| X | LiveUpdate32 | services.exe | "Added by the VB.BAU BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\isas"
|
| X | Ljx | rundll32.exe | "Added by the LINEAG-ABD TROJAN! Note - this is not the legitimate rundll32.exe process |
| ? | LLMODCL2 | "rundll.exe setupx.dll | InstallHinfSection ..LLMODCL2.INF" |
| N | LM Status | LMSTATUS.EXE | Xerox WorkCenter XE - language monitor status application
|
| N | LMSTATUS | LMSTATUS.EXE | Xerox WorkCenter XE - language monitor status application
|
| X | lmu | LMU.exe | "Detected by Kaspersky as the AGENT.BG TROJAN!"
|
| X | lnternet Update | lExplore.exe | "Added by the RBOT-GRH WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
|
| X | load | rundll32.exe | "Added by the WOWCRAFT TROJAN!"
|
| X | load | rundl132.exe | "Added by the LOOKED-CK WORM!"
|
| X | Load-Guard | Wscript.exe LGuarg.exe.vbs | "Added by the YENO.B and YENO.C WORMS! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""LGuarg.exe.vbs"" file is located in %Windir%"
|
| X | LoadDBackUp | BcTool.exe | "Added by the GIBE WORM!"
|
| U | LoadFujitsuQuickTouch | QuickTouch.exe | Maps the keys on a Fujitsu Siemens Lifebook application panel to various programs and functions
|
| X | LoadGolfCourses | LoadGolfCourses.exe | PlayMiniGolf.com foistware - stealth installed!
|
| X | Loadhg | rundll32.exe | "Added by the LINEAG-ABX TROJAN!"
|
| X | LoadHTML | "rundll32.exe regsvr32.exe | MShtmpre" |
| X | loadMecq3 | rundll32.exe | "Added by the LEGMIR-AS TROJAN! Note - this is not the legitimate rundll32.exe process |
| X | loadMefs | rundll32.exe | "Added by the LEGMIR-JB TROJAN! Note - this is not the legitimate rundll32.exe process |
| U | Loadout Manager | nost_LM.exe | "Manager for the Belkin Nostromo n50 SpeedPad game controller - see here"
|
| U | LoadPowerProfile | Rundll32.exe powrprof.dll | "Power management specifics such as monitor shut-off |
| X | LoadPowerProfile | Rundll.exe powerprof.dll | "Added by the LOXOSCAM TROJAN! Note - do not confuse with the valid LoadPowerProfile entry! Notice that the infected version uses ""Rundll.exe"" whereas the uninfected version uses ""Rundll32.exe"""
|
| X | LoadPowerProfile | rundl.exe | "Added by the TOFAZZOL TROJAN! Not to be confused with the valid LoadPowerProfile entry where the command is Rundll32.exe powrprof.dll"
|
| X | LoadPowerProfile | Rundll32.exe | "Added by the MIROOT WORM! Note - do not confuse with the valid LoadPowerProfile entry which has ""powrprof.dll"" appended to the command/data line"
|
| X | LoadPowerScheme | rundll32.exe powerprof.dll CheckPowerProfile | "Ulubione adult content dialer. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted"
|
| X | loads.exe | suploads.exe | "Added by the AGENT-BZ TROJAN!"
|
| X | LoadService | Virus | "Added by the CAGER.A WORM!"
|
| X | LoadSIPS | "rundll32.exe SIPSPI32.dll | SIPSPI32" |
| X | Local Authority Service | lsass.exe | "Added by the MARKTMAN-C TROJAN! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | LOCAL INTERNET WEB DRIVERS FOR WIN32 | phqghume.exe | "Added by a variant of the RBOT WORM!"
|
| X | Local Page | http://find.naupoint.com | "Naupoint browser hijacker"
|
| X | Local runole service | srvc32.exe | "Added by the SMALL-DP TROJAN!"
|
| X | Local Security Authority Servce | lssas.exe | "Added by the POEBOT-T WORM!"
|
| X | Local Security Authority Service | lssas.exe | "Added by the POEBOT-J WORM!"
|
| X | Local Security Authority Service | Isass.exe | "Added by the LINKBOT.M WORM!"
|
| X | Local-Settings-of-[User Name] | [User Name].exe | "Added by the GAVGENT.A WORM!"
|
| X | loginui32 | loginui32.exe | "Added by the LONGNU.A TROJAN!"
|
| Y | Logitech | Communications_Helper.exe | "Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also |
| N | Logitech . Product Registration | eReg.exe | "Registration reminder from Leader Technologies for Logitech software such as SetPoint for their range of wired and wireless keyboards and pointing devices (mice |
| X | Logitech Camera | Soundcane.exe | "Added by the SDBOT.MUC WORM!"
|
| N | Logitech Desktop Messenger | setup-8876480.exe | "Installer for Logitech Desktop Messenger included with older versions of the software for Logitech products - which automatically checks for software upgrades and new products |
| U | Logitech ImageStudio | ISStart.exe | "Installed with Logitech's ImageStudio webcam software. The exact purpose of this startup entry is unknown at present |
| U | Logitech ImageStudio | LogiTray.exe | "System Tray access to ImageStudio |
| U | Logitech ImageStudio | LVCOMS.EXE | Entry added when you install Logitech ImageStudio webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
|
| U | Logitech QuickCam | CameraAssistant.exe | "Entry added when you install versions of the Logitech QuickCam webcam software and used to configure and tweak your webcam settings. Includes support for the Quick Assistant - which launches when a video application (such as video conferencing in an instant messaging client) accesses to camera so you can quickly fine tune face tracking and zoom |
| U | Logitech QuickCam | ISStart.exe | "Installed with older versions of Logitech's QuickCam webcam software. The exact purpose of this startup entry is unknown at present |
| U | Logitech QuickCam | LogiTray.exe | "System Tray access to My Logitech Pictures |
| U | Logitech QuickCam | LVCOMS.EXE | Entry added when you install older versions of Logitech QuickCam webcam software. It allows the camera to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
|
| U | Logitech QuickCam | LVComSX.exe | Entry added when you install versions of the Logitech QuickCam webcam software - allows the full camera features (such as face tracking) to be accessed by both the Logitech software and (amongst others) NetMeeting and Windows Movie Maker. If you don't use the camera on a daily basis create your own shortcut and run it manually when required
|
| N | Logitech QuickCam | ManifestEngine.exe | "Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
|
| U | Logitech Utility | Logi_MwX.exe | "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
|
| N | Logitech Wakeup | lgwakeup.exe | Loads at startup and monitors the scanner. When a document is inserted in the scanner the wakeup program feeds the document a fraction of a inch into the scanner and then it launches the control center software. From the control center you can select whether to fax or copy or print the scanned documents. If you uncheck the Logitech wakeup software from the startup it no longer launches the control center or feeds the document a fraction of an inch. You can manually launch the control center software via Start ->Programs and still be able to scan images
|
| Y | LogitechCommunicationsManager | Communications_Helper.exe | "Entry added when you install versions of the Logitech QuickCam webcam software. Used to interface your webcam with third party chat and voice programs such as instant messaging clients and Skype. Also |
| U | LogitechImageStudioTray | LogiTray.exe | "System Tray access to ImageStudio |
| N | LogitechQuickCamRibbon | QuickCam10.exe | "Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled |
| N | LogitechQuickCamRibbon | LWS.exe | "Loads versions of the Logitech Webcam Software and is required to support features such as face tracking. If enabled |
| N | LogitechQuickCamRibbon | Quickcam.exe | "Loads versions of the Logitech QuickCam webcam software and is required to support features such as face tracking. If enabled |
| N | LogitechSoftwareUpdate | ManifestEngine.exe | "Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
|
| U | LogMeIn GUI | LogMeInSystray.exe | "RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN |
| U | LogMeIn GUI | ragui.exe | "RemotelyAnywhere is a remote administration and remote control solution for Windows. It allows access to the host computer via the network (the LAN |
| Y | Logoff | SCTUINotify.exe | "Part of Windows SteadyState |
| X | Logon | CSRSS.EXE | "Added by the BRONTOK-BH WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in Documents and Settings\<User>\Local Settings\Application Data\WINDOWS"
|
| U | LogonStudio | logonstudio.exe | "WinCustomize LogonStudio - "Allows Windows XP users to edit |
| X | logonUiInit | Rundll32.exe rgtndz.dll | "Identified as a variant of the Trojan-Clicker.Win32.Agent.bqy malware. Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""rgtndz.dll"" file is found in %System%"
|
| X | Lookup_Sys | lookupsys.exe | P04n trojan
|
| X | LosMejoresMP3 | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | LotsOfGames | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | LotsOfJokes | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| N | Lotus Organizer EasyClip | easyclip.exe | ""The Easy Clip icon automates the collection of information from sources such as e-mail to create an Organizer address |
| N | Lotus QuickStart | smartctr.exe | "Lotus central application |
| U | Lotus SuiteStart | suitest.exe | Puts the individual Lotus components in the system tray taskbar when you start Windows. Can be disabled via MSCONFIG -> Startup as "Lotus SuiteStart 97 Edition". All individual components available via Start -> Programs
|
| X | LotusHlp | LotusHlp.exe | "Added by the WINKO.AO WORM!"
