Welcome Guest (Log In | Create Account)
New Member? Join for free.




A    B    C    D    E    F    G    H    I    J    K    L    M    N    O    P    Q    R    S    T    U    V    W    X    Y    Z    Other   
HJT: F0, F1, F2, F3 · O4 · O20 · O21 · O22 · O23
Rootkit List  · Submit a Startup  · Top Submitters
 Startup Index · Newest Entries · Mozilla Search Tools · WebMaster Site Tools · Status Key
Startup Database Forum · How to use the Startup Database

Enter the filename or keyword you would like to search for:
Advanced Search

Name Filename Status Description
com servoce
3c1807pd 3cmlink.exe 3cpipe-3c1807pd
Y
3Com WinModem driver. See here for more WinModem information
3capplnk 3capplnk.exe
Y
US Robotics Modem driver
3Cmlink 3CmlinkW.exe
Y
For a US Robotics WinModem. Provides the link to Windows as the CPU does the processing on WinModems - won't work without it. See here for more WinMod ... Read More
3dfx Tools 3dfxCmn.dll
Y
Updates the registry with information that can't be held for Voodoo 3/4/5 series graphics cards. Important for owners of these cards ... Read More
3dfxv2ps.dll 3dfxv2ps.dll
Y
Updates the registry with info that can't be held for 3dfx Voodoo 2 video cards. Important for owners of these cards ... Read More
3ware 3DM 3dm.exe
Y
Monitors status of the disk array on 3ware IDE RAID controllers
FoolProofSweep <unknown>
Y
Part of FoolProof Security PC security software from SmartStuff
Initialize8x8 8x8_init.exe
Y
Tool that initializes a Pinnacle PCTV card - maybe in capture or in showing overlay ... Read More
VS.VSN [unknown]
Y
Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added ... Read More
3DMouse.EXE 3DMouse.EXE
Y
Dritek System Inc. 3D Mouse drive
vs.vsn
Y
Part of eSafe antivirus "SmartScan" - alerts the user if files have been changed/added ... Read More
2kadiras 2kadiras.exe
Y
Allied_Telesyn AT series router/modem related - apparently required
9xadiras 9xadiras.exe
Y
Allied_Telesyn AT series router/modem related - apparently required ... Read More
usrpda USRmlnkA.exe
Y
US_Robotics modem driver ... Read More
Kodak Camera Connection Software KodakCCS.exe
Y
Kodak DC File System Driver
<not used> r3hook.dll
Y
Related to Kaspersky Antivirus.
<not used> eNetHook.dll
Y
Related to Acer's eNet Management software for Acer laptops.
APC PBE Server pbeserver.exe
Y
Related to APC PowerChute Business Edition. This startup allows you to monitor UPS connected to different computers and servers. ... Read More
NETGEAR FA410TX Fast Ethernet PC Card Driver \fa410nd5.sys
Y
Driver for the Netgear FA410TX PCMCIA network card.
Application Identity appidsvc.dll
Y
A Microsoft Service that is used by AppLocker to determine and verify the identity of an applicaiton. Please note that this service is launched by s ... Read More
CNG Key Isolation lsass.exe
Y
The Windows CNG key isolation service is hosted in the LSA process. The service provides key process isolation to private keys and associated cryptogr ... Read More
ActivControl ActivControl2.exe
Y
Added by Promethean's interactive whiteboard software.
McAfee Application Installer Cleanup (random numbers) <random #s>~1.exe
Y
McAfee service that cleans up installations files created by a previous installation or update. After this service is run, it should automatically re ... Read More
Power Control [date] 000.fcl
Y
Added by the PowerDVD universal media player.
%cmpmixtitle% Unknown
N
Possibly related to C-Media Mixer Control panel?
3cdminic 3CDMINIC.EXE
N
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards ... Read More
3ComDMIAgent 3CDMINIC.EXE
N
3Com DMI (DynamicAccess Desktop Management Interface) Agent associated with 3Com network cards ... Read More
3dfx Task Manager 3dfxMan.exe
N
System Tray application for 3dfx Voodoo 3/4/5 functions. Available via Start -> Programs ... Read More
AccuWeather.com® Desktop <unknown>
N
Desktop weather from AccuWeather.com
AIMster <unknown>
N
Peer to Peer (P2P) file sharing client that runs over the AOL Instant Messenger network. Available via Start -> Programs ... Read More
Compaq Video CD Watcher <unknown>
N
For Compaq PC's. MPEG viewer
HP Info Express <unknown>
N
On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb ... Read More
HP Updates <unknown>
N
On HP PCs, allows the computer to automatically receive notifications from HP over the Internet. Associated with BackWeb ... Read More
Imesh <unknown>
N
Imesh is a file sharing system
Imesh Auto Update <unknown>
N
Update check for the Imesh file sharing system. Turn the update off under "options" ... Read More
Introduction-Registration <unknown>
N
For Compaq PC's. Should only run first time, PC Introduction & Compaq registration ... Read More
LS120 Superdisk <unknown>
N
Supposed to accelerate transfer rate on LS-120, contributes to system lockups
McAfee Winguage <unknown>
N
Part of McAfee Nuts & Bolts. "WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications, to alert you to ... Read More
One Touch Monitor 1tou~2.exe
N
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
OneTouchMonitor 1tou~2.exe
N
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
ONETOU~2 1tou~2.exe
N
For Visioneer OneTouch scanners. System tray access to the control panel for the scanner ... Read More
Operator <unknown>
N
Media Pilot operator, in Win.ini. Locks port open
Printer [path to file]
N
Added by the LOWTAPER TROJAN!
SB Audigy 2 Startup Menu /l:eng
N
Related to the Dell OEM version of the Sound Blaster Audigy 2 sound card. If this item is listed and checked in startup, the System32 Folder will appe ... Read More
Startup <unknown>
N
Related to an Iomega drive
TGCMG <unknown>
N
Related to Rogers@Home, causes errors in WinSock32.dll. Not required for connection to work ... Read More
Usrobotics Online Registration <unknown>
N
Pop-up reminding customers to register their products online at US Robotics
Windows Eyes <unknown>
N
For blind people, gives a voice description of items on the screen. Windows application which gives you total control over what you hear, when you hea ... Read More
DumpFaultCheck %system%
N
Added by the W32/Scanbot-A worm and IRC backdoor. Though this infection adds these entries, they have no effect on your computer other than open the ... Read More
49ersScreenServer 49ersScreenServer.exe
N
Software from the MercurySports for streaming information about the San Francisco 49ers US Football team. Slightly loose Terms or Use and Privacy pol ... Read More
49ersScreenServerSvc 49ersScreenServer.exe
N
Software from the MercurySports for streaming information about the San Francisco 49ers US Football team. Slightly loose Terms or Use and Privacy pol ... Read More
MEMSWEEP2 <random locations>
N
Added by the Sophos Anti-Rootkit security software. This service is only used when the software is scanning your computer. Otherwise, it can be remo ... Read More
000StTHK 000StTHK.exe
U
Toshiba Hot key functionality for the function keys (Fn-Esc, Fn-F1 (lock), Fn-F2, Fn-F3, Fn-F4, Fn-F5 (switching between laptop and CRT display output ... Read More
00THotkey 00THotKey.exe
U
For Toshiba Satellite notebook series to use the front buttons, play, stop, next, prev. ... Read More
12Ghosts Popup-Killer 12popup.exe
U
2wSysTray 2portalmon.exe
U
2Wire Homeportal user interface
3Deep Control Panel 3DeepCTL.EXE
U
From LightSurf Technologies (nee E-Color) - 3Deep corrects lighting, shading and color for all your 2D and 3D games ... Read More
3DLabsHelperDemon 3dldemon.exe
U
Directly from the programs author "It is a tiny program that is installed by the Permedia2/3 and probably other Oxygen-series cards. Normally it sits ... Read More
3qdctl.exe 3qdctl.exe
U
Provided with Terratec 128i PCI and similar sound cards. Loads a sound profile at bootup, restoring volume and other audio settings to a pre-determine ... Read More
BelNotify [path] NPBelv32.dll, RunDll32_BelNotify
U
"BelTech enables licensees to offer automated, Web-based problem resolution to their end-users. BelTech allows the end-user to simply go to a web page ... Read More
EDRestore <unknown>
U
Set Point from Easy Desk Software - "small utility that automatically sets System Restore points for WinME/XP" ... Read More
HP RecordNow <unknown>
U
From HP "Software for the CD writer. Do not prevent from starting unless the CD writer is never going to be used." ... Read More
Primax 3D Mouse 3dmoused.exe
U
Enables the scroll button on the Primax 3-D Scroll mouse
SMS Win9x Message Agent <unknown>
U
This program assigns a user to a Systems Management Server site
WheelMouse 4DMAIN.EXE
U
Mouse software for "Fellowes" Wheelman mouse. Has caused some users problems but shouldn't be needed if you don't use any enhanced features it may pro ... Read More
ZeroAds 0
U
ZeroAds - culls ads, cookies and pop-ups. Tells ZeroAds not to run at startup - needed to start it manually ... Read More
AWatch Awatch.exe
U
Diagnosis tool that monitors DSL connections, installed alongside DSL drivers from AVM Fritz's range of modem products. ... Read More
$Volumouse$ volumouse.exe
U
Having this program started allows you to control the sound volume on your computer by using the mouse wheel on your mouse. ... Read More
PPSVC [path to Spyware.PCPolice]
U
Added by the PC Police surveillance program. This program should be uninstalled if it was not installed by yourself. ... Read More
Plug and Play Device Manager $sys$DRMServer.exe
U
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
$sys$cor.sys $sys$cor.sys
U
Added by the Sony/XCP DRM security software. This service is part of the digital rights management system utilized on certain Sony CDs. If you remove ... Read More
legalnoticeapplication ""
U
Added by the Spyware.PCProwler surveillance software. If this program was not installed by yourself, it should be uninstalled immediately. ... Read More
ES Current Services [FILE NAME].exe
U
Added by the Spyware.123Keylogger surveillance software. pyware.123Keylogger is a spyware program that logs user activity on the compromised computer, ... Read More
ShowLOMControl (No file name)
U
Shows as O4 - HKLM\..\Run: [ShowLOMControl]  (note strange symbol here) HKLM\Software\Microsoft\Windows\Current Version\Run ShowLOMControl Reg_DWORD ... Read More
hsys HSYS.EXE
U
Added by the Spyware.ExpressKeylog surveillance software. Spyware.ExpressKeylog is a spyware program that records keystrokes on the computer. This sof ... Read More
(default) [random filename].exe
X
Added by the BLACKMAL WORM!
*WinLogon [trojan path]
X
Added by the VUNDO TROJAN!
180adsolution 180adsolution.exe
X
180Solutions/N-Case adware variant
180ax 180ax.exe
X
180Solutions/N-Case adware variant
1on1 1on1.exe
X
Adult content dialler
2thousandbuck [path to file]
X
Added by the RANKY.L TROJAN!
3D Text 3D Text.scr
X
Added by the JERMY.A WORM!
5-2-46-112 5-2-46-112.exe
X
Adult content pop-up dialler. Removal instructions here
;Rundll [filename]
X
Added by the PWSLEGMIR.E TROJAN!
@tour_ww @tour_ww[1].exe
X
Adult content dialler
ACCDEFRAGINFO [path to worm]
X
Added by the DARBY-O WORM!
AddClass [Installation_Path]
X
Added by the STARTPAGE.F TROJAN!
AHU [path to worm]
X
Added by the ANACON-B WORM!
AlevirOld [worm filename]
X
Added by the OPASERV.G WORM!
alkasr ÎäÒíÑ.exe
X
Added by the BALKART TROJAN!
AOL Messenger [random filename]
X
Added by an unidentified VIRUS, WORM or TROJAN!
App.EXEName [path to worm]\.exe
X
Added by the BODIRU WORM!
ara-key [random filename]
X
Added by the ANTINNY WORM!
*ms setup [random file name]
X
Virtumondo adware, also known as the VUNDO TROJAN! ... Read More
Avril Lavigne - Muse [random filename]
X
Added by the AVRIL-A WORM!
Band-Aid [path to file]
X
Added by the RANKY.O TROJAN!
Bnexe [random filename]
X
Added by the KITRO.D (or ARGEN.A) WORM!
