legitimate |
Item found in 2-spyware.com database. NVIDIA related software. nvsvc32.exe is an executable file that is responsible for launching... |
Change status
|
| O23 - Service: M-Audio Ozone Installer (OzoneInstallerService) - Nemesis - C:\Program Files\M-Audio\Ozone\Install\ozinst.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE |
Legitimate |
Related to Yahoo |
Change status
|