Welcome Guest (Log In | Create Account)
New Member? Join for free.




A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List  · Submit a Startup  · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
$sys$cmp $sys$xp.exe
X
Added by the Troj/Stinx-F backdoor Trojan. Troj/Stinx-F may be stealthed on an infected system by exploiting Sony DRM (Digital Rights Management) sof ... Read More
$sys$cor.sys $sys$cor.sys
U
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
$sys$crash $sys$WeLoveMcCOL.exe
X
Added by the Trojan.Welomoch Trojan.
$sys$crash $sys$sos$sys$.exe
X
Added by the Trojan.Welomoch Trojan.
$sys$crash $sys$sonyTimer.exe
X
Added by the Trojan.Welomoch Trojan.
$sys$drv $sys$drv.exe
X
Added by the Backdoor.Ryknos Trojan backdoor that attempts to utilize the SecurityRisk.First4DRM security risk to hide itself on the compromised compu ... Read More
$Volumouse$ volumouse.exe
U
Having this program started allows you to control the sound volume on your computer by using the mouse wheel on your mouse. ... Read More
%cmpmixtitle% Unknown
N
Possibly related to C-Media Mixer Control panel?
(default) [random filename].exe
X
Added by the BLACKMAL WORM!
(default) ~~.exe
X
Added by the Troj/DownLdr-QR Trojan downloader.
(default) ¡¡NOTEPAD.EXE
X
Added by the Troj/Vaq-A Trojan downloader.
(Default) 5640.exe
X
Added by the Troj/DownLd-ABF advertising related downloader Trojan.
(randomly chosen existing folder name) _setup.exe
X
Added by the W32/Antinny-L ... Read More
*ms setup [random file name]
X
Virtumondo adware, also known as the VUNDO TROJAN! ... Read More
*WinLogon [trojan path]
X
Added by the VUNDO TROJAN!
0000000 0.exe
X
Added by the W32/Sdbot-CPP worm and IRC backdoor.

W32/Sdbot-CPP spreads to other network computers by exploiting common buffer overflo ... Read More
000StTHK 000StTHK.exe
U
Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output ... Read More
0050726-007-i32-1 0050726-007-i32-1.exe
X
Added by the Troj/Bancban-EC ... Read More
00THotkey 00THotKey.exe
U
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. ... Read More
0b82c247.exe 0b82c247.exe
X
Added by the Troj/Tiny-Q Trojan.
0CF48.exe 0CF48.exe
X
Added by the SecureDefense rogue anti-spyware program.
0mcamcap 0mcamcap.exe
X
Added by the Troj/Cosiam-H proxy Trojan.
0utlook express *****.exe (where * = random char)
X
Added by the W32/RBOT-CC WORM! ... Read More
1.bat 1.exe
X
Added by the Troj/Banload-LK Trojan.
1.exe 1.exe
X
Added by the Troj/Multidr-C Trojan! This Trojan downloads and installs further malware onto your computer. ... Read More
10.1.08 10.1.08.exe
X
Added by the W32.Redlofs worm.
104D840A 104D840A.EXE
X
Added by the Troj/Agent-ENR Trojan.
1111swapmgr.exe 1111swapmgr.exe
X
Added by the Troj/Bdoor-IC backdoor trojan.
128 Module win128.exe
X
Added by the W32/Forbot-ES WORM/backdoor Trojan, which allows unauthorized access to the PC using the IRC network and registration of a new service pr ... Read More
12Ghosts Popup-Killer 12popup.exe
U
180adsolution 180adsolution.exe
X
180Solutions/N-Case adware variant
180ax 180ax.exe
X
180Solutions/N-Case adware variant
18wheelsofsteelconvoy.exe 18wheelsofsteelconvoy.exe
X
Added by the Adware.Trymedia.D adware.
1916435341.exe 1916435341.exe
X
Added by the Troj/Dloadr-AXU Trojan downloader.
196_150_ni 196_150_ni.exe
X
Added by WinSoftware/WinFixer.Process TROJAN! ... Read More
197_150_ni_3 197_150_ni_3.exe
X
A variant TROJAN! ... Read More
19E7E238 19E7E238.EXE
X
Added by the Troj/Agent-ELX Trojan.
1on1 1on1.exe
X
Adult content dialler
1u7 1u7.exe
X
Added by the Troj/Bckdr-PQL backdoor Trojan.
2.exe 2.exe
X
Added by the Troj/Multidr-C Trojan! This file is found in the Windows folder.
20050726-007-i32-1 20050726-007-i32-1.exe
X
Added by the Troj/Bancban-EC information stealing Trojan.
2006Server 2006.exe
X
Added by the Troj/Feutel-DA backdoor Trojan.
29547098.exe 29547098.exe
X
Identified as Downloader.Win32.Small.equ.
2kadiras 2kadiras.exe
Y
Allied_Telesyn AT series router/modem related - apparently required
2thousandbuck [path to file]
X
Added by the RANKY.L TROJAN!
2wSysTray 2portalmon.exe
U
2Wire Homeportal user interface
357aa41a-b7a8-4632-a27d-5b980b25cf43 [path to svchost.exe]
X
Added by the SMALL-AQ TROJAN! ... Read More
36Osafe 36Osafe.exe
X
Added by the Troj/Dloadr-BKC Trojan.
39672EA4 39672EA4.EXE
X
Added by the Troj/GrayBir-EW backdoor Trojan.
3c1807pd 3cmlink.exe 3cpipe-3c1807pd
Y
3Com WinModem driver. See here for more WinModem information
3capplnk 3capplnk.exe
Y
US Robotics Modem driver
3cdminic 3CDMINIC.EXE
N
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards ... Read More
3CM Link 3cmcnkw.exe
?
??
3Cmlink 3CmlinkW.exe
Y
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinMod ... Read More
3ComDMIAgent 3CDMINIC.EXE
N
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards ... Read More
3D Text 3D Text.scr
X
Added by the JERMY.A WORM!
3Deep Control Panel 3DeepCTL.EXE
U
From LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games ... Read More
3dfx Task Manager 3dfxMan.exe
N
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs ... Read More
3dfx Tools 3dfxCmn.dll
Y
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards ... Read More
3dfxv2ps.dll 3dfxv2ps.dll
Y
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards ... Read More
3Dlabs Taskbar Display Manager 3DLman.exe
?
3DLabs graphics driver related. System Tray access to display settings?
3DLabsHelperDemon 3dldemon.exe
U
Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits ... Read More
3DMouse.EXE 3DMouse.EXE
Y
Dritek System Inc. 3D Mouse drive
3d_sound 3d_sound.exe
X
Added by the Troj/Riados-A Trojan that attempts a distributed denial of service (DDoS) attack against www.riaa.com. ... Read More
3klagia 3klagia.dll
X
Added by the Backdoor.Rustock backdoor rootkit.
3qdctl.exe 3qdctl.exe
U
Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determine ... Read More
3ware 3DM 3dm.exe
Y
Monitors status of the disk array on 3ware IDE RAID controllers
49ersScreenServer 49ersScreenServer.exe
N
Software from the MercurySports for streaming information about the San Francisco 49ers US Football team. Slightly loose Terms or Use and Privacy pol ... Read More
49ersScreenServerSvc 49ersScreenServer.exe
N
Software from the MercurySports for streaming information about the San Francisco 49ers US Football team. Slightly loose Terms or Use and Privacy pol ... Read More
49U5T1N4 49U5T1N4.exe
X
Added by the W32.Korron.B worm. W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible dr ... Read More
4c0f6e34.exe 4c0f6e34.exe
X
Added by the Troj/Dloadr-XP downloader Trojan.
4ccc3cea.exe 4ccc3cea.exe
X
Added by the TROJ_ZLOB.ACB Trojan.
4da92ad5.exe 4da92ad5.exe
X
Added by the Troj/Dloadr-WZ Trojan.
4fdw 4fdw.dll
X
Added by the Backdoor.Rustock backdoor rootkit.
4k51k4 4k51k4.exe
X
Added by the W32/Brontok-BH worm.
5-2-46-112 5-2-46-112.exe
X
Adult content pop-up dialler. Removal instructions here
55euf6 55euf6.sys
X
Added by the Troj/DwnLdr-GWX Trojan downloader.
5p4m [path to Trojan]
X
Added by the Troj/Litebot-C Trojan.
63cica 63cica.sys
X
Added by a variant of the Troj/NTRootK-CL rootkit.
7v3j <filename.exe>
X
Added by the Troj/Dloadr-ARK Trojan downloader. The filenames associated with this infection are random. ... Read More
7VGAV 7VGAV.exe
X
Part of the Adware.Winpup infection. File is found in the Windows system folder. ... Read More
80xFire daemon 80xFire.exe
X
Added by the W32/Tilebot-BK worm and IRC backdoor. This also infects your computer with the rootkit rdriv.sys. ... Read More
9xadiras 9xadiras.exe
Y
Allied_Telesyn AT series router/modem related - apparently required ... Read More
;Rundll [filename]
X
Added by the PWSLEGMIR.E TROJAN!
<not used> r3hook.dll
Y
Related to Kaspersky Antivirus.
<not used> eNetHook.dll
Y
Related to Acer's eNet Management software for Acer laptops.
<not used> ^^^^^.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
<not used> %%%.exe
X
A variant of the Troj/Nymod-A malware.
<not used> .security
X
Identified as part of the Fake.Alert Trojan.
<not used> 22CC6C32.exe
X
Added by the Troj/Ransom-BO Trojan. This Trojan makes it so you cannot access your computer unless you pay a ransom. ... Read More
<not used> 64dlls.exe
X
Added by the Troj/Zbot-OK Trojan.
<random> <random>tssd.exe
X
Added by the Antivirus Suite rogue anti-spyware program.
<random> <random>tssd.exe
X
Added by the AntiSpyware Soft rogue anti-spyware program.
<random> <random>shdw.exe
X
Added by the Security Suite rogue anti-spyware program.
<random> <random>wagnz.exe
X
Added by the Antivirus Action rogue anti-spyware program.
<random>onin <random>onin.exe
X
Added by the Ghost Antivirus rogue anti-spyware program.
<unknown> asusrx25.sys
X
Variant of the Troj/Haxdor-Fam rootkit.
<Various Startup Names> _qbotinj.exe
X
Added by the Troj/Dloadr-BLP Trojan. The components of this infection are C:\documents and settings\all users\_qbothome\_qbotinj.exe and C:\documents ... Read More
?ekio Startups ?nksvc32.exe
X
Added by the W32/Agobot-OV WORM/IRC backdoor. ? is a random character. It will kill processes, record keystrokes, allowing unauthorised access to enab ... Read More
@ %1
X
Added by the W32/Protorid-AD WORM!
@liberamovilespt @liberamovilespt
X
Added by the Dialer.UDIS premium adult dialer.
@tour_ww @tour_ww[1].exe
X
Adult content dialler
A5118r _default32142.pif
X
Added by the W32/Brontok-AK mass-mailing worm.
AAAKeyboard <unknown>
?
??
aaprotect <Trojan Filename>
X
Added by the Troj/Bancban-MJ Trojan.
ACCDEFRAGINFO [path to worm]
X
Added by the DARBY-O WORM!
AccuWeather.com® Desktop <unknown>
N
Desktop weather from AccuWeather.com
ActivControl ActivControl2.exe
Y
Added by Promethean's interactive whiteboard software.
AddClass [Installation_Path]
X
Added by the STARTPAGE.F TROJAN!
admggxp admggxp.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
Adobe SpeedLaunch (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
agent browser [random file name]
X
Added by the PPdoor.M-bdr backdoor TROJAN!
AHU [path to worm]
X
Added by the ANACON-B WORM!