|
| X | LowRiskFileTypes | sysguard.exe | "Added by the FAKEAV-UY TROJAN!"
|
| X | LowVersionSupport | [filename] | "Added by the LASTRAS TROJAN!"
|
| X | LRBZ Utility 32 | lrbz32.exe | "Added by the AGOBOT-JQ WORM!"
|
| N | LS120 Superdisk | ?? | "Supposed to accelerate transfer rate on LS-120 |
| X | LSA Shellu | lsass.exe | "Added by the AUTORUN-CW WORM! Note - this is not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %UserProfile%"
|
| X | LSASS Authority | lshosts32.exe | "Added by the SDBOT-UY TROJAN!"
|
| X | LSASS Authority | lsvhosts.exe | "Added by the SDBOT.BCE WORM!"
|
| X | lsass2k Update | lsass2k.exe | "Added by a variant of the RBOT WORM!"
|
| Y | lsburnwatcher | lsburnwatcher.exe | "HP software which helps one create labels after a music CD is burned using LightScribe discs. If you want to use LightScribe labeling |
| Y | LSBWatcher | lsburnwatcher.exe | "HP software which helps one create labels after a music CD is burned using LightScribe discs. If you want to use LightScribe labeling |
| X | Lssas Monitoring Startup | LSSAS.EXE | "Added by the RBOT.XJ WORM!"
|
| X | LTM2 | winupdate.exe | "Added by the LITMUS.203 TROJAN!"
|
| X | LTM2 | RundlI.exe | "Added by the MULTIDRP.BG TROJAN!"
|
| X | ltssvc | "rundll32.exe ltssvc.dll | start" |
| X | LTT2 | rundll32.exe | "Added by the LINEAGE-BI TROJAN!"
|
| X | luacai | luacai.exe | "Added by the AUTOINF-AK WORM!"
|
| Y | LUCENT TECHNOLOGIES ltmsg | ltmsg.exe | "Lucent Technologies (now Alcatel-Lucent) WinModem - which uses software rather than hardware |
| X | Lucky charms CD | mylcuky.exe | "Added by the SDBOT-SP WORM!"
|
| U | LUGuard | LUGuard.exe | "PC-Duo Remote Control enables your help desk technicians to take instant control of any remote desktop PC at any location across the LAN |
| X | lup | lup.exe | "Added by the IRCBOT_GEN WORM!"
|
| Y | Lusetup | LUSetup.exe | "Symantec LiveUpdate installer - required to install a new version of the application. Will only run once |
| U | LWBMOUSE | lwbwheel.exe | Mouse driver - required if you use non-standard Windows driver features
|
| U | LWBMOUSE | MOUSE32A.EXE | Mouse utility for a Lenovo brand (and possibly others) mouse. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| N | Lwinst Run Profiler | lwtest.exe | Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
|
| X | lwjcjuti.exe | lwjcjuti.exe | "Added by the DWNLDR-GTQ TROJAN!"
|
| Y | LXBSCATS | "rundll32 [path] LXBStime.dll | _RunDLLEntry@16" |
| Y | LXBTCATS | "rundll32 [path] LXBTtime.dll | _RunDLLEntry@16" |
| Y | LXBUCATS | "rundll32 [path] LXBUtime.dll | _RunDLLEntry@16" |
| U | lxbumon.exe | lxbumon.exe | Lexmark 6200 Series printer device monitor
|
| Y | LXBXCATS | "rundll32 [path] LXBXtime.dll | _RunDLLEntry@16" |
| Y | LXBYCATS | "rundll32 [path] LXBYtime.dll | _RunDLLEntry@16" |
| Y | LXCCCATS | "rundll32 [path] LXCCtime.dll | _RunDLLEntry@16" |
| U | LXCDCATS | "rundll32 [path] LXCDtime.dll | _RunDLLEntry@16" |
| Y | LXCECATS | "rundll32 [path] LXCEtime.dll | _RunDLLEntry@16" |
| Y | LXCFCATS | "rundll32 [path] LXCFtime.dll | _RunDLLEntry@16" |
| Y | LXCGCATS | "rundll32 [path] LXCGtime.dll | _RunDLLEntry@16" |
| Y | LXCJCATS | "rundll32 [path] LXCJtime.dll | _RunDLLEntry@16" |
| Y | LXCQCATS | "rundll32 [path] LXCQtime.dll | _RunDLLEntry@16" |
| Y | LXCRCATS | "rundll32 [path] LXCRtime.dll | _RunDLLEntry@16" |
| Y | LXCTCATS | "rundll32 [path] LXCTtime.dll | _RunDLLEntry@16" |
| Y | LXCYCATS | "rundll32 [path] LXCYtime.dll | _RunDLLEntry@16" |
| Y | LXDBCATS | "rundll32 [path] LXDBtime.dll | _RunDLLEntry@16" |
| Y | LXDCCATS | "rundll32 [path] LXDCtime.dll | _RunDLLEntry@16" |
| Y | LXDDCATS | "rundll32 [path] LXDDtime.dll | _RunDLLEntry@16" |
| Y | LXDICATS | "rundll32 [path] LXDItime.dll | _RunDLLEntry@16" |
| U | LXDJCATS | "rundll32 [path] LXDJtime.dll | _RunDLLEntry@16" |
| N | LXSUPMON | LXSUPMON.EXE | "Lexmark printer related. The printer should work fine without it but what does it do?"
|
| X | LzioMediaUpdater | LzioMediaUpdater.exe | "LZIO.com adware downloader"
|
| N | M-Audio Delta Taskbar Icon | DeltTray.exe | M-Audio Delta Control Panel for M-Audio brand Delta series audio cards. System Tray access to audio settings - available through Control Panel
|
| U | M-Audio MobilePre Control Panel Launcher | MPTask.exe | "Control Panel Launcher for MobilePre USB bus-powered preamp and audio interface from M-Audio"
|
| U | M-Audio Taskbar Icon | DeltaIITray.exe | "System Tray access to the Delta Control Panel for the M-Audio Delta series of PCI audio cards"
|
| X | M1cr0s0ft S3rcurity | systemconfig.exe | "Added by the RBOT.BKB WORM!"
|
| X | M1cr0s0ft Upd4t4zS | update32.exe | "Added by the RBOT-MI WORM!"