Bonzi Buddy <unknown>
X
Spyware - read here for information and here for removal instructions
BrasilOld [worm filename]
X
Added by the OPASERV.P WORM!
cAgOu [filename].hta
X
Added by the KAKWORM WORM!
ccApp [random filename]
X
Added by the OBSORB TROJAN! Note the random filename compared to the valid Norton AntiVirus ... Read More
Cekirge [path to worm]
X
Added by the KERGEZ.A WORM!
center [random name]32.exe
X
Added by the BOFRA.A WORM!
clock [various filenames]
X
LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe ... Read More
Configuration [filename]
X
Added by the SDBOT-ML WORM!
Control handler ***********.exe [* = random char]
X
CoolWebSearch parasite variant
ControlPanel [path] cmd32.exe internat.dll, LoadKeyboardProfile
X
Awmcash.biz foistware
Cryptographic Service ******.exe [* = random char]
X
Added by the KORGO.W or KORGO.X or KORGO.AB WORMS!
CSRSWIN [trojan filename]
X
Added by the WINSHELL.50 TROJAN!
CSRSX [trojan filename]
X
Added by the WINSHELL.50.B TROJAN!
CTime [path to trojan]
X
Added by the HTTPDOS TROJAN!
cyberfree.exe ****.dat [* = random char]
X
Unidentified adware
Danton* [random filename]
X
Added by the DANTON TROJAN! where * = random number
DATABASE MySql [path] repcale.exe [path] beird.exe
X
Added by a variant of the RANDON.AN WORM!
Disk Master [trojan name]
X
Added by the DISTER TROJAN! - a spam relayer
DLL Service Manager [path to worm]
X
Added by the RPCBOT.F TROJAN!
DSAcass [path to file]
X
Added by the RANKY.M TROJAN!
educational writer [random filename]
X
Added by the RBOT-LZ WORM!
Explorer [path to worm]
X
Added by the AUTEX WORM!
G00123 [worm filename]
X
Added by the BUGBROS WORM!
GDAX [path to backdoor]
X
Added by the RANKY.K TROJAN!
GustavVED [filename].exe
X
Added by the OPASERV.H WORM!
hen [filename].exe
X
Added by the TARNO.G TROJAN!
hpsysconf1 [random filename]
X
Added by a variant of the VIVIA.A TROJAN!
ICQ Center [path to worm]
X
Added by the RANDIN WORM!
ICQ Lite Messenger [random filename]
X
Added by an unidentified VIRUS, WORM or TROJAN! Unlike the legitimate ICQ Lite executable, which will be located in the ICQLITE folder in Program File ... Read More
InterceptedSystem [path to worm]
X
Added by the ANACON-B WORM!
Internal [trojan filename]
X
Added by the SMOTHER and TRANSLAT TROJANS!
Irwftp [path to trojan]
X
Added by the BANCOS.CR TROJAN!
ist service uninstall [random filename]
X
ISTBar parasite related
JavaUpdate0.07 [filename]
X
Added by the JUPDATE TROJAN!
KAVutil [worm filename]
X
Added by the WINTOO.B WORM!
KAZAACuf 9
X
Added by the KITRO.D (or ARGEN.A) WORM!
kern64dll [random filename]
X
Added by the TARNO.J TROJAN!
lar [trojan filename]
X
Added by the ROXY.C TROJAN!
LiveUpdate [Windows username]05.exe
X
Added by the LINEAGE TROJAN!
load32 1111a.exe
X
Added by the DUMARU.AH WORM!
LoadOrderVerification [random filename]
X
Added by the TRON.A TROJAN!
LoadWindowsFile [filename]
X
Added by the DELF.B TROJAN! where [filename] is the infected file
Locator Service [filename]
X
Added by the AGOBOT-KY TROJAN!
Login Service [path to file]
X
Added by the MIGMAF TROJAN!
LowVersionSupport [filename]
X
Added by the LASTRAS TROJAN!
lsass [path to lsass.exe]
X
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate lasss.exe process which should NOT appear in Msconfig/Startup! ... Read More
Mantis [filename]
X
Added by the MANTIBE VIRUS!
MatrixScreen [filename]
X
Added by the MATRIXSCREEN TROJAN!
mdetect [path to trojan]
X
Added by the SPABOT TROJAN!
messnger [worm filename]
X
Added by the DELODER WORM!
Mickey Mouse Cereal [random filename].exe
X
Added by the RANKY.Q TROJAN!
MicroLoad [random filename]
X
Added by the DARBY WORM!
Microsoft Corporation [random filename]
X
Added by various VIRUSES, WORMS & TROJANS!
Microsoft Diagnostic [random filename]
X
Added by the ACEBOT TROJAN!
Microsoft IT Update [random filename]
X
Added by a variant of the RBOT WORM!
Microsoft Java Windows Update [filename]
X
Added by the RBOT-DZ WORM!
Microsoft Locals 332 [random filename]
X
Added by the RBOT-KU WORM!
microsoft software ****.exe E255 [* = random char]
X
Added by an unidentified WORM or TROJAN!
Microsoft Synchronization Manager ___synmgr.exe
X
Added by the MASLAN.A or MASLAN.C WORMS!
Microsoft Tray [random filename]
X
Added by the DELF.BZ TROJAN!
Microsoft Update Loader [random filename]
X
Added by a variant of the RBOT WORM!
Microsoft Update Machine [random filename]
X
Added by a variant of the RBOT WORM!
Microsoft Windows DHCP ___r.exe
X
Added by the MASLAN.A or MASLAN.C WORMS!
Microsofts Security Manager ****.exe [**** = random char]
X
Added by the RBOT-WH TROJAN!
MicrosoftWindows [various filenames]
X
MagicSearch - a CoolWebSearch parasite variant
MS-HTML [random filename]
X
Added by the LATINUS.15 TROJAN!
MsgApi [path to file]
X
Added by the DEDLER-D TROJAN!
Msgmgr [path to worm]
X
Added by the BABYBEAR WORM!
MSKCES32 [random filename]
X
Added by the CLONER TROJAN!
Mspatch69 [path to trojan]
X
Added by the MPROX TROJAN!
MSSGisg [path to file]
X
Added by the RANKY.N TROJAN!
mssvc [path to trojan]
X
Added by the PSK TROJAN!
mswspl [random filename]
X
Added by the SMALL.IQ TROJAN!
Myapp [filename]
X
Added by the FATEE.B WORM!
Narrator ******.exe [* = random char]
X
Transponder/VX2 related adware
NAV Live Update [path to worm]
X
Added by the DEBORMS.C WORM! Note - this is not a valid Norton Anti-Virus (NAV) function from Symantec ... Read More
NavScan [filename]
X
Added by the OBSORB TROJAN!
NBT System alias [path] repcale.exe [path] beird.exe
X
Added by a variant of the RANDON.AN WORM!
Nero.ma ***.exe [*** = 2 to 3 digits]
X
Added by the JONBARR.D WORM!
Network Host Controller [path to trojan]
X
Added by the WHISPER TROJAN!
Network Security Guard **********.exe [* = random char]
X
CoolWebSearch parasite related
Nocana [path to worm]
X
Added by the ANACON-B WORM!
nssysconf [random filename]
X
Added by the VIVIA.A TROJAN!
Ntech.patchs [trojan filename]
X
Added by the LEMIR.G TROJAN!
NTP Server [path to trojan]
X
Added by the RANKY.F TROJAN!
Nvid [8 random charachters]
X
Unidentified adware
OLE [filename]
X
Added by the STAWIN or TARNO.D TROJANS!
PAV.EXE %Number%
X
Added by the KITRO.D (or ARGEN.A) WORM! %Number% can be any number
PGStub.exe [various filenames]
X
Unidentified adware
pmc 764.exe
X
Adult content dialler
pnpsvc_lock ******.exe [* = random digit]
X
Browser hijacker
print sharing [path] hidden32.exe [path] explorer.exe
X
Added by the ZCREW.B TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) ... Read More
PrinterSpool [path] RESTORE.EXE [path] SPOOL.EXE
X
Added by the ALADINZ.K TROJAN!
PrivateNet [various filenames]
X
Premium rate adult content dialler
Protection [path] runtask.exe [path] protection.exe
X
Added by a variant of the AGENT.3.AU TROJAN!
putil [filename]
X
Added by the LDPINCH TROJAN!
qbotd [random filename]
X
Added by the BOTTEN TROJAN!
rate.exe ********.exe [* = random char]
X
Unidentified adware
RavTimeXP [worm filename]
X
Added by the WULLIK.B WORM!
RavTimXP [worm filename]
X
Added by the WULLIK.B WORM!
rdvs [worm filename]
X
Added by the ULTIMAX WORM!
Reactor3 [random name]32.exe
X
Added by the BOFRA.A WORM!
Reactor5 [random name]32.exe
X
Added by the BOFRA.D WORM!
Reactor6 [random name]32.exe
X
Added by the BOFRA.C WORM!
Reactor7 [random name]32.exe
X
Added by the BOFRA.B WORM!
Reactor8 [random name]32.exe
X
Added by the BOFRA.E WORM!
Reactor9 [random name]32.exe
X
Added by the BOFRA.E WORM!
REEGRUN [path to file]
X
Added by the SECDROP.AI TROJAN
Regcheck ~CAB001.EXE
X
Added by the CYBRSPY.13A or CYBRSPY.13B TROJANS!
Rhino [random name]32.exe
X
Added by the BOFRA.A WORM!
rngmf [path to trojan]
X
Added by the RANKY.C TROJAN!
romahere2 ************.exe [* = random char]
X
SuperSpider hijacker - a CoolWebSearch parasite variant
romahere3 ************.exe [* = random char]
X
SuperSpider hijacker - a CoolWebSearch parasite variant
RPC Patcher [path to worm]
X
Added by the BOLGI WORM!
RSPC Driver [random filename].exe
X
Added by the RBOT-SN WORM!
RSPC Driver D [random filename]
X
Added by a variant of the RBOT WORM!
rundll32 [path to worm]
X
Added by the AUTEX WORM!
rundll64 [path to worm]
X
Added by the AUTEX WORM!
Scanreg [filename]
X
Added by the QQPASS.E TROJAN!
ScrSvrOld [worm filename]
X
Added by the OPASERV WORM!
Search.vbs [unknown]
X
Hijacker
Service [trojan filename]
X
Added by the KAITEX.E TROJAN!
Service Host [filename].exe
X
Added by the TORVEL.B WORM!
Services [path to trojan]
X
Added by the METEORSHELL TROJAN!
Services004 [worm filename]
X
Added by the BUGBROS WORM!
ShellCommand [path to file]
X
Added by the REMCON-A TROJAN!
smss [path to smss.exe]
X
Added by the ALADINZ.F TROJAN! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup! ... Read More
SpeedBoss [worm filename]
X
Added by the OPASERV.AD WORM!
Spool [path to trojan]
X
Added by the RANKY.R TROJAN!
sr64 ********. exe
X
Adware, as yet unidentified
Srv32Old [worm filename].PIF
X
Added by the OPASERV.J WORM!
Supernova [worm filename]
X
Added by the SURNOVA (or SUPOVA) WORM!
svchost [path to trojan]
X
Added by the HAZZER TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup! ... Read More
svchost [path] SETUP.EXE
X
Added by the SETCLO WORM!
svchost [path] SETUP.EXE
X
Added by the SETCLO WORM!
svcwinprocess32 [path to worm]
X
Added by the UPERING WORM!
Swf32 _backup.exe
X
Added by the SYMTEN WORM!
sws.exe [random filename]
X
Haldex type adult content dialler
SYDNEY [file path]
X
Added by the SYNEY WORM!
System Restore Data [path] repcale.exe [path] beird.exe
X
Added by the RANDON.AN WORM!
System Update [filename].exe
X
CoolWebSearch parasite variant
System Update [random filename]
X
Added by the KORGO.W or KORGO.X WORMS!
SystemEmergency [various filenames]
X
SmartSearch - a CoolWebSearch parasite variant
SystemWideHook for Windows NT %WinHook32.exe
X
Added by the MYDOOM.AC WORM!
Systray [filename.exe]
X
Winfavorites adware
Systry [path to worm]
X
Added by the AUTEX WORM!
Systryt [path to worm]
X
Added by the AUTEX WORM!
Taskmgo [path to file]
X
Added by the BANCBAN-T TROJAN!
TaskReg [random filename]
X
Added by the CBLAD WORM!
TempCom [randomname].com
X
Added by the TRAXG WORM!
tjstartup [path to file]
X
Added by the TJSERV.C TROJAN!
Update [original file path]
X
Added by the LYNDEGG WORM!
UpdSys [random filename]
X
Added by the BJ TROJAN!
upme dllman.exe
X
Added by the MUGLY.F WORM!
User32 [filename]
X
Added by the NETTRASH TROJAN!
