| Name |
Filename |
Status |
Description |
|
<not used>
|
DisMgnt.exe
|
X
|
Added by the Troj/Enfal-A Trojan.
|
|
[not used]
|
winvsp.exe
|
X
|
Added by the Troj/Paproxy-C Trojan.
|
|
[not used]
|
CulaterLoader.exe
|
X
|
Added by the Spyware.Mom spyware.
|
|
[not used]
|
nmst.exe
|
U
|
Added by the Spyware.NetMama surveillance software. This program should be uninstalled if it was not installed by yourself.
|
|
[not used]
|
dllhst2d.exe
|
X
|
Added by the Troj/Sharp-R backdoor Trojan.
|
|
[not used]
|
clicnt40.exe
|
X
|
Added by the Troj/PPdoor-AT backdoor Trojan.
|
|
[not used]
|
dmadoin.exe
|
X
|
Added by the Troj/Prosti-BU backdoor Trojan.
|
|
[not used]
|
rundl132.exe
|
X
|
Added by the W32/Looked-A EXE virus.
|
|
[not used]
|
o4321427.exe
|
X
|
Added by the W32/Brontok-AK mass-mailing worm.
|
|
[not used]
|
ntndis.exe
|
X
|
Added by the W32/Rbot-DPG worm and IRC backdoor.
|
|
[not used]
|
rsmss.exe
|
X
|
Added by the Troj/Prosti-BL backdoor Trojan. Explorer.exe is not part of this infection and should not be removed.
|
|
[not used]
|
wmiadapt.exe
|
X
|
Added by the Troj/Small-BNQ backdoor Trojan.
|
|
[not used]
|
Cable.exe
|
X
|
Added by the W32/Cablenet-A worm.
|
|
[not used]
|
mshttcpl.exe
|
X
|
Added by the Troj/PPdoor-AR backdoor Trojan.
|
|
[not used]
|
spdr.exe
|
X
|
Added by the Troj/Zagaban-E Trojan.
|
|
[not used]
|
dcompcss.exe
|
X
|
Added by the Troj/PPdoor-AQ Trojan.
|
|
[not used]
|
System Idle Procese.exe
|
X
|
Added by the Troj/DDoS-E Trojan.
|
|
[not used]
|
cinderawasih-4321427.exe
|
X
|
Added by the W32/Brontok-R mass-mailing worm.
|
|
[not used]
|
Latent.com
|
X
|
Added by the Troj/Agent-ADU password-stealing Trojan.
|
|
[not used]
|
RECYCLER.exe
|
X
|
Added by the Troj/Agent-AET password-stealing Trojan.
|
|
[not used]
|
sfcrt20.exe
|
X
|
Added by the Troj/PPdoor-AP backdoor Trojan.
|
|
[not used]
|
Kerne0110.exe
|
X
|
Added by the Troj/Lineage-FU password-stealing Trojan for the online game Lineage.
|
|
nwisse
|
nwisse.exe
|
X
|
Added by the Troj/Fusion-B keylogging backdoor Trojan.
|
|
[not used]
|
winspols.scr
|
X
|
Added by the Troj/Fusion-B keylogging backdoor Trojan.
|
|
[not used]
|
sembako-cfzjmmg.exe
|
X
|
Added by the W32/Brontok-N worm.
|
|
[not used]
|
sembako-cfzjkmg.exe
|
X
|
Added by the W32/Brontok-M worm.
|
|
[not used]
|
KesenjanganSosial.exe
|
X
|
Added by the W32/Brontok-K mass-mailing worm.
|
|
[not used]
|
kane.exe
|
X
|
Added by the Backdoor.Dckane backdoor. This infection also installs the file c:\windows\system32\kane.dll.
|
|
[not used]
|
Kerne1211.exe
|
X
|
Added by the Troj/Lineage-CA password-stealing Trojan for the online game Lineage.
|
|
[not used]
|
syscom32.exe
|
X
|
Added by the W32/Spybot-EM worm and IRC backdoor.
|
|
[not used]
|
dpnetmsg.exe
|
X
|
Added by the Troj/PPdoor-Q backdoor Trojan. This infection may also make the files C:\Windows\System32\dpnetmsg.exe, C:\Windows\System32\iueninet.dll, C:\Windows\System32\fsmgntfs.dll, C:\Windows\System32\ntmapast.dll, C:\Windows\System32\ir50psrv.exe, C:\Windows\System32\kbd1uery.dll, C:\Windows\System32\lfyockaa.dll, C:\Windows\System32\a15svcs.exe, C:\Windows\System32\dpnmdlib.exe, C:\Windows\System32\c_28usic.dll, C:\Windows\System32\atiysnpn.dll, C:\Windows\System32\treemqoa.dll, C:\Windows\System32\arptutdn.dll, C:\Windows\System32\eulapart.dll, C:\Windows\System32\smlo8thk.exe, C:\Windows\System32\odbcfwci.ime, C:\Windows\System32\hgakheg.dll, C:\Windows\System32\jkwbhew.dll, and C:\Windows\System32\testtest.exe.