|
| X | M3Development_WhenUSave_Installer | M3Development_WhenUSave_Installer.exe | "WhenU.Save adware"
|
| X | Mabochine Deybug Malnager | kdm.exe | "Added by the SDBOT-SD WORM!"
|
| ? | MacDrive7.0.4TimeOutPatch | TimeOutPatch.EXE | "Part of MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| X | Macfee Security Patch | Mpfsheild.exe | "Added by the RBOT-NP WORM!"
|
| U | Machine Debug Manager | MDM.EXE | "Used by developers for debugging and is a component of several MS products including Office and Visual Studio. Those who have encountered it have unchecked it with no degradation in performance. It may cause your computer to ""hang"" if you have Visual Studio installed and this disabled because it appears to take over error handling - hence the U recommendation. For this entry it loads under the ""RunServices"" key in Me (located in C:\WINDOWS\SYSTEM). It also loads a service in XP/Vista (located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug)"
|
| X | Machine Debug Manager | msdn.exe | "Added by a variant of the RBOT WORM!"
|
| X | Machine Debug Manager | mdm.exe | "Added by the SDBOT-APE WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or %System% (Me only). This one is located in %Windir%"
|
| X | Machine Debug Manager | mdms.exe | "Added by the SDBOT-CH WORM!"
|
| X | Machine Update Soft | wusas.exe | Added by an unidfentified WORM!
|
| X | machine-debugger | WMIPRVSW.exe | "Added by the AGOBOT.WW WORM!"
|
| X | machine-debugger | mdmsv.exe | "Added by the AGOBOT-BR WORM!"
|
| X | Macromedia Critical Updater | rarww.exe | "Added by a variant of the RBOT WORM!"
|
| X | Macromedia Flash Update | scvhost.exe | "Added by a variant of the RBOT WORM!"
|
| N | Macrovision Update Service | issch.exe | "InstallShield is used by a number of software producers to install their programs and manage software updates. This entry runs scheduled searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
|
| N | Macrovision Update Service | ISUSPM.exe | "InstallShield is used by a number of software producers to install their programs and manage software updates. This entry searches for and performs any updates to supported installed software so you're always working with the most current version. Manually check for software updates for installed programs on a regular basis"
|
| N | MadExe | LaunchRA.exe | "Part of Dell Resolution Assistant - ""a diagnostic program that allows you to contact Dell. When factory-installed by Dell |
| N | MagicalUnInstall | MagicalUnInstall.exe | "Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation |
| N | MagUninstall | MagicalUnInstall.exe | "Ashampoo® Magical UnInstall from Ashampoo GmbH & Co. KG - which monitors each new program installation |
| X | mahmud | mahmud.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| Y | MailScan Dispatcher | Launch.exe | "MicroWorld MailScan Dispatcher splits each e-mail message into various components such as the header |
| ? | Main Executable (HP) | HP05T0R5.exe | "HP (Hewlett-Packard) related. Maybe related to printers. Now - what does it do?"
|
| X | MainDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | main_module | drvmmx32.exe | "Added by the DILA TROJAN!"
|
| X | Malware Cleaner | [random numbers].exe | "Malware Cleaner rogue security software - not recommended |
| X | Malware Destructor 2009 | MD345d.exe | "Malware Destructor 2009 rogue security software - not recommended |
| X | MalwareBurn 6.9 | MalwareBurn 6.9.exe | "MalwareBurn rogue security software - not recommended |
| X | MalwareBurn 7.0 | MalwareBurn 7.0.exe | "MalwareBurn rogue security software - not recommended |
| X | MalwareBurn 7.1 | MalwareBurn 7.1.exe | "MalwareBurn rogue security software - not recommended |
| X | MalwareBurn 7.2 | MalwareBurn 7.2.exe | "MalwareBurn rogue security software - not recommended |
| X | MalwareBurn 7.3 | MalwareBurn 7.3.exe | "MalwareBurn rogue security software - not recommended |
| Y | Malwarebytes' Anti-Malware | mbamgui.exe | "System tray access to and realtime protection agent for the registered version of MalwareBytes' Anti-Malware - which is ""considered to be the next step in the detection and removal of malware. In our product we have compiled a number of new technologies that are designed to quickly detect |
| Y | Malwarebytes' RogueRemover PRO | RogueRemoverPRO.exe | "Part of Malwarebytes' RogueRemover PRO - the realtime ""RogueMonitor will alert you before you download a rogue application keeping you safe and secure before trouble occurs."" Now discontinued and the funtionality is included in Malwarebytes' Anti-Malware"
|
| X | MalwareCrush | MalwareCrush.exe | "MalwareCrush rogue security software - not recommended |
| Y | Mamutu | mamutu.exe | "Background Guard feature of Mamutu from Emsi Software GmbH - which provides behaviour rather than signature based protection that ""recognizes new and unknown Trojans |
| Y | Mamutu Guard | mamutu.exe | "Background Guard feature of Mamutu from Emsi Software GmbH - which provides behaviour rather than signature based protection that ""recognizes new and unknown Trojans |
| X | Mascro soft SDK updates2 | SDKrepair2.exe | "Added by the SDBOT.BXM WORM!"
|
| N | Mass storage check registry | "rundll32.exe MSDServ.dll | check registry" |
| X | Master Card Updaate 32 | Mastercard32.exe | "Added by a variant of the RBOT WORM!"
|
| U | Master Volume Spy | MASTERVOLUMESPY.EXE | "Volume control for the Gateway Destination ""DestiVu"" media interface"
|
| X | MasterBoot Switch | popupkill.exe | "Added by a variant of the RBOT WORM!"
|
| U | Matador | mlfbuddy.exe | "MailFrontier - anti-spam application"
|
| N | Matrox QuickDesk | mgaqdesk.exe | For Matrox video cards. Quick access to tweak your card to your liking
|
| X | MAV_check | mav_startupmon.exe | "Part of the WinAntiVirus Pro 2007 rogue security software - not recommended |
| X | mav_startupmon | mav_startupmon.exe | "Part of the WinAntiVirus Pro 2007 rogue security software - not recommended |
| U | MaxBackSchedule | maxbackservice.exe | Backup scheduler for the Maxtor (now Seagate) range of external hard drives - part of Maxtor Quick Start
|
| Y | MaxtorCombo | ComboButton.exe | Required to be able to use the Maxtor OneTouch button on your external Maxtor harddrive. It is used to start up backup software (Retrospect)
|
| U | MaxtorOneTouch | OneTouch.exe | "Maxtor OneTouch Hard Drives/OneTouch Family hard disk backup software"
|
| U | MaxtorReg | AUTOREG.EXE | Part of SYSagent - small utility for retrieving all the hardware and software information required by anyone administering a machine and/or the network it's a part of
|
| Y | mbamgui | mbamgui.exe | "System tray access to and realtime protection agent for the registered version of MalwareBytes' Anti-Malware - which is ""considered to be the next step in the detection and removal of malware. In our product we have compiled a number of new technologies that are designed to quickly detect |
| U | MBMon | "Rundll32 CTMBHA.DLL | MBMon" |
| X | mbssm32 | monstu.exe | "Detected by AVG as the AGENT.CNM TROJAN - see here"
|
| X | McAfee Antivirus | McAfeeAV.exe | "Added by a variant of the RBOT WORM!"
|
| X | McAfee Antivirus 32 | MCAFEEAV32.EXE | "Added by the SPYBOT-EH WORM!"
|
| X | Mcafee Antivirus Monitoring System326 | VSStatmn326.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Mcafee Antivirus Monitoring System32mn | VSStatmn32.exe | "Added by a variant of the RBOT WORM!"
|
| X | McAfee Antivirus Protection | mcafeeAV.exe | "Added by a variant of the RBOT WORM!"
|
| X | Mcafee Auto Protect | mcafeshield.exe | "Added by the RBOT-UH WORM!"