AIM Instant Message Cookies [random filenames]
X
Added by the W32/Rbot-AFV worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
AIMster <unknown>
N
Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs ... Read More
Alerter AlerterALG <random>.exe
X
Added by the W32/Backdr-AR backdoor.
AlevirOld [worm filename]
X
Added by the OPASERV.G WORM!
Alexa bridge <random>.exe
X
Added by the Troj/Agent-EBL Trojan.
alkasr ÎäÒíÑ.exe
X
Added by the BALKART TROJAN!
angnan <random filename.exe>
X
Added by the W32/Bobax-DB worm.
ansjava [path to mirc application]
X
Added by the W32/Randon-AN worm and IRC backdoor..
Anti-Virus <random>.exe
X
Added by the Troj/Caprobad-A proxy Trojan.
anti-virus product sync [AN UNPRINTABLE CHARACTER][3 CHARACTERS]log.exe
X
Added by the W32.Kedebe.D(AT)mm ... Read More
Anti-Virus Update Scheduler V1.39.12R [path to .exe]
X
Added by the Troj/Fireby-A proxy TROJAN!
Antispyware Shield Pro /antispyshield.exe
X
Added by the AntiSpyware Shield Pro rogue anti-spyware program.
AOL Messenger [random filename]
X
Added by an unidentified VIRUS, WORM or TROJAN!
ApachInc <random>.dll
X
Unknown malware typically bundled with LiveProtect. The dll is random but the registry entry will always be named ApachInc. ... Read More
APC PBE Server pbeserver.exe
Y
Related to APC PowerChute Business Edition. This startup allows you to monitor UPS connected to different computers and servers. ... Read More
Apoint System <Trojan Executable>
X
Added by the Troj/Banker-WK Trojan.
App.EXEName [path to worm]\.exe
X
Added by the BODIRU WORM!
Application Identity appidsvc.dll
Y
A Microsoft Service that is used by AppLocker to determine and verify the identity of an applicaiton. Please note that this service is launched by s ... Read More
ara-key [random filename]
X
Added by the ANTINNY WORM!
arprmdg0 arprmdg0.dll
X
Added by the Troj/Haxdoor-DI trojan. This infection utilizes the arprmdg5.sys rootkit to hide itself. ... Read More
ASDPLUGIN 100176br.exe
X
Added by a variant of the ASDPLUG adult content premium rate dialer!
ASDPLUGIN 100171be.exe
X
AsdPlug premium rate adult content dialer variant
asfqft [random]
X
Added by the Troj/Ranck-BU proxy Trojan, allowing HTTP traffic to be routed through the computer by malicious attackers. ... Read More
Audio HD Driver <random.exe>
X
Added by the Troj/Agent-OAL Trojan.
Auth Starter Ident startauth.exe
X
Added by the W32/Rbot-WP WORM!
Auto Scroll Loader (Random 6 Letter).exe
X
A variant of the SpyBot.dw family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
avgsys 64444.reg
X
Added by the Volcano Security Suite rogue anti-spyware program.
avguard3876 000b09274b.exe
X
Added by the AntiVirus ransomware program.
avptask 1explore.exe
X
Added by the Troj/Nofere-G Trojan. Troj/Nofere-G contains functionality to communicate with a remote server using HTTP, execute downloaded files, kill ... Read More
Avril Lavigne - Muse [random filename]
X
Added by the AVRIL-A WORM!
Avxnews <unknown>
?
??
AWatch Awatch.exe
U
Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products. ... Read More
Background Intelligent Transfer Service rundll32.exe
X
Added by Troj/VB-ZD, which also adds another to insure starting.
BackUp Windows 2009 <random>.exe
X
Added by the Troj/Agent-LUJ Trojan.
Band-Aid [path to file]
X
Added by the RANKY.O TROJAN!
bbdjmrxcX [random filename]
X
Added by the Troj/Ranck-AX proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
bcnswsx (path to file)
X
Added as result of a Ranck-AJ trojan infection ... Read More
BD [random]
X
The Troj/Agent-CM backdoor TROJAN will first place DC.EXE in the Temporary folder, then modify HKCUSoftwareMicrosoftWindowsCurrentVersionRun to ensure automatic startup.
bdffefqes32 [random filename]
X
Added by the Troj/Ranck-Z proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
begins 0.exe
X
Added by the W32/Mytob-HE mass-mailing worm and IRC backdoor.
BelNotify [path] NPBelv32.dll, RunDll32_BelNotify
U
"BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page ... Read More
BIOS XP Loader [random]
X
Added by the W32/Rbot-IC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
block 05.vbs
X
Added by the W32.Pusia.A@mm worm.
bluestart [random]
X
Added by Troj/Dloader-IR, a TROJAN!
Bmsnwss [random filename]
X
Added by the Troj/Ranck-BK proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Bnexe [random filename]
X
Added by the KITRO.D (or ARGEN.A) WORM!
boarddata [path] repcale.exe [path] palsp.exe
X
Added by a variant of the RANDON.AN WORM! ... Read More
Bonzi Buddy <unknown>
X
Spyware - read here for information and here for removal instructions
BrasilOld [worm filename]
X
Added by the OPASERV.P WORM!
Bron-Spizaetus-5118REPM _default32142.pif
X
Added by the W32/Brontok-R mass-mailing worm.
c7 [name of worm]
X
Added by the W32.MEDIAKILL.A WORM! ... Read More
CacheLoader [random]
X
Troj/Dloader-IX will download the [random] file to the Windows folder, sub-folder "Cache". That done, it moves to "Security iGuard.exe", found in the ... Read More
Caesvrn [path to .exe]
X
Added by the Troj/Ranck-CQ. This infection sits on a randomly selected TCP port between 1025 and 9997, awaiting contact by a remote attacker. ... Read More
cAgOu [filename].hta
X
Added by the KAKWORM WORM!
ccApp [random filename]
X
Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus ... Read More
ccApp [path to .exe]
X
Added by the W32/Rbot-LJ WORM/IRC backdoor Trojan!
ccapp .EXE
X
Added by the W32/RBOT-LJ WORM! ... Read More
ccapp .EXE
X
Added by the W32/RBOT-LJ WORM! ... Read More
Cekirge [path to worm]
X
Added by the KERGEZ.A WORM!
center [random name]32.exe
X
Added by the BOFRA.A WORM!
ChanService 2pack.exe
X
Identified as a variant of Backdoor.Win32.SpyBoter.fb.
ChkDsk32 <random>.exe
X
Added by the Troj/DwnLdr-GZO downloader Trojan.
cintaku [RANDOM CHARACTERS].exe
X
Added by the Trojan.Nickzul Trojan.
Client Agent [path to .exe]
X
Added by the Troj/PPdoor-F trojan. It will target Windows XP firewall and other security related processes for termination. ... Read More
clock [various filenames]
X
LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe ... Read More
clock (various file names)
X
LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe ... Read More
CNG Key Isolation lsass.exe
Y
The Windows CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptogr ... Read More
Cognac <random.exe>
X
Added by the Troj/DwnLdr-HLQ downloading Trojan.
com servoce
Compaq Video CD Watcher <unknown>
N
For Compaq PC's. MPEG viewer
Configuration [filename]
X
Added by the SDBOT-ML WORM!
Configuration apphost.exe
X
Added by W32/Sdbot-VP, a network WORM!
Configuration Loader seru32.exe
X
Added by the 32/Forbot-EL WORM! File is found in the Windows system folder.
Connectivity Tool [path to trojan]
X
Added by the Troj/Litebot-E IRC backdoor Trojan.
Content connector <various filenames.exe>
X
Added by the Troj/Dialer-Y dialer.
Control handler ***********.exe [* = random char]
X
CoolWebSearch parasite variant
ControlPanel [path] cmd32.exe internat.dll, LoadKeyboardProfile
X
Awmcash.biz foistware
Coupon Offers <unknown>
?
??
CouponAlert_2p Browser Plugin Loader 2pbrmon.exe
X
Detected by ESET Nod32 as a variant of the Win32/AdInstaller malware.
cppc <Trojan executable>
X
Added by the Troj/VB-NV Trojan. This trojan pretends to be a Half-Life 2 crack. ... Read More
CQSCP2P SERVER <unknown>
?
"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually ... Read More
CQSCP2PS <unknown>
?
"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually ... Read More
crtfmon <random>.exe
X
Added by the Troj/Dialer-EM dialer.
Cryptographic Service ******.exe [* = random char]
X
Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!
CSRS Windows NT [various names]
X
Added by the Backdoor.WinShell.50 backdoor.
CSRSWIN [trojan filename]
X
Added by the WINSHELL.50 TROJAN!
CSRSX [trojan filename]
X
Added by the WINSHELL.50.B TROJAN!
ctfmonn [random filename]
X
Added by the Troj/Ranck-O proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
CTime [path to trojan]
X
Added by the HTTPDOS TROJAN!
Ctykd %Malware path and filename%
X
Added by the TSPY_SMALL.SN spyware.
cyberfree.exe ****.dat [* = random char]
X
Unidentified adware
Danton* [random filename]
X
Added by the DANTON TROJAN! where * = random number
DATABASE MySql [path] repcale.exe [path] beird.exe
X
Added by a variant of the RANDON.AN WORM!
DBGA0EEG <random filename>.dll
X
Added by the W32/Doxpar-D password-stealing network worm.
DER005 <random filename>
X
Added by the Troj/Hackvan-B Trojan rootkit.
Description of Shortcuts *.exe
?
* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e ... Read More
Détection matériel noyau ShellHWDetectionwinmgmt 3com_dmin.exe
X
Identified by Kaspersky as the Backdoor.Win32.IRCBot.ab malware.
DeviceSys (Random Name).exe
X
Identified as a variant of the Backdoor.Win32.VB.btu Trojan.
Devicewin <pathname of the Trojan executable>
X
Added by the Troj/Banker-AEV Trojan.
Devlog <unknown>
?
??
dfasack [random filename]
X
Added by the Troj/Ranck-BE proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
DI2 [random]
X
Diagnostic Manager <random numbers>.exe
X
Unknown malware.
DirectX Service <Unknown>
X
Added by the Troj/Bdoor-AAT backdoor Trojan.
Disk Keeper [random]
X
Added by the Troj/Small-VE TROJAN!
Disk Master [trojan name]
X
Added by the DISTER TROJAN! - a spam relayer
DLL Service Manager [path to worm]
X
Added by the RPCBOT.F TROJAN!
DllExecutable [path to .exe]
X
Added by the W32/VB-SP WORM!
DllLoader32 <filename>.exe
X
Added by the Troj/Bdoor-QD backdoor Trojan.
dm_service [path to file]
X
Added by the MITGLIEDER.P TROJAN! ... Read More
doit.exe doit.exe
X
Added by the W32/Forbot-EK WORM! This file is found in the Windows system folder. May also create a Windows service called doit.exe. ... Read More
DomainService <random name>.exe
X
Service associated with Vundo infections.
Dosbat <unknown>
?
??
down winhelp.exe
X
Added by a TROJAN/DOWNLOADER, Troj/Dloader-FQ, and is found in the Windows system folder. ... Read More
down [random filename]
X
Added by the DLOADER.BG trojan downloader!
DownLmm <original Trojan filename>
X
Added by the Troj/Dloadr-APL Trojan.
Downm <original Trojan filename>
X
Added by the Troj/Dloadr-APL Trojan.
DriversLoad <random>.dll
X
Added by the Malware Defender rogue anti-spyware program.
DSAcass [path to file]
X
Added by the RANKY.M TROJAN!
DTInstall <filename.>.dll
X
Added by the Troj/Small-ALM Trojan.