|
|
[not used]
|
syscom832.exe
|
X
|
Added by the W32/Spybot-EN worm.
|
|
[not used]
|
b0ff.exe
|
X
|
Added by the W32/Protorid-AF worm and IRC backdoor.
|
|
[not used]
|
Kerne121.exe
|
X
|
Added by the Troj/Lineage-BW password-stealing Trojan for the online game Lineage.
|
|
[not used]
|
svchostl.exe
|
X
|
Added by the W32/Blaster-M worm.
|
|
[not used]
|
rejoice.exe
|
X
|
Added by the Troj/Prosti-Q Trojan.
|
|
[not used]
|
assistseex.exe
|
X
|
Added by the Troj/LegMir-BW Trojan.
|
|
[not used]
|
assistse.exe
|
X
|
Added by the Troj/Bravo-C Trojan.
|
|
[not used]
|
msbnc.exe
|
X
|
Added by the Troj/Agent-PL backdoor Trojan.
|
|
[not used]
|
stealth.worm.exe
|
X
|
Added by the PE_THEALS.A file infector. This infection also utilizes rootkit technology.
|
|
[not used]
|
kiamarsi.exe
|
X
|
Added by the Troj/Detest-A Trojan.
|
|
[not used]
|
winupdate.exe
|
X
|
Added by the Troj/Agent-FD Trojan. This infection also creates the files c:\windows\system32\Filesys.ini and c:\windows\system32\ntfilesys.ini.
|
|
[not used]
|
Kerne1412.exe
|
X
|
Added by the Troj/Lineage-OJ password-stealing Trojan.
|
|
[not used]
|
systcom32.exe
|
X
|
Added by the W32/Spybot-ED worm. When started, this infection connects to a remote IRC server where it waits for commands to execute
|
|
[not used]
|
BIDBFn.exe
|
X
|
Added by the Troj/DBdoor-A backdoor Trojan. This infection also creates the files c:\windows\inf\3EQ2_w.inf
c:\windows\system32\drivers\d6iXjEe.sys
c:\windows\system32\libeay32.dll
c:\windows\system32\ssleay32.dll
c:\windows\system32\Systen.dll
|
|
[not used]
|
gld.exe
|
X
|
Added by the Backdoor.Zagaban backdoor Trojan.
|
|
[not used]
|
System.com
|
X
|
Added by the Troj/LegMir-BG keylogger Trojan. It also creates the file CQQ_Fileqq_dll.dll.
|
|
[not used]
|
rundll64.exe
|
X
|
Added by the Troj/Legmir-BD informations stealing Trojan for the online game Legend of Mir.
|
|
[not used]
|
Kerne14.exe
|
X
|
Added by the Troj/Lineage-BA password-stealing Trojan for the online game Lineage.
|
|
[not used]
|
eksplorasi.pif
|
X
|
Added by the W32/Korbo-A worm and backdoor Trojan.
|
|
[not used]
|
Phantom.exe
|
X
|
Added by the W32/Mytob-FT mass-mailing worm and IRC backdoor.
|
|
[not used]
|
winldr.exe
|
X
|
Added by the W32/Bagle-AK worm.
|
|
[not used]
|
Kerne12.exe
|
X
|
Added by the Troj/Lineage-AS Trojan.
|
|
[not used]
|
winlog.exe
|
X
|
Added by the Troj/Sharp-J Trojan.
|
|
[not used]
|
svchsto.exe
|
X
|
Added by the Troj/GWGhost-R information stealing Trojan.
|
|
[not used]
|
inetinfo.exe
|
X
|
Added by the Troj/Proxy-GG proxy Trojan.
|
|
[not used]
|
mdm.exe
|
X
|
Added by the Troj/Proxy-GG proxy Trojan.
|
|
[not used]
|
svcroot.exe
|
X
|
Added by the Troj/Heles-B keylogger Trojan.
|
|
[not used]
|
winmgd.win
|
X
|
Added by the VBS_GEDZA.A worm.
|
|
[not used]
|
_Kerne1.exe
|
X
|
Added by the Troj/Lineage-AN password-stealing Trojan for the online game Lineage.
|
|
[not used]
|
realone.exe
|
X
|
Added by the Troj/LegMir-AU Trojan.
|
|
[not used]
|
msscript.exe
|
X
|
Added by the Troj/StartPa-HC Trojan.
|
|
[not used]
|
STFU.exe
|
X
|
Added by the W32/Rirc-E worm and IRC backdoor.
|
|
[not used]
|
svchsot.exe
|
X
|
Added by the Troj/GWGhost-N Trojan.
|
|
[not used]
|
Winroad.exe
|
X
|
Added by the Backdoor.Augudor backdoor.