|
| U | McAfee Backup | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Backup and Restore | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Data Backup | LogOnHook.exe | "Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
|
| U | McAfee Data Backup | McAfeeDataBackup.exe | "McAfee Data Backup (now Online Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Guardian | CMGrdian.exe | "McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security |
| U | McAfee Online Backup | MOBKstat.exe | "System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Online Backup Status | MOBKstat.exe | "System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| X | McAfee Online virus Scanner | avp.exe | "Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
|
| X | McAfee Online Virus Scanner | nzm.exe | "Added by the IRCBOT.XV WORM!"
|
| U | McAfee QuickClean Imonitor | Plguni.exe | "Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection |
| Y | McAfee SecurityCenter | mcagent.exe | "McAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection |
| Y | McAfee SecurityCenter | McUpdate.exe | Automatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
|
| Y | McAfee VirusScan | mcmnhdlr.exe | "Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically |
| Y | McAfee VirusScan | mcvsshld.exe | "ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed |
| Y | McAfee VirusScan | oasclnt.exe | "On-access real-time scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files for malware as you access |
| X | Mcafee VirusScan Manager | mvcsvm.exe | "Added by the SILLYFDC.BBV TROJAN!"
|
| N | McAfee Winguage | ?? | "Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications |
| U | McAfee.InstantUpdate.Monitor | RuLaunch.exe | "Instant Updater for McAfee's VirusScan |
| U | McAfeeDataBackup | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| X | MCAFEEIPS | setup.exe | "Added by the WHITEWELL TROJAN!"
|
| X | McAfeeScanPlus | McAfeeScanPlus.exe | "Added by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder"
|
| Y | McAfeeUpdaterUI | UpdaterUI.exe | McAfee common updater user interface
|
| Y | McAfeeUpdaterUI | UdaterUI.exe | Updater user interface for McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
|
| Y | McAfeeVirusScanService | Avsynmgr.exe | "From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe) |
| X | Mcaffe Antivirus | Mcafeescn.exe | "Added by a variant of the SPYBOT WORM!"
|
| N | McENUI | McENUI.exe | "McAfee's EasyNetwork user interface - ""enables secure file sharing |
| U | MCI USB Icon | USBIcon.exe | MCI USB software used for managing a USB card reader
|
| N | MCPLaunch | MCPLaunch.exe | "Launcher for Message Center Plus ""which alerts you when conditions arise on your computer that require your attention"" on IBM/Lenovo ThinkCentre desktops |
| X | Mcrosoftr Update | Mcrosoftr.exe | "Added by a variant of the RBOT WORM!"
|
| Y | mcui_exe | mcagent.exe | "McAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection |
| Y | McUpdate | McUpdate.exe | Automatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
|
| Y | MCUpdateExe | McUpdate.exe | Automatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
|
| X | MCX Update | wisp.exe | "Added by the RBOT-AQH WORM!"
|
| X | MCX Updte | scorti.exe | "Added by the RBOT-ARP WORM!"
|
| X | MD IE Plugin | md.exe | "Marketdart spyware"
|
| X | MD IE Plugin | winy.exe | Adware
|
| N | mdac_runonce | runonce.exe | Associated with MS Data Access Components (MDAC). Sometimes left over after installation - not required. NOTE :- don't delete "runonce.exe".
|
| U | Media Codec Update Service | update.exe | "Windows Essentials Codec Pack 1.0 is a collection of the most commonly needed video and audio codecs. This program allows keeps these codecs updated"
|
| U | Media Manager Indexer | AIRSVCU.EXE | "Part of MS Visual InterDev |
| X | Media Player Update | xpsp1mfh.exe | "Added by a variant of the RBOT WORM!"
|
| X | Media Plug x.1.2 | msdm.exe | Added by the MULDROP.352 VIRUS!
|
| X | Media Software UPdater | sscs.exe | "Added by the RBOT-ABE WORM!"
|
| U | MediaButtons | MediaButtons.exe | "Supports the eject button on the front on the Dell Studio Hybrid desktop. If disabled |
| U | Mediafour Mac Volume Notifications | MACVNTFY.EXE | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | Mediafour MacDrive | MacDrive.exe | "MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
|
| U | Mediafour MacDrive | MDDiskProtect.exe | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | Mediafour MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | "Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod"
|
| U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | "Xplay 2 from Mediafour Corporation - ""expands what you can do with any iPod |
| U | MediafourGettingStartedWithMacDrive6 | MacDrive.exe | "MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| X | mediamotor.exe | mmups.exe | "Added by the AGENT-BY TROJAN!"
|
| X | MediaPlayeS | MediaPlayer_update.exe | "Added by the STARTER-K TROJAN!"
|
| X | mediapluscash.exe | mediapluscash.exe | "MediaGateway adware"
|
| X | media_stub | stub.exe | "Mini-Player |
| X | Meeting Connection | comsutil.exe | "Added by the PPDOOR-E TROJAN!"
|
| X | MegaVirusKit | pgs.exe | "MegaVirusKit rogue security software - not recommended. A member of the AVSystemCare family"
|
| X | MemConfig | SetupIE.com | "Added by the TAPLAK WORM!"
|
| X | memory | outlookrem.exe | "Added by the NOPIR.C WORM!"
|
| U | MemoryZipperPlus | memzip.exe | "Memory Zipper Plus - ""optimizes the memory management of your system and boost-up its performance amazingly!"""
|
| U | MemTurbo | memturbo.exe | "MemTurbo memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| X | MenaceSecure | pgs.exe | "MenaceSecure rogue security software - not recommended. A member of the AVSystemCare family"
|
| N | MenuSnap | MenuSnap.exe | "MenuSnap from Rietta Solutions. Utility that re-orders your Start Menu items alphabetically. You may not want this utility if you're able to do this manually by selecting Start -> Programs and right-clicking and choosing "Sort by Name" if availabe"
|
| N | Message Center Plus | MCPLaunch.exe | "Launcher for Message Center Plus ""which alerts you when conditions arise on your computer that require your attention"" on IBM/Lenovo ThinkCentre desktops |
| X | Message Queuing | msmqs.exe | "Added by the FREEFORS TROJAN!"
|
| X | Messanger | s_menu.exe | "Added by the TACTSLAY.C TROJAN!"
|
| X | Messenger | ntsubsys.exe | "Added by the SDBOT.BGE WORM!"
|
| X | Messenger Service Updater | svshost.exe | "Added by the MYTOB.GC WORM!"
|
| X | Messenger start-up | Msgran.exe | "Added by the GRAMOS WORM!"
|
| N | MessengerPlus | MsgPlus.exe | "MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
|
| N | MessengerPlus2 | MsgPlus.exe | "MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
|
| N | MessengerPlus3 | MsgPlus.exe | "MessengerPlus - third party MSN Messenger extension that adds a number of useful features. Bundles the hard to remove C2Media LOP adware. The software does offer you a choice during setup - make sure to install MessengerPlus WITHOUT that ""sponsor program""!"
|
| X | MeTaLRoCk (irc.musirc.com) has sex with printers | metalrock-is-gay.exe | "Added by the RANDEX.Q WORM!"
|
| X | MeuPrograma | accwizz.exe | "Added by the RULAND.A WORM!"
|
| X | mfhsornwnduy | regsvr32.exe gisyflngpshcvuakv.dll | "Pro AntiSpyware 2009 rogue spyware remover - not recommended |
| N | MGA Quickdesk | MGAQDESK.EXE | For Matrox video cards. Quick access to tweak your card to your liking
|
| N | MGA_CD_Install | mgasetup.exe | Matrox Millennium video driver. Not required once drivers installed
|
| X | Mickey Mouse Cereal | [random filename].exe | "Added by the RANKY.Q TROJAN!"