DumpFaultCheck %system%
N
Added by the W32/Scanbot-A worm and IRC backdoor. Though this infection adds these entries, they have no effect on your computer other than open the ... Read More
E6F7BD90 <random>.exe
X
Added by the Troj/BDoor-ADP backdoor Trojan.
Easy Protect NT Driver _epnt.sys
X
Added by the Spyware.Ezurl spyware.
EDRestore <unknown>
U
Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP" ... Read More
educational writer [random filename]
X
Added by the RBOT-LZ WORM!
Edzy AntiVirus <random>.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
element furth [path] repcale.exe [path] palsp.exe
X
Added by a variant of the RANDON.AN WORM! ... Read More
eMCryT Sh3ars Panagers <random filename.exe>
X
Added by the W32/Rbot-AWI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
enbrowser [name of file]
X
WINBO adware component ... Read More
eProxy [random]
X
Added as a new service by the Troj/Daemoni-AL TROJAN, using a displayname of Microsoft Security Subsystem Provider. ... Read More
eqvwamkl eqvwamkl.dll
X
Identified as a variant of the Adware.Agent malware.
ES Current Services [FILE NAME].exe
U
Added by the Spyware.123Keylogger surveillance software. pyware.123Keylogger is a spyware program that logs user activity on the compromised computer, ... Read More
eTunnel <random filename>.exe
X
Added by the Troj/Meteor-E backdoor Trojan.
Expatch [random]
X
Added by the Troj/PWSLmir-G TROJAN to steal passwords.
Explorer [path to worm]
X
Added by the AUTEX WORM!
explorer `.vbe
X
Added by the Troj/Psyme-FE Trojan.
ezurl _epnt.sys
X
Added by the Spyware.Ezurl spyware.
fasdqwdwq [path to .exe]
X
Added by the Troj/Ranck-CP TROJAN. It will listen on a randomly chosen TCP port in the range 10000-50000 when run. ... Read More
ffeqOME [random filename]
X
Added by the Troj/Ranck-AR proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
File0_0 [path of Trojan]
X
Added by the Troj/Dloader-OR trojan downloader.
FindHack <Trojan executable>
X
Added by the W32/Kelvir-BA Trojan.
Fire Well service <random>.exe
X
Added by the W32/Rbot-FJU worm and IRC backdoor.
FiresWallservices <random>.exe
X
Added by the W32/Rbot-FJT worm and IRC backdoor.
Flash Media ^^^^^.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Flash Media %%%%%.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Flash Media ^^^^^^.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
FLASH32 -flash32.exe
?
??
Floppy Master [random]
X
Added by the Troj/Zonit-E TROJAN to send spam using other computers.
Floppy Master [path to trojan]
X
Added by the Troj/Zonit-F backdoor trojan.

Some potential file names may be:

C:\WINDOWS\wavplay.exe
C:\WINDOWS\system ... Read More
FoolProofSweep <unknown>
Y
Part of FoolProof Security PC security software from SmartStuff
fqxsbk [random filename]
X
Added by the Troj/Ranck-BS proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
fsdsft [file name]
X
Added by the Backdoor.Ranky.S Backdoor!
G00123 [worm filename]
X
Added by the BUGBROS WORM!
GarenaPEngine <random chars>.tmp
X
Unknown malware.
GbpSvc GbpKms.sys
X
Added by the nfostealer.Bancos.BB Trojan. Infostealer.Bancos.BB is a Trojan horse that attempts to steal information from the compromised computer. ... Read More
gCac gcac.exe
X
Added by the Tactslay Family Trojan.
GDAX [path to backdoor]
X
Added by the RANKY.K TROJAN!
Generic Host Process [random]
X
The Troj/Ciadoor-H TROJAN adds the file, enabling an attacker remote access to the computer. ... Read More
Generic Host Process for Win32 Services bazzi.exe
X
Added by the W32/Ahker-E WORM, from an email attachment. First added to the Startup folder as BADO.EXE and MICHO.EXE, it copies itself to bazzi.exe. ... Read More
GlobalSCAPE <filename>.exe
X
Added by the W32/Rbot-AYM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Google Earth <random name>.pif
X
Added by the W32/Rbot-AXK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
gramdate 2Stop.exe
?
??
Graphics _default.pif
X
Added by the W32.Autosky worm. W32.Autosky is a worm that attempts to spread to all shared and removable drives that are accessible from the compromis ... Read More
Gray_Pigeon .exe
X
Added by the Troj/GrayBrd-EH backdoor Trojan. This infection also creates the file c:\windows\temp\8e4ds4.dll. ... Read More
grgtgvgb.exe <random>.exe
X
Added by the Troj/Agent-EBF Trojan.
Grogotix <random 5 characters>.exe
X
Added by the W32/Flukan-C backdoor virus. W32/Flukan-C infects files with ".zip" extensions on the local system, by overwriting the contents of the ZI ... Read More
GustavVED [filename].exe
X
Added by the OPASERV.H WORM!
halloween stream [random filename]
X
Added by the Troj/Ranck-AY proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
HATAPE <Trojan executable>
X
Added by the Troj/Banker-QF Trojan.
HDAudio Driver 1.0 [random name].exe
X
Added by the Troj/Teadoor-D backdoor trojan.
HDAudio Driver 2.0 [randomstring].exe
X
Added by the Troj/Teadoor-E trojan.
hdlpscom <random 8 letters>.exe
X
Added by the W32/Rbot-FUL worm and IRC backdoor.
HELLBOT TEST 1hellbot.exe
X
Added by the W32/Mytob-BC worm/trojan.
Help Temp Files netreg.exe
X
Added by a network worm with backdoor functionality, W32/Forbot-EJ copies itself to the Windows system folder as netreg.exe and sets registry entries ... Read More
hen [filename].exe
X
Added by the TARNO.G TROJAN!
himem.exe <filename.exe>
X
Added by the W32/Stration-FW worm. The filename associated with this infection is random. Examples of some are dlksr32.exe, skksd32.exe, skcc32.exe, ... Read More
Home Safety Essentials <random chars and numbers>.exe
X
Added by the Home Safety Essentials rogue anti-spyware program.
HP Info Express <unknown>
N
On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb ... Read More
HP RecordNow <unknown>
U
From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used." ... Read More
HP Updates <unknown>
N
On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb ... Read More
hpsysconf1 [random filename]
X
Added by a variant of the VIVIA.A TROJAN!
hsys HSYS.EXE
U
Added by the Spyware.ExpressKeylog surveillance software. Spyware.ExpressKeylog is a spyware program that records keystrokes on the computer. This sof ... Read More
Human Interface Device Access HidServNetDDEdsdm 1054j.exe
X
Added by the Troj/Agent-GVN Trojan.
Hutley-Spieluhr <filename.exe>
X
Added by the Troj/Shpiel-A backdoor Trojan.
hxadsec [executable name]
X
Added by the Troj/AdClick-AP trojan.
Iamnacho On Irc. MusicIrc.com Is a Homosexual! [random name]
X
Added by the W32/Randex-T worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
ibin (Pathname of the Trojan executable)
X
Added by the Troj/Perda-C ... Read More
icccomp (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
ICQ Center [path to worm]
X
Added by the RANDIN WORM!
ICQ Lite Messenger [random filename]
X
Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program File ... Read More
idlesam (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Idoneus <random filename>
X
Added by the MSIL.Idonut virus.
ifperx (Random 8 Letter).exe
X
Identified as the Trojan-Proxy.Win32.Slaper Trojan.
Imesh <unknown>
N
Imesh is a file sharing system
Imesh Auto Update <unknown>
N
Update check for the Imesh file sharing system. Turn the update off under "options" ... Read More
imgit [path to .exe]
X
Added by the Troj/Banker-CG TROJAN!
Initialize8x8 8x8_init.exe
Y
Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay ... Read More
installs sp2 [path] repcale.exe [path] palsp.exe
X
Added by a variant of the RANDON.AN WORM! ... Read More
Installs SP4 %system%\ekrlgc\repcale.exe c:\windows\system32\ekrlgc\p0rd.exe
X
Added by the W32/Randon-AK worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands. ... Read More
InterceptedSystem [path to worm]
X
Added by the ANACON-B WORM!
Internal [trojan filename]
X
Added by the SMOTHER and TRANSLAT TROJANS!
Internet Agent [random CLSID]
X
Added by the Troj/PPdoor-F. It also uses a name Client Agent when changing the registry run key to enable auto-starting at logon. ... Read More
Internet Explorer [RANDOM NAME].dll
X
Added by the Backdoor.Berbew.T backdoor.
Internet Explorer [random letters].dll
X
Added by the Troj/Proxma-A proxy and backdoor Trojan.
Introduction-Registration <unknown>
N
For Compaq PC's. Should only run first time, PC Introduction & Compaq registration ... Read More
IO System Debug [random filename]
X
Added by Backdoor.Bla
Ipod Help (Random 9 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Irwftp [path to trojan]
X
Added by the BANCOS.CR TROJAN!
ist service uninstall [random filename]
X
ISTBar parasite related
ivhost (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
jamil _.exe
X
Added by the Troj/Lulador-A backdoor Trojan.
JavaUpdate0.07 [filename]
X
Added by the JUPDATE TROJAN!
JGhsdk393ktrfggh9dtj (Random Name).dll
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hko malware.
JVM0.14 [random]
X
Added by the Troj/Teadoor-B backdoor TROJAN!
Kadoc [random filename].exe
X
Added by the Staprew TROJAN!
KavSvc [random 6 char filename]
X
Qoologic downloader trojan variant using random file names (examples: nzkklz.exe) ... Read More
KAVutil [worm filename]
X
Added by the WINTOO.B WORM!
KAZAACuf 9
X
Added by the KITRO.D (or ARGEN.A) WORM!
kdmsx (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
kerberos4 (Random Name).dll
X
A variant of the Win32:Agent-NZR malware.
kern64dll [random filename]
X
Added by the TARNO.J TROJAN!
kernel32.dll <pathname of the Trojan executable>
X
Added by the Troj/Zlob-AP Trojan.
klop [random]exe
X
Added by the Troj/Dloader-WA downloading Trojan.
Kodak Camera Connection Software KodakCCS.exe
Y
Kodak DC File System Driver
LanGuard [random]
X
Added by Troj/Dloader-JZ .
lar [trojan filename]
X
Added by the ROXY.C TROJAN!
LDpswSend <random>.dll
X
Identified as Trojan-Downloader.Win32.Agent.
Legacy [RANDOM CHARACTERS]
X
Added by the Backdoor.Eparssa backdoor Trojan.
legalnoticeapplication ""
U
Added by the Spyware.PCProwler surveillance software. If this program was not installed by yourself, it should be uninstalled immediately. ... Read More
Litebot [Trojan executable name]
X
Added by the Troj/Litebot-A Trojan.
LiveUpdate [Windows username]05.exe
X
Added by the LINEAGE TROJAN!
lk3h1 [random]
X
Added by the Troj/Mosuck-G TROJAN into the Windows system folder.
load32 1111a.exe
X
Added by the DUMARU.AH WORM!
loader32 [path to .exe]
X
Added by Troj/Domcom-D downloading TROJAN.
LoadOrderVerification [random filename]
X
Added by the TRON.A TROJAN!
LoadWindowsFile [filename]
X
Added by the DELF.B TROJAN! where [filename] is the infected file
Locator Service [filename]
X
Added by the AGOBOT-KY TROJAN!
Login Service [path to file]
X
Added by the MIGMAF TROJAN!
lololol _hideme_imhiddenlololol.exe
X
Added by the Troj/Hideme-A Trojan. This infection is hidden by the rootkit file C:\_hideme_MYFILE.SYS. ... Read More
LowVersionSupport [filename]
X
Added by the LASTRAS TROJAN!
