| X | Security | WindowsSecurityUpdate.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Security 2009 | Security2009.exe | "Security 2009 rogue security suite - not recommended |
| X | Security Accounts Manager SM | samsm.exe | "Added by the SPYBOT.JE WORM!"
|
| X | Security Agent | securag.exe | "Added by the BANCBAN-F TROJAN!"
|
| X | Security Agent Manager | mssams.exe | "Added by the RBOT-SV WORM!"
|
| X | Security Antivirus | SA[random characters].exe | "Security Antivirus rogue security software - not recommended |
| X | Security Antivirus Xp 1 | inetfor.exe | "Added by the SDBOT.BAV WORM!"
|
| X | Security Center | AppControl.exe | "Added by the SDBOT.CFT WORM!"
|
| X | Security Center Distribution | securesec.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Security essentials 2010 | SE2010.exe | "Security Essentials 2010 rogue security software - not recommended |
| X | Security Guard | SG[random characters].exe | "Security Guard rogue security software - not recommended |
| X | Security iGuard | Security iGuard.exe | "Security iGuard spyware remover - not recommended |
| U | Security Manager | SecurityManager.exe | "A ComCast Internet software suite that provides a variety of features (firewall |
| X | Security Master AV | SM[random characters].exe | "Security Master AV rogue security software - not recommended |
| X | Security Mechanic | lsascs.exe | "Security Mechanic rogue security software - not recommended |
| X | Security Monitor | securemon.exe | "Added by the SLENFBOT.ABH WORM!"
|
| X | Security Patch | scmss.exe | "Added by the RBOT-ZW WORM!"
|
| X | Security Patch | WinUpdate32.exe | "Added by the SDBOT-BM WORM!"
|
| X | Security Patches | msnkn.exe | "Added by the RBOT.WW WORM!"
|
| X | Security Patches | WinLab32.exe | "Added by the SDBOT-KB WORM!"
|
| X | Security Server DB | secserver.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | security service | syss.exe | Added by an unidentified WORM or TROJAN!
|
| X | Security Service | secsvc.exe | "Added by the RBOT-GGF WORM!"
|
| X | Security Service DB | secservice.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Security Service Process | svhost.exe | "Added by the AGOBOT-LC WORM!"
|
| X | Security System | securesys.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Security Update Service | wmiprvce.exe | "Added by the AGOBOT.ZW WORM!"
|
| X | Security Update Service Process | svrhost23.exe | "Added by the AGOBOT-GN WORM!"
|
| X | SecurityCenter | securitycenter.exe | "Desktop Security 2010 rogue security software - not recommended |
| X | SecurityFighter | SecurityFighter.exe | "SecurityFighter rogue security software - not recommended |
| X | SecurityScanner | ss2008.exe | "Security Scanner 2008 rogue security software - not recommended |
| X | SecuritySoldier | SecuritySoldier.exe | "SecuritySoldier rogue security software - not recommended |
| X | Sepate Security Firewall | sepate.exe | "Added by the RBOT.BLC BACKDOOR!"
|
| X | Shield Security | shield.exe | "Added by the RIZO.A TROJAN!"
|
| X | Shield32 Security | shield32.exe | "Added by the RIZO.A TROJAN!"
|
| X | SmartSecurity | SmartSecurity.exe | "Smart Security rogue security software - not recommended |
| X | Social Security Agency | rpcxsocsa.exe | "Added by a variant of the RBOT WORM!"
|
| X | Symantec Client Security | symclient.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Symantec Security | symantec32.exe | "Added by the RANDEX.PR or RANDEX.YR WORMS!"
|
| X | Symantec Security Addon | nvsvc.exe | "Added by a variant of the AGOBOT/GAOBOT WORM! Note - do NOT confuse with the legitimate NVIDIA Driver Helper Service file of the same name as described here"
|
| X | Symantec Security Routine Addon | navpaw.exe | "Added by the AGOBOT-ES BACKDOOR!"
|
| X | Symantec Security Routine Addon for Microsoft Windows | navpxaw32.exe | "Added by the AGOBOT-GJ TROJAN!"
|
| X | System Security Checker | ssc.exe | "Added by the IRCBOT-WI TROJAN!"
|
| X | System Security Updaters | vsmons.exe | "Added by the RBOT-OW WORM!"
|
| X | SystemSecurity | zprot32.exe | "Added by the AGENT-FK TROJAN!"
|
| Y | TELUS Security service | freedom.exe | "Freedom Internet Security & Privacy - anti-virus |
| Y | USB SECURITY DEVICE CoInstaller | JupitCo.exe | "ButterflyMedia USB Flash drive related - required for the password security feature to work"
|
| X | Volcano Security Suite | VS[random characters].exe | "Volcano Security Suite rogue security software - not recommended |
| X | Win Security | msw32.pif | "Added by the RBOT-AQT WORM!"
|
| X | Win Security | winsecure.exe | "Added by the SLENFBOT.RD WORM!"
