| X | NeuerSchild | pgs.exe | "NeuerSchild |
| X | NI.ERS_9999_N91S3108 | [path to file] | "Installer for the ErrorSafe rogue system error and cleaning utility - see here"
|
| X | NI.UERSM_0001_N68M1602 | [path to file] | "Installer for the ErrorSafe rogue system error and cleaning utility - see here"
|
| X | Norton Personal Firewall | jah.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Norton Personal Firewall | npfw.exe | "Added by the RBOT-UI WORM!"
|
| X | Norton Personal Firewall | lah.exe | "Added by a variant of the RBOT WORM!"
|
| X | Norton Personal Firewall | npfw32.exe | "Added by the RBOT-UQ WORM!"
|
| Y | Norton Personal Firewall | IntroWiz.exe | Part of Norton Personal Firewall or Norton Internet Security
|
| X | Norton Personal Firewall | winmpts.exe | "Added by the RBOT.ANT WORM!"
|
| X | Nvid | [8 random charachters] | Unidentified adware
|
| X | nVidia Application Drivers | nvidiav32.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | nVidia Display Drivers (x86) | nvsys86.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | nVidia Drivers | nVidiaDrvers.exe | "Added by the SDBOT-AFX WORM! Note - this is not related to any nVidia based motherboard or graphics card"
|
| X | NVidia Drivers | [path to trojan] | "Added by the RANCK-R TROJAN! Note - this is not related to any nVidia based motherboard or graphics card"
|
| X | nVidia System Drivers | nvsys32.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | NVIDIA Video drivers | video_32D.exe | "Added by the AGOBOT.KV WORM!"
|
| X | NVIDIA Video drivers | video_32sD.exe | "Added by the RBOT-BB WORM!"
|
| X | Offer Companion | offers.exe | Adware
|
| X | Offers | offers.exe | Adware
|
| X | Open Service Drivers | opiater.exe | "Added by a variant of the RBOT WORM!"
|
| X | OpenGL Drivers | 0penGLD.exe | "Added by the YIMP-A WORM!"
|
| X | Optional Web Drivers For WIN32 | phqghume.exe | "Added by a variant of the RBOT WORM!"
|
| X | orderShell | order****.exe [* = random char] | "Added by the DLOADR-UN TROJAN!"
|
| ? | Packard Bell EverSafe Tray Control | TrayControl.exe | "Packard Bell EverSafe software. What does it do |
| X | PC Live Guard | PC[random characters].exe | "PC Live Guard rogue security software - not recommended |
| Y | PersFw | PersFw.exe | "Kerio or Tiny Personal Firewall"
|
| U | Persistence | igfxpers.exe | "Installed with the graphics drivers for Intel desktop and mobile motherboard chipsets with integrated graphics. It's purpose or function isn't known at present but testing with it disabled would appear to indicate it isn't required - hence the recommended ""U"" status"
|
| X | Personal Anti Malware | PAM.exe | "Unregistered version of Personal Anti Malware rogue security software - not recommended |
| X | Personal Anti Malware Center | AMC.exe | "Registered version of Personal Anti Malware rogue security software - not recommended |
| X | Personal Antivirus | PerAvir.exe | "Personal Antivirus rogue security software - not recommended |
| X | Personal Computer | scvhost.exe | "Added by the RBOT-AJE WORM!"
|
| X | Personal Defender 2009 | pdefendr.exe | "Personal Defender 2009 rogue security software - not recommended |
| X | Personal Firewall V9 | Firewall-UpdateV9.exe | "Added by the RBOT-BJR WORM!"
|
| X | Personal Firwall | ptmedsrv.exe | "Added by the SDBOT.XY WORM!"
|
| X | Personal Security Center Monitor | isc_ui.exe | "Added by the FAKEALERT TROJAN!"