UserSystem [filename]
X
CoolWebSearch SmartSearch variant - also see here
ValidData [path to trojan]
X
Added by the RANKY.H TROJAN!
Video Process [random filename]
X
Added by the RBOT-LM WORM!
VideoDriver [filename]
X
Added by the GSPOT20.A TROJAN!
W32Load [random filename].scr
X
Added by the CASPID WORM!
web ******.exe [* = random char]
X
Added by a variant of the EASTO.A TROJAN!
Win2Drv [worm filename]
X
Added by the WINTOO WORM!
Win32 USB2.0 Driver 386.exe
X
Added by the IRCBOT.D WORM!
Win32system [random filename]
X
Added by the DDV.B WORM!
Win32SystemMonitor ***.exe [* = random char]
X
Browser hijacker
windows [path to trojan]
X
Added by the AIMWIN TROJAN!
Windows Compliant [random filename]
X
Added by the RBOT-IR WORM!
Windows Explorer [filename].exe
X
Added by the SDBOT TROJAN! Note - this is not the valid Windows Explorer (explorer.exe) which would only be in startups if you added it manually ... Read More
Windows Media Player [random filename]
X
Added by a variant of the RBOT WORM!
Windows Media Player Update [random filename]
X
Added by the RBOT-ET WORM!
Windows Media SP.2.37 [random filename]
X
Added by the LEMIR.C TROJAN!
Windows NNT [path to trojan]
X
Added by the RANKY.E TROJAN!
Windows Taskbar Manager [path to file]
X
Added by the PROTORIDE.B WORM!
Windows Update [filename]
X
Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites ... Read More
Windows Update Checker [random filename]
X
Adware downloader trojan
Windows Update V6 [random filename]
X
Added by the RBOT-KT WORM!
WindowsReg% update [random filename].exe
X
Added by the RBOT-HH WORM!
WindowsRegistration [random filename]
X
Added by the RBOT-NO WORM!
WindowsRegKey Autoupdate [random filename]
X
Added by a variant of the RBOT WORM!
WindowsRegKey upd4te2d4te *********.exe [* = random char]
X
Added by the RBOT.XQ WORM!
WindowsRegKey update [random filename]
X
Added by a variant of the RBOT WORM!
WindowsSetup [path to trojan]
X
Added by the EZBOT TROJAN!
WindUpdates [path to trojan]
X
Added by the AGENT.BF TROJAN!
wingo [various filenames]
X
Added by the BAGLE-AU WORM!
WinKernel [path to worm]
X
Added by the PLEA VIRUS!
WinLoader [random filename]
X
Added by variants of the SUBSEVEN TROJAN!
Winres32vis [path to worm]
X
Added by the THRAX.A WORM!
WINSYS [path to trojan]
X
Added by the GOLDPLAY TROJAN!
winXP 33.exe
X
Added by the ANPES WORM!
WinXP fix [path to file]
X
Added by the RANKY.P TROJAN!
winzip [path to trojan]
X
Added by the BANCOS.G or BANCOS.K TROJANS!
x3yy [path to trojan]
X
Added by the TANNICK TROJAN!
yyyyyyyy [path to trojan]
X
Added by the MUMUBOY.B TROJAN!
ZaCker [filename].PIF
X
Added by the HOLAR.A WORM!
Zen.A [path to trojan]
X
Added by the ZOOMEN-A TROJAN!
Zonavirus 0
X
Added by the KITRO.D (or ARGEN.A) WORM!
zonealarm [random filename]
X
Added by an unidentified VIRUS, WORM or TROJAN! The only exception is if you have an older version of the ZoneAlarm firewall running ... Read More
[Ephemeral 2.x] by TreeHugger, [path to worm]
X
Added by the LEMOOR.A WORM! where "x" represents 3 or 4
agent browser [random file name]
X
Added by the PPdoor.M-bdr backdoor TROJAN!
^`d}qZxu ~`d}qzxu3zYF
X
Added by the GAOBOT.GEN!POLY WORM!
_Hazafibb [path to file]
X
Added by the ZAFI.B WORM!
_x-Finder _x-Finder.exe
X
Disconnects and redials an ISP modem to an adult content site
fsdsft [file name]
X
Added by the Backdoor.Ranky.S Backdoor!
7VGAV 7VGAV.exe
X
Part of the Adware.Winpup infection. File is found in the Windows system folder. ... Read More
2.exe 2.exe
X
Added by the Troj/Multidr-C Trojan! This file is found in the Windows folder.
1.exe 1.exe
X
Added by the Troj/Multidr-C Trojan! This Trojan downloads and installs further malware onto your computer. ... Read More
Microsoft Java Virtual Machine MsConfiG.exe
X
Added by the W32/Forbot-DV WORM/BACKDOOR! The file is found in the Windows system folder. This infection also installs a service called draeco.sytes ... Read More
Sav32 [random filename]
X
Added by the W32/Famus-G WORM! File found in c:recycled
Help Temp Files netreg.exe
X
Added by a network worm with backdoor functionality, W32/Forbot-EJ copies itself to the Windows system folder as netreg.exe and sets registry entries ... Read More
WinMsgServices ?.exe
X
Added by the Troj/Kelebek-G. This file is added to the Windows system folder. The name of the filename is the ASCII character 255 which corresponds ... Read More
Microsoft Internet Explorer smiissm.exe
X
Added by the Troj/Delf-KK Trojan! The infection creates a folder called SYS in the Windows folder and copies itself there. ... Read More
usbn [random]
X
Added by the Troj/Hogil-B Trojan. This infection adds various links to porn sites in your Desktop and Start Menu. ... Read More
vadseinst [random]
X
Added by the Troj/Ranck-CM Trojan!
Windows boot system cfg32 actboost.exe
X
Added by W32/Forbot-G, a network WORM!
Wins32 Online cfgpwnz.exe
X
Added by W32/Rbot-WN, a network WORM!
taskmrg.exe [random]
X
Added by Troj/Bancban-BN, a TROJAN that attempts to steal banking details.
Configuration apphost.exe
X
Added by W32/Sdbot-VP, a network WORM!
svhost windows services Svhost8.exe
X
Added by a WORM, W32/Rbot-WQ, with backdoor Trojan functionality and found in the Windows system folder. ... Read More
Auth Starter Ident startauth.exe
X
Added by the W32/Rbot-WP WORM!
virtual-machine wini.exe
X
Added by the WORM W32/Rbot-WR, and found in the Windows system folder.
Microsoft Diagnostic msdiag32.exe
X
Added by W32/Rbot-UC, a network worm and IRC backdoor Trojan found in the Windows system folder. ... Read More
Services [random]
X
Added by the Troj/Agent-BV Trojan.
NT Virtual Machine [random]
X
Added by Troj/Agent-BV, a network WORM with backdoor Trojan functionality found in the Windows system folder. ... Read More
doit.exe doit.exe
X
Added by the W32/Forbot-EK WORM! This file is found in the Windows system folder. May also create a Windows service called doit.exe. ... Read More
down winhelp.exe
X
Added by a TROJAN/DOWNLOADER, Troj/Dloader-FQ, and is found in the Windows system folder. ... Read More
Configuration Loader seru32.exe
X
Added by the 32/Forbot-EL WORM! File is found in the Windows system folder.
DI2 [random]
X
Microsoft IIS [random]
X
Added by the WORM variant, W32/Francette-Q.
bluestart [random]
X
Added by Troj/Dloader-IR, a TROJAN!
xpsystem [random]
X
Added by Troj/Krepper-M, a TROJAN! It will be found in a subfolder of the Windows system folder named "services". ... Read More
XpAspy [random]
X
Added by Troj/Delf-WH, a TROJAN! It will be found in the Windows folder.
WXcmeinst [random]
X
Added by Troj/Ranck-CD, a backdoor TROJAN! It will chose a TCP port in the range 10000-49999 to notify a remote web server on that port using a web re ... Read More
CacheLoader [random]
X
Troj/Dloader-IX will download the [random] file to the Windows folder, sub-folder "Cache". That done, it moves to "Security iGuard.exe", found in the ... Read More
sixtysix [random]
X
Troj/LowZone-R TROJAN is responsible for a file found in the Windows folder that will reduce IE security zone settings. ... Read More
lk3h1 [random]
X
Added by the Troj/Mosuck-G TROJAN into the Windows system folder.
128 Module win128.exe
X
Added by the W32/Forbot-ES WORM/backdoor Trojan, which allows unauthorized access to the PC using the IRC network and registration of a new service pr ... Read More
Generic Host Process for Win32 Services bazzi.exe
X
Added by the W32/Ahker-E WORM, from an email attachment. First added to the Startup folder as BADO.EXE and MICHO.EXE, it copies itself to bazzi.exe. ... Read More
System Registry Settings regedit.exe
X
Added by the W32/Rbot-WL WORM/backdoor Trojan and allows unauthorised remote access to infected computers via the IRC network. ... Read More
?ekio Startups ?nksvc32.exe
X
Added by the W32/Agobot-OV WORM/IRC backdoor. ? is a random character. It will kill processes, record keystrokes, allowing unauthorised access to enab ... Read More
[not used] mcafee32.exe
X
w32rbotxe drops a TROJAN, creating several files in %Program Files%, %Windir%, and %system% in addition to this file. ... Read More
Floppy Master [random]
X
Added by the Troj/Zonit-E TROJAN to send spam using other computers.
mssp3 mssp22.exe
X
The Troj/IBank-D TROJAN adds this to steal data entered into a variety of web pages relating to money. ... Read More
RunWin [random]
X
Added by the Troj/Banker-BN TROJAN!
Microsoft (C) HTML Application host [random]
X
Added by the W32/Rbot-YB WORM/IRC backdoor, this file will allow termination of processes by way of a remote attacker using an IRC channel. ... Read More
Microsoft PCHealth32 [random]
X
The Troj/Nice-A TROJAN will log keystrokes using this file, and submit the data via email. ... Read More
down [random filename]
X
Added by the DLOADER.BG trojan downloader!
WinNetDDE [random characters].exe
X
dded by the _blank>NETDEPIX.B TROJAN!
BD [random]
X
The Troj/Agent-CM backdoor TROJAN will first place DC.EXE in the Temporary folder, then modify HKCUSoftwareMicrosoftWindowsCurrentVersionRun to ensure automatic startup.
LanGuard [random]
X
Added by Troj/Dloader-JZ .
MSSGisg [unidentified]
X
Added by the Troj/Ranck-BI TROJAN, it will allow an unauthorized attacker to route HTTP traffic through the infected computer. ... Read More
sVideo2 [random]
X
Added by Dial/Switch-D , a TROJAN premium-rate dialler
msn [random]
X
Added by the Troj/Bancban-BG TROJAN to steal passwords.
Expatch [random]
X
Added by the Troj/PWSLmir-G TROJAN to steal passwords.
Microsoft Internet Acceleration Utility [random]
X
Added by the Troj/Agent-BM TROJAN!
asfqft [random]
X
Added by the Troj/Ranck-BU proxy Trojan, allowing HTTP traffic to be routed through the computer by malicious attackers. ... Read More
Generic Host Process [random]
X
The Troj/Ciadoor-H TROJAN adds the file, enabling an attacker remote access to the computer. ... Read More
USB controller [random]
X
Troj/Miewer-A, a TROJAN, adds the file!
Microsoft DirectX [random]
X
A variant of the Rbot WORM/IRC backdoor will add this file.
Service Manager [random]
X
Added by the Troj/Migmaf-G TROJAN!
_ntrdlhost _ntrdlhost.exe
X
A downloader TROJAN, Troj/Dloader-JV, adds this file.
sox [random]
X
Added by the Troj/Proxyser-G to start a SOCKS4 proxy server on a randomly-chosen TCP port. ... Read More
Kadoc [random filename].exe
X
Added by the Staprew TROJAN!
[random name] ??xplore.exe
X
PurityScan adware variant.
[random name] ??oolsv.exe
X
PurityScan adware variant.
[random name] ??chost.exe
X
PurityScan adware variant.
JVM0.14 [random]
X
Added by the Troj/Teadoor-B backdoor TROJAN!
winreg_32 [random]
X
Added by the Troj/Bancban-BY TROJAN!
reg_run [random]
X
Added by the Troj/Banker-BQ TROJAN!
ccApp [path to .exe]
X
Added by the W32/Rbot-LJ WORM/IRC backdoor Trojan!
Disk Keeper [random]
X
Added by the Troj/Small-VE TROJAN!
RGZCDHTN %System%\RGZCDHTN.exe /install
X
nsysconf [random filename]
X
Added by the Adware.ZioCom.C adware.