LS120 Superdisk <unknown>
N
Supposed to accelerate transfer rate on LS-120, contributes to system lockups
lsass [path to lsass.exe]
X
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup! ... Read More
L]kLp <random name>.exe
X
Identified by Kaspersky antivirus as the Net-Worm.Win32.Bobic.n worm.
Malware Cleaner <random number>.exe
X
Added by the MalwareCleaner rogue anti-spyware program.
Managment Service <random>.exe
X
Added by the W32/Rbot-GQM worm and IRC backdoor.
Mantis [filename]
X
Added by the MANTIBE VIRUS!
MatrixScreen [filename]
X
Added by the MATRIXSCREEN TROJAN!
McAfee Application Installer Cleanup (random numbers) <random #s>~1.exe
Y
McAfee service that cleans up installations files created by a previous installation or update. After this service is run, it should automatically re ... Read More
McAfee Winguage <unknown>
N
Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to ... Read More
mceipww (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mdetect [path to trojan]
X
Added by the SPABOT TROJAN!
MEAOI Service _meaoi.exe
X
Added by the W32/Tilebot-AM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. This infection ... Read More
MEDIA32 [pathname of the executable]
X
Added by the Troj/PurScan-Z trojan.
MEMSWEEP2 <random locations>
N
Added by the Sophos Anti-Rootkit security software. This service is only used when the software is scanning your computer. Otherwise, it can be remo ... Read More
Messenger 514.exe
X
Added by the Trojan.Esteems.D Trojan.
messnger [worm filename]
X
Added by the DELODER WORM!
mfgboot <unknown>
?
??
Mickey Mouse Cereal [random filename].exe
X
Added by the RANKY.Q TROJAN!
MicroLoad [random filename]
X
Added by the DARBY WORM!
MICROSFT RAMA UPDATE SUPPORT <random filename.exe>
X
Added by the W32/Rbot-ASM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Microsft Windows Adapter 5.1.3013 <random filename.exe>
X
Identified as the Trojan.PWS.LDPinch.TDD malware.
Microsoft (C) HTML Application host [random]
X
Added by the W32/Rbot-YB WORM/IRC backdoor, this file will allow termination of processes by way of a remote attacker using an IRC channel. ... Read More
Microsoft (R) Windows Network Latency Controller 1.tmp
X
Added by the Backdoor.Ranky backdoor Trojan. This infection also installs a Windows service of the same name and filename. ... Read More
Microsoft (R) Windows Protocol Deployment Manager (Random Name).tmp
X
Added by the Backdoor.Ranky backdoor Trojan.
Microsoft Anti-Virus <Random Filename.exe>
X
Added by the W32/Kassbot-O worm and IRC backdoor.
Microsoft Console Manager mcm.exe
X
Added by the Troj/WinShel-A backdoor Trojan.
Microsoft Corporation [random filename]
X
Added by various VIRUSES, WORMS & TROJANS!
Microsoft Diagnostic [random filename]
X
Added by the ACEBOT TROJAN!
Microsoft Diagnostic msdiag32.exe
X
Added by W32/Rbot-UC, a network worm and IRC backdoor Trojan found in the Windows system folder. ... Read More
Microsoft DirectX [random]
X
A variant of the Rbot WORM/IRC backdoor will add this file.
MicroSoft Getway Dire (Random 9 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
MicroSoft Getway mqbol (Random 12 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.etg family of worms and IRC backdoor Trojans. ... Read More
Microsoft I Service _svchost.exe
X
Identified as a variant of the Troj/Dwnldr-GYS malware.
Microsoft IIS [random]
X
Added by the WORM variant, W32/Francette-Q.
Microsoft Inet Service _svchost.exe
X
Added by the Troj/Dwnldr-GYS Trojan. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
Microsoft Int Service _svchost.exe
X
Identified as a variant of the Win32/TrojanDownloader.Tiny.NJ malware.
Microsoft Internet Acceleration Utility [random]
X
Added by the Troj/Agent-BM TROJAN!
Microsoft Internet Explorer smiissm.exe
X
Added by the Troj/Delf-KK Trojan! The infection creates a folder called SYS in the Windows folder and copies itself there. ... Read More
Microsoft Internet Explorer _svchost.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Tiny.nj malware.
Microsoft IT Update [random filename]
X
Added by a variant of the RBOT WORM!
Microsoft Java Virtual Machine MsConfiG.exe
X
Added by the W32/Forbot-DV WORM/BACKDOOR! The file is found in the Windows system folder. This infection also installs a service called draeco.sytes ... Read More
Microsoft Java Windows Update [filename]
X
Added by the RBOT-DZ WORM!
Microsoft Live 8.5 (Random 7 Letters).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Locals 332 [random filename]
X
Added by the RBOT-KU WORM!
Microsoft LV [random filename]
X
Added by the Troj/Bdoor-BDL trojan.
Microsoft Manager 1 KKI1.exe
X
Added by the Troj/Banker-EMT information-stealing Trojan for online banks.
MicroSoft Media Services [RANDOM 8 CHARACTER].sys
X
Added by the virus. W32.Mediasups is a virus that spreads by infecting executable files, may download files and communicate with a remote server. ... Read More
Microsoft Moniter Control <worm filename>
X
Added by the W32/Rbot-BAX worm and IRC backdoor.
Microsoft P2P Service _svchost.exe
X
Identified as a variant of the Troj/Dwnldr-GYS variant malware.
Microsoft P2P2 Service _svchost.exe
X
Identified as a variant of the Troj/Dwnldr-GYS variant malware.
Microsoft PCHealth32 [random]
X
The Troj/Nice-A TROJAN will log keystrokes using this file, and submit the data via email. ... Read More
Microsoft PS Service _svchost.exe
X
Identified as a variant of the TrojanDownloader:Win32/Tipikit.A malware.
Microsoft Redirect <pathname of the Trojan executable>
X
Added by the Troj/Banker-FW Internet banking Trojan.
microsoft security gmanagers [random file name]
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft Security Manager [random filename]
X
Added by the W32/Rbot-TU worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Security Panager [worm filename]
X
Added by the W32/Rbot-ANL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
microsoft security panagers [random file name]
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Microsoft Service Host Manager 32svchost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
microsoft software ****.exe E255 [* = random char]
X
Added by an unidentified WORM or TROJAN!
Microsoft Synchronization Manager ___synmgr.exe
X
Added by the MASLAN.A or MASLAN.C WORMS!
Microsoft Tray [random filename]
X
Added by the DELF.BZ TROJAN!
Microsoft Update Loader [random filename]
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine [random filename]
X
Added by a variant of the RBOT WORM!
Microsoft UpToDate Driver (32-bits) [random filename]
X
Added by the W32/Rbot-ZV worm. When this infection starts it connects to an IRC server where it waits for remote commands to execute. It also instal ... Read More
Microsoft Windows Adapter 5.1.3214 <random filename.exe>
X
Related to the Zinaps Anti-Spyware 2008 rogue anti-spyware program.
Microsoft Windows DHCP ___r.exe
X
Added by the MASLAN.A or MASLAN.C WORMS!
Microsofts Security Manager ****.exe [**** = random char]
X
Added by the RBOT-WH TROJAN!
MicrosoftWindows [various filenames]
X
MagicSearch - a CoolWebSearch parasite variant
Microsong [random filename]
X
Added by the Troj/Ranck-A proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Mike3 222.exe
X
Added by the Troj/Wombat-A Trojan.
minimo [random]
X
Added by the Troj/Mosuck-X. A backdoor Trojan, it can log keypresses, capture screen and webcam images, steal files, provide a remote command shell a ... Read More
Mioft Wiws Seice ent (Random 5 Letter).exe
X
A variant of the W32/Rbot-GIJ family of worms and IRC backdoor Trojans.
mmsddlx (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
Monitor Test [random filename]
X
Added by the W32/Sdbot-NC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
MPatrolPRO MPatrolPRO.exe
X
Added by the MalwarePatrolPro rogue anti-spyware program.
MS SQL Server Moniter _sqlsrvd.exe
X
Possible new variant of W32.Spybot.NLX. This infection has root kit capabilities so it is possible you have further files that can not be seen.
ms window update ******.exe (* = random character)
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
MS-HTML [random filename]
X
Added by the LATINUS.15 TROJAN!
msapps32 <Trojan executable>
X
Added by the Troj/Banker-IS Trojan.
msbsc [path to trojan]
X
Added by the Troj/Banker-DF password-stealing trojan of Brazilian banks.
MSFox <random.exe>
X
Added by the Troj/DwnLdr-HKP Trojan.
MsgApi [path to file]
X
Added by the DEDLER-D TROJAN!
Msgmgr [path to worm]
X
Added by the BABYBEAR WORM!
msinfo 2.tmp.exe
X
Added by the Troj/Newmen-A Trojan.
MSKCES32 [random filename]
X
Added by the CLONER TROJAN!
msmsgss [random filename]
X
Added by the Troj/Ranck-S proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
msn [random]
X
Added by the Troj/Bancban-BG TROJAN to steal passwords.
Msn <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MSN 9.0 Plus [random.exe]
X
Added by the W32/Rbot-ALY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Msn Home [random filename]
X
Added by the Troj/Ranck-W proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Msn Update SUPPORT <random filename>
X
Added by the W32/Rbot-BPS worm and IRC backdoor.
MsnConvert <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MsnHost <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MsnLoad <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MsnMessendger <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
msnmsgy [unknown]
X
Added by the Troj/Banker-EQ password-stealing trojan targetting Brazilian banks. ... Read More
Mspatch69 [path to trojan]
X
Added by the MPROX TROJAN!
MSPRO32 <pathname of the worm executable>
X
Added by the W32/Hiberi-B worm.
msproject [path to .exe]
X
Added by the Troj/Sdbot-TF TROJAN!
msresear <pathname of the Trojan executable>
X
Added by the Troj/Weasyw-B Trojan.
MSServer <random>.dll
X
Unknown malware. Please note that C:\Windows\System32\rundll32.exe is a legitimate file. ... Read More
MSSever <Trojan Filename.exe>
X
Added by the Troj/PWS-CW password-stealing Trojan.
MSSGisg [path to file]
X
Added by the RANKY.N TROJAN!
MSSGisg [unidentified]
X
Added by the Troj/Ranck-BI TROJAN, it will allow an unauthorized attacker to route HTTP traffic through the infected computer. ... Read More
mssp3 mssp22.exe
X
The Troj/IBank-D TROJAN adds this to steal data entered into a variety of web pages relating to money. ... Read More
mssvc [path to trojan]
X
Added by the PSK TROJAN!
mssysif (Random Name).exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.pnv malware.
mssysif (Random Name).tmp
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.pnv malware.
mswspl [random filename]
X
Added by the SMALL.IQ TROJAN!
ms_net_update <Original Filename of Worm>.exe
X
Added by the W32/Womble-A mass mailing worm. W32/Womble-A uses Exp/WMF-A which exploits a vulnerability in the image rendering functionality of the DL ... Read More
mxb2 [RANDOM].exe
X
Added by the W32.Maniccum worm.
mxcll
X
Added by the Echo AntiVirus 2010 rogue anti-spyware program.
Myapp [filename]
X
Added by the FATEE.B WORM!
Myfault <Trojan.exe>
X
Added by the Troj/Ranck-DJ Trojan.
Narrator ******.exe [* = random char]
X
Transponder/VX2 related adware
NAV Live Update [path to worm]
X
Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec ... Read More
NAVNet <Name of Executable>
X
Added by the Troj/Small-FR Trojan. The filenames and locations are random.
NavScan [filename]
X
Added by the OBSORB TROJAN!