|
| X | Micosoft Data Core | runservice.exe | "Added by the IRCBOT.BK WORM!"
|
| X | Micosoft Data Core stuff | svshosts.exe | "Added by the RBOT.FZA WORM!"
|
| X | Micosoft Startup | syscall.exe | "Added by the SDBOT-JI WORM!"
|
| X | Micosoft Startup | systall.exe | "Added by the SDBOT-GM BACKDOOR!"
|
| X | Micr Update | soundblaster.exe | "Added by the SDBOT.NP WORM!"
|
| X | Micr Update System | upwin.exe | "Added by the SDBOT.YS WORM!"
|
| X | Micr0s0ft Upd4t4z | svchost32.exe | "Added by the RBOT.ALF WORM!"
|
| X | Micrcoft Updat | spoolsae.exe | "Added by the RBOT-AIB WORM!"
|
| X | Micrcoft Updat | spoolsaex.exe | "Added by the RBOT-AJM WORM!"
|
| X | Micrcoft Updat | Internet.exe | "Added by the RBOT-ANA WORM!"
|
| X | Micro Update | dailin.exe | "Added by the RBOT-ER WORM!"
|
| N | Microangelo Desktop | Muamgr.exe | "Using MicroAngelo On Display |
| N | microAttuneDownload | atmdlusr.exe | "Application Launcher |
| X | Microfot Update | winldx32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microft Update 32 | winssx.exe | "Added by the RBOT-AQS WORM!"
|
| X | Micromedia Flash Update | wdfmrg.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Micromedia Flash Update | xptxt.exe | "Added by the RBOT-GAB WORM!"
|
| X | Microoft Timing | pupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | MICROSFT ANTIVIRUS UPDATE SUPPORT | [random 10-letter filename].EXE | "Added by the RBOT-AQA WORM!"
|
| X | MICROSFT ANTIVIRUS UPDATE SUPPORT | MSGUPDATED.EXE | "Added by the RBOT-APZ WORM!"
|
| X | Microsft Confige 32 | msaconfigurez.exe | "Added by the RBOT.CLC WORM!"
|
| X | MICROSFT MX UPDATE SUPPORT | taskmngrs.exe | "Added by the RBOT-AUZ WORM!"
|
| X | MICROSFT MX UPDATE SUPPORT | winmx32.EXE | "Added by the IRCBOT-FD WORM!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | [random filename] | "Added by the RBOT-ASM or RBOT-AUW WORMS!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | MSN32.EXE | "Added by the RBOT-AWJ WORM!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | mtakthmyn.EXE | "Added by the RBOT-AUJ WORM!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | MSGUPDAT32.EXE | "Added by the RBOT-BBB WORM!"
|
| X | Microsft Remote Procedure Daemon | msrpcd.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsft Security Monitor Process | cmh.exe | "Added by the EGGDROP.V WORM!"
|
| X | Microsft Security Monitor Process | mssmppp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsft Security Monitor Process | mssmpp.exe | "Added by the SDBOT-DJW WORM!"
|
| X | Microsft Updtes | sarvice.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsft Upgraed | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | microsft windows updates | mwupdate32.exe | "Added by a variant of the TOXBOT/CODBOT WORM!"
|
| X | Microsof Value | nmatt.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft | wuauclt.exe | "Added by the QQROB-AAQ TROJAN! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft | guard.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft | MSUPDATE.exe | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft | updater.exe | "Added by the RBOT-GHP WORM!"
|
| X | Microsoft | rundll.exe | "Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
|
| X | Microsoft | WinSecUp.exe | "Added by the RBOT-GPL WORM!"
|
| X | Microsoft | soundvol32.exe | "Added by the RBOT.CIJ BACKDOOR!"
|
| X | Microsoft (R) Windows Configuration Backup Service | svchost.exe | "Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config"" |
| X | Microsoft (R) Windows DLL Loader | rundll32.exe | "Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process |
| X | Microsoft (R) Windows Network Security Management Service | nsms.exe | "Added by the RANKY.LC TROJAN!"
|
| X | Microsoft (R) Windows Update Service | wuauclt.exe | "Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft (R) Windows Vista/NT Runtime Compatibility Service | nrcs.exe | "Added by the RANKY.X TROJAN!"
|
| X | Microsoft .NET Confingurator | msnconf.exe | "Added by an unidentified VIRUS |
| X | Microsoft 16Bit Update | wuapdate16.exe | "Added by the RBOT.CZ WORM!"
|
| X | Microsoft 64 Bit Runtime Updater | wupdt64.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft ActiveX Debugger NT | [path to trojan] | "Added by the BANCOS-DO TROJAN!"
|
| N | Microsoft Announcement Listener | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
|
| X | Microsoft Ansti Update | msie.exe | "Added by the RBOT-LE WORM!"
|
| X | Microsoft Anti Virus Controller | msavc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Anti Virus Controller | msavc32.exe | "Added by the SDBOT.EPW BACKDOOR!"
|
| X | Microsoft AUT Update | MSlti32.exe | "Added by the RBOT-X WORM!"
|
| X | Microsoft AUT Update | MSlti16.exe | "Added by the RBOT.EB WORM!"
|
| X | Microsoft Authority Service | lsass.exe | "Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process |
| X | Microsoft auto update | winupdate.exe | "Added by the BMBOT TROJAN!"
|
| X | Microsoft Auto Update | WINHLP16.EXE | "Added by the RBOT.GY WORM!"
|
| X | Microsoft auto update | wuauclt.exe | "Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft Automatic Update Serivce | msautou.exe | "Added by the RBOT-AOB WORM!"
|
| X | Microsoft Automatic Updater | Explorer.exe | "Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft AutoUpdater | svhost.exe | "Added by the RBOT.QG WORM!"
|
| X | Microsoft Bool Value | MV2.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Buffer App | msbuffer.exe | "Added by the SLINBOT.NQ BACKDOOR!"
|
| X | Microsoft Calculator | calc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Client/Server Runtime Server Subsystem | csrs.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Client/Server Runtime Server Subsystem | csrssa.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft ConfgKeys | wurmgrd32.exe | "Added by the RBOT-ARX WORM!"
|
| X | Microsoft Config Loader | msrun32.exe | "Added by the AGOBOT-DY WORM!"
|
| X | Microsoft Configuewe | msconfiguwe.exe | "Added by the SDBOT-BPK WORM!"
|
| X | Microsoft Configuration | msconfig32.exe | "Added by the SDBOT.MQ WORM!"
|
| X | Microsoft Configuration 35 | microsot1.exe | "Added by an unidentified TROJAN!"
|
| X | Microsoft Configuration Wizard | taskmrg.exe | "Added by the SDBOT-MX TROJAN!"
|
| X | Microsoft Configure 32 | msgconfigre.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Core Support | MSxUP32.exe | "Added by the RBOT-ANR WORM!"
|
| X | Microsoft Core Support | [random filename] | "Added by a variant of the RBOT TROJAN!"
|
| X | Microsoft Corp TLS Certificates | msauth.exe | "Added by the RBOT-GAC WORM!"
|
| X | Microsoft Corp Updates | wupdates.exe | "Added by the RBOT-AUU WORM!"
|
| X | Microsoft CPU Over Heat Manager | CPU.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DDE Control | wupades.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft DDEs Control | Erun.pif | "Added by the RBOT-AMU WORM!"
|
| X | Microsoft Debug Manager Console | mdm32.exe | "Added by the AGOBOT-AQ WORM!"
|
| X | Microsoft Debug Service | dbgbgr.exe | "Added by a variant of the RBOT WORM!"
|
| U | Microsoft Default Manager | DefMgr.exe | "Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
|
| X | Microsoft Development Debugger | msdev.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft DirectX | wuamgrd.exe | "Added by the SDBOT.MY WORM!"