|
| X | Win Security 360 | WinSecurity360.exe | "Win Security 360 rogue security software - not recommended |
| X | Win32 Security Protocol | secure32.exe | "Added by the RBOT-ETI WORM!"
|
| X | Win32 Security Service | crsss.exe | "Added by the DELBOT-O WORM!"
|
| X | win32 security updates downloader | tskmngr.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Wind Security | mswi32.pif | "Added by the RBOT-ARH WORM!"
|
| X | Windows bypass security SMSS Service | SbiCvy.exe | "Added by the RBOT-GRF WORM!"
|
| U | Windows IP Security | ipsec.exe | "Related to the VPN IPSec utility - used to create Security Policy (SP) entries and Security Association (SA) entries in the kernel"
|
| X | Windows IP Security Service | ipsecs.exe | "Added by the RBOT.BPW WORM!"
|
| X | Windows Login Security | winlogin.pif | Added by an unidentified WORM or TROJAN!
|
| X | Windows Proffesional Security | WinSecure32.exe | "Added by the AGOBOT.VA WORM"
|
| X | Windows Registry Security | crss.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | WINDOWS SECURITY | wingrd.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Security | win.pif | "Added by the RBOT-APT WORM!"
|
| X | Windows Security | ms32.pif | "Added by the RBOT-ARN WORM!"
|
| X | Windows Security | winscure.exe | "Added by the RBOT-BAF WORM!"
|
| X | Windows Security Assistant | rundll32.vbe | "CoolWebSearch Alfasearch parasite variant - also detected as the STARTPA-U TROJAN!"
|
| X | Windows Security Assistant | winsec.exe | "CoolWebSearch parasite variant"
|
| X | Windows Security Authority Service | lsass.exe | "Added by the KALEL-A WORM! Note - this is not the legitimate lsass.exe process |
| X | Windows Security Center Notification App | wscnfty.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Security Center Notification Appls | sxe.exe | "Added by the RBOT-GKX WORM!"
|
| X | Windows Security Center Notification Applse | sxes.exe | "Added by the RBOT-GLR WORM!"
|
| X | Windows Security Center Notification Applse | os.exe | "Added by a variant of the RBOT-GLR WORM!"
|
| X | Windows Security Center Notification Applsee | sysecurex.exe | "Added by a variant of the RBOT-GKX WORM!"
|
| X | Windows Security Control | wuaucls.exe | "Added by the FORBOT-V WORM!"
|
| X | Windows Security Manager | winsecurity.exe | "Added by the AGOBOT-KI WORM!"
|
| X | Windows Security Manager | winsecure.exe | "Affilred adware"
|
| X | Windows Security Manager | svchost.exe | "Added by the ANTINNY.AX WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""Microsoft"" subfolder"
|
| X | Windows Security Manager | svhost.exe | "Added by the GAOBOT.ALU WORM!"
|
| X | Windows Security Module | module.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Security Policy | lsass32.exe | "Added by the AGOBOT-CR WORM!"
|
| X | Windows Security Service | [random file name] | "Added by the RBOT-ALV WORM!"
|
| X | Windows Security Service | arrdt.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Security Service | windows.pif | "Added by the RBOT-AMG WORM!"
|
| X | Windows Security Suite | WI[random characters].exe | "Windows Security Suite rogue security software - not recommended |
| X | Windows Security Survy | svchosl.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Security Tool | WinSecure.exe | "Added by the AGENT-GPY TROJAN!"
|
| X | Windows Security Update | security32.exe | "Affilred adware"
|
| X | Windows Security Update | ndsass.exe | "Added by the RBOT.ESM BACKDOOR!"
|
| X | Windows System Security | winmp.exe | "Added by the RBOT.IV WORM!"
|
| X | Windows System Security | sys32.pif | "Added by the RBOT-AOL WORM!"
|
| X | Windows System Security Monitor | [4 random letters].exe | "Added by the PINKTON.A WORM!"
|
| X | WindowsXp Security | spool.exe | "Added by the RBOT-GRK WORM!"
|
| X | Windows_LowLevel_Security_Core | lsass.exe | "Added by the PADMIN-A TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Repair"
|
| X | WinSecurity | uninstall.exe | "Added by the SILLYFDC.BCJ WORM!"
|
| X | WinwebSecurity | WinwebSecurity.exe | "Winweb Security rogue security software - not recommended |
| X | WinX Security Center | WinX Security Center.exe | "WinX Security Center rogue security software - not recommended |
| X | Wsecurity | ldanw32.exe | "Added by the AGENT-BUC TROJAN!"
|
| X | XP SecurityCenter | XPSecurityCenter.exe | "XPSecurityCenter rogue security software - not recommended |
| X | zone alarm security | zlclint.exe | "Added by the NIRBOT WORM!"
|
| X | zSecurity Service | szsvc.exe | "Added by the SDBOT-DAB WORM!"
|