| Line: |
Status: |
Comments: |
Actions: |
C:\WINDOWS\System32\smss.exe More info about file smss.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\winlogon.exe More info about file winlogon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\services.exe More info about file services.exe |
Legitimate |
In most of cases it is legitimate system process, only sometimes can be used by malicious software |
Change status |
C:\WINDOWS\system32\lsass.exe More info about file lsass.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\brsvc01a.exe More info about file brsvc01a.exe |
Legitimate |
Item found in 2-spyware.com library This is an essential component of Brother printer drivers. File brsvc01a.exe.exe is used to control... |
Change status |
C:\WINDOWS\system32\spoolsv.exe More info about file spoolsv.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\brss01a.exe More info about file brss01a.exe |
Legitimate |
Item found in 2-spyware.com library This is an essential component of Brother printer drivers. File brss01a.exe is used to control a... |
Change status |
| C:\WINDOWS\system32\Brmfrmps.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe More info about file sqlservr.exe |
Legitimate |
Item found in 2-spyware.com library Main component of Microsoft SQL Server |
Change status |
C:\WINDOWS\System32\svchost.exe More info about file svchost.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\system32\rundll32.exe More info about file rundll32.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\System32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Process found in system process library |
Change status |
C:\WINDOWS\Explorer.EXE More info about file explorer.exe |
Legitimate |
Process found in system process library |
Change status |
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe More info about file sunthreatengine.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of legitimate CounterSpy anti-spyware. |
Change status |
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe More info about file sunprotectionserver.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of legitimate CounterSpy anti-spyware. |
Change status |
| C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\WINDOWS\System32\hphmon05.exe More info about file hphmon05.exe |
Legitimate |
Item found in 2-spyware.com library Executable hphmon05.exe is a part of HP printer drivers. It is required to enable support for the... |
Change status |
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe More info about file syntplpr.exe |
Legitimate |
Item found in 2-spyware.com library Related to Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
created by:... |
Change status |
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe More info about file syntpenh.exe |
Legitimate |
Item found in 2-spyware.com library System tray access for Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
Change status |
|
C:\WINDOWS\System32\igfxtray.exe More info about file igfxtray.exe |
Legitimate |
Item found in 2-spyware.com library From a user: I just(hours ago) installed some newer Intel graphics drivers in my system(82810E),... |
Change status |
C:\WINDOWS\System32\hkcmd.exe More info about file hkcmd.exe |
Legitimate |
Item found in 2-spyware.com library Hotkey Command Module for Intel Graphics Contollers. Located in "C:\WINNT\System32\" on Windows... |
Change status |
C:\Program Files\QuickTime\qttask.exe More info about file qttask.exe |
Legitimate |
Item found in 2-spyware.com library Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status |
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe More info about file hpgs2wnd.exe |
Legitimate |
Item found in 2-spyware.com library Hewlett Packard Share-to-Web utility built into thier products. |
Change status |
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe More info about file acrotray.exe |
Legitimate |
Item found in 2-spyware.com library Related to Adobe Acrobat Reader program. |
Change status |
C:\Program Files\Winamp\winampa.exe More info about file winampa.exe |
Legitimate |
Item found in 2-spyware.com library System tray icon for Winamp. |
Change status |
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe More info about file pptd40nt.exe |
Legitimate |
Item found in 2-spyware.com library Part of Scansoft's PaperPort scanner application. Usually located in "C:\Program... |
Change status |
C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Item found in 2-spyware.com library Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status |
C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe More info about file sunserver.exe |
Legitimate |
Item found in 2-spyware.com library An essential component of the CounterSpy anti-spyware program. |
Change status |
C:\Program Files\MSN Messenger\msnmsgr.exe More info about file msnmsgr.exe |
Legitimate |
Item found in 2-spyware.com library Microsoft Windows Messenger chat client. |
Change status |
C:\Program Files\Messenger\msmsgs.exe More info about file msmsgs.exe |
Legitimate |
Item found in 2-spyware.com library Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status |
C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com library This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status |
| C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe |
Unknown |
No exact entries found |
Insert file into database
|
| C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Program Files\Trend Micro\Tmas\Tmas.exe More info about file tmas.exe |
Legitimate |
Item found in 2-spyware.com library Main component of Trend Micro Anti-Spyware |
Change status |
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe More info about file hpgs2wnf.exe |
Legitimate |
Item found in 2-spyware.com library Related to software from HP. Located in "C:\Program Files\Hewlett-Packard\HP Share-to-Web\". |
Change status |
| C:\WINDOWS\System32\wbem\wmiapsrv.exe |
Unknown |
No exact entries found |
Insert file into database
|
C:\Documents and Settings\tim\Desktop\hijackthis\HijackThis.exe More info about file hijackthis.exe |
Legitimate |
Item found in 2-spyware.com library This is the main component of HijackThis security application, designed to perform system scans and... |
Change status |
| R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/ |
Not necessary |
http://www.hotmail.com/ is your start page. If you do not like this fact, fix this item. |
Change status |
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll More info about file acroiefavclient.dll |
Legitimate |
System item according to inner database
|
Change status
|
| O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - HKLM\..\Run: [HP Software Update] "c:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe More info about file hphmon05.exe |
Legitimate |
Application program item according to inner database Executable hphmon05.exe is a part of HP printer drivers. It is required to enable support for the... |
Change status
|
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe More info about file syntplpr.exe |
Legitimate |
System item according to inner database Related to Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".