|
| X | Microsoft DirectX | wupdate.exe | "Added by the RBOT-L WORM!"
|
| X | Microsoft Directx push | directxpushup.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft DLL | fumeta.exe | "Added by the RBOT-AUG WORM!"
|
| X | Microsoft Dll | runapidll.exe | "Added by the RBOT-GRG WORM!"
|
| X | Microsoft DLL Authentification | dllsecure.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Source | dllsrc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Verifier | winavguard.exe | Added by the SDBOT.AAD WORM!
|
| X | Microsoft DNS Host Resolution | hostres.exe | "Added by the AGOBOT-MK BACKDOOR!"
|
| X | Microsoft DNS Query | msdns.exe | "Added by the AGENT-BS TROJAN!"
|
| X | Microsoft Document | krisp.exe | "Added by the SDBOT-RQ WORM!"
|
| X | Microsoft Driver Setup | msddrv42.exe | "Added by the PALEVO WORM!"
|
| X | Microsoft Driver Setup | Jwrb.exe | "Added by the AUTORUN-AOB WORM!"
|
| X | Microsoft Driver Setup | dllhost.exe | "Added by the AUTORUN-AOZ WORM!"
|
| X | Microsoft Driver Setup | sysmngsr322.exe | "Added by the BUZUS-AS TROJAN!"
|
| X | Microsoft Driver Setup | w7services.exe | "Added by the AUTORUN-ARJ WORM!"
|
| X | Microsoft Driver Setup | mslsrv32.exe | "Added by the SDBOT-DPF TROJAN!"
|
| X | Microsoft Driver Setup | ccdrive32.exe | "Added by the AGENT-LYL TROJAN!"
|
| X | Microsoft Driver Setup | cidrive32.exe | "Added by the AGENT-NES TROJAN!"
|
| X | Microsoft driver update | Mshome.exe | Added by the SDBOT.BL WORM!
|
| X | Microsoft Excell | wuamngr32.exe | "Added by the RBOT-QH WORM!"
|
| X | Microsoft Executing | microsoft.exe | "Added by the AGOBOT.UV WORM!"
|
| X | Microsoft explorer Update | internal.exe | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft Features | ms32cfg.exe | "Added by the RBOT.HO WORM!"
|
| X | Microsoft Features | msie.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft FixUp | pevblbvr.exe | "Added by the RBOT.DWK WORM!"
|
| X | Microsoft FixUp | wnpzjpuw.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Generic Update Manager | wupdate.exe | "Added by the RBOT-AWC TROJAN!"
|
| X | Microsoft Genuine Logon | msnmsg.exe | "Added by the IRCBOT-XH WORM!"
|
| X | Microsoft Genuine Logon | svchost.exe | "Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Help Support | mshelp32.exe | "Addded by the KELVIR-BF WORM!"
|
| X | Microsoft IE Execute shell | IEExec.exe | "Added by the ALADINZ.N TROJAN!"
|
| X | Microsoft Information | securenet.exe | "Added by the SDBOT.AJM WORM!"
|
| X | Microsoft Install Shield Services | rundll64 | "Added by the RBOT-FSH WORM!"
|
| X | Microsoft Installshield | nundll32.exe | "Added by the AGOBOT-AHZ WORM!"
|
| X | Microsoft Internal AntiVirus Systems | dIlhost.exe | "Added by the RBOT-AEV WORM!"
|
| X | Microsoft Internet Acceleration Utility | iau.exe | "EasySearch adware"
|
| X | Microsoft Internet Acceleration Utility | [path to file] | "Added by the AGENT-CX TROJAN!"
|
| X | Microsoft Internet Acceleration Utility | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Microsoft Internet Antivirus Protection | antivirus.exe | "Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
|
| X | Microsoft Internet Dumping Protocol | inetdump.exe | "Added by the IRCBOT.BLL BACKDOOR!"
|
| X | Microsoft Internet Explorer Update | ieupdate.exe | "Added by the SHEUR.MH TROJAN!"
|
| X | Microsoft Internet Firewall Update | updater.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Intrenet Explorer | Soundsyst.exe | "Added by the RBOT-AQU WORM!"
|
| X | Microsoft Intrenet Explorer | wcumrg.exe | "Added by the SDBOT-AFD WORM!"
|
| X | Microsoft IT Update | win64.exe | "Added by the RBOT.GA WORM!"
|
| X | Microsoft IT Update | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft IT Update | IEserv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft IT Update | msupdate.exe | "Added by the RBOT-FE WORM!"
|
| X | Microsoft IT Update | winn43.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft IT Update | svchsst.exe | "Added by the RBOT-DH WORM!"
|
| X | Microsoft IT Update | win43.exe | "Added by the RBOT-SA WORM!"
|
| X | Microsoft IT Update | windows.exe | "Added by the RBOT-JM WORM!"
|
| X | Microsoft IT Update | winsyst32.exe | "Added by the RBOT-FC WORM!"
|
| X | Microsoft IT Update | Rhost32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Java Virtual Machine | MsConfiG.exe | "Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
|
| X | Microsoft Java Virtual Machine | msjvm.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Java Virtual Machine | javavm.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Java Virtual Machine | msjavarxp.exe | "Added by the FORBOT-DL WORM!"
|
| X | Microsoft Java Virtual Machine | winscr32.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Microsoft Java Windows Update | [filename] | "Added by the RBOT-DZ WORM!"
|
| X | Microsoft JavaVM | msjarun.exe | "Added by the RBOT-JW WORM!"
|
| X | Microsoft Logon User Interface | logonnui.exe | "Added by the RBOT-BCC WORM!"
|
| X | Microsoft Machine | updata.exe | "Added by the RBOT-DJ WORM!"
|
| X | Microsoft MachineUpdatese | tempes.exe | "Added by the RBOT.EWN BACKDOOR!"
|
| X | Microsoft Macro Protection SubSsy | msacroprots386.exe | "Added by the RBOT-KE WORM!"
|
| X | Microsoft Macro Protection Subsystems | msmacroprotxz.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Macro Protection Subsystems | Msmacroprot32.exe | "Added by the RBOT.KN WORM!"
|
| X | Microsoft Memory Dumping Protocol | memdump.exe | "Added by the IRCBOT.BJK BACKDOOR!"
|
| X | Microsoft MSGPLUS32 Protocol | msgplus32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft msnseru | msnseru.exe | "Added by the RBOT-APB WORM!"
|
| X | Microsoft MSUPDATE | SpoolSvc.exe | "Added by the SXTB-A TROJAN!"
|
| X | Microsoft Network Neighbourhood | networknbh.exe | "Added by the RBOT.DMN WORM!"
|
| X | Microsoft Norotn Anti Virus | mnhpot.exe | "Added by the RBOT-GRO WORM!"
|
| X | Microsoft Norton Antivirus | norton.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft NT Update | winexec32.exe | "Added by a variant of the RBOT WORM!"
|
| N | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | "System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes |
| X | Microsoft Office quick launch | OSA.exe | "Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
|
| X | Microsoft Office Quick Launcher | iau1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| N | Microsoft Office Shortcut Bar | Msoffice.exe | Feature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
|
| X | Microsoft Office Start | winupdates.exe | "Added by the GAOBOT.BC WORM!"
|
| N | Microsoft Office Startup | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| N | Microsoft Office Startup | Osa9.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft Office Studio | scvhvst.exe | "Added by the RANDEX.CST WORM!"
|
| X | Microsoft Outlook Express Protocol | svchst.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Patch Update | bootini.exe | "Added by the RBOT-FMN WORM!"
|
| X | Microsoft Procedure Call | MSPCALL.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft quick launch | OSA.exe | "Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
|
| X | MicroSoft Remote Secure Service | MSRSS.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Router Manager | linksys.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Router Manager | router.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Rundll | windos.exe | "Added by the SDBOT-WF WORM!"