|
| X | PersonalAntiSpy Free | pas.exe | "PersonalAntiSpy rogue spyware remover - not recommended |
| X | PersonalAV | pav.exe | "PersonalAV rogue security software - not recommended. Detected as the FAKEAV.FT TROJAN by Trend. Located in %ProgramFiles%\PersonalAV"
|
| X | personalguard | personalguard.exe | "Personal Guard 2009 rogue security software - not recommended |
| X | personalprotector | personalprotector.exe | "Personal Protector rogue security software - not recommended |
| X | PersonalSec | psecurity.exe | "Personal Security rogue security software - not recommended |
| X | PersonSecurity | psecurity.exe | "Personal Security rogue security software - not recommended |
| X | PersSecurity | personalsecurity.exe | "Personal Security rogue security software - not recommended |
| X | PersSecurity | psecurity.exe | "Personal Security rogue security software - not recommended |
| U | PhoneFree version 6.2 | PHONEF??.EXE | "An Internet telephony application. Complicated registration and ad banners tailored to your profile - see here"
|
| U | PMT | personalmoneytree.exe | "According to the web site Personal Money Tree is an automatic cash rebate program. Note: Not recommended"
|
| X | PopularScreensaversWallpaper | "rundll32 [path] F3SCRCTR.DLL | LES" |
| X | Popup and Advertisement Killers | adkillers.exe | "Added by the RBOT-DDH WORM!"
|
| X | popuppers | newpop63.exe | "Medload adware"
|
| X | popuppers64 | a64sddd.exe | "Popuppers adware |
| X | popuppers65 | [path to file] | "Medload adware"
|
| X | Power Scan | powerscan.exe | "Foistware by Integrated Search Technologies - the people behind ISTBar adware"
|
| U | PowerPanel Personal Edition User Interaction | pppeuser.exe | "CyberPower PowerPanel Personal Edition UPS Monitoring & Control Software - ""is included with CyberPower's products. This exclusive software allows control and monitoring of your UPS to provide protection for your computer system |
| ? | PowerS | PowerS.exe | "ProlinkTest for either their AGP graphics card or TV/FM capture card. Is it required?"
|
| ? | PowerSet | Regedit.exe /s ...PowerSet_8100_CU.REG | "Appears to be Toshiba power management related"
|
| N | PowerStrip | powerstrip.exe | "PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings"
|
| N | PowerStrip | PSTRIP.EXE | "PowerStrip is a Video Mode Editor to allow special Refresh Rates and Tweaking of Video Settings"
|
| X | PrinterSpool | [path] RESTORE.EXE [path] SPOOL.EXE | "Added by the ALADINZ.K TROJAN!"
|
| X | Program Access Service | [10 random letters].exe | "Added by the RBOT.GJJ WORM!"
|
| X | proses | [5 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | RegistryMonitor1 | igfxpers.exe | "Added by the DELF-EZZ TROJAN! Note - this is not the legitimate Intel graphics driver which has the same filename"
|
| X | Required Service Drivers | micront.exe | "Added by the RBOT-ABD WORM!"
|
| X | reszrv | [8 random letters].exe | "Added by a variant of the SDBOT WORM! See here"
|
| U | RetrieverScheduler | retrieverscheduler.exe | "80-20 Retriever from 80-20 - ""80-20 Retriever is a powerful personal search tool that encompasses email folders |
| U | RivaTunerStartupDaemon | RivaTuner.exe | "Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for XP and applies overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
|
| U | RivaTunerStartupDaemon | RivaTunerWrapper.exe | "Part of RivaTuner - a tweaking utility for NVIDIA (and to a lesser extent AMD/ATI) chipset based graphics cards. This entry is for Vista and loads the main application (RivaTuner.exe) to apply overclocking changes to clocks and memory (for example) at startup and then exits. See the FAQ for more information"
|
| X | RPC Drivers | rpcall.exe | "Added by the SDBOT.FLY WORM!"
|
| X | SearchNavVersion | searchnavversion.exe | SearchNav adware - IEFeatures/Popnav variant
|
| U | SecureOnlineAccountNumbers | SOAN.exe | "Related to Secure Online Account Numbers by Discover(R) Card from Orbiscom Ltd. Secure and innovative payment solutions"
|
| X | Security Antivirus | SA[random characters].exe | "Security Antivirus rogue security software - not recommended |
| X | Security Guard | SG[random characters].exe | "Security Guard rogue security software - not recommended |
| X | Security Master AV | SM[random characters].exe | "Security Master AV rogue security software - not recommended |
| X | Service Drivers | msnpg.exe | "Added by the RBOT.BMD WORM!"
|
| X | Service Drivers | PC.EXE | "Added by the SDBOT-WK WORM!"
|
| X | Service Drivers | Compt.exe | "Added by the RBOT-ZJ WORM!"