|
|
[not used]
|
dllcnfg.exe
|
X
|
Added by the Backdoor.Samkams backdoor Trojan.
|
|
[not used]
|
iexplore.com
|
X
|
Added by the Troj/Pcik-A trojan.
|
|
[not used]
|
Celine.scr
|
X
|
Added by the Troj/Celine-A backdoor trojan.
|
|
[not used]
|
mscarrt32.exe
|
X
|
Added by the W32/Oscabot-K worm and IRC backdoor.
|
|
[not used]
|
svhost32.exe
|
X
|
Added by the Troj/Lineage-AB trojan.
|
|
[not used]
|
mssvces.exe
|
X
|
Added by the W32/Rbot-BSH worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
|
|
[not used]
|
mssvcnes.exe
|
X
|
Added by the W32/Rbot-BSG worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
|
|
[not used]
|
zlibc.exe
|
X
|
Added by the Troj/Chorus-A browser hijacker.
|
|
[not used]
|
htmlsync.exe
|
X
|
Added by the Troj/Chorus-A browser hijacker.
|
|
[not used]
|
msreged32.exe
|
X
|
Added by the W32/Rbot-BAA worm.
|
|
[not used]
|
gr33n.exe
|
X
|
Added by the W32/Sdbot-ZP worm. When started, this infections connects to a remote IRC server where it waits for commands to execute.
|
|
[not used]
|
setup32.exe
|
X
|
Added by the W32/Rbot-AFJ worm. When started, this infection connects to a remote IRC server and waits for commands to execute.
|
|
[not used]
|
_huytam_.exe
|
X
|
Added by the Ssearch.biz and a-search.biz hijackers.
|
|
[not used]
|
msdrv.exe
|
X
|
Added by the Troj/CmjSpy-U keylogger.
|
|
[not used]
|
AUserInit.exe
|
Y
|
Added by Curtains for Windows. Removing this file WILL cause your computer to have problems starting. You should contact Authentium for the proper removal procedure. Unknown as to what function it plays in this program.
|
|
[not used]
|
svcmgr32.exe.exe
|
X
|
Added by the W32/Oscabot-D worm. When started, this infection connects to an IRC where it waits for remote commands to execute.
|
|
[not used]
|
hidedown.exe
|
X
|
Added by the Troj/Leodon-B trojan downloader.
|
|
[not used]
|
FF.EXE
|
X
|
Added by the W32/Rirc-D worm.
|
|
[not used]
|
Bdsf32.scr
|
X
|
|
|
[not used]
|
primary.exe
|
X
|
Added by the Troj/Sharp-G backdoor trojan.
|
|
[not used]
|
mlg1.exe
|
X
|
Added by the W32/Kelvir-I instant messaging worm.
|
|
[not used]
|
Navw32.exe
|
X
|
Added by the Troj/Agent-CG backdoor.
|
|
[not used]
|
mpdat.exe
|
X
|
Added by the W32/Rbot-WG worm. When started this infection connects to a remote IRC server where it waits for commands to execute. These infections also log keystrokes, so if you are infected you should change all your passwords.
|
|
Internet Agent
|
[random CLSID]
|
X
|
Added by the Troj/PPdoor-F. It also uses a name Client Agent when changing the registry run key to enable auto-starting at logon.
|
|
[not used]
|
msapi.exe
|
X
|
Added by the Troj/LegMir-W infection.
|
|
[not used]
|
sound_drive16.exe
|
X
|
Added by the Troj/Bdoor-GP backdoor trojan.
|
|
[not used]
|
MSMSGS.EXE
|
X
|
Added by the Troj/Bancban-BW password stealing trojan. This trojan affects users of Brazillian banks.
|
|
[not used]
|
init32m.exe
|
X
|
Added by the Troj/Dloader-JT or Troj/Dlsw-B trojan downloaders.
|
|
[not used]
|
userinit32.exe
|
X
|
Added by the W32/Rbot-YE irc backdoor trojan.
|
|
[not used]
|
xpjava.exe
|
X
|
Added by the W32/Rbot-YC network worm/backdoor.
|
|
[not used]
|
svchost.exe
|
X
|
Added by the W32/Tex-A mass-mailing worm.
|
|
[not used]
|
Nail.exe
|
X
|
This infection is a Abetterinternet adware variant. It is notoriously difficult to remove and is usually bundled with other malware that are hard to remove as well. One method that we have found that is able to remove this infection and the other malware that are bundled with it is the ewido security suite which you can download and try for free.
|
|
[not used]
|
Notify.exe
|
X
|
|
|
[not used]
|
mcafee32.exe
|
X
|
w32rbotxe drops a TROJAN, creating several files in %Program Files%, %Windir%, and %system% in addition to this file.
|
|
[not used]
|
penis.exe
|
X
|
Added by the W32/Cissi-F WORM, the system .ini field {boot} will be modiified and remote access made available to an attacker(s) using an IRC channel(s).
|