|
| X | Microsoft Runtime | CfgDll32.exe | "Added by the RANDEX.BD WORM!"
|
| X | Microsoft Secure | Messenger.NET Service | "Added by the FORBOT-AM WORM!"
|
| X | Microsoft Secure Messenger.NET Service | securitychk.exe | "Added by the SDBOT.VT WORM!"
|
| X | Microsoft Security | winService.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft security adviser | mssadv.exe | "Microsoft Security Adviser rogue security software - not recommended"
|
| X | Microsoft Security Center | savservices.exe | "Added by the RBOT-ANU WORM!"
|
| X | Microsoft Security Center | wcsntfy.exe | "Added by the SDBOT.BYD WORM!"
|
| X | Microsoft Security Controlers | fxsecues.exe | "Added by a variant of the SDBOT WORM!"
|
| Y | Microsoft Security Essentials | msseces.exe | "System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses |
| X | Microsoft Security GManagers | [random filename] | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Security Hot Fix Update | mshotfix.exe | "Affilred adware"
|
| X | Microsoft Security Management | winnt.exe | "Added by the RBOT-MQ WORM!"
|
| X | Microsoft Security Management | winserv.exe | "Added by the RBOT-MJ WORM!"
|
| X | Microsoft Security Management | winamp.exe | "Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Microsoft Security Management | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Security Management | bling.exe | "Added by the RBOT.XL WORM!"
|
| X | Microsoft Security Management | sp2fix.exe | "Added by the RBOT.UB WORM!"
|
| X | Microsoft Security Manager | winamp.exe | "Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
|
| X | Microsoft Security Monitor Process | mssmp.exe | "Added by the RBOT-FUB WORM!"
|
| X | Microsoft Security Monitor Process | mnsmp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | msmp.exe | "Added by the RBOT.GKQ WORM!"
|
| X | Microsoft Security Monitor Process | mssm32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Security Monitor Process | lsas.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | msword.exe | "Added by the VIRUT.P VIRUS!"
|
| X | Microsoft Security Monitor Process | service.exe | "Added by the DELF.BERW BACKDOOR!"
|
| X | Microsoft Security Monitor Process | svcchost.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | windowsupdate.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | [random filename] | "Added by variants of the RBOT WORM! See here"
|
| X | Microsoft Security Monitor Process | com.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | exel.exe | "Added by the SDBOT.AFX BACKDOOR!"
|
| X | Microsoft Security Monitor Process | firewall.exe | "Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
|
| X | Microsoft Security Monitor Process | flash.exe | "Added by the EGGDROP.EE BACKDOOR!"
|
| X | Microsoft Security Monitor Process | hel.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Microsoft Security Monitor Process | HelpMe.exe | "Added by the VB.BJO TROJAN!"
|
| X | Microsoft Security Monitor Process | kar.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | lindicracker.exe | "Added by the BIFROSE.GR BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mail.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mmp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mssm32.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mssmpi32.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Security Monitor Process | nitty.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Microsoft Security Monitor Process | ofice.exe | "Added by the VIRUT.N VIRUS!"
|
| X | Microsoft Security Monitor Process | point.exe | "Added by the IRCBOT.AVP BACKDOOR!"
|
| X | Microsoft Security Monitor Process | princ.exe | "Added by the HUPIGON.WTL TROJAN!"
|
| X | Microsoft Security Monitor Process | web.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Microsoft Security Monitor Process | winsys32.exe | "Added by the VIRUT.N VIRUS!"
|
| X | Microsoft Security Monitor Process | winsyss32.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Microsoft Security Monitor Process | word.exe | "Added by the EGGDROP.DC BACKDOOR!"
|
| X | Microsoft Security Panager | [filename] | "Added by the RBOT-ANL WORM!"
|
| X | Microsoft Security Panagers | [random filename] | "Added by the RBOT-AIG WORM!"
|
| X | Microsoft Security Panagers | zzoboony.exe | "Added by the RBOT-AOI WORM!"
|
| X | Microsoft Security Pansasagers | dgkztsqgn.exe | "Added by the RBOT-BBJ WORM!"
|
| X | Microsoft Security Process | wininit.exe | "Added by the RBOT-FKM WORM!"
|
| X | Microsoft Security System | mssecsys.exe | "Added by the IRCBOT-WJ TROJAN!"
|
| X | Microsoft Security Update | security32.exe | "Added by the DELF-JJ TROJAN!"
|
| X | Microsoft Server Applacations | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Server Application | Sound.exe | "Added by the RBOT-NE WORM!"
|
| X | Microsoft Service | rundll.exe | "Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
|
| X | Microsoft Service Execution Manager | execute.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Microsoft Services | module.exe | "Added by the LAVITS WORM!"
|
| X | Microsoft Services Unitd | MSU32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Session Manager Subsystem | smss.exe | "Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
|
| X | Microsoft Setup Initializazion | localhost.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Sinsup | odjiwjf.exe | "Added by the RBOT-DN WORM!"
|
| X | Microsoft Software Update | nmon.exe | "Added by the RBOT.HZ WORM!"
|
| X | Microsoft Sound Driver | sound32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Sound Technology | winsound.exe | "Added by the RBOT-AGG WORM!"
|
| N | Microsoft Sound Volume Tool | mssvol.exe | This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
|
| X | Microsoft Sounds | soundman.exe | "Added by the RBOT-GCI WORM!"
|
| X | Microsoft SpA Service | Winupd32.exe | "Added by the RBOT.LT WORM!"
|
| X | Microsoft Standard Executions Library | win32lib.exe | "Added by the RBOT-AUK WORM!"
|
| X | Microsoft startup | wmpIayer.exe | Added by the IRCBOT.ACI TROJAN!
|
| X | Microsoft Startup Manager | sysservice.exe | "Added by the AVALANEC TROJAN!"
|
| X | Microsoft Stuff you know | winslogin.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Sum32 | sum32.exe | "Added by the RBOT-YW WORM!"
|
| X | Microsoft Support | sys32ms.exe | "Added by the RBOT-AHI WORM!"
|
| X | microsoft support | svchostt.exe | "Added by the AGOBOT.AWN WORM!"
|
| X | Microsoft Synchronization Manager | winupdate.exe | "Added by the SDBOT.ER WORM!"
|
| X | Microsoft Synchronization Manager | mircup.exe | "Added by the SDBOT.BQD WORM!"
|
| X | Microsoft System | msupdtm.exe | "Added by the SPYBOT.PKC WORM!"
|
| X | Microsoft System Backup | [random filename] | "Added by the RBOT-AGM WORM!"
|
| X | Microsoft System Checkup | Cool.exe | "Added by the DONK.B WORM!"
|
| X | Microsoft System Checkup | Wnetlib.exe | "Added by the DONK.C WORM!"
|
| X | Microsoft System Checkup | dbnetlib.exe | "Added by the DONK.L WORM!"
|
| X | Microsoft System Checkup | Keymgr.exe | "Added by the DONK.M WORM!"
|
| X | Microsoft System Checkup | inetman.exe | "Added by the DONK.O WORM!"
|
| X | Microsoft System Checkup | ntsysmgr.exe | "Added by the DONK.S WORM!"
|
| X | Microsoft System Checkup | ntsysman.exe | "Added by the SDBOT-QW WORM!"
|
| X | Microsoft System Checkup | libsysmgr.exe | "Added by the SDBOT-CAF WORM!"
|
| X | Microsoft System Checkup | sysmgr.exe | "Added by the SDBOT-OO TROJAN!"
|
| X | Microsoft System Checkup | netapi32.exe | "Added by the DONK-E WORM!"
|
| X | Microsoft System Checkup | wnetmgr.exe | "Added by the DONK.Q WORM!"