NBT System alias [path] repcale.exe [path] beird.exe
X
Added by a variant of the RANDON.AN WORM!
Ndpldaemon [random name]
X
Added by the W32/RpcSdbot-A backdoor trojan.
Nero.ma ***.exe [*** = 2 to 3 digits]
X
Added by the JONBARR.D WORM!
NetDDEipx [Random file name].exe
X
Added by the Trojan.Netdepix Trojan.
NETGEAR FA410TX Fast Ethernet PC Card Driver \fa410nd5.sys
Y
Driver for the Netgear FA410TX PCMCIA network card.
nethost.exe <randomfilename>.exe
X
Added by the Troj/Perda-J backdoor Trojan.
NetPanel Starter.exe
X
Added by the Trackware.Gemius trackware. Trackware.Gemius is a program that monitors and records networking activity and sends the gathered informatio ... Read More
Network Client [Unknown]
X
Added by the Trojan.Boxed.C Trojan.
Network Client Monitor [unknown]
X
Added by the Trojan.Boxed.B Trojan.
Network Connections internat.exe
X
Added by Troj/VB-ZD along with another file run from the system folder, "/rundll32.exe", named Background Intelligent Transfer Service. ... Read More
Network Devices Controller [unknown filename]
X
Added by the Backdoor.Alnica backdoor. Listens on port 6667 awaiting a remote connection. ... Read More
Network Host Controller [path to trojan]
X
Added by the WHISPER TROJAN!
Network Security Guard **********.exe [* = random char]
X
CoolWebSearch parasite related
newname <application executable>
X
Added by the Troj/Drsmartl-S Trojan.
ni.uwfx5_0001_n57m2112 1D7C.tmp
X
This is WinFixer Malware.
Nocana [path to worm]
X
Added by the ANACON-B WORM!
Norton Antivirus 7.0a [random filenames]
X
Added by the Troj/Perda-B trojan proxy.
Notebook Manager Service anbmServiceNetman 2052d.exe
X
Unknown malware.
nssysconf [random filename]
X
Added by the VIVIA.A TROJAN!
nsysconf [random filename]
X
Added by the Adware.ZioCom.C adware.
NSystem [downloaded file]
X
Added by the Troj/Nsys-A trojan downloader.
NT Virtual Machine [random]
X
Added by Troj/Agent-BV, a network WORM with backdoor Trojan functionality found in the Windows system folder. ... Read More
Ntech.patchs [trojan filename]
X
Added by the LEMIR.G TROJAN!
NTP Server [path to trojan]
X
Added by the RANKY.F TROJAN!
NTServ [random filename]
X
Added by the Troj/Ranck-P proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
NTupdater <path to a renamed Mirc client>
X
Added by the Troj/Digarix-D backdoor Trojan.
Numerical Xterm Agent 0x32.exe
X
Added by the W32/Rbot-FWP worm and IRC backdoor.
Numerical Xterm Agents 2x32.exe
X
Added by the W32/Rbot-FWY worm and IRC backdoor. W32/Rbot-FWY spreads to other computers by exploiting common buffer overflow vulnerabilities like SRV ... Read More
Numerical Xtermz Agent 1x32.exe
X
Added by the W32/Rbot-FWX worm and IRC backdoor.
Numerical Xtermz Agent 1x32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
NvCp1Do <Trojan executable>
X
Added by the Troj/DwnLdr-GWE Trojan downloader.
NVFW <Path to worm executable>
X
Added by the W32/Mofei-S worm.
NvGraphicsInterface <random name>.exe
X
Added by the Troj/Bckdr-QKI backdoor Trojan.
Nvid [8 random charachters]
X
Unidentified adware
NVidia Drivers [random filename]
X
Added by the Troj/Ranck-R proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
nvviddrv32 [random]
X
Added by the W32/Rbot-HT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
office_update <Trojan executable>
X
Added by the Troj/Dloader-ZB Trojan.
OLE [filename]
X
Added by the STAWIN or TARNO.D TROJANS!
One Touch Monitor 1tou~2.exe
N
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
OneTouchMonitor 1tou~2.exe
N
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
ONETOU~2 1tou~2.exe
N
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
OpenCloud Security <random chars>.exe
X
Added by the OpenCloud Security rogue anti-spyware program.
OpenGL Drivers 0penGLD.exe
X
Added by the W32/Yimp-A Instant Messaging worm.
OpenMstart [path to .exe]
X
Added by the Dial/Switch-E DIALER.
Operator <unknown>
N
Media Pilot operator, in Win.ini. Locks port open
outlook express config *****.exe (where * = random char)
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
pangu_service_display <variousnames>.exe
X
Added by the Troj/DDoS-V DDOS Trojan. This infection can have various names such as C:\WINDOWS\System32\temp2.exe, C:\WINDOWS\system32\1003.exe, and ... Read More
PAV.EXE %Number%
X
Added by the KITRO.D (or ARGEN.A) WORM! %Number% can be any number
PDCOMP _amdevntas.sys
X
Added by the Trojan-Spy.Win32.Batton.rk spyware and information stealer. Trojan-Spy spies upon user's activity and steals confidential user informatio ... Read More
pe386 <random number>
X
Added by the Backdoor.Rustock.A backdoor Trojan. This infection uses Alternate Data Streams and rootkit technology to hide itself and the service ent ... Read More
PGStub.exe [various filenames]
X
Unidentified adware
PHIME2OO2ASyst <Trojan executable>
X
Added by the Troj/DBdoor-B backdoor Trojan. This filename for this trojan can be change to one specified by the hacker. ... Read More
Physical Memory Protector (Random Name).exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent malware.
PlanCx [random filename]
X
Added by the Troj/Ranck-CE proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Plug and Play Device Manager $sys$DRMServer.exe
U
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
pmc 764.exe
X
Adult content dialler
PNP FIX [unknown]
X
Added by the W32/Rbot-AKQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
pnpsvc_lock ******.exe [* = random digit]
X
Browser hijacker
PornoTop [path to .exe]
X
Added by Troj/Delf-RX, and will be found in the Program Files folder.
Power Control [date] 000.fcl
Y
Added by the PowerDVD universal media player.
PPSVC [path to Spyware.PCPolice]
U
Added by the PC Police surveillance program. This program should be uninstalled if it was not installed by yourself. ... Read More
present .exe
X
Added by the W32/Rubble-C worm.
Primax 3D Mouse 3dmoused.exe
U
Enables the scroll button on the Primax 3-D Scroll mouse
print sharing [path] hidden32.exe [path] explorer.exe
X
Added by the ZCREW.B TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) ... Read More
Print Spooler Service <Random Filename.exe>
X
Added by the W32/Bobax-DZ worm. W32/Bobax-DZ spreads to other network computers by exploiting common buffer overflow vulnerabilities. The filename for ... Read More
Print Spooler Service <random file name>.exe
X
Added by the Troj/HacDef-DJ backdoor Trojan and rootkit.
Printer [path to file]
N
Added by the LOWTAPER TROJAN!
PrinterSpool [path] RESTORE.EXE [path] SPOOL.EXE
X
Added by the ALADINZ.K TROJAN!
PrivateNet [various filenames]
X
Premium rate adult content dialler
Proc112 <File name of the dropped file>
X
Added by the WORM_IXBOT.A worm.
Proc992 <random filename.exe>
X
Added by the W32/Ixbot-C worm and IRC backdoor.
Program Access Service (Random 10 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
proses (Random 5 letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Protection [path] runtask.exe [path] protection.exe
X
Added by a variant of the AGENT.3.AU TROJAN!
putil [filename]
X
Added by the LDPINCH TROJAN!
putil 5845.exe
X
Added by the Backdoor.Zinx backdoor. This backdoor listens on ports 14728 and 24759. ... Read More
qbotd [random filename]
X
Added by the BOTTEN TROJAN!
Qdsafe <unknown>
?
??
qffecdas [random filename]
X
Added by the Troj/Ranck-BF proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
qgqqft [random]
X
Added by the Troj/Ranck-BX TROJAN!
Rapdetnlu <Trojan executable>
X
Added by the Troj/MapStor-A password-stealing Trojan.
Rapdyleys <pathname of the Trojan executable>
X
Added by the Troj/QQPass-AD Trojan.
rarup dns ...explore.xe
X
Identified as the Rbot.cnn worm and IRC backdoor.
rate.exe ********.exe [* = random char]
X
Unidentified adware
RavTimeXP [worm filename]
X
Added by the WULLIK.B WORM!
RavTimXP [worm filename]
X
Added by the WULLIK.B WORM!
rdvs [worm filename]
X
Added by the ULTIMAX WORM!
Reactor3 [random name]32.exe
X
Added by the BOFRA.A WORM!
Reactor5 [random name]32.exe
X
Added by the BOFRA.D WORM!
Reactor6 [random name]32.exe
X
Added by the BOFRA.C WORM!
Reactor7 [random name]32.exe
X
Added by the BOFRA.B WORM!
Reactor8 [random name]32.exe
X
Added by the BOFRA.E WORM!
Reactor9 [random name]32.exe
X
Added by the BOFRA.E WORM!
RealVNC Setup [random filename]
X
Added by the Troj/Ranck-V proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
REEGRUN [path to file]
X
Added by the SECDROP.AI TROJAN
Regcheck ~CAB001.EXE
X
Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!
Regisry Configuration [random]
X
Added by the W32/Rbot-IY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
reg_run [random]
X
Added by the Troj/Banker-BQ TROJAN!
Remote Procedure Call (RPC) Activator [Currently unknown]
X
Added by the Troj/Fiserv-A backdoor Trojan.
Remote System Protection <random>.dll
X
Unknown malware.
reszrv (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
RGZCDHTN %System%\RGZCDHTN.exe /install
X
Rhino [random name]32.exe
X
Added by the BOFRA.A WORM!
rngmf [path to trojan]
X
Added by the RANKY.C TROJAN!
romahere2 ************.exe [* = random char]
X
SuperSpider hijacker - a CoolWebSearch parasite variant
romahere3 ************.exe [* = random char]
X
SuperSpider hijacker - a CoolWebSearch parasite variant
ROME ROTYUS hxdefdrv.sys
X
Added by the Troj/HacDef-DR rootkit.
Root_Machine [pathname of the Trojan executable]
X
Added by the Troj/Bancban-DP password-stealing trojan for customers of Brazilian banks. ... Read More
RPC Patcher [path to worm]
X
Added by the BOLGI WORM!
RSPC Driver [random filename].exe
X
Added by the RBOT-SN WORM!
RSPC Driver D [random filename]
X
Added by a variant of the RBOT WORM!
rtkernsw (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
rundll32 [path to worm]
X
Added by the AUTEX WORM!
Rundll32_8 1.dll
X
Added by the Adware.BrowserAid adware.
rundll64 [path to worm]
X
Added by the AUTEX WORM!
RunWin [random]
X
Added by the Troj/Banker-BN TROJAN!
Safe <path to Trojan EXE>
X
Added by the Troj/Banker-DT password stealing Trojan aimed primarily at users of Brazilian banks. ... Read More
Sav32 [random filename]
X
Added by the W32/Famus-G WORM! File found in c:recycled
SB Audigy 2 Startup Menu /l:eng
N
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appe ... Read More
ScanFile <unknown>
?
??
Scanreg [filename]
X
Added by the QQPASS.E TROJAN!
ScrSvrOld [worm filename]
X
Added by the OPASERV WORM!
Search.vbs [unknown]
X
Hijacker
search.vbs
X
Hijacker
SearchClick <original Trojan filename>
X
Added by the Troj/Agent-DWR Trojan.
Service [trojan filename]
X
Added by the KAITEX.E TROJAN!
Service Host [filename].exe
X
Added by the TORVEL.B WORM!