Network Devices Controller [unknown filename]
X
Added by the Backdoor.Alnica backdoor. Listens on port 6667 awaiting a remote connection. ... Read More
[random name] ??erinit.exe
X
IO System Debug [random filename]
X
Added by Backdoor.Bla
System-Tray [random filename]
X
minimo [random]
X
Added by the Troj/Mosuck-X. A backdoor Trojan, it can log keypresses, capture screen and webcam images, steal files, provide a remote command shell a ... Read More
winupdateconn_ [path to exe]
X
Added by the W32/Combra-A WORM.
Srv32 spool service [path to .exe]
X
Added by Troj/Dloader-LB.
WebRun [random]
X
Added by Troj/Bube-K.
Background Intelligent Transfer Service rundll32.exe
X
Added by Troj/VB-ZD, which also adds another to insure starting.
Network Connections internat.exe
X
Added by Troj/VB-ZD along with another file run from the system folder, "/rundll32.exe", named Background Intelligent Transfer Service. ... Read More
loader32 [path to .exe]
X
Added by Troj/Domcom-D downloading TROJAN.
Windows update 32 [random]
X
Added by the W32/Rbot-ADG WORM/IRC backdoor Trojan!
fasdqwdwq [path to .exe]
X
Added by the Troj/Ranck-CP TROJAN. It will listen on a randomly chosen TCP port in the range 10000-50000 when run. ... Read More
Windows USB Service 666.exe
X
Added by the W32/Mytob-AW WORM/IRC backdoor trojan!
DllExecutable [path to .exe]
X
Added by the W32/VB-SP WORM!
PornoTop [path to .exe]
X
Added by Troj/Delf-RX, and will be found in the Program Files folder.
Win32DLL [random]
X
Added by the W32/Woned-A WORM!
vb6 [random]
X
Added by the W32/Rbot-TD WORM/IRC backdoor trojan!
Visual Element FX5 [various file names]
X
ClearStream Accelerator adware
eProxy [random]
X
Added as a new service by the Troj/Daemoni-AL TROJAN, using a displayname of Microsoft Security Subsystem Provider. ... Read More
upme [random]
X
Added by the W32/Rbot-TH WORM/IRC backdoor trojan!
qgqqft [random]
X
Added by the Troj/Ranck-BX TROJAN!
SunJavaUpdateSched [path to .exe]
X
Added by the Troj/Banker-AU TROJAN!
msproject [path to .exe]
X
Added by the Troj/Sdbot-TF TROJAN!
@ %1
X
Added by the W32/Protorid-AD WORM!
imgit [path to .exe]
X
Added by the Troj/Banker-CG TROJAN!
xset [random]
X
Added by the Troj/Bdoor-HT.
Verif [random]
X
Added by the W32/Nopir-B WORM!
Anti-Virus Update Scheduler V1.39.12R [path to .exe]
X
Added by the Troj/Fireby-A proxy TROJAN!
OpenMstart [path to .exe]
X
Added by the Dial/Switch-E DIALER.
nvviddrv32 [random]
X
Added by the W32/Rbot-HT trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
BIOS XP Loader [random]
X
Added by the W32/Rbot-IC trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Regisry Configuration [random]
X
Added by the W32/Rbot-IY trojan backdoor. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
Microsoft UpToDate Driver (32-bits) [random filename]
X
Added by the W32/Rbot-ZV worm. When this infection starts it connects to an IRC server where it waits for remote commands to execute. It also instal ... Read More
MS SQL Server Moniter _sqlsrvd.exe
X
Possible new variant of W32.Spybot.NLX. This infection has root kit capabilities so it is possible you have further files that can not be seen.
sqlsrvd _sqlexec.exe
X
Possible new variant of W32.Spybot.NLX. This infection has root kit capabilities so it is possible you have further files that can not be seen.
putil 5845.exe
X
Added by the Backdoor.Zinx backdoor. This backdoor listens on ports 14728 and 24759. ... Read More
Client Agent [path to .exe]
X
Added by the Troj/PPdoor-F trojan. It will target Windows XP firewall and other security related processes for termination. ... Read More
Internet Agent [random CLSID]
X
Added by the Troj/PPdoor-F. It also uses a name Client Agent when changing the registry run key to enable auto-starting at logon. ... Read More
ASDPLUGIN 100176br.exe
X
Added by a variant of the ASDPLUG adult content premium rate dialer!
ASDPLUGIN 100171be.exe
X
AsdPlug premium rate adult content dialer variant
Windows Service Host Process svchost.exe
X
Added by the W32.Ezio.A@mm WORM.
0utlook express *****.exe (where * = random char)
X
Added by the W32/RBOT-CC WORM! ... Read More
357aa41a-b7a8-4632-a27d-5b980b25cf43 [path to svchost.exe]
X
Added by the SMALL-AQ TROJAN! ... Read More
bcnswsx (path to file)
X
Added as result of a Ranck-AJ trojan infection ... Read More
search.vbs
X
Hijacker
windows runtime proccess 32RUNdll.exe
X
Added by the SDBOT.QW WORM! ... Read More
windowsregkey update 16winupdate32.exe
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
[random name] ?hkntfs.exe
X
PurityScan/Clickspring adware ... Read More
Caesvrn [path to .exe]
X
Added by the Troj/Ranck-CQ. This infection sits on a randomly selected TCP port between 1025 and 9997, awaiting contact by a remote attacker. ... Read More
HELLBOT TEST 1hellbot.exe
X
Added by the W32/Mytob-BC worm/trojan.
System CPL manager [random filename]
X
Added by the W32/Rbot-SR worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
Microsoft Security Manager [random filename]
X
Added by the W32/Rbot-TU worm. This infection connects to an IRC server where it waits for remote commands. ... Read More
ccapp .EXE
X
Added by the W32/RBOT-LJ WORM! ... Read More
windll32 _WIN32.EXE
X
Added by the LEGMIR.AQ TROJAN! ... Read More
supernova .exe
X
Added as a result of the SURNOVA (or SUPOVA) VIRUS! .exe is the chosen name ... Read More
[not used] _huytam_.exe
X
Added by the Ssearch.biz and a-search.biz hijackers.
ccapp .EXE
X
Added by the W32/RBOT-LJ WORM! ... Read More
clock (various file names)
X
LiveChat Adware - known file names include: mssetup.exe, kstatus.exe, spoolsv.exe, sptsupd.exe, osk.exe, msswchx.exe, netdde.exe, msbkup.exe ... Read More
[random name] ?ttrib.exe
X
PurityScan/Clickspring adware ... Read More
_ntrrescueservice _ntrrs.exe
X
Added by the TROJ/DLOADER-JV TROJAN! ... Read More
Ndpldaemon [random name]
X
Added by the W32/RpcSdbot-A backdoor trojan.
VCbvnczsxcX [random filename]
X
Added by the Troj/Ranck-AK proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vcxcxvxcX [random filename]
X
Added by the Troj/Ranck-AQ proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
ffeqOME [random filename]
X
Added by the Troj/Ranck-AR proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vDSAGGQEvbA ASDAS dqdw [random filename]
X
Added by the Troj/Ranck-AT proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vDGDGvvsa dqdw [random filename]
X
Added by the Troj/Ranck-AV proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
bbdjmrxcX [random filename]
X
Added by the Troj/Ranck-AX proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
halloween stream [random filename]
X
Added by the Troj/Ranck-AY proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vxcxcvfck. [random filename]
X
Added by the Troj/Ranck-AZ proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
dfasack [random filename]
X
Added by the Troj/Ranck-BE proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
qffecdas [random filename]
X
Added by the Troj/Ranck-BF proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Bmsnwss [random filename]
X
Added by the Troj/Ranck-BK proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vXCXssdss [random filename]
X
Added by the Troj/Ranck-BO proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
fqxsbk [random filename]
X
Added by the Troj/Ranck-BS proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Wdqvsst [random filename]
X
Added by the Troj/Ranck-BT proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
SysData [random filename]
X
Added by the Troj/Ranck-BA proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
tkaskqjw [random filename]
X
Added by the Troj/Ranck-CA proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
PlanCx [random filename]
X
Added by the Troj/Ranck-CE proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
vadeinst [random filename]
X
Added by the Troj/Ranck-CF proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
WinManage [random filename]
X
Added by the Troj/Ranck-KH proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
svchosts32 [random filename]
X
Added by the Troj/Ranck-L proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Windows NT [random filename]
X
Added by the Troj/Ranck-M proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
ctfmonn [random filename]
X
Added by the Troj/Ranck-O proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
NTServ [random filename]
X
Added by the Troj/Ranck-P proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
msmsgss [random filename]
X
Added by the Troj/Ranck-S proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
NVidia Drivers [random filename]
X
Added by the Troj/Ranck-R proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
RealVNC Setup [random filename]
X
Added by the Troj/Ranck-V proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Msn Home [random filename]
X
Added by the Troj/Ranck-W proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
bdffefqes32 [random filename]
X
Added by the Troj/Ranck-Z proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Microsong [random filename]
X
Added by the Troj/Ranck-A proxy trojan. This infection allows a remote intruder to use your Internet connection to hide his location. ... Read More
Iamnacho On Irc. MusicIrc.com Is a Homosexual! [random name]
X
Added by the W32/Randex-T worm. When started, this infection connects to an IRC server where it waits for remote commands to execute. ... Read More
Installs SP4 %system%\ekrlgc\repcale.exe c:\windows\system32\ekrlgc\p0rd.exe
X
Added by the W32/Randon-AK worm. This infection, when started, connects to an IRC server using a provided MIRC client to receive commands. ... Read More
Window service [random]
X
Added by the W32/Rbot-ACH worm. This infection has backdoor functionality, allowing unauthorized access to perform a wide variety of actions. ... Read More
[random name] ??rvices.exe
X
PurityScan adware variant.
Microsoft LV [random filename]
X
Added by the Troj/Bdoor-BDL trojan.
c7 [name of worm]
X
Added by the W32.MEDIAKILL.A WORM! ... Read More
dm_service [path to file]
X
Added by the MITGLIEDER.P TROJAN! ... Read More
outlook express config *****.exe (where * = random char)
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
winupdateconn [path to file]
X
Added by the W32/COMBRA-A WORM! ... Read More
winupdate_ [path to file]
X
Added by the W32.COMDOR.A WORM! ... Read More
Visual Lube.html
X
Added by the WM97/Lebone-A Microsoft Word macro virus.
[random name] ??anregw.exe
X
PurityScan/Clickspring adware ... Read More
voltage manager [random file name]
X
Added by the W32.DREFFORT WORM!
Norton Antivirus 7.0a [random filenames]
X
Added by the Troj/Perda-B trojan proxy.
1111swapmgr.exe 1111swapmgr.exe
X
Added by the Troj/Bdoor-IC backdoor trojan.
winupdatefiv_ [file name]
X
Added by the W32/Combra-C email worm.
TSystem [original filename]
X
Added by the Troj/Nsys-A trojan downloader.
NSystem [downloaded file]
X
Added by the Troj/Nsys-A trojan downloader.
MEDIA32 [pathname of the executable]
X
Added by the Troj/PurScan-Z trojan.
vbs.ipnuker@mm (original worm file name).vbs
X
Added by the VBS.Nukip ... Read More
windowz (original worm file name).vbs
X
Added by the VBS.Nukip ... Read More
boarddata [path] repcale.exe [path] palsp.exe
X
Added by a variant of the RANDON.AN WORM! ... Read More
element furth [path] repcale.exe [path] palsp.exe
X
Added by a variant of the RANDON.AN WORM! ... Read More
installs sp2 [path] repcale.exe [path] palsp.exe
X
Added by a variant of the RANDON.AN WORM! ... Read More
ms window update ******.exe (* = random character)
X
Added by a variant of the WIN32.RBOT WORM! ... Read More
hxadsec [executable name]
X
Added by the Troj/AdClick-AP trojan.
vbs_auto_update 0548656X.vbs
X
Added by the VBS/Gormlez-A ... Read More
Monitor Test [random filename]
X
Added by the W32/Sdbot-NC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
ansjava [path to mirc application]
X
Added by the W32/Randon-AN worm and IRC backdoor..
WinUpgrader [path to EXE]
X
Added by the trojan.
File0_0 [path of Trojan]
X
Added by the Troj/Dloader-OR trojan downloader.
msbsc [path to trojan]
X
Added by the Troj/Banker-DF password-stealing trojan of Brazilian banks.