|
| X | Service Drivers | abl.exe | "Added by the SDBOT-YX WORM!"
|
| X | Service Drivers | MSNMEssenger.exe | "Added by a variant of the RBOT WORM!"
|
| X | Services Managers | svcmanager.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | SGPUpdater | sgpUpdaters.exe | "Fast Browser Search/Search Guard Plus parasite - installed with ""Make the Web Better"" applications such as My Web Tattoo |
| X | SichererSchutz | pgs.exe | "SichererSchutz |
| U | skinkers | skinkers.exe | "Selection of desktop messaging/marketing tools with celebrity tie-ins including MTV's ""Desktop Ozzy"" and Arsenal's ""Desktop Wenger"" - see here. Leave enabled if you want to receive messages"
|
| X | Smart Virus Eliminator | SM[random characters].exe | "Smart Virus Eliminator rogue security software - not recommended |
| X | SMSERIALWORKERSTART | shellexcon.exe | "Added by the FAKEALERT-AH TROJAN! Installed with the SpyBurner spyware remover - which is not recommended |
| X | SMSERIALWORKERSTARTER | winstrse.exe | "Added by the RENOS.IC TROJAN! Installed with the SpyBurner spyware remover - which is not recommended |
| X | SoundMax Audio Drivers | SndMAX.exe | "Added by a variant of the SDBOT WORM!"
|
| X | SpecialOffers | SpecialOffers*.exe [* = digit] | "SpecialOffers adware"
|
| X | SpecialOffers | SpecialOffers.exe | "SpecialOffers adware"
|
| X | SpoolerSubSystemProcess | SpooI32.exe | "Added by the EHKS.21 keylogger! Note - the ""I"" between ""o"" and ""3"" is a capital ""i"" not a lower case ""L"""
|
| X | Streams Drivers | [trojan filename] | "Added by the RESTARTER.E TROJAN!"
|
| U | Super X Desktop Version 3.4 | SXDesk.exe | "Super X Desktop - virtual desktop manager"
|
| X | superslut | msslut32.exe | "Added by the SLUTER-A WORM!"
|
| U | SuperSpamKiller Pro | Ssk.exe | "SuperSpamKiller Pro email spam blocker"
|
| X | support-reverse-smileys | [trojan filename] | "Added by the LITEBOT TROJAN!"
|
| X | SwiftCleaner | SwiftCleanerScanner.exe | "SwiftCleaner rogue cleaning utility - not recommended |
| X | Sygaete Personal Firewall | SyGate.exe | "Added by the RBOT-GLX WORM!"
|
| X | Sygate Personal 3 | svrv.exe | "Added by the RBOT-XD WORM!"
|
| X | Sygate Personal Block | Studio.exe | "Added by the RBOT-TW WORM!"
|
| X | Sygate Personal Firewall | Win32x.exe | "Added by the RBOT-KZ WORM!"
|
| X | Sygate Personal Firewall | system32.exe | "Added by the RBOT.VI WORM!"
|
| X | Sygate Personal Firewall | sysgut.exe | "Added by the SDBOT.WM WORM!"
|
| X | Sygate Personal Firewall | Sygate.exe | "Added by the RBOT-PN WORM!"
|
| X | Sygate Personal Firewall | Mcafeeupdate.exe | "Added by the RBOT.YN WORM!"
|
| X | Sygate Personal Firewall | Sygate32.exe | "Added by the RBOT.ATW WORM!"
|
| X | Sygate Personal Firewall | MSNSRV32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Firewall | service.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Firewall | t1ktik.exe | "Added by the RBOT-VP WORM!"
|
| X | Sygate Personal Firewall | host32.exe | "Added by the RBOT.ALD WORM!"
|
| X | Sygate Personal Firewall | sexy.exe | "Added by the RBOT-XY WORM!"
|
| X | Sygate Personal Firewall | sys.exe | "Added by the RBOT-ZC WORM!"
|
| X | Sygate Personal Firewall | syserror.exe | "Added by the RBOT.UC WORM!"
|
| X | Sygate Personal Firewall | hostserv.exe | "Added by the RBOT.BKO WORM!"
|
| X | Sygate Personal Firewall | msnmsgrs.exe | "Added by the RBOT.XN WORM!"
|
| X | Sygate Personal Firewall | Sygat.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Firewall | wins.exe | "Added by the RBOT.AOB WORM!"