created by:... |
Change status
|
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe More info about file syntpenh.exe |
Legitimate |
System item according to inner database System tray access for Synaptics touch pads. Located in "C:\Program Files\Synaptics\SynTP\".<br... |
Change status
|
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe More info about file igfxtray.exe |
Legitimate |
System item according to inner database From a user: I just(hours ago) installed some newer Intel graphics drivers in my system(82810E),... |
Change status
|
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe More info about file hkcmd.exe |
Legitimate |
System item according to inner database Hotkey Command Module for Intel Graphics Contollers. Located in "C:\WINNT\System32\" on Windows... |
Change status
|
| O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe |
Questionable |
questionable item according to our database |
Change status
|
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime More info about file qttask.exe |
Legitimate |
Application program item according to inner database Provides system tray access to Apple's Quicktime Player. Located in "C:\Program Files\QuickTime\".... |
Change status
|
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r More info about file sgtray.exe |
Legitimate |
Application program item according to inner database Part of the Veritas Storage Guard. Located in "C:\Program Files\VERITAS Software\Update Manager\". |
Change status
|
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 More info about file imjpmig.exe |
Legitimate |
System item according to inner database Related to Windows East Asian language support (Japanese keyboard entry). Located in... |
Change status
|
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC More info about file imscinst.exe |
Legitimate |
Application program item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\PINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName More info about file tintsetp.exe |
Legitimate |
System item according to inner database Translation component from Microsoft. Located in "C:\WINDOWS\System32\IME\TINTLGNT\". |
Change status
|
| O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl03a\BrStDvPt.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe More info about file hpgs2wnd.exe |
Legitimate |
System item according to inner database Hewlett Packard Share-to-Web utility built into thier products. |
Change status
|
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" More info about file acrotray.exe |
Legitimate |
Application program item according to inner database Related to Adobe Acrobat Reader program. |
Change status
|
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe More info about file winampa.exe |
Legitimate |
Application program item according to inner database System tray icon for Winamp. |
Change status
|
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe More info about file pptd40nt.exe |
Legitimate |
System item according to inner database Part of Scansoft's PaperPort scanner application. Usually located in "C:\Program... |
Change status
|
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe More info about file ituneshelper.exe |
Legitimate |
Application program item according to inner database Related to Apple's iTunes for Windows. Located in "C:\Program Files\iTunes\". |
Change status
|
| O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe |
Legitimate |
Related to ScanSoft PaperPort, legitimate scanner software |
Change status
|
| O4 - HKLM\..\Run: [defender] C:\\defender26.exe |
Unknown |
No exact entries found |
Insert file into database
|
O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe More info about file sunserver.exe |
Legitimate |
Application program item according to inner database An essential component of the CounterSpy anti-spyware program. |
Change status
|
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe More info about file ctfmon.exe |
Legitimate |
Application program item according to inner database When you run a Microsoft Office XP or Microsoft Office 2003 program, the file Ctfmon.exe (Ctfmon)... |
Change status
|
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background More info about file msnmsgr.exe |
Legitimate |
System item according to inner database Microsoft Windows Messenger chat client. |
Change status
|
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background More info about file msmsgs.exe |
Legitimate |
System item according to inner database Windows Messenger from Microsoft. Located in "C:\Program Files\Messenger\". If you don't use... |
Change status
|
| O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE More info about file osa9.exe |
Legitimate |