AIM Instant Message Cookies [random filenames]
X
Added by the W32/Rbot-AFV worm. When started, this infections connects to a remote IRC server where it waits for commands to execute. ... Read More
anti-virus product sync [AN UNPRINTABLE CHARACTER][3 CHARACTERS]log.exe
X
Added by the W32.Kedebe.D(AT)mm ... Read More
ibin (Pathname of the Trojan executable)
X
Added by the Troj/Perda-C ... Read More
virus removal tool (pathname of the Trojan executable)
X
Added by the Troj/Tometa-B ... Read More
Floppy Master [path to trojan]
X
Added by the Troj/Zonit-F backdoor trojan.

Some potential file names may be:

C:\WINDOWS\wavplay.exe
C:\WINDOWS\system ... Read More
worknote1 [unknown]
X
Added by the W32.Meetot worm.
KavSvc [random 6 char filename]
X
Qoologic downloader trojan variant using random file names (examples: nzkklz.exe) ... Read More
[random name] ??ool32.exe
X
PurityScan/Clickspring adware ... Read More
_tdiserv_ _tdicli_.exe
X
Added by the W32.TDISERV.A WORM! ... Read More
Root_Machine [pathname of the Trojan executable]
X
Added by the Troj/Bancban-DP password-stealing trojan for customers of Brazilian banks. ... Read More
HDAudio Driver 1.0 [random name].exe
X
Added by the Troj/Teadoor-D backdoor trojan.
_System_Run _svchost_.exe
X
Added by the Troj/Lineage-Z password-stealing trojan for the online game Lineage. ... Read More
HDAudio Driver 2.0 [randomstring].exe
X
Added by the Troj/Teadoor-E trojan.
xserv [random name].exe
X
Added by the Troj/Stumpy-A trojan.
Windows System Security Monitor [4 random letters].exe
X
Added by the W32.Pinkton.A worm.
[random name] ??rss.exe
X
PurityScan/Clickspring adware ... Read More
microsoft security gmanagers [random file name]
X
Added by a variant of the W32/SDBOT WORM! ... Read More
microsoft security panagers [random file name]
X
Added by a variant of the W32/SDBOT WORM! ... Read More
Windows Logon Application services.exe
X
Added by the Troj/Ciadoor-L trojan.
Rundll32_8 1.dll
X
Added by the Adware.BrowserAid adware.
msnmsgy [unknown]
X
Added by the Troj/Banker-EQ password-stealing trojan targetting Brazilian banks. ... Read More
Windows ASN Service [random name]
X
Added by the W32/Agobot-TC worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
SNInstall [various names]
X
Added by the Troj/Spyhoax-A trojan.
Vaganza-XPloit-[User Name] [User Name].exe
X
Added by the W32.Gavgent.A worm.
(randomly chosen existing folder name) _setup.exe
X
Added by the W32/Antinny-L ... Read More
enbrowser [name of file]
X
WINBO adware component ... Read More
Symantec Autoscan [random filename]
X
Added by the W32/Rbot-AJO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Litebot [Trojan executable name]
X
Added by the Troj/Litebot-A Trojan.
20050726-007-i32-1 20050726-007-i32-1.exe
X
Added by the Troj/Bancban-EC information stealing Trojan.
Winport.com [various]
X
Added by the Backdoor.Acropolis backdoor. The name of the backdoor is Acropolis 1.0. It listens on ports 32791, 45673 for connections. ... Read More
Web Event Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.B backdoor.
Web Event Logger <random>.exe
X
Added by the Backdoor.Berbew.D backdoor.
Web Event Logger <8 random characters>.dll
X
Added by the Backdoor.Berbew.F backdoor.
WebEvent Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.F backdoor.
Web Event Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.M backdoor.
Web Event Logger [8 random characters].dll
X
Added by the Backdoor.Berbew.P backdoor.
Internet Explorer [RANDOM NAME].dll
X
Added by the Backdoor.Berbew.T backdoor.
Ctykd %Malware path and filename%
X
Added by the TSPY_SMALL.SN spyware.
msresear <pathname of the Trojan executable>
X
Added by the Troj/Weasyw-B Trojan.
Windows ExpIorer [random filename]
X
Added by the W32/Rbot-AKO worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
PNP FIX [unknown]
X
Added by the W32/Rbot-AKQ worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
5p4m [path to Trojan]
X
Added by the Troj/Litebot-C Trojan.
Vanquish Autoloader v0.1 beta10 [various names]
X
Added by the Hacktool.Vanquish rootkit.
Network Client Monitor [unknown]
X
Added by the Trojan.Boxed.B Trojan.
NetDDEipx [Random file name].exe
X
Added by the Trojan.Netdepix Trojan.
Messenger 514.exe
X
Added by the Trojan.Esteems.D Trojan.
CSRS Windows NT [various names]
X
Added by the Backdoor.WinShell.50 backdoor.
@liberamovilespt @liberamovilespt
X
Added by the Dialer.UDIS premium adult dialer.
Network Client [Unknown]
X
Added by the Trojan.Boxed.C Trojan.
SSDP Discovery Service Locator [unknown]
X
Added by the Troj/Pndoor-A backdoor Trojan.
Windows Standard Securty [random 3 letter filename]
X
Added by the W32/Rbot-ALF worm.
support-reverse-smileys [random filename]
X
Added by the Troj/Litebot-D Trojan.
Windows Security Service [random filename]
X
Added by the W32/Rbot-ALV worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Trayz [random filename]
X
Added by the Troj/Bdoor-JG backdoor Trojan.
MSN 9.0 Plus [random.exe]
X
Added by the W32/Rbot-ALY worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
[not used] _Kerne1.exe
X
Added by the Troj/Lineage-AN password-stealing Trojan for the online game Lineage. ... Read More
0050726-007-i32-1 0050726-007-i32-1.exe
X
Added by the Troj/Bancban-EC ... Read More
SysTray.Excn [random 8 character dll)
X
Added by the Troj/Cozdoor-C Trojan.
winlogon32_ [PATH TO THE WORM]
X
Added by the W32.Mailbancos@mm worm.
Internet Explorer [random letters].dll
X
Added by the Troj/Proxma-A proxy and backdoor Trojan.
SysTray.Exsh [random 8 character dll]
X
Added by the Troj/Cozdoor-D bacdoor Trojan.
spoolax [pathname of the Trojan executable]
X
Added by the Troj/Perda-D Trojan.
Microsoft Security Panager [worm filename]
X
Added by the W32/Rbot-ANL worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
stdlib [pathname of the Trojan executable]
X
Added by the Troj/Perda-E password-stealing Trojan.
OpenGL Drivers 0penGLD.exe
X
Added by the W32/Yimp-A Instant Messaging worm.
Connectivity Tool [path to trojan]
X
Added by the Troj/Litebot-E IRC backdoor Trojan.
MSPRO32 <pathname of the worm executable>
X
Added by the W32/Hiberi-B worm.
SFTRANSFER [unknown]
X
Added by the Backdoor.Brakkeshell backdoor Trojan.
WheelsMouse <path to Trojan>
X
Added by the Troj/SocksPr-D proxy server Trojan.
Devicewin <pathname of the Trojan executable>
X
Added by the Troj/Banker-AEV Trojan.
kernel32.dll <pathname of the Trojan executable>
X
Added by the Troj/Zlob-AP Trojan.
[Ephemeral 2.5] by TreeHugger, [randomname].exe
X
Added by the W32/Lemoor-C worm.
Virus Cleaner <original Trojan filename>
X
Added by the Troj/Delta-E Trojan.
__ZF5 [unknown name]
X
Added by the W32.Erkez.F@mm mass-mailing worm.
NTupdater <path to a renamed Mirc client>
X
Added by the Troj/Digarix-D backdoor Trojan.
SysStart 1.exe
X
Added by the Adware.ZenoSearch adware.
Safe <path to Trojan EXE>
X
Added by the Troj/Banker-DT password stealing Trojan aimed primarily at users of Brazilian banks. ... Read More
[various names] 80d0.exe
X
MediaMotor/Popuppers adware variant. Names spotted include 80d0, SWOD, g$p$, elos, seli, "piz, :C=e, resU and so on ... Read More
Windows Socketheader [random filename]
X
Added by the W32/Ixbot-A worm and IRC backdoor.
Microsoft Redirect <pathname of the Trojan executable>
X
Added by the Troj/Banker-FW Internet banking Trojan.
Telnet24 <random filename>
X
Added by the W32/Rbot-ARD worm. This infection, when started, connects to an IRC server where it sits on a channel awaiting commands. ... Read More
klop [random]exe
X
Added by the Troj/Dloader-WA downloading Trojan.
Startup Configuration [random 6 letter filename]
X
Added by the W32/Rbot-ARV worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. ... Read More
Idoneus <random filename>
X
Added by the MSIL.Idonut virus.
WinShell <path to worm>
X
Added by the W32/Fanbot-B mass-mailing and P2P worm.
MICROSFT RAMA UPDATE SUPPORT <random filename.exe>
X
Added by the W32/Rbot-ASM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
Rapdyleys <pathname of the Trojan executable>
X
Added by the Troj/QQPass-AD Trojan.
Legacy [RANDOM CHARACTERS]
X
Added by the Backdoor.Eparssa backdoor Trojan.
System Power Managment svcnost.exe
X
Added by the W32/Dref-I email worm and backdoor Trojan.
[not used] 896588AppInit.DLL
X
Added by the Troj/LegMir-BI Trojan. This infection also creates the %WinDir%896588.dll file. ... Read More
Proc992 <random filename.exe>
X
Added by the W32/Ixbot-C worm and IRC backdoor.
MEAOI Service _meaoi.exe
X
Added by the W32/Tilebot-AM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. This infection ... Read More
st3i <random filename.dll>
X
Added by the Troj/Hasum-A Trojan.
3d_sound 3d_sound.exe
X
Added by the Troj/Riados-A Trojan that attempts a distributed denial of service (DDoS) attack against www.riaa.com. ... Read More
HATAPE <Trojan executable>
X
Added by the Troj/Banker-QF Trojan.
eMCryT Sh3ars Panagers <random filename.exe>
X
Added by the W32/Rbot-AWI worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
office_update <Trojan executable>
X
Added by the Troj/Dloader-ZB Trojan.
Win_BooT <Path to Trojan>
X
Added by the Troj/Banker-GI password-stealing Trojan.
wuauon <random filename>.exe
X
Added by the Troj/Bdoor-MC backdoor Trojan.
MSSever <Trojan Filename.exe>
X
Added by the Troj/PWS-CW password-stealing Trojan.
$sys$cmp $sys$xp.exe
X
Added by the Troj/Stinx-F backdoor Trojan. Troj/Stinx-F may be stealthed on an infected system by exploiting Sony DRM (Digital Rights Management) sof ... Read More
$sys$drv $sys$drv.exe
X
Added by the Backdoor.Ryknos Trojan backdoor that attempts to utilize the SecurityRisk.First4DRM security risk to hide itself on the compromised compu ... Read More
Gray_Pigeon .exe
X
Added by the Troj/GrayBrd-EH backdoor Trojan. This infection also creates the file c:\windows\temp\8e4ds4.dll. ... Read More
DBGA0EEG <random filename>.dll
X
Added by the W32/Doxpar-D password-stealing network worm.
PHIME2OO2ASyst <Trojan executable>
X
Added by the Troj/DBdoor-B backdoor Trojan. This filename for this trojan can be change to one specified by the hacker. ... Read More
FindHack <Trojan executable>
X
Added by the W32/Kelvir-BA Trojan.
80xFire daemon 80xFire.exe
X
Added by the W32/Tilebot-BK worm and IRC backdoor. This also infects your computer with the rootkit rdriv.sys. ... Read More
System32Check <random>.exe
X
Added by the Troj/Chast-A backdoor and keylogging Trojan.
Google Earth <random name>.pif
X
Added by the W32/Rbot-AXK worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
SysTray.Exys <random filename with DLL extension>
X
Added by the Troj/Slogger-D Trojan.
GlobalSCAPE <filename>.exe
X
Added by the W32/Rbot-AYM worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
winabc <ORIGFILENAME>.DLL
X
Added by the Troj/Lineage-PN password-stealing Trojan for the online game Lineage. ... Read More
Service Screan <random filename>
X
Added by the W32/Rbot-BAC worm. When started, this infection connects to a remote IRC server where it waits for commands to execute. ... Read More
_accwiz.exe _accwiz.exe
X
Added by the Troj/Certif-N password-stealing Trojan.