Service Manager [random]
X
Added by the Troj/Migmaf-G TROJAN!
Service PAck hard (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Service PAck SFVP (Random 4 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Service Screan <random filename>
X
Added by the W32/Rbot-BAC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Service Transaction Provisioning <variousnames>.exe
X
Added by the Troj/DDoS-U DDOS Trojan.
Services [path to trojan]
X
Added by the METEORSHELL TROJAN!
Services [random]
X
Added by the Troj/Agent-BV Trojan.
Services004 [worm filename]
X
Added by the BUGBROS WORM!
SfKg6wIP (RandomName).exe
X
Identified as a variant of the TrojanDownloader.Matcash malware.
SFTRANSFER [unknown]
X
Added by the Backdoor.Brakkeshell backdoor Trojan.
SharedAPPs <random filename.exe>
X
Added by the Troj/Banloa-ET Trojan.
ShareSearcher <random filename.exe>
X
Added by the Troj/Agent-FPE Trojan.
ShellCommand [path to file]
X
Added by the REMCON-A TROJAN!
ShowLOMControl (No file name)
U
Shows as O4 - HKLM\..\Run: [ShowLOMControl]  (note strange symbol here) HKLM\Software\Microsoft\Windows\Current Version\Run ShowLOMControl Reg_DWORD ... Read More
SilentSoftech <filename.exe>
X
Added by the W32/SillyFDC-BL removable device worm.
sInErA .exe
X
Added by the W32/SillyFDC-AB worm. W32/SillyFDC-AB will attempt to copy itself to removable drives and create a file autorun.inf in an attempt to auto ... Read More
sixtysix [random]
X
Troj/LowZone-R TROJAN is responsible for a file found in the Windows folder that will reduce IE security zone settings. ... Read More
sklfc94krteetj (Random Name).dll
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hko malware.
skype.exe \ic&#111;nchanger.exe
X
Identified as a variant of the Backdoor.Win32.Poison.cpb malware.
SmartIndex _ex-08.exe
X
Added by the WORM_KELIHOS.SM worm.
SmartTesting <Trojan executable>
X
Added by the Troj/Ranck-DO http proxy trojan.
SMS Win9x Message Agent <unknown>
U
This program assigns a user to a Systems Management Server site
smss [path to smss.exe]
X
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! ... Read More
Smsvr <Trojan executable>
X
Added by the Troj/Dloadr-APC Trojan.
sniffer _ex-08.exe
X
Added by the Troj/Oficla-X Trojan.
SNInstall [various names]
X
Added by the Troj/Spyhoax-A trojan.
solid 0.exe
X
Added by the WORM_MYTOB.PP worm and IRC backdoor.
Somefox <random>.exe
X
Added by the Troj/Dwnldr-HHB Trojan.
sox [random]
X
Added by the Troj/Proxyser-G to start a SOCKS4 proxy server on a randomly-chosen TCP port. ... Read More
SpeedBoss [worm filename]
X
Added by the OPASERV.AD WORM!
Spool [path to trojan]
X
Added by the RANKY.R TROJAN!
spoolax [pathname of the Trojan executable]
X
Added by the Troj/Perda-D Trojan.
spyclean 1ClickSpyClean.exe
X
The application "1 Click Spy Clean" is using a database that was stolen from SpybotS&D A Rogue anti-spyware program see note ... Read More
sqlsrvd _sqlexec.exe
X
Possible new variant of W32.Spybot.NLX. This infection has root kit capabilities so it is possible you have further files that can not be seen.
sr64 ********. exe
X
Adware, as yet unidentified
Srv32 spool service [path to .exe]
X
Added by Troj/Dloader-LB.
Srv32Old [worm filename].PIF
X
Added by the OPASERV.J WORM!
SSDP Discovery Service Locator [unknown]
X
Added by the Troj/Pndoor-A backdoor Trojan.
st3i <random filename.dll>
X
Added by the Troj/Hasum-A Trojan.
Startup <unknown>
N
Related to an Iomega drive
Startup Configuration [random 6 letter filename]
X
Added by the W32/Rbot-ARV worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
stdlib [pathname of the Trojan executable]
X
Added by the Troj/Perda-E password-stealing Trojan.
stup 138762763.exe
X
Added by the Troj/FireSpy-A Spyware Trojan. This Trojan monitors the browsing behaviour of the FireFox browser. ... Read More
stup1db0t _win.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
SunJava Updater v7 \javale.exe
X
Added by the W32.Ackantta.B@mm worm. W32.Ackantta.B@mm is a mass-mailing worm that gathers email addresses from the compromised computer and spreads b ... Read More
SunJavaUpdateSched [path to .exe]
X
Added by the Troj/Banker-AU TROJAN!
Supernova [worm filename]
X
Added by the SURNOVA (or SUPOVA) WORM!
supernova .exe
X
Added as a result of the SURNOVA (or SUPOVA) VIRUS! .exe is the chosen name ... Read More
support-reverse-smileys [random filename]
X
Added by the Troj/Litebot-D Trojan.
svchost [path to trojan]
X
Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! ... Read More
svchost [path] SETUP.EXE
X
Added by the SETCLO WORM!
svchost [path] SETUP.EXE
X
Added by the SETCLO WORM!
svchosts32 [random filename]
X
Added by the Troj/Ranck-L proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
SvcManager <Trojan executable>
X
Added by the Troj/Zalon-A backdoor Trojan.
svcwinprocess32 [path to worm]
X
Added by the UPERING WORM!
svhost windows services Svhost8.exe
X
Added by a WORM, W32/Rbot-WQ, with backdoor Trojan functionality and found in the Windows system folder. ... Read More
sVideo2 [random]
X
Added by Dial/Switch-D , a TROJAN premium-rate dialler
Swf32 _backup.exe
X
Added by the SYMTEN WORM!
sws.exe [random filename]
X
Haldex type adult content dialler
SYDNEY [file path]
X
Added by the SYNEY WORM!
Symantec Autoscan [random filename]
X
Added by the W32/Rbot-AJO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
SysCalcPlus <Spyware file name>
X
Added by the TSPY_BANKER.FTD spyware.
Sysconf32 (Random 7 Letter).exe
X
A variant of the SpyBot.am family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
SysData [random filename]
X
Added by the Troj/Ranck-BA proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
SySPower [Unknown at this time]
X
Added by the Troj/SpyAgen-G keylogging Trojan.
SysStart 1.exe
X
Added by the Adware.ZenoSearch adware.
System CPL manager [random filename]
X
Added by the W32/Rbot-SR worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
System handler ~~~OuUuW_YeAh~~~.exe
X
Added by the W32.Kabab.A worm.
System Power Managment svcnost.exe
X
Added by the W32/Dref-I email worm and backdoor Trojan.
System Registry Settings regedit.exe
X
Added by the W32/Rbot-WL WORM/backdoor Trojan and allows unauthorised remote access to infected computers via the IRC network. ... Read More
System Restore Data [path] repcale.exe [path] beird.exe
X
Added by the RANDON.AN WORM!
System SSDP Services <random letters>.sys
X
Added by the Troj/Pardot-A rootkit.
System Update [filename].exe
X
CoolWebSearch parasite variant
System Update [random filename]
X
Added by the KORGO.W or KORGO.X WORMS!
System-Tray [random filename]
X
System32Check <random>.exe
X
Added by the Troj/Chast-A backdoor and keylogging Trojan.
SystemEmergency [various filenames]
X
SmartSearch - a CoolWebSearch parasite variant
SystemWideHook for Windows NT %WinHook32.exe
X
Added by the MYDOOM.AC WORM!
Systray [filename.exe]
X
Winfavorites adware
SysTray.Excn [random 8 character dll)
X
Added by the Troj/Cozdoor-C Trojan.
SysTray.Exiv <random>.dll
X
Added by the Troj/Slogger-F backdoor Trojan.
SysTray.Exsh [random 8 character dll]
X
Added by the Troj/Cozdoor-D bacdoor Trojan.
SysTray.Exys <random filename with DLL extension>
X
Added by the Troj/Slogger-D Trojan.
Systry [path to worm]
X
Added by the AUTEX WORM!
Systryt [path to worm]
X
Added by the AUTEX WORM!
systwyns <random name>.exe
X
Added by the Troj/PWS-ADX password-stealing Trojan.
syswin.txt (Random 3 Letter).exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
taskbar <Trojan executable>
X
Added by the Troj/Perda-I backdoor Trojan.
Taskmgo [path to file]
X
Added by the BANCBAN-T TROJAN!
taskmrg.exe [random]
X
Added by Troj/Bancban-BN, a TROJAN that attempts to steal banking details.
TaskReg [random filename]
X
Added by the CBLAD WORM!
tDefault <random name>.exe
X
Identified as a variant of the Backdoor.Win32.VB.btu Trojan.
Telnet24 <random filename>
X
Added by the W32/Rbot-ARD worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
TempCom [randomname].com
X
Added by the TRAXG WORM!
TempCom 8746D.com
X
Added by the W32/Traxg-H mass-mailing worm.
TGCMG <unknown>
N
Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work ... Read More
Think-Adz <random name>.exe
X
A variant of Adware.ZenoSearch.
Timer Service <Trojan Executable>
X
Added by the Troj/WoW-IL password-stealing Trojan for the online game World of Warcraft. ... Read More
tjstartup [path to file]
X
Added by the TJSERV.C TROJAN!
tkaskqjw [random filename]
X
Added by the Troj/Ranck-CA proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
tlz 47681727.exe
X
Identified as a Trojan downloader.
ToolHelp <random>.exe
X
Identified as a variant of the Trojan:Win32/Meredrop malware.
Trayz [random filename]
X
Added by the Troj/Bdoor-JG backdoor Trojan.
Tspy <Trojan Filename>
X
Added by the Troj/TSpy-B keylogging Trojan.
Tssh <unknown>
X
Added by the Troj/Mlsuc-E backdoor Trojan.
TSystem [original filename]
X
Added by the Troj/Nsys-A trojan downloader.
ttool 9129837.exe
X
Added by the Troj/DwnLdr-FSA downloader Trojan.
uidenhiufgsduiazghs <random>.exe
X
Unknown malware.
Update [original file path]
X
Added by the LYNDEGG WORM!
UpdateWin (Random Name).exe
X
Identified as a variant of the Trojan.Dropper.LDPinch.Q Trojan.
UpdSys [random filename]
X
Added by the BJ TROJAN!
upme dllman.exe
X
Added by the MUGLY.F WORM!
upme [random]
X
Added by the W32/Rbot-TH WORM/IRC backdoor trojan!
USB controller [random]
X
Troj/Miewer-A, a TROJAN, adds the file!
usbn [random]
X
Added by the Troj/Hogil-B Trojan. This infection adds various links to porn sites in your Desktop and Start Menu. ... Read More
User32 [filename]
X
Added by the NETTRASH TROJAN!
UserSystem [filename]
X
CoolWebSearch SmartSearch variant - also see here
UserTools <random.exe>
X
Identified as a variant of the Backdoor.Win32.VB.btu Trojan.
Usrobotics Online Registration <unknown>
N
Pop-up reminding customers to register their products online at US Robotics
usrpda USRmlnkA.exe
Y
US_Robotics modem driver ... Read More
V128IITV <unknown>
?
Loads drivers for some STB graphics cards. May be related to such a card with a TV out option? ... Read More
vadeinst [random filename]
X
Added by the Troj/Ranck-CF proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vadseinst [random]
X
Added by the Troj/Ranck-CM Trojan!
Vaganza-XPloit-[User Name] [User Name].exe
X
Added by the W32.Gavgent.A worm.
