Record Statuses

CESAM sets specific statuses to records (there can be several statuses per record). These statuses greatly simplify the analysis of automatically loaded components, help search and detect malware. Text statuses are displayed in the detailed object information section.

Text status Description
File signed by Microsoft The files has been signed by Microsoft. This is a trusted file and it is absolutely safe for your system.
System default value The default system value. It’s also absolutely safe for you and your computer.
File found, but can’t get any details The file has been found, but it does not contain any information about the name of the product, its version and manufacturer. In the majority of cases, such files are part of malware and a serious threat to your system. However, it’s not necessarily so – sometimes even files signed by Microsoft do not have manufacturer information. For instance, MSSPY.EXE, secdrv.sys, etc. It is important to keep an eye on such a file if it’s not signed by Microsoft. We recommend checking it with an online scanner.
File not found The file referred to by a link in the system registry is missing on the hard drive. This situation is possible in several cases:
  • Some Windows system drivers (about 55) are defined in the system registry, but they are not installed in the system by default;
  • Some Windows libraries are registered as components, but are missing in the system by default (for instance, hticons.dll, mvfs32.dll);
  • You deleted a program without uninstalling it or the program uninstaller did not clean up the registry;
  • Some antivirus deleted an infected file, but left a record associated with it in the system registry (virtually all antivirus applications do that).
COM-object registry key not found  Under construction
Hidden registry record, rootkit activity  Under construction
File is exclusively opened, access blocked  Under construction
File  Under construction
HTTP value  Under construction