SysTray.Exiv <random>.dll
X
Added by the Troj/Slogger-F backdoor Trojan.
$sys$crash $sys$WeLoveMcCOL.exe
X
Added by the Trojan.Welomoch Trojan.
$sys$crash $sys$sos$sys$.exe
X
Added by the Trojan.Welomoch Trojan.
$sys$crash $sys$sonyTimer.exe
X
Added by the Trojan.Welomoch Trojan.
taskbar <Trojan executable>
X
Added by the Troj/Perda-I backdoor Trojan.
Proc112 <File name of the dropped file>
X
Added by the WORM_IXBOT.A worm.
Myfault <Trojan.exe>
X
Added by the Troj/Ranck-DJ Trojan.
zzzsoft <Trojan executable>
X
Added by the Troj/QQRob-AD Trojan.
DER005 <random filename>
X
Added by the Troj/Hackvan-B Trojan rootkit.
XRW005 <random filename>
X
Added by the Troj/Hackvan-B Trojan rootkit.
msapps32 <Trojan executable>
X
Added by the Troj/Banker-IS Trojan.
Remote Procedure Call (RPC) Activator [Currently unknown]
X
Added by the Troj/Fiserv-A backdoor Trojan.
aaprotect <Trojan Filename>
X
Added by the Troj/Bancban-MJ Trojan.
NAVNet <Name of Executable>
X
Added by the Troj/Small-FR Trojan. The filenames and locations are random.
cppc <Trojan executable>
X
Added by the Troj/VB-NV Trojan. This trojan pretends to be a Half-Life 2 crack. ... Read More
Winsocket log <random characters>.exe
X
Added by the Troj/Sdbot-AKF worm and IRC backdoor.
Windows Overlay Components <randomfilename>.exe
X
Added by the Troj/Agent-JK Trojan.
Hutley-Spieluhr <filename.exe>
X
Added by the Troj/Shpiel-A backdoor Trojan.
Win Prosess0r <random filename>
X
Added by the W32/Rbot-BIT worm and IRC backdoor.
(default) ~~.exe
X
Added by the Troj/DownLdr-QR Trojan downloader.
eTunnel <random filename>.exe
X
Added by the Troj/Meteor-E backdoor Trojan.
Microsoft Console Manager mcm.exe
X
Added by the Troj/WinShel-A backdoor Trojan.
ni.uwfx5_0001_n57m2112 1D7C.tmp
X
This is WinFixer Malware.
[Various Names] _ctcp.exe
X
Part of the Wareout infection as described here.
[Various Names] 34763.exe
X
Part of the Wareout infection as described here.
[Various Names] 10010.exe
X
Part of the Wareout infection as described here.
[Various Names] 321102.exe
X
Part of the Wareout infection as described here.
[Various Names] 321102.exe
X
Part of the Wareout infection as described here.
Apoint System <Trojan Executable>
X
Added by the Troj/Banker-WK Trojan.
1.bat 1.exe
X
Added by the Troj/Banload-LK Trojan.
Content connector <various filenames.exe>
X
Added by the Troj/Dialer-Y dialer.
nethost.exe <randomfilename>.exe
X
Added by the Troj/Perda-J backdoor Trojan.
Msn Update SUPPORT <random filename>
X
Added by the W32/Rbot-BPS worm and IRC backdoor.
SmartTesting <Trojan executable>
X
Added by the Troj/Ranck-DO http proxy trojan.
spyclean 1ClickSpyClean.exe
X
The application "1 Click Spy Clean" is using a database that was stolen from SpybotS&D A Rogue anti-spyware program see note ... Read More
VSSTAT <random>.exe
X
Added by the W32/Gobot-N worm and IRC backdoor.
Microsoft Moniter Control <worm filename>
X
Added by the W32/Rbot-BAX worm and IRC backdoor.
Windows Firewall Monitor <random filename>.exe
X
Added by the Troj/Proxy-AX proxy Trojan.
TempCom 8746D.com
X
Added by the W32/Traxg-H mass-mailing worm.
DllLoader32 <filename>.exe
X
Added by the Troj/Bdoor-QD backdoor Trojan.
DTInstall <filename.>.dll
X
Added by the Troj/Small-ALM Trojan.
SySPower [Unknown at this time]
X
Added by the Troj/SpyAgen-G keylogging Trojan.
mxb2 [RANDOM].exe
X
Added by the W32.Maniccum worm.
newname <application executable>
X
Added by the Troj/Drsmartl-S Trojan.
Bron-Spizaetus-5118REPM _default32142.pif
X
Added by the W32/Brontok-R mass-mailing worm.
2006Server 2006.exe
X
Added by the Troj/Feutel-DA backdoor Trojan.
(default) ¡¡NOTEPAD.EXE
X
Added by the Troj/Vaq-A Trojan downloader.
Tspy <Trojan Filename>
X
Added by the Troj/TSpy-B keylogging Trojan.
begins 0.exe
X
Added by the W32/Mytob-HE mass-mailing worm and IRC backdoor.
solid 0.exe
X
Added by the WORM_MYTOB.PP worm and IRC backdoor.
Microsoft Anti-Virus <Random Filename.exe>
X
Added by the W32/Kassbot-O worm and IRC backdoor.
0mcamcap 0mcamcap.exe
X
Added by the Troj/Cosiam-H proxy Trojan.
angnan <random filename.exe>
X
Added by the W32/Bobax-DB worm.
A5118r _default32142.pif
X
Added by the W32/Brontok-AK mass-mailing worm.
4da92ad5.exe 4da92ad5.exe
X
Added by the Troj/Dloadr-WZ Trojan.
pe386 <random number>
X
Added by the Backdoor.Rustock.A backdoor Trojan. This infection uses Alternate Data Streams and rootkit technology to hide itself and the service ent ... Read More
0b82c247.exe 0b82c247.exe
X
Added by the Troj/Tiny-Q Trojan.
4c0f6e34.exe 4c0f6e34.exe
X
Added by the Troj/Dloadr-XP downloader Trojan.
Windows Recycler <random filename.exe>
X
Identified by Kaspersky as a variant of the Backdoor.Win32.Rbot.gen worm and backdoor family. ... Read More
4ccc3cea.exe 4ccc3cea.exe
X
Added by the TROJ_ZLOB.ACB Trojan.
Rapdetnlu <Trojan executable>
X
Added by the Troj/MapStor-A password-stealing Trojan.
Tssh <unknown>
X
Added by the Troj/Mlsuc-E backdoor Trojan.
wowexecl ""
X
Added by the Troj/Vanity-A Trojan. This infection includes the files C:\Windows\System32\wowexecl.dll and c:\Windows\System32\wowexecl.ini. Due to ... Read More
196_150_ni 196_150_ni.exe
X
Added by WinSoftware/WinFixer.Process TROJAN! ... Read More
197_150_ni_3 197_150_ni_3.exe
X
A variant TROJAN! ... Read More
Wiinamp <random>.exe
X
Added by the Troj/IRCBot-OH backdoor Trojan which utilizes IRC to receive its commands. ... Read More
Easy Protect NT Driver _epnt.sys
X
Added by the Spyware.Ezurl spyware.
ezurl _epnt.sys
X
Added by the Spyware.Ezurl spyware.
{2C1CD3D7-86AC-4068-93BC-A02304BB2236} 2236_27.dll
X
Identified by Kaspersky Anti-Virus as Backdoor.Win32.Agent.adr.
stup 138762763.exe
X
Added by the Troj/FireSpy-A Spyware Trojan. This Trojan monitors the browsing behaviour of the FireFox browser. ... Read More
4k51k4 4k51k4.exe
X
Added by the W32/Brontok-BH worm.
<unknown> asusrx25.sys
X
Variant of the Troj/Haxdor-Fam rootkit.
Print Spooler Service <Random Filename.exe>
X
Added by the W32/Bobax-DZ worm. W32/Bobax-DZ spreads to other network computers by exploiting common buffer overflow vulnerabilities. The filename for ... Read More
DirectX Service <Unknown>
X
Added by the Troj/Bdoor-AAT backdoor Trojan.
FiresWallservices <random>.exe
X
Added by the W32/Rbot-FJT worm and IRC backdoor.
Fire Well service <random>.exe
X
Added by the W32/Rbot-FJU worm and IRC backdoor.
ms_net_update <Original Filename of Worm>.exe
X
Added by the W32/Womble-A mass mailing worm. W32/Womble-A uses Exp/WMF-A which exploits a vulnerability in the image rendering functionality of the DL ... Read More
{855875B5-93F3-429D-FF34-660B206D897C} 32CCF.dll
X
Identified by Kaspersky as Trojan-Downloader.Win32.Small.ddx.
Windows NT Session Managers smss.exe
X
Added by the W32/Sdbot-CPN worm and IRC backdoor. This infection should not be confused with the legitimate file C:\Windows\System32\smss.exe. ... Read More
0000000 0.exe
X
Added by the W32/Sdbot-CPP worm and IRC backdoor.

W32/Sdbot-CPP spreads to other network computers by exploiting common buffer overflo ... Read More
WinSysModule <Trojan executable>
X
Added by the Troj/Agent-DIQ keylogging Trojan.
ttool 9129837.exe
X
Added by the Troj/DwnLdr-FSA downloader Trojan.
Mike3 222.exe
X
Added by the Troj/Wombat-A Trojan.
_mzu_stonedrv3 _mzu_stonedrv3.exe
X
Added by the Troj/DwnLdr-FTB downloader Trojan.
Print Spooler Service <random file name>.exe
X
Added by the Troj/HacDef-DJ backdoor Trojan and rootkit.
_mzu_stonedrv2 _mzu_stonedrv2.exe
X
Added by the Trojan.Jupillites.B backdoor Trojan. Trojan.Jupillites.B is a Trojan horse the downloads remote files and opens a back door on the compro ... Read More
Winsvr <random filename>.exe
X
Added by the Troj/AdClick-DK Trojan.
arprmdg0 arprmdg0.dll
X
Added by the Troj/Haxdoor-DI trojan. This infection utilizes the arprmdg5.sys rootkit to hide itself. ... Read More
Windows Insecure <4 random letters>.exe
X
Added by the W32/Rbot-FSM worm and IRC backdoor. W32/Rbot-FSM spreads to computers vulnerable to common exploits, including: LSASS (MS04-011), RPC-DCO ... Read More
Smsvr <Trojan executable>
X
Added by the Troj/Dloadr-APC Trojan.
hdlpscom <random 8 letters>.exe
X
Added by the W32/Rbot-FUL worm and IRC backdoor.
{A0EE316A-316A-0EE6-6A0E-16AEE16A0EE6} 316a0ee6.dll
X
Added by the Troj/QQRob-AAS Trojan. The filename can be random but will be found in the same location. ... Read More
Windows S1ystem Managment <random characters>.exe
X
Added by the W32/Rbot-FUN worm and IRC backdoor.

W32/Rbot-FUN spreads to other network computers by:

- exploiting common ... Read More
winValidate <random filename>.exe
X
Added by the Troj/Bckdr-PNO Instant Messaging Trojan.
DownLmm <original Trojan filename>
X
Added by the Troj/Dloadr-APL Trojan.
Downm <original Trojan filename>
X
Added by the Troj/Dloadr-APL Trojan.
System SSDP Services <random letters>.sys
X
Added by the Troj/Pardot-A rootkit.
Timer Service <Trojan Executable>
X
Added by the Troj/WoW-IL password-stealing Trojan for the online game World of Warcraft. ... Read More
1u7 1u7.exe
X
Added by the Troj/Bckdr-PQL backdoor Trojan.
whxpin service <RandomName>.exe
X
Added by the W32/Rbot-FWU worm and IRC backdoor.
Numerical Xterm Agent 0x32.exe
X
Added by the W32/Rbot-FWP worm and IRC backdoor.
SvcManager <Trojan executable>
X
Added by the Troj/Zalon-A backdoor Trojan.
Numerical Xtermz Agent 1x32.exe
X
Added by the W32/Rbot-FWX worm and IRC backdoor.
Numerical Xterm Agents 2x32.exe
X
Added by the W32/Rbot-FWY worm and IRC backdoor. W32/Rbot-FWY spreads to other computers by exploiting common buffer overflow vulnerabilities like SRV ... Read More
NVFW <Path to worm executable>
X
Added by the W32/Mofei-S worm.
SysCalcPlus <Spyware file name>
X
Added by the TSPY_BANKER.FTD spyware.
SearchClick <original Trojan filename>
X
Added by the Troj/Agent-DWR Trojan.