ValidData [path to trojan]
X
Added by the RANKY.H TROJAN!
value .svchost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Vanquish Autoloader v0.1 beta10 [various names]
X
Added by the Hacktool.Vanquish rootkit.
vb6 [random]
X
Added by the W32/Rbot-TD WORM/IRC backdoor trojan!
vbcdtm (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
vbs.ipnuker@mm (original worm file name).vbs
X
Added by the VBS.Nukip ... Read More
vbs_auto_update 0548656X.vbs
X
Added by the VBS/Gormlez-A ... Read More
VCbvnczsxcX [random filename]
X
Added by the Troj/Ranck-AK proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vcxcxvxcX [random filename]
X
Added by the Troj/Ranck-AQ proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vDGDGvvsa dqdw [random filename]
X
Added by the Troj/Ranck-AV proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vDSAGGQEvbA ASDAS dqdw [random filename]
X
Added by the Troj/Ranck-AT proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Verif [random]
X
Added by the W32/Nopir-B WORM!
Video Process [random filename]
X
Added by the RBOT-LM WORM!
VideoDriver [filename]
X
Added by the GSPOT20.A TROJAN!
Vinny <unknown>
?
??
Virtual Memory Dispatcher (RandomName).exe
X
Identified as a variant of the Win32:Agent-XKO/Backdoor.Hamweq.B malware.
Virtual Memory Protector (Random Name).exe
X
Identified as as variant of the Win32:Agent-XKO/Backdoor.Hamweq.B malware.
virtual-machine wini.exe
X
Added by the WORM W32/Rbot-WR, and found in the Windows system folder.
Virus Cleaner <original Trojan filename>
X
Added by the Troj/Delta-E Trojan.
virus removal tool (pathname of the Trojan executable)
X
Added by the Troj/Tometa-B ... Read More
Visual Lube.html
X
Added by the WM97/Lebone-A Microsoft Word macro virus.
Visual Element FX5 [various file names]
X
ClearStream Accelerator adware
voltage manager [random file name]
X
Added by the W32.DREFFORT WORM!
Volume Task (Random 10 Letter).exe
X
A variant of the SpyBot.bn family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
VS.VSN [unknown]
Y
Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added ... Read More
vs.vsn
Y
Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added ... Read More
VSSTAT <random>.exe
X
Added by the W32/Gobot-N worm and IRC backdoor.
vxcxcvfck. [random filename]
X
Added by the Troj/Ranck-AZ proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vXCXssdss [random filename]
X
Added by the Troj/Ranck-BO proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
W32Load [random filename].scr
X
Added by the CASPID WORM!
Watch 1200UBWATCH.EXE
?
??
Wdqvsst [random filename]
X
Added by the Troj/Ranck-BT proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
web ******.exe [* = random char]
X
Added by a variant of the EASTO.A TROJAN!
Web Event Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.B backdoor.
Web Event Logger <random>.exe
X
Added by the Backdoor.Berbew.D backdoor.
Web Event Logger <8 random characters>.dll
X
Added by the Backdoor.Berbew.F backdoor.
Web Event Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.M backdoor.
Web Event Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.P backdoor.
Web Search <unknown>
?
??
WebEvent Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.F backdoor.
WebRun [random]
X
Added by Troj/Bube-K.
WheelMouse 4DMAIN.EXE
U
Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may pro ... Read More
WheelsMouse <path to Trojan>
X
Added by the Troj/SocksPr-D proxy server Trojan.
whxpin service <RandomName>.exe
X
Added by the W32/Rbot-FWU worm and IRC backdoor.
Wiinamp <random>.exe
X
Added by the Troj/IRCBot-OH backdoor Trojan which utilizes IRC to receive its commands. ... Read More
Win Prosess0r <random filename>
X
Added by the W32/Rbot-BIT worm and IRC backdoor.
Win2Drv [worm filename]
X
Added by the WINTOO WORM!
Win32 USB2.0 Driver 386.exe
X
Added by the IRCBOT.D WORM!
Win32DLL [random]
X
Added by the W32/Woned-A WORM!
Win32system [random filename]
X
Added by the DDV.B WORM!
Win32SystemMonitor ***.exe [* = random char]
X
Browser hijacker
winabc <ORIGFILENAME>.DLL
X
Added by the Troj/Lineage-PN password-stealing Trojan for the online game Lineage. ... Read More
winapi _.exe
X
Added by the Troj/Lulador-A backdoor Trojan.
windll32 _WIN32.EXE
X
Added by the LEGMIR.AQ TROJAN! ... Read More
WinDLLProcessor <random name>.exe
X
Added by the Troj/Bancos-BDO password stealing Trojan for online banks. If you are infected with this Trojan you should immediately change all of you ... Read More
Windos Seres Agnts <random>.exe
X
Added by the W32/Rbot-GUN worm and IRC backdoor.
Window service [random]
X
Added by the W32/Rbot-ACH worm. This infection has backdoor functionality, allowing unauthorized access to perform a wide variety of actions. ... Read More
windows [path to trojan]
X
Added by the AIMWIN TROJAN!
Windows Accounts Driver <random name>.exe
X
Added by the Troj/Agent-GGY Trojan.
Windows ASN Service [random name]
X
Added by the W32/Agobot-TC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Windows boot system cfg32 actboost.exe
X
Added by W32/Forbot-G, a network WORM!
Windows Compliant [random filename]
X
Added by the RBOT-IR WORM!
Windows Desktop Multimedia ntkrnl.exe
X
Unknown malware.
Windows ExpIorer [random filename]
X
Added by the W32/Rbot-AKO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Explorer [filename].exe
X
Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually ... Read More
Windows Eyes <unknown>
N
For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hea ... Read More
Windows Firewall Monitor <random filename>.exe
X
Added by the Troj/Proxy-AX proxy Trojan.
Windows haz Layer (Random 5 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.fbx family of worms and IRC backdoor Trojans. ... Read More
Windows Insecure <4 random letters>.exe
X
Added by the W32/Rbot-FSM worm and IRC backdoor. W32/Rbot-FSM spreads to computers vulnerable to common exploits, including: LSASS (MS04-011), RPC-DCO ... Read More
Windows Installer Class ~~install.dll
X
Identified as a variant of the Trojan.FakeAlert malware. This malware will issue fake alerts on your computer stating you have security problems and ... Read More
Windows Live Messenger <random>.exe
X
Added by the W32/Rbot-GVL worm and IRC backdoor.
Windows Logon Application services.exe
X
Added by the Troj/Ciadoor-L trojan.
Windows Media Player [random filename]
X
Added by a variant of the RBOT WORM!
Windows Media Player Update [random filename]
X
Added by the RBOT-ET WORM!
Windows Media SP.2.37 [random filename]
X
Added by the LEMIR.C TROJAN!
Windows Microsoft Service (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Microsoft Services (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
WINDOWS MSI Installer Application msiexec.exe
X
A variant of the RBot.cgu family of worms and IRC backdoor Trojans.
Windows Newresck (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows NNT [path to trojan]
X
Added by the RANKY.E TROJAN!
Windows NT [random filename]
X
Added by the Troj/Ranck-M proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Windows NT Session Managers smss.exe
X
Added by the W32/Sdbot-CPN worm and IRC backdoor. This infection should not be confused with the legitimate file C:\Windows\System32\smss.exe. ... Read More
Windows NTFS Volume Manage (Random 6 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.edl family of worms and IRC backdoor Trojans. ... Read More
Windows Overlay Components <randomfilename>.exe
X
Added by the Troj/Agent-JK Trojan.
Windows Recycler <random filename.exe>
X
Identified by Kaspersky as a variant of the Backdoor.Win32.Rbot.gen worm and backdoor family. ... Read More
Windows Resurections <random>.exe
X
Unknown malware.
windows runtime proccess 32RUNdll.exe
X
Added by the SDBOT.QW WORM! ... Read More
Windows S1ystem Managment <random characters>.exe
X
Added by the W32/Rbot-FUN worm and IRC backdoor.

W32/Rbot-FUN spreads to other network computers by:

- exploiting common ... Read More
Windows Secure talal32 (Random 7 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Security Service [random filename]
X
Added by the W32/Rbot-ALV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Windows Security Suite <random>.exe
X
Added by the Windows Security Suite rogue anti-spyware program.
Windows Serces Agnt (Random 9 Letter).exe
X
A variant of the Rbot.civ family of worms and IRC backdoor Trojans.
Windows Servces Agent <random name>.exe
X
Identified by Kaspersky antivirus as the Backdoor.Win32.IRCBot.acg worm and IRC backdoor. ... Read More
Windows Servcesc (Random 9 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service Ag3nt (Random 4 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.gox family of worms and IRC backdoor Trojans. ... Read More
Windows Service Agnts (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service alge (Random 8 Letter).exe
X
A variant of the WORM_RBOT.GJO family of worms and IRC backdoor Trojans.
Windows Service CV (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service Host Process svchost.exe
X
Added by the W32.Ezio.A@mm WORM.
Windows Services Aganters (Random 10 Letter).exe
X
A variant of the WORM_RBOT.CUN family of worms and IRC backdoor Trojans.
Windows Services alges2 (Random 8 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.esc family of worms and IRC backdoor Trojans. ... Read More
Windows Serviece Agents (Random 9 Letter).exe
X
A variant of the Worm.Rbot.ABFK family of worms and IRC backdoor Trojans.
Windows Socketheader [random filename]
X
Added by the W32/Ixbot-A worm and IRC backdoor.
Windows Standard Securty [random 3 letter filename]
X
Added by the W32/Rbot-ALF worm.
Windows System Security Monitor [4 random letters].exe
X
Added by the W32.Pinkton.A worm.
Windows Taskbar Manager [path to file]
X
Added by the PROTORIDE.B WORM!
Windows Update [filename]
X
Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites ... Read More
Windows update 32 [random]
X
Added by the W32/Rbot-ADG WORM/IRC backdoor Trojan!
Windows update 55 (Random 10 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.aus family of worms and IRC backdoor Trojans. ... Read More
Windows Update Checker [random filename]
X
Adware downloader trojan
Windows Update V6 [random filename]
X
Added by the RBOT-KT WORM!
Windows USB Service 666.exe
X
Added by the W32/Mytob-AW WORM/IRC backdoor trojan!
WindowsReg% update [random filename].exe
X
Added by the RBOT-HH WORM!
WindowsRegistration [random filename]
X
Added by the RBOT-NO WORM!
WindowsRegKey Autoupdate [random filename]
X
Added by a variant of the RBOT WORM!
WindowsRegKey upd4te2d4te *********.exe [* = random char]
X
Added by the RBOT.XQ WORM!
WindowsRegKey update [random filename]
X
Added by a variant of the RBOT WORM!
windowsregkey update 16winupdate32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
WindowsSetup [path to trojan]
X
Added by the EZBOT TROJAN!
windowz (original worm file name).vbs
X
Added by the VBS.Nukip ... Read More
Winds Sers Agts (Random 5 Letter).exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
WindUpdates [path to trojan]
X
Added by the AGENT.BF TROJAN!
wingo [various filenames]
X
Added by the BAGLE-AU WORM!
WinKernel [path to worm]
X
Added by the PLEA VIRUS!
WinLoader [random filename]
X
Added by variants of the SUBSEVEN TROJAN!
winlogon32_ [PATH TO THE WORM]
X
Added by the W32.Mailbancos@mm worm.
WinManage [random filename]
X
Added by the Troj/Ranck-KH proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
WinMsgServices ?.exe
X
Added by the Troj/Kelebek-G. This file is added to the Windows system folder. The name of the filename is the ASCII character 255 which corresponds ... Read More
WinNetDDE [random characters].exe
X
dded by the _blank>NETDEPIX.B TROJAN!