Application program item according to inner database Loads Microsoft Office components at reboot, to improve the startup time of the Office programs.... |
Change status
|
| O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe |
Unknown |
No exact entries found |
Insert file into database
|
| O4 - Global Startup: SmartUI.lnk = ? |
Not necessary |
Fix this item because it points to nowhere |
Change status
|
O4 - Global Startup: Trend Micro Anti-Spyware.lnk = C:\Program Files\Trend Micro\Tmas\Tmas.exe More info about file tmas.exe |
Legitimate |
Runs Trend Micro Anti-Spyware on every Windows startup. |
Change status
|
| O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html |
Not necessary |
Do you want item 'Convert link target to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html |
Not necessary |
Do you want item 'Convert link target to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html |
Not necessary |
Do you want item 'Convert selected links to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html |
Not necessary |
Do you want item 'Convert selected links to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html |
Not necessary |
Do you want item 'Convert selection to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html |
Not necessary |
Do you want item 'Convert selection to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html |
Not necessary |
Do you want item 'Convert to Adobe PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html |
Not necessary |
Do you want item 'Convert to existing PDF' to appear in your internet explorer context menu when you do the right click? If you don't, fix this item. |
Change status
|
| O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE |
Not necessary |
This item represents extra button in your IE toolbar with a name 'Messenger' and points to file 'C:\Program Files\Messenger\MSMSGS.EXE'. If you do not want it to be there, fix this item. |
Change status
|
| O9 - Extra ''Tools'' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE |
Not necessary |
This item represents extra menu item in your Tools menu in IE with a name 'Messenger' and points to file 'C:\Program Files\Messenger\MSMSGS.EXE'. If you do not want it to be there, fix this item. |
Change status
|
| O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 |
Questionable |
Are you using an ActiveX object with a name 'Windows Genuine Advantage Validation Tool' located in 'http://go.microsoft.com/fwlink/?linkid=39204'? If not, fix this item. |
Change status
|
| O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab |
Questionable |
Are you using an ActiveX object with a name 'Symantec AntiVirus scanner' located in 'http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab'? If not, fix this item. |
Change status
|
| O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab |
Questionable |
Are you using an ActiveX object with a name 'Symantec RuFSI Utility Class' located in 'http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab'? If not, fix this item. |
Change status
|
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1150855010140 |
Questionable |
Are you using an ActiveX object with a name 'MUWebControl Class' located in 'http://update.microsoft.com/microsoftupdate/v6/V5Controls /en/x86/client/muweb_site.cab?1150855010140'? If not, fix this item. |
Change status
|
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://eu-housecall.trendmicro-europe.com/housecall /applet/html/native/x86/win32/activex/hcImpl.cab |
Questionable |
Are you using an ActiveX object with a name 'Housecall ActiveX 6.5' located in 'http://eu-housecall.trendmicro-europe.com/housecall /applet/html/native/x86/win32/activex/hcImpl.cab'? If not, fix this item. |
Change status
|
| O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\d2j02c1mgf.dll |
Unknown |
No exact entries found |
Change status
|
| O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe |
Legitimate |
Required for PhotoshopCS |
Change status
|
| O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing) |
Not necessary |
Fix this item because it points to a file that does not exist |
Change status
|
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe More info about file brsvc01a.exe |
Legitimate |
Item found in 2-spyware.com database. This is an essential component of Brother printer drivers. File brsvc01a.exe.exe is used to control... |
Change status
|
| O23 - Service: HP WMI Interface (hpqwmi) - Hewlett Packard Company - C:\Program Files\HPQ\SHARED\HPQWMI.exe |
Legitimate |
Related to Hewlett-Packard |
Change status
|
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe More info about file ipodservice.exe |
Legitimate |
Item found in 2-spyware.com database. This is a legitimate component of iTunes music program. It offers wide range of music playing and... |
Change status
|