MicroSoft Media Services [RANDOM 8 CHARACTER].sys
X
Added by the virus. W32.Mediasups is a virus that spreads by infecting executable files, may download files and communicate with a remote server. ... Read More
ROME ROTYUS hxdefdrv.sys
X
Added by the Troj/HacDef-DR rootkit.
Grogotix <random 5 characters>.exe
X
Added by the W32/Flukan-C backdoor virus. W32/Flukan-C infects files with ".zip" extensions on the local system, by overwriting the contents of the ZI ... Read More
winapi _.exe
X
Added by the Troj/Lulador-A backdoor Trojan.
jamil _.exe
X
Added by the Troj/Lulador-A backdoor Trojan.
systwyns <random name>.exe
X
Added by the Troj/PWS-ADX password-stealing Trojan.
Wupdate 1037v.exe
X
Added by the Troj/Clagger-AR Trojan.
grgtgvgb.exe <random>.exe
X
Added by the Troj/Agent-EBF Trojan.
Alexa bridge <random>.exe
X
Added by the Troj/Agent-EBL Trojan.
pangu_service_display <variousnames>.exe
X
Added by the Troj/DDoS-V DDOS Trojan. This infection can have various names such as C:\WINDOWS\System32\temp2.exe, C:\WINDOWS\system32\1003.exe, and ... Read More
Service Transaction Provisioning <variousnames>.exe
X
Added by the Troj/DDoS-U DDOS Trojan.
{3771BD45-B3B5-46FF-B309-028D126B9103} 299E55F.dll
X
Added by the Troj/Gampass-H password-stealing Trojan for online games.
Zul_Cinta_Anick [RANDOM CHARACTERS].exe
X
Added by the Trojan.Nickzul Trojan.
cintaku [RANDOM CHARACTERS].exe
X
Added by the Trojan.Nickzul Trojan.
{79921D3F-7537-463E-9E38-CD503A8FA485} 45ad9fca.dll
X
Added by the Troj/Lineag-AJK password-stealing Trojan for the online game Lineage. ... Read More
_explore manager _explore.exe
X
Added by the Troj/Spexta-B Trojan.
Anti-Virus <random>.exe
X
Added by the Troj/Caprobad-A proxy Trojan.
19E7E238 19E7E238.EXE
X
Added by the Troj/Agent-ELX Trojan.
{AD11A17C-83C2-4121-89C8-D0660555685C} 08835b.dll
X
Added by the Troj/Lineag-ANA password-stealing Trojan for the online game Lineage. ... Read More
avptask 1explore.exe
X
Added by the Troj/Nofere-G Trojan. Troj/Nofere-G contains functionality to communicate with a remote server using HTTP, execute downloaded files, kill ... Read More
{1A2B5BD6-5867-48C3-B826-807FC6AE8F3D} 30835167.dll
X
Added by the Troj/Lineag-ANB password-stealing Trojan for the online game Lineage. ... Read More
104D840A 104D840A.EXE
X
Added by the Troj/Agent-ENR Trojan.
39672EA4 39672EA4.EXE
X
Added by the Troj/GrayBir-EW backdoor Trojan.
Think-Adz <random name>.exe
X
A variant of Adware.ZenoSearch.
1916435341.exe 1916435341.exe
X
Added by the Troj/Dloadr-AXU Trojan downloader.
(Default) 5640.exe
X
Added by the Troj/DownLd-ABF advertising related downloader Trojan.
himem.exe <filename.exe>
X
Added by the W32/Stration-FW worm. The filename associated with this infection is random. Examples of some are dlksr32.exe, skksd32.exe, skcc32.exe, ... Read More
sInErA .exe
X
Added by the W32/SillyFDC-AB worm. W32/SillyFDC-AB will attempt to copy itself to removable drives and create a file autorun.inf in an attempt to auto ... Read More
7v3j <filename.exe>
X
Added by the Troj/Dloadr-ARK Trojan downloader. The filenames associated with this infection are random. ... Read More
NetPanel Starter.exe
X
Added by the Trackware.Gemius trackware. Trackware.Gemius is a program that monitors and records networking activity and sends the gathered informatio ... Read More
ShareSearcher <random filename.exe>
X
Added by the Troj/Agent-FPE Trojan.
Managment Service <random>.exe
X
Added by the W32/Rbot-GQM worm and IRC backdoor.
Graphics _default.pif
X
Added by the W32.Autosky worm. W32.Autosky is a worm that attempts to spread to all shared and removable drives that are accessible from the compromis ... Read More
29547098.exe 29547098.exe
X
Identified as Downloader.Win32.Small.equ.
{F75BA725-26A4-4F94-94EC-F6F6758ADA38} 4CE9831689C2.DLL
X
Added by the W32/Lineage-AAB worm.
E6F7BD90 <random>.exe
X
Added by the Troj/BDoor-ADP backdoor Trojan.
ApachInc <random>.dll
X
Unknown malware typically bundled with LiveProtect. The dll is random but the registry entry will always be named ApachInc. ... Read More
block 05.vbs
X
Added by the W32.Pusia.A@mm worm.
lololol _hideme_imhiddenlololol.exe
X
Added by the Troj/Hideme-A Trojan. This infection is hidden by the rootkit file C:\_hideme_MYFILE.SYS. ... Read More
ifperx (Random 8 Letter).exe
X
Identified as the Trojan-Proxy.Win32.Slaper Trojan.
mmsddlx (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
rarup dns ...explore.xe
X
Identified as the Rbot.cnn worm and IRC backdoor.
rtkernsw (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
vbcdtm (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
wpxmls (Random 8 Letter).exe
X
Identified as a variant of the Trojan-Proxy.Win32.Slaper Trojan.
WINDOWS MSI Installer Application msiexec.exe
X
A variant of the RBot.cgu family of worms and IRC backdoor Trojans.
crtfmon <random>.exe
X
Added by the Troj/Dialer-EM dialer.
NvCp1Do <Trojan executable>
X
Added by the Troj/DwnLdr-GWE Trojan downloader.
{56CF31C1-A46F-4B57-886C-6638DA412087} 28bfe5.dll
X
Added by the Troj/Lineag-AD password-stealing Trojan for the online game Lineage. ... Read More
DomainService <random name>.exe
X
Service associated with Vundo infections.
tlz 47681727.exe
X
Identified as a Trojan downloader.
Microsoft (R) Windows Network Latency Controller 1.tmp
X
Added by the Backdoor.Ranky backdoor Trojan. This infection also installs a Windows service of the same name and filename. ... Read More
Microsoft (R) Windows Protocol Deployment Manager (Random Name).tmp
X
Added by the Backdoor.Ranky backdoor Trojan.
Windows Servces Agent <random name>.exe
X
Identified by Kaspersky antivirus as the Backdoor.Win32.IRCBot.acg worm and IRC backdoor. ... Read More
L]kLp <random name>.exe
X
Identified by Kaspersky antivirus as the Net-Worm.Win32.Bobic.n worm.
LDpswSend <random>.dll
X
Identified as Trojan-Downloader.Win32.Agent.
Windows Desktop Multimedia ntkrnl.exe
X
Unknown malware.
Edzy AntiVirus <random>.exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
55euf6 55euf6.sys
X
Added by the Troj/DwnLdr-GWX Trojan downloader.
Auto Scroll Loader (Random 6 Letter).exe
X
A variant of the SpyBot.dw family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Sysconf32 (Random 7 Letter).exe
X
A variant of the SpyBot.am family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Volume Task (Random 10 Letter).exe
X
A variant of the SpyBot.bn family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Winsocgfhk driver (Random 7.Letter).exe
X
A variant of the SpyBot.a family of worms and IRC backdoor Trojans. This family of worms spread via mIRC and the Kazaa file sharing network. ... Read More
Windows Serces Agnt (Random 9 Letter).exe
X
A variant of the Rbot.civ family of worms and IRC backdoor Trojans.
present .exe
X
Added by the W32/Rubble-C worm.
gCac gcac.exe
X
Added by the Tactslay Family Trojan.
ChanService 2pack.exe
X
Identified as a variant of Backdoor.Win32.SpyBoter.fb.
Détection matériel noyau ShellHWDetectionwinmgmt 3com_dmin.exe
X
Identified by Kaspersky as the Backdoor.Win32.IRCBot.ab malware.
__adware1__ __adware1__.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
__adware2__ __adware2__.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
System handler ~~~OuUuW_YeAh~~~.exe
X
Added by the W32.Kabab.A worm.
Winds Sers Agts (Random 5 Letter).exe
X
A variant of the RBot family of worms and IRC backdoor Trojans.
{83B78794-1991-4BE4-A439-D5EF37E8DC97} 4B8A877E1319.dll
X
Added by the Troj/Lineag-BA password-stealing Trojan for the online game Lineage. ... Read More
{36EAFED6-FE52-42E5-8FEC-703424BAA9CF} 4D1B90FDDF6B.dll
X
Added by the Troj/Lineag-BF password-stealing Trojan for the online game Lineage. ... Read More
Service PAck SFVP (Random 4 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
{47994C89-1857-4D33-B196-263ED6FA4CFF} 231346E28D27.dll
X
Added by the Troj/PWS-AOV password-stealing Trojan.
explorer `.vbe
X
Added by the Troj/Psyme-FE Trojan.
Windows update 55 (Random 10 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.aus family of worms and IRC backdoor Trojans. ... Read More
{79FC744E-75CA-49B0-8F02-AEAE4CAACBE0} 2ACE4CFBAF2C.dll
X
Added by the Troj/Lineag-CG password-stealing Trojan for the online game Lineage. ... Read More
Windos Seres Agnts <random>.exe
X
Added by the W32/Rbot-GUN worm and IRC backdoor.
Ipod Help (Random 9 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Servcesc (Random 9 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Internet Explorer _svchost.exe
X
Identified as a variant of the Trojan-Downloader.Win32.Tiny.nj malware.
Windows Services alges2 (Random 8 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.esc family of worms and IRC backdoor Trojans. ... Read More
Numerical Xtermz Agent 1x32.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
stup1db0t _win.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
value .svchost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Inet Service _svchost.exe
X
Added by the Troj/Dwnldr-GYS Trojan. This infection should not be confused with the legitimate C:\Windows\System32\svchost.exe file. ... Read More
Microsft Windows Adapter 5.1.3013 <random filename.exe>
X
Identified as the Trojan.PWS.LDPinch.TDD malware.
Mioft Wiws Seice ent (Random 5 Letter).exe
X
A variant of the W32/Rbot-GIJ family of worms and IRC backdoor Trojans.
NvGraphicsInterface <random name>.exe
X
Added by the Troj/Bckdr-QKI backdoor Trojan.
Windows Accounts Driver <random name>.exe
X
Added by the Troj/Agent-GGY Trojan.
SilentSoftech <filename.exe>
X
Added by the W32/SillyFDC-BL removable device worm.
SharedAPPs <random filename.exe>
X
Added by the Troj/Banloa-ET Trojan.
WinDLLProcessor <random name>.exe
X
Added by the Troj/Bancos-BDO password stealing Trojan for online banks. If you are infected with this Trojan you should immediately change all of you ... Read More
Windows Live Messenger <random>.exe
X
Added by the W32/Rbot-GVL worm and IRC backdoor.
63cica 63cica.sys
X
Added by a variant of the Troj/NTRootK-CL rootkit.
ChkDsk32 <random>.exe
X
Added by the Troj/DwnLdr-GZO downloader Trojan.
kerberos4 (Random Name).dll
X
A variant of the Win32:Agent-NZR malware.
MicroSoft Getway mqbol (Random 12 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.etg family of worms and IRC backdoor Trojans. ... Read More
WintelUpdate <random filename.exe>
X
Added by the Troj/Small-EKW backdoor Trojan.
WinSysW 896588L.exe
X
Added by the Troj/LegMir-ARQ password-stealing Trojan for the online game The Legend of Mir. ... Read More
18wheelsofsteelconvoy.exe 18wheelsofsteelconvoy.exe
X
Added by the Adware.Trymedia.D adware.
sklfc94krteetj (Random Name).dll
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hko malware.
JGhsdk393ktrfggh9dtj (Random Name).dll
X
Identified as a variant of the Trojan-Downloader.Win32.Small.hko malware.
Microsoft Int Service _svchost.exe
X
Identified as a variant of the Win32/TrojanDownloader.Tiny.NJ malware.
WinSysW 124327L.exe
X
Added by the Infostealer.Gampass information stealing Trojan for online games.
Microsoft P2P Service _svchost.exe
X
Identified as a variant of the Troj/Dwnldr-GYS variant malware.