Winport.com [various]
X
Added by the Backdoor.Acropolis backdoor. The name of the backdoor is Acropolis 1.0. It listens on ports 32791, 45673 for connections. ... Read More
winreg_32 [random]
X
Added by the Troj/Bancban-BY TROJAN!
Winres32vis [path to worm]
X
Added by the THRAX.A WORM!
Wins32 Online cfgpwnz.exe
X
Added by W32/Rbot-WN, a network WORM!
WinShell <path to worm>
X
Added by the W32/Fanbot-B mass-mailing and P2P worm.
Winsocgfhk driver (Random 7.Letter).exe
X
A variant of the SpyBot.a family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Winsock2 driver 5ystem.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Winsocket log <random characters>.exe
X
Added by the Troj/Sdbot-AKF worm and IRC backdoor.
Winsvr <random filename>.exe
X
Added by the Troj/AdClick-DK Trojan.
WINSYS [path to trojan]
X
Added by the GOLDPLAY TROJAN!
WinSysModule <Trojan executable>
X
Added by the Troj/Agent-DIQ keylogging Trojan.
WinSysW 896588L.exe
X
Added by the Troj/LegMir-ARQ password-stealing Trojan for the online game The Legend of Mir. ... Read More
WinSysW 124327L.exe
X
Added by the Infostealer.Gampass information stealing Trojan for online games.
WintelUpdate <random filename.exe>
X
Added by the Troj/Small-EKW backdoor Trojan.
winupdateconn [path to file]
X
Added by the W32/COMBRA-A WORM! ... Read More
winupdateconn_ [path to exe]
X
Added by the W32/Combra-A WORM.
winupdatefiv_ [file name]
X
Added by the W32/Combra-C email worm.
winupdate_ [path to file]
X
Added by the W32.COMDOR.A WORM! ... Read More
WinUpgrader [path to EXE]
X
Added by the trojan.
winValidate <random filename>.exe
X
Added by the Troj/Bckdr-PNO Instant Messaging Trojan.
winXP 33.exe
X
Added by the ANPES WORM!
WinXP fix [path to file]
X
Added by the RANKY.P TROJAN!
winzip [path to trojan]
X
Added by the BANCOS.G or BANCOS.K TROJANS!
Win_BooT <Path to Trojan>
X
Added by the Troj/Banker-GI password-stealing Trojan.
win_drivr32 <random>.exe
X
Added by the Troj/Dloadr-CKT downloader Trojan.
worknote1 [unknown]
X
Added by the W32.Meetot worm.
wowexecl ""
X
Added by the Troj/Vanity-A Trojan. This infection includes the files C:\Windows\System32\wowexecl.dll and c:\Windows\System32\wowexecl.ini. Due to ... Read More
wpxmls (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
WRECK GUARD <unknown>
?
??
wuauon <random filename>.exe
X
Added by the Troj/Bdoor-MC backdoor Trojan.
Wupdate 1037v.exe
X
Added by the Troj/Clagger-AR Trojan.
WXcmeinst [random]
X
Added by Troj/Ranck-CD, a backdoor TROJAN! It will chose a TCP port in the range 10000-49999 to notify a remote web server on that port using a web re ... Read More
x3yy [path to trojan]
X
Added by the TANNICK TROJAN!
XpAspy [random]
X
Added by Troj/Delf-WH, a TROJAN! It will be found in the Windows folder.
xpsystem [random]
X
Added by Troj/Krepper-M, a TROJAN! It will be found in a subfolder of the Windows system folder named "services". ... Read More
XRW005 <random filename>
X
Added by the Troj/Hackvan-B Trojan rootkit.
xserv [random name].exe
X
Added by the Troj/Stumpy-A trojan.
xset [random]
X
Added by the Troj/Bdoor-HT.
xswdmse (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Yeah ^$4!N$^.exe
X
Added by the W32/VB-DZA worm.
yyyyyyyy [path to trojan]
X
Added by the MUMUBOY.B TROJAN!
ZaCker [filename].PIF
X
Added by the HOLAR.A WORM!
Zen.A [path to trojan]
X
Added by the ZOOMEN-A TROJAN!
ZeroAds 0
U
ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually ... Read More
Zonavirus 0
X
Added by the KITRO.D (or ARGEN.A) WORM!
zonealarm [random filename]
X
Added by an unidentified VIRUS, WORM or TROJAN! The only exception is if you have an older version of the ZoneAlarm firewall running ... Read More
Zul_Cinta_Anick [RANDOM CHARACTERS].exe
X
Added by the Trojan.Nickzul Trojan.
zzzsoft <Trojan executable>
X
Added by the Troj/QQRob-AD Trojan.
[Ephemeral 2.5] by TreeHugger, [randomname].exe
X
Added by the W32/Lemoor-C worm.
[Ephemeral 2.x] by TreeHugger, [path to worm]
X
Added by the LEMOOR.A WORM! where "x" represents 3 or 4
[not used] mcafee32.exe
X
w32rbotxe drops a TROJAN, creating several files in %Program Files%, %Windir%, and %system% in addition to this file. ... Read More
[not used] _huytam_.exe
X
Added by the Ssearch.biz and a-search.biz hijackers.
[not used] _Kerne1.exe
X
Added by the Troj/Lineage-AN password-stealing Trojan for the online game Lineage. ... Read More
[not used] 896588AppInit.DLL
X
Added by the Troj/LegMir-BI Trojan. This infection also creates the %WinDir%896588.dll file. ... Read More
[random name] ??xplore.exe
X
PurityScan adware variant.
[random name] ??oolsv.exe
X
PurityScan adware variant.
[random name] ??chost.exe
X
PurityScan adware variant.
[random name] ??erinit.exe
X
[random name] ?hkntfs.exe
X
PurityScan/Clickspring adware ... Read More
[random name] ?ttrib.exe
X
PurityScan/Clickspring adware ... Read More
[random name] ??rvices.exe
X
PurityScan adware variant.
[random name] ??anregw.exe
X
PurityScan/Clickspring adware ... Read More
[random name] ??ool32.exe
X
PurityScan/Clickspring adware ... Read More
[random name] ??rss.exe
X
PurityScan/Clickspring adware ... Read More
[various names] 80d0.exe
X
MediaMotor/Popuppers adware variant. Names spotted include 80d0, SWOD, g$p$, elos, seli, "piz, :C=e, resU and so on ... Read More
[Various Names] _ctcp.exe
X
Part of the Wareout infection as described here.
[Various Names] 34763.exe
X
Part of the Wareout infection as described here.
[Various Names] 10010.exe
X
Part of the Wareout infection as described here.
[Various Names] 321102.exe
X
Part of the Wareout infection as described here.
[Various Names] 321102.exe
X
Part of the Wareout infection as described here.
^`d}qZxu ~`d}qzxu3zYF
X
Added by the GAOBOT.GEN!POLY WORM!
_accwiz.exe _accwiz.exe
X
Added by the Troj/Certif-N password-stealing Trojan.
_explore manager _explore.exe
X
Added by the Troj/Spexta-B Trojan.
_Hazafibb [path to file]
X
Added by the ZAFI.B WORM!
_mzu_stonedrv2 _mzu_stonedrv2.exe
X
Added by the Trojan.Jupillites.B backdoor Trojan. Trojan.Jupillites.B is a Trojan horse the downloads remote files and opens a back door on the compro ... Read More
_mzu_stonedrv3 _mzu_stonedrv3.exe
X
Added by the Troj/DwnLdr-FTB downloader Trojan.
_ntrdlhost _ntrdlhost.exe
X
A downloader TROJAN, Troj/Dloader-JV, adds this file.
_ntrrescueservice _ntrrs.exe
X
Added by the TROJ/DLOADER-JV TROJAN! ... Read More
_System_Run _svchost_.exe
X
Added by the Troj/Lineage-Z password-stealing trojan for the online game Lineage. ... Read More
_tdiserv_ _tdicli_.exe
X
Added by the W32.TDISERV.A WORM! ... Read More
_x-Finder _x-Finder.exe
X
Disconnects and redials an ISP modem to an adult content site
__adware1__ __adware1__.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
__adware2__ __adware2__.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
__c0028830 __c0028830.dat
X
Added by the Troj/Mdrop-BUX Trojan.
__ZF5 [unknown name]
X
Added by the W32.Erkez.F@mm mass-mailing worm.
{1A2B5BD6-5867-48C3-B826-807FC6AE8F3D} 30835167.dll
X
Added by the Troj/Lineag-ANB password-stealing Trojan for the online game Lineage. ... Read More
{2C1CD3D7-86AC-4068-93BC-A02304BB2236} 2236_27.dll
X
Identified by Kaspersky Anti-Virus as Backdoor.Win32.Agent.adr.
{36EAFED6-FE52-42E5-8FEC-703424BAA9CF} 4D1B90FDDF6B.dll
X
Added by the Troj/Lineag-BF password-stealing Trojan for the online game Lineage. ... Read More
{3771BD45-B3B5-46FF-B309-028D126B9103} 299E55F.dll
X
Added by the Troj/Gampass-H password-stealing Trojan for online games.
{47994C89-1857-4D33-B196-263ED6FA4CFF} 231346E28D27.dll
X
Added by the Troj/PWS-AOV password-stealing Trojan.
{56CF31C1-A46F-4B57-886C-6638DA412087} 28bfe5.dll
X
Added by the Troj/Lineag-AD password-stealing Trojan for the online game Lineage. ... Read More
{79921D3F-7537-463E-9E38-CD503A8FA485} 45ad9fca.dll
X
Added by the Troj/Lineag-AJK password-stealing Trojan for the online game Lineage. ... Read More
{79FC744E-75CA-49B0-8F02-AEAE4CAACBE0} 2ACE4CFBAF2C.dll
X
Added by the Troj/Lineag-CG password-stealing Trojan for the online game Lineage. ... Read More
{83B78794-1991-4BE4-A439-D5EF37E8DC97} 4B8A877E1319.dll
X
Added by the Troj/Lineag-BA password-stealing Trojan for the online game Lineage. ... Read More
{855875B5-93F3-429D-FF34-660B206D897C} 32CCF.dll
X
Identified by Kaspersky as Trojan-Downloader.Win32.Small.ddx.
{9B71D88C-C598-4935-C5D1-43AA4DB90836} [KD]Naruto.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
{A0EE316A-316A-0EE6-6A0E-16AEE16A0EE6} 316a0ee6.dll
X
Added by the Troj/QQRob-AAS Trojan. The filename can be random but will be found in the same location. ... Read More
{AD11A17C-83C2-4121-89C8-D0660555685C} 08835b.dll
X
Added by the Troj/Lineag-ANA password-stealing Trojan for the online game Lineage. ... Read More
{F75BA725-26A4-4F94-94EC-F6F6758ADA38} 4CE9831689C2.DLL
X
Added by the W32/Lineage-AAB worm.


> Status Key
Each entry in the database will have a Status assigned to it. The key to this status is the following:
  • Y - This status flag means that this entry should be left alone and be allowed to run as if it is unchecked it may break the functionality or use of a particular program.
  • N - This status flag means it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
  • U - This status flag means it is up to you whether or not you feel this program needs to run automatically.
  • X - This status flags means the item should definitely not start up automatically. Items that have this flag are generally malware such as viruses, trojans, hijackers, spyware but could also be programs that are not desirable to run on your computer.
  • ? - This status flag means the status of this entry is unknown at this time and more research is necessary.
If you require assistance in removing one of these files you can ask us in the Startup Database Forum.

> Disclaimer
It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. BleepingComputer.com will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides


Portions of this database © Paul Collins
© 2003-2012 All Rights Reserved Bleeping Computer LLC.
PGT: 0.2295 Queries: 4