|
| X | Sygate Personal Firewall | winxpstat.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Firewall | Syga.exe | "Added by the RBOT-AQD WORM!"
|
| X | Sygate Personal Firewall | svchots.exe | "Added by the RBOT.ABT WORM!"
|
| X | Sygate Personal Firewall | win31243.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Sygate Personal Firewall Start | services32.exe | "Added by the RBOT-MB WORM!"
|
| X | Sygate Personal Firewall Start | servic.exe | "Added by the RBOT-RY WORM!"
|
| X | Sygate Personal Port | crss.exe | "Added by the RBOT-PX WORM!"
|
| X | Sygate Personal Port Blocker | volume.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personal Port Blocker | winupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygate Personals Firewalls | ccsrn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Sygates Personal Firewall | sygs.exe | "Added by the RBOT.XB WORM!"
|
| X | Synchronization Manager | rservers.exe | "Added by the FORBOT-FM WORM!"
|
| X | SysDefenders | SysDefenders.exe | "SysDefenders rogue security software - not recommended |
| X | Sysgate Personal Firewall | syst3ms.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | sysPersonalFirewall | msnmssgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | sysPersonalFirewall | system.exe | "Added by the WOOTBOT.FH WORM!"
|
| X | sysPersonalFirewall | tskm0nitor.exe | "Added by the SDBOT.APC WORM!"
|
| X | System Defender | WS[random characters].exe | "System Defender rogue security software - not recommended |
| X | System Device Version | systemdv.exe | "Added by a variant of the RBOT WORM!"
|
| X | System Drivers | wingmt.exe | "Added by the SDBOT-MG WORM!"
|
| X | System Drivers | cpsq32.exe | "Added by the SDBOT.AXH WORM!"
|
| X | System Drivers | sysdrv32.exe | "Added by the AGOBOT-ZX WORM!"
|
| X | System File Drivers | nvsysvc32.exe | "Added by the AGOBOT.WJ WORM!"
|
| X | System Security Updaters | vsmons.exe | "Added by the RBOT-OW WORM!"
|
| X | SystemB | MessengerStopper.exe | "MessStopper adware"
|
| X | syswin.txt | [3 random letters].exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Taesk managers | tase.pif | "Added by the RBOT-AYK TROJAN!"
|
| U | tgcmdprovidersbc | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| Y | Tiny Personal Firewall | persfw.exe | "Tiny Personal Firewall"
|
| X | Trojan Guarder Gold Version | Trojan Guarder.exe | "TrojanGuarder rogue security software - not recommended"
|
| X | ttool | [random numbers].exe | "Added by the BCKDR-QII BACKDOOR! The filename seen most often is ""9129837.exe"""
|
| X | UERScw | UERScw.exe | "Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | Universal Plug & Play devices | WinUPPD.exe | Added by an unidentified WORM/TROJAN!
|
| X | Universal USB Service | svchost32.exe | "Added by the KELVIR.R WORM!"
|
| X | USB Drivers1 | msupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | user | users.exe | "Added by the AUTORUN-AMK WORM!"
|
| X | User Services | usersvc.exe | "Added by the REVCUSS.A TROJAN!"
|
| X | UserSystem | [filename] | "CoolWebSearch Smartsearch parasite variant. Also detected as the SEARCH-A TROJAN!"
|
| U | versato | versato.exe | """Hot"" button (such as volume and browser control) management and a CD player as supplied with QTronix (as possibly Micro Innovations) keyboards"
|
| X | verse | verse.exe | "Added by the STAP-C WORM!"
|
| X | Version | Version.exe | "JRAUN adware variant"
|
| X | Version | manage.exe | "JRAUN adware variant"
|
| X | version | [random].exe | "DealHelper adware"
|
| X | VidiaDrivers | [path to trojan] | "Added by the RANKY.U TROJAN!"
|
| X | VIEW POINT DRIVERS | phqghum.exe | "Added by the RBOT.BRX WORM!"
|
| X | VIEW POINT DRIVERS FOR WIN32 | phqghu.exe | "Added by a variant of the RBOT WORM!"