Microsoft I Service _svchost.exe
X
Identified as a variant of the Troj/Dwnldr-GYS malware.
Winsock2 driver 5ystem.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Microsoft Windows Adapter 5.1.3214 <random filename.exe>
X
Related to the Zinaps Anti-Spyware 2008 rogue anti-spyware program.
Microsoft P2P2 Service _svchost.exe
X
Identified as a variant of the Troj/Dwnldr-GYS variant malware.
proses (Random 5 letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Notebook Manager Service anbmServiceNetman 2052d.exe
X
Unknown malware.
Windows NTFS Volume Manage (Random 6 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.edl family of worms and IRC backdoor Trojans. ... Read More
admggxp admggxp.dll
X
Added by a variant of the MyGeek/CPVFeed adware.
MicroSoft Getway Dire (Random 9 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Service Ag3nt (Random 4 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.gox family of worms and IRC backdoor Trojans. ... Read More
Microsoft PS Service _svchost.exe
X
Identified as a variant of the TrojanDownloader:Win32/Tipikit.A malware.
4fdw 4fdw.dll
X
Added by the Backdoor.Rustock backdoor rootkit.
UpdateWin (Random Name).exe
X
Identified as a variant of the Trojan.Dropper.LDPinch.Q Trojan.
tDefault <random name>.exe
X
Identified as a variant of the Backdoor.Win32.VB.btu Trojan.
DeviceSys (Random Name).exe
X
Identified as a variant of the Backdoor.Win32.VB.btu Trojan.
UserTools <random.exe>
X
Identified as a variant of the Backdoor.Win32.VB.btu Trojan.
Microsoft Service Host Manager 32svchost.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Windows haz Layer (Random 5 Letter).exe
X
A variant of the Backdoor.Win32.Rbot.fbx family of worms and IRC backdoor Trojans. ... Read More
syswin.txt (Random 3 Letter).exe
X
A variant of the Backdoor.Sdbot family of worms and IRC backdoor Trojans.
Windows Secure talal32 (Random 7 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Installer Class ~~install.dll
X
Identified as a variant of the Trojan.FakeAlert malware. This malware will issue fake alerts on your computer stating you have security problems and ... Read More
Program Access Service (Random 10 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
3klagia 3klagia.dll
X
Added by the Backdoor.Rustock backdoor rootkit.
ToolHelp <random>.exe
X
Identified as a variant of the Trojan:Win32/Meredrop malware.
Yeah ^$4!N$^.exe
X
Added by the W32/VB-DZA worm.
<not used> ^^^^^.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Flash Media ^^^^^.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
36Osafe 36Osafe.exe
X
Added by the Troj/Dloadr-BKC Trojan.
Flash Media %%%%%.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
Flash Media ^^^^^^.exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
<not used> %%%.exe
X
A variant of the Troj/Nymod-A malware.
Human Interface Device Access HidServNetDDEdsdm 1054j.exe
X
Added by the Troj/Agent-GVN Trojan.
Windows Services Aganters (Random 10 Letter).exe
X
A variant of the WORM_RBOT.CUN family of worms and IRC backdoor Trojans.
SfKg6wIP (RandomName).exe
X
Identified as a variant of the TrojanDownloader.Matcash malware.
Microsoft Live 8.5 (Random 7 Letters).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
<Various Startup Names> _qbotinj.exe
X
Added by the Troj/Dloadr-BLP Trojan. The components of this infection are C:\documents and settings\all users\_qbothome\_qbotinj.exe and C:\documents ... Read More
ivhost (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
MPatrolPRO MPatrolPRO.exe
X
Added by the MalwarePatrolPro rogue anti-spyware program.
Windows Serviece Agents (Random 9 Letter).exe
X
A variant of the Worm.Rbot.ABFK family of worms and IRC backdoor Trojans.
Windows Service alge (Random 8 Letter).exe
X
A variant of the WORM_RBOT.GJO family of worms and IRC backdoor Trojans.
Windows Microsoft Service (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Microsoft Services (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
xswdmse (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
reszrv (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
icccomp (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
idlesam (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
kdmsx (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
mceipww (Random 8 Letter).exe
X
A variant of the IRCBot family of worms and IRC backdoor Trojans.
MSServer <random>.dll
X
Unknown malware. Please note that C:\Windows\System32\rundll32.exe is a legitimate file. ... Read More
mssysif (Random Name).exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.pnv malware.
mssysif (Random Name).tmp
X
Identified as a variant of the Trojan-Downloader.Win32.Agent.pnv malware.
eqvwamkl eqvwamkl.dll
X
Identified as a variant of the Adware.Agent malware.
Windows Service Agnts (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Microsoft Manager 1 KKI1.exe
X
Added by the Troj/Banker-EMT information-stealing Trojan for online banks.
Virtual Memory Dispatcher (RandomName).exe
X
Identified as a variant of the Win32:Agent-XKO/Backdoor.Hamweq.B malware.
Virtual Memory Protector (Random Name).exe
X
Identified as as variant of the Win32:Agent-XKO/Backdoor.Hamweq.B malware.
__c0028830 __c0028830.dat
X
Added by the Troj/Mdrop-BUX Trojan.
Somefox <random>.exe
X
Added by the Troj/Dwnldr-HHB Trojan.
Service PAck hard (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Windows Newresck (Random 8 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Adobe SpeedLaunch (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
Physical Memory Protector (Random Name).exe
X
Identified as a variant of the Trojan-Downloader.Win32.Agent malware.
{9B71D88C-C598-4935-C5D1-43AA4DB90836} [KD]Naruto.exe
X
A variant of the Backdoor.Bifrose backdoor Trojan. Backdoor.Bifrose is a Trojan horse that uses a backdoor server to send information to a remote serv ... Read More
<not used> .security
X
Identified as part of the Fake.Alert Trojan.
Windows Service CV (Random 6 Letter).exe
X
A variant of the Rbot family of worms and IRC backdoor Trojans.
skype.exe \ic&#111;nchanger.exe
X
Identified as a variant of the Backdoor.Win32.Poison.cpb malware.
MSFox <random.exe>
X
Added by the Troj/DwnLdr-HKP Trojan.
10.1.08 10.1.08.exe
X
Added by the W32.Redlofs worm.
Cognac <random.exe>
X
Added by the Troj/DwnLdr-HLQ downloading Trojan.
<not used> 22CC6C32.exe
X
Added by the Troj/Ransom-BO Trojan. This Trojan makes it so you cannot access your computer unless you pay a ransom. ... Read More
win_drivr32 <random>.exe
X
Added by the Troj/Dloadr-CKT downloader Trojan.
SunJava Updater v7 \javale.exe
X
Added by the W32.Ackantta.B@mm worm. W32.Ackantta.B@mm is a mass-mailing worm that gathers email addresses from the compromised computer and spreads b ... Read More
DriversLoad <random>.dll
X
Added by the Malware Defender rogue anti-spyware program.
Windows Resurections <random>.exe
X
Unknown malware.
Malware Cleaner <random number>.exe
X
Added by the MalwareCleaner rogue anti-spyware program.
Diagnostic Manager <random numbers>.exe
X
Unknown malware.
uidenhiufgsduiazghs <random>.exe
X
Unknown malware.
49U5T1N4 49U5T1N4.exe
X
Added by the W32.Korron.B worm. W32.Korron.B is a worm that replaces some file types with a copy of itself. It also copies itself to all accessible dr ... Read More
Windows Security Suite <random>.exe
X
Added by the Windows Security Suite rogue anti-spyware program.
MsnMessendger <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MsnConvert <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MsnLoad <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
MsnHost <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
Msn <DOWNLOADED FILE NAME>
X
Added by the Trojan.Kryski Trojan. Trojan.Kryski is a Trojan horse that downloads and executes files from remote Web sites. ... Read More
Alerter AlerterALG <random>.exe
X
Added by the W32/Backdr-AR backdoor.
GbpSvc GbpKms.sys
X
Added by the nfostealer.Bancos.BB Trojan. Infostealer.Bancos.BB is a Trojan horse that attempts to steal information from the compromised computer. ... Read More
avgsys 64444.reg
X
Added by the Volcano Security Suite rogue anti-spyware program.
BackUp Windows 2009 <random>.exe
X
Added by the Troj/Agent-LUJ Trojan.
mxcll
X
Added by the Echo AntiVirus 2010 rogue anti-spyware program.
Antispyware Shield Pro /antispyshield.exe
X
Added by the AntiSpyware Shield Pro rogue anti-spyware program.
<random>onin <random>onin.exe
X
Added by the Ghost Antivirus rogue anti-spyware program.
PDCOMP _amdevntas.sys
X
Added by the Trojan-Spy.Win32.Batton.rk spyware and information stealer. Trojan-Spy spies upon user's activity and steals confidential user informatio ... Read More
Remote System Protection <random>.dll
X
Unknown malware.
avguard3876 000b09274b.exe
X
Added by the AntiVirus ransomware program.
<random> <random>tssd.exe
X
Added by the Antivirus Suite rogue anti-spyware program.
<random> <random>tssd.exe
X
Added by the AntiSpyware Soft rogue anti-spyware program.
<not used> 64dlls.exe
X
Added by the Troj/Zbot-OK Trojan.
Audio HD Driver <random.exe>
X
Added by the Troj/Agent-OAL Trojan.
sniffer _ex-08.exe
X
Added by the Troj/Oficla-X Trojan.
<random> <random>shdw.exe
X
Added by the Security Suite rogue anti-spyware program.
0CF48.exe 0CF48.exe
X
Added by the SecureDefense rogue anti-spyware program.
<random> <random>wagnz.exe
X
Added by the Antivirus Action rogue anti-spyware program.
SmartIndex _ex-08.exe
X
Added by the WORM_KELIHOS.SM worm.
msinfo 2.tmp.exe
X
Added by the Troj/Newmen-A Trojan.
GarenaPEngine <random chars>.tmp
X
Unknown malware.
Home Safety Essentials <random chars and numbers>.exe
X
Added by the Home Safety Essentials rogue anti-spyware program.
CouponAlert_2p Browser Plugin Loader 2pbrmon.exe
X
Detected by ESET Nod32 as a variant of the Win32/AdInstaller malware.
OpenCloud Security <random chars>.exe
X
Added by the OpenCloud Security rogue anti-spyware program.
3CM Link 3cmcnkw.exe
?
??
3Dlabs Taskbar Display Manager 3DLman.exe
?
3DLabs graphics driver related. System Tray access to display settings?
AAAKeyboard <unknown>
?
??
Avxnews <unknown>
?
??
Coupon Offers <unknown>
?
??
CQSCP2P SERVER <unknown>
?
"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually ... Read More
CQSCP2PS <unknown>
?
"Compaq printer utility which is required in the startup menu in order to make the printer work correctly". Personally I doubt whether it is actually ... Read More
Description of Shortcuts *.exe
?
* seems to be a sequence of alphanumerics that can be different, i.e., 1960F8A9, 4EBD23F5, etc. Each of these files would appear to be a shortcut, i.e ... Read More
Devlog <unknown>
?
??
Dosbat <unknown>
?
??
FLASH32 -flash32.exe
?
??
gramdate 2Stop.exe
?
??
mfgboot <unknown>
?
??
Qdsafe <unknown>
?
??
ScanFile <unknown>
?
??
V128IITV <unknown>
?
Loads drivers for some STB graphics cards. May be related to such a card with a TV out option? ... Read More
Vinny <unknown>
?
??
Watch 1200UBWATCH.EXE
?
??
Web Search <unknown>
?
??
WRECK GUARD <unknown>
?
??


> Status Key
Each entry in the database will have a Status assigned to it. The key to this status is the following:
  • Y - This status flag means that this entry should be left alone and be allowed to run as if it is unchecked it may break the functionality or use of a particular program.
  • N - This status flag means it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
  • U - This status flag means it is up to you whether or not you feel this program needs to run automatically.
  • X - This status flags means the item should definitely not start up automatically. Items that have this flag are generally malware such as viruses, trojans, hijackers, spyware but could also be programs that are not desirable to run on your computer.
  • ? - This status flag means the status of this entry is unknown at this time and more research is necessary.
If you require assistance in removing one of these files you can ask us in the Startup Database Forum.

> Disclaimer
It is assumed that users are familiar with the operating system they are using and comfortable with making the suggested changes. BleepingComputer.com will not be held responsible if changes you make cause a system failure.

This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. If in doubt, don't do anything.


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides


Portions of this database © Paul Collins
© 2003-2012 All Rights Reserved Bleeping Computer LLC.
PGT: 0.23055 Queries: 4