|
| X | Virus-Bursters | virus-bursters.exe | "VirusBursters rogue security software - not recommended |
| X | VirusBursters | virusbursters.exe | "VirusBursters rogue security software - not recommended |
| X | Volcano Security Suite | VS[random characters].exe | "Volcano Security Suite rogue security software - not recommended |
| U | VPCUserServices | VMUSrvc.exe | "Part of ""DOS Virtual Machine Additions"" for Microsoft Virtual PC |
| N | vTunerStartUp | vTuner.exe | "vTuner - "an easy way to find and listen to radio and TV broadcasts over the Internet""
|
| U | WallpaperSS | WallpaperSS.exe | "Wallpaper Slideshow LT from gPhotoShow.com - ""a great utility for displaying your favorite photos as your desktop wallpaper"""
|
| N | Weatherscope | Weatherscope.exe | "WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| X | WeatherStudio Desktop | WeatherStudio Desktop.exe | "WeatherStudio adware"
|
| X | WEB DRIVERS FOR WIN32 | phqgh.exe | "Added by a variant of the RBOT WORM!"
|
| X | wersds | doriot.exe | "Added by the JECT.C TROJAN!"
|
| X | wersds.exe | doriot.exe | "Added by the BAGLEDI-A TROJAN!"
|
| N | WhitephonePersonal | WhitePhonePersonal.exe | "WhitePhone Personal from Voice Commerce Group - ""provides free PC to PC calls globally and access to low cost calls to phones worldwide."" Free internet telephony utility using the VoIP (Voice over Internet Protocol). No longer appears to be available"
|
| X | Win Drivers SSL | hpws.exe | "Added by the IRCBOT.67098 WORM!"
|
| X | Win Drivers SSL | TASKMAN4.exe | "Added by a variant of the RBOT WORM!"
|
| X | Win Drivers SSL32 | hpwsnnsbc.exe | "Added by the SPYBOT.MAR WORM!"
|
| X | Win32 Drivers | winlogons.exe | "Added by the FORBOT-FG WORM!"
|
| X | Win32 Firewall Drivers | winfirewall.exe | "Added by the WOOTBOT.GX WORM!"
|
| X | Windows Acer Service | acersv.exe | "Added by the IRCBOT.YFQ BACKDOOR!"
|
| X | Windows Additional Guard | WI[random characters].exe | "Windows Additional Guard rogue security software - not recommended |
| X | Windows Domain Name Drivers | windns.exe | "Added by the FORBOT-EP WORM!"
|
| X | Windows Drivers | ssms.exe | "Added by the RBOT-AT WORM!"
|
| X | Windows drivers update | windowsupdate.exe | "Added by the RBOT-ACE WORM!"
|
| X | Windows Enterprise Suite | WE[random characters].exe | "Windows Enterprise Suite rogue security software - not recommended |
| X | Windows Graphics Loaders | wingraphics.exe | "Added by the SPYBOT.JG WORM!"
|
| X | Windows haz Layer | [5 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows HP Drivers | hpdmws.exe | "Added by the SDBOT.AQU WORM!"
|
| X | Windows IPv6 Drivers | wipv6.exe | "Added by the SDBOT-VJ WORM!"
|
| X | Windows Memory Drivers | memretain.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Windows messenger | messengers.exe | "Added by the MYTOB.EI WORM!"
|
| X | Windows Messenger Service | kaspersky.exe | "Added by the MYTOB.HY WORM!"
|
| X | Windows Micro Drivers | wupdates32.exe | "Added by the RBOT-AEH WORM!"
|
| X | Windows Microsoft Services | [8 random letters].exe | "Added by the KOLAB.AW WORM!"
|
| X | Windows ms Drivers | msnup32.exe | "Added by the SDBOT-AAL WORM!"
|
| X | Windows MSX drivers | winmsx.exe | "Added by the RBOT-AYG TROJAN!"
|
| X | Windows NTFS Volume Manage | [6 random letters].exe | "Added by the RBOT.EDL BACKDOOR!"
|
| X | Windows PC Defender | WP[random characters].exe | "Windows PC Defender rogue security software - not recommended |
| X | Windows Portable Device Drivers | MSKSVRVS.EXE | "Added by a TROJAN - see here"
|
| X | Windows Protection Suite | WI[random characters].exe | "Windows Protection Suite rogue security software - not recommended |
| X | Windows Registers | winservicess.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Registry Manager | tasksmanagers.exe | "Added by the MYTOB.ER WORM!"
|
| X | Windows Reverse Preperation | winrvp.exe | "Added by the SLENFBOT.CB WORM!"
|
| X | Windows Reversed Virus Protection | winrsvp.exe | "Added by the SLENFBOT.HX WORM!"
|
| X | Windows Secure talal32 | [7 random letters].exe | "Added by the RBOT.HTP TROJAN!"
|
| X | Windows Security Suite | WI[random characters].exe | "Windows Security Suite rogue security software - not recommended |
| X | Windows Servcesc | [9 random letters].exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Server Drivers | syssrv.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Service Ag3nt | [6 random letters].exe | "Added by the SDBOT.EZX TROJAN!"
|
| X | Windows Service Agent | [3 random letters].exe | "Added by the AGENT.AMEB TROJAN - see examples here and here"
|
| X | Windows Service Agnts | [8 random letters].exe | "Added by the SDBOT.BCQ WORM!"
|
| X | Windows Service oi worms | [6 random letters].exe | "Added by the SYSTEMHI.OS TROJAN!"
|
| X | Windows Services | NetworkDrivers.exe | "Added by the SDBOT-YO WORM!"
|
| X | Windows Services Aganters | [10 random letters].exe | "Added by the RBOT.CUN WORM!"
|
| X | Windows Services alges2 | [8 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Services Tower | svctowers.exe | "Added by the IRCBOT.AGJ BACKDOOR!"
|
| X | Windows Serviece Agents | [8 random letters].exe | "Added by the AGENT.BHR TROJAN!"
|
| X | Windows SP2 Version Load | wuauclt32.exe | "Added by the GAOBOT.CX WORM!"
|
| X | Windows SpoolPrint Service | spoolersrv.exe | "Added by the SDBOT-ZT WORM!"
|
| X | Windows sq Drivers | winmsn32.exe | "Added by the RBOT-ADI WORM!"
|
| X | Windows SSL Secondary Drivers | SSL32Dr.exe | "Added by the SDBOT.ASQ WORM!"
|
| X | Windows Stand Sound Drivers | Sounddrv.exe | "Added by the SDBOT-XF WORM!"
|
| X | Windows Storm-Memory Drivers | memorystorm.exe | "Added by the SLENFBOT.CO WORM!"
|
| X | Windows System Defender | WS[random characters].exe | "Windows System Defender rogue security software - not recommended |
| X | Windows System Drivers | sysretain.exe | "Added by the SLENFBOT.BY WORM!"
|
| X | Windows System Security Monitor | [4 random letters].exe | "Added by the PINKTON.A WORM!"
|
| X | Windows System Suite | WS[random characters].exe | "Windows System Suite rogue security software - not recommended |
| X | Windows System-Control Drivers | syscontrl.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | windows updaters | winupdats.exe | "Added by the SPYBOT-IS WORM!"
|
| N | Windows Version Check | ver_chk.exe | "Version checker for CyberAudioLibrary - ""a new way to exchange information through the Internet"""
|
| X | Windows Version Service | sysvers.exe | "Added by the SLENFBOT.IF WORM!"
|
| X | Windows Version Service | sysvers32.exe | "Added by the SLENFBOT.HZ WORM!"
|
| X | Windows Video Drivers | videons32.exe | "Added by the GAOBOT.AZT WORM!"
|
| X | Windows Video Drivers | VIDEONS3.EXE | "Added by the AGOBOT-KZ BACKDOOR!"
|
| X | windowsupdate | RPC[RANDOM CHARACTERS].exe | "Added by the IRCBOT.B TROJAN!"
|
| X | Winds Sers Agts | [5 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | Winds Sersc Agts | rzrzncrtz.exe | "Added by the RBOT-GTV WORM!"
|
| X | WinNetDDE | [random characters].exe | "Added by the NETDEPIX.B TROJAN!"
|
| X | Winproxy Personal | WINPROXY.EXE | "Added by the SDBOT.BMF WORM!"
|
| X | WinRunners | WinDrivers.exe | "Added by the DULOAD.C WORM!"
|
| X | winversion | winversion.exe | "Browser hijacker |
| U | XemiComputers Scheduler | Scheduler.exe | "Smooth Program Scheduler from XemiComputers ""will start any program you want at a scheduled time"""
|
| X | xswdmse | [8 random letters].exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | XTN Service Drivers | winxtn.exe | "Added by the SDBOT-YK WORM!"
|
| X | Xupiter Startup | XupiterStartup.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| X | xupiterstartup2003 | xupiterstartup2003.exe | "Xupiter - adware and homepage hijacker. Use Spybot S&D |
| X | Yahoo Messengger | IEXPLORERS.exe | "Added by the AUTOIT.DH TROJAN!"
|
| X | ZtgServerSwitch | server.vbs | ZTGServerswitch is part of Sony's Vaio support agent - designed by Support.com. Not required if the user does not wish to use the Vaio support agent and regarded as spyware
|
| X | [12 random characters] | avifile5.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bootvid4.exe | "IeDriver adware variant"
|
| X | [12 random characters] | browser8.exe | "IeDriver adware variant"
|
| X | [12 random characters] | atitvo32.exe | "IeDriver adware variant"
|
| X | [12 random characters] | autodisc.exe | "IeDriver adware variant"
|
| X | [12 random characters] | cabview1.exe | "IeDriver adware variant"
|
| X | [12 random characters] | advpack1.exe | "IeDriver adware variant"
|
| X | [12 random characters] | batmeter.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bidispl2.exe | "IeDriver adware variant"
|
| X | [12 random characters] | asferror.exe | "IeDriver adware variant"
|
| X | [12 random characters] | catsrvps.exe | "IeDriver adware variant"
|
| X | [12 random characters] | admparse.exe | "IeDriver adware variant"
|
| X | [12 random characters] | audiosrv.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bootvid2.exe | "IeDriver adware variant"
|
| X | [12 random characters] | cmpbk321.exe | "IeDriver adware variant"
|
| X | [12 random characters] | ADPTIF67.exe | "IeDriver adware variant"
|
| X | [12 random characters] | asycfilt.exe | "IeDriver adware variant"
|
| X | [12 random characters] | ati2dvag.exe | "IeDriver adware variant"
|
| X | [12 random characters] | atl91036.exe | "IeDriver adware variant"
|
| X | [12 random characters] | blackbox.exe | "IeDriver adware variant"
|
| X | [12 random characters] | browser5.exe | "IeDriver adware variant"
|
| X | [12 random characters] | bthserv1.exe | "IeDriver adware variant"
|
| X | [12 random characters] | camocx28.exe | "IeDriver adware variant"
|
| X | [12 random characters] | CAMOCX74.exe | "IeDriver adware variant"
|
| X | [12 random characters] | capesnpn.exe | "IeDriver adware variant"
|
| X | [14 random numbers] | mradll.exe | "Green AV rogue security software - not recommended |
| X | [14 random numbers] | rwg.exe | "Green AV rogue security software - not recommended |
| X | [3-4 random letters] | nslookup.exe | "PurityScan adware. Not to be confused with the legitimate nslookup.exe which is found in the System32 folder"
|
| X | [3-4 random letters]Srv32 | [path to file] | "Added by the BANCSADE-A TROJAN!"
|
| X | [32 random hex numbers] | tsc.exe | "Total Security rogue security software - not recommended |
| X | [32 random hex numbers] | badware-protector.exe | "Badware Protector rogue security software - not recommended |
| X | [32 random numbers] | av2009.exe | "AntiVirus 2009 rogue security software - not recommended |
| X | [32 random numbers] | av360.exe | "Antivirus 360 rogue security software - not recommended |
| X | [32 random numbers] | AVS.exe | "Antivirus Sentry rogue security software - not recommended |
| X | [32 random numbers] | xpa.exe | "XP Antivirus rogue security software - not recommended"
|
| X | [32 random numbers] | total.exe | "Total Antivirus rogue security software - not recommended |
| X | [random characters] | securewinload32x.exe | "Added by the OPTIXP-N TROJAN!"
|
| X | [random characters] | rsbmsc.exe | "Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
|
| X | [random characters] | _default[random].pif | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | j[random].exe | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | sv[random].exe | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | yesbron.com | "Added by the BRONTOK-AI WORM and variants!"
|
| X | [random characters] | systs.exe | "Added by the AGENT-GDC TROJAN!"
|
| X | [random characters] | xvassdf.exe | "Added by the AUTORUN-BAD WORM!"
|
| X | [various names] | UserSp1.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|