|
| X | Microsoft System Checkup | libsys32.exe | "Added by the SDBOT-ACK WORM!"
|
| X | Microsoft System Checkup | netlogin32.exe | "Added by the SDBOT-GN BACKDOOR!"
|
| N | Microsoft System Configuration Utility | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
|
| X | Microsoft System Debug | services32.exe | "Added by the RBOT.AKH WORM!"
|
| X | Microsoft System DLL Services Configuration | windir32.exe | "Added by the SDBOT-ACY TROJAN!"
|
| X | Microsoft System Restore Configuration | CBRSS.EXE | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft System Security Agent | MSTSA.EXE | "Added by the RBOT.CCM WORM!"
|
| X | Microsoft System Update | sysupdate.exe | "Added by the SDBOT.DG WORM!"
|
| X | Microsoft system Value | sys57.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft System32 Update | cmsrg.exe | "Added by the RBOT-GN WORM!"
|
| X | Microsoft Taskmanager Updater | keyboard.exe | "Added by the RBOT-ALU WORM!"
|
| X | Microsoft Telecoms Center | winupn.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft U | wuamkopxp.exe | "Added by the RBOT-AHC WORM!"
|
| X | Microsoft UMA Update | MSuma32.exe | "Added by the RBOT.FS WORM!"
|
| X | MICROSOFT UNPACCKER SYSTEM | unpak32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MICROSOFT UNPACK SYSTEM | winrarx.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updat3 | mswkst32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | Microsoft.exe | "Added by the GAOBOT.AFJ WORM!"
|
| X | Microsoft Update | mssmgrd.exe | "Added by the SDBOT.JT WORM!"
|
| X | Microsoft Update | mvsc.exe | "Added by the SPYBOT.DAZ WORM!"
|
| X | Microsoft Update | ascdl.exe | "Added by the GAOBOT.SY WORM!"
|
| X | Microsoft Update | Isac.exe | "Added by the RBOT-AU WORM!"
|
| X | Microsoft Update | automgr32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | mediap.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | Microsoftx.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | msconfg.exe | "Added by the RBOT.H WORM!"
|
| X | Microsoft Update | Mslti32.exe | "Added by the RBOT-LX WORM!"
|
| X | Microsoft Update | muamgrd.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Update | navmgrd.exe | "Added by the SDBOT.DP TROJAN!"
|
| X | Microsoft Update | Smss32.exe | "Added by the RBOT-CB WORM!"
|
| X | Microsoft Update | sys32cfg.exe | "Added by the RBOT.DR WORM!"
|
| X | Microsoft Update | VPC32.EXE | "Added by the AGOBOT.XM WORM!"
|
| X | Microsoft Update | winsys32.exe | "Added by the RBOT.BD WORM!"
|
| X | Microsoft Update | wuamgrd.exe | "Added by the RBOT-LK WORM!"
|
| X | Microsoft Update | wuammgr32.exe | "Added by the RBOT-AW WORM!"
|
| X | Microsoft Update | wudmate.exe | "Added by the RBOT.AP WORM!"
|
| X | Microsoft Update | msawindows.exe | "Added by the GAOBOT.AFJ WORM!"
|
| X | Microsoft Update | msiwin84.exe | "Added by the GAOBOT.AFJ WORM!"
|
| X | Microsoft Update | wuamgrd32.exe | "Added by the RBOT.ZB WORM!"
|
| X | Microsoft Update | NAV.exe | "Added by the RBOT-IV WORM!"
|
| X | Microsoft Update | systemi32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Update | xpupdate.exe | "Added by the RBOT-QE WORM!"
|
| X | Microsoft Update | webm.exe | "Added by the SDBOT.WK WORM!"
|
| X | Microsoft Update | wuagrd.exe | "Added by the RBOT-FK WORM!"
|
| X | Microsoft Update | aaupdt.exe | "Added by the RBOT-RQ WORM!"
|
| X | Microsoft Update | lsac.exe | "Added by the GAOBOT.XW WORM!"
|
| X | Microsoft Update | Mupdate.exe | "Added by the RBOT-AG WORM!"
|
| X | Microsoft Update | prowind32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Update | snlogsvc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | svhost.exe | "Added by the RBOT-PI WORM!"
|
| X | Microsoft Update | wauguard.exe | "Added by the RBOT.AEE WORM!"
|
| X | Microsoft Update | winscv.exe | "Added by the RBOT-BH WORM!"
|
| X | Microsoft Update | winsys.exe | "Added by the RBOT-GV WORM!"
|
| X | Microsoft Update | wserv32.exe | "Added by the RBOT.AF WORM!"
|
| X | Microsoft Update | wtm32.exe | "Added by the RBOT-AQ WORM!"
|
| X | Microsoft Update | wumgrd.exe | "Added by the SDBOT-KY WORM!"
|
| X | Microsoft Update | wuampd.exe | "Added by the RBOT-UT WORM!"
|
| X | Microsoft Update | msupdate32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Update | Botnet.exe | "Added by the RBOT.AFL WORM!"
|
| X | Microsoft Update | sghost.exe | "Added by the SDBOT.AKV WORM!"
|
| X | Microsoft Update | update_w.exe | "Added by the RBOT-EW WORM!"
|
| X | Microsoft Update | windows24.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | wingrd32.exe | "Added by the RBOT-DW WORM!"
|
| X | Microsoft Update | wssvr.exe | "Added by the RBOT-OD WORM!"
|
| X | Microsoft Update | wuamagr32.exe | "Added by the SPYBOT.CG WORM!"
|
| X | Microsoft Update | WinUpdate32.exe | "Added by the RBOT-TI WORM!"
|
| X | Microsoft Update | wkfix.exe | "Added by the RBOT-ABZ WORM!"
|
| X | Microsoft Update | Kkk.exe | "Added by the RBOT-AHL WORM!"
|
| X | Microsoft Update | mcupdate.exe | "Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
|
| X | Microsoft Update | Micr0s0ft.exe | "Added by the AGOBOT.AAR WORM!"
|
| X | Microsoft Update | Msnmsngr.exe | "Added by the RBOT.BQS WORM!"
|
| X | Microsoft Update | msupdate32.exe | "Added by the SPYBOT.LZ WORM!"
|
| X | Microsoft Update | scvhost.exe | "Added by the RBOT-AEM WORM!"
|
| X | Microsoft Update | svghost.exe | "Added by the RBOT.BUJ WORM!"
|
| X | Microsoft Update | sys.exe | "Added by the RBOT-AJ WORM!"
|
| X | Microsoft Update | up2dat5.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | winamp.exe | "Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
|
| X | Microsoft Update | win-mang.exe | "Added by the RBOT-AFK WORM!"
|
| X | Microsoft Update | winupdater.exe | "Added by the RBOT.BIN WORM!"
|
| X | Microsoft Update | wuamk0032.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | wuamk032.exe | "Added by the RBOT-AHD WORM!"
|
| X | Microsoft Update | wuamk0p32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | wuamkop.exe | "Added by the RBOT-AFI WORM!"
|
| X | Microsoft Update | wuamkop32.exe | "Added by the RBOT.BGU WORM!"
|
| X | Microsoft Update | wuampkd.exe | "Added by the SDBOT.BBX WORM!"
|
| X | Microsoft Update | svzhost.exe | "Added by the RBOT.OX WORM!"
|
| X | Microsoft Update | win32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | wininit.exe | "Added by the RBOT-AKR WORM!"
|
| X | Microsoft Update | wuamgrd3.exe | "Added by the RBOT-AMC WORM!"
|
| X | Microsoft Update | Wudates.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | ms.exe | "Added by the SDBOT.CC WORM!"
|
| X | Microsoft Update | wuagmsd.exe | "Added by the RBOT-AX WORM!"
|
| X | Microsoft Update | cmss.exe | "Added by the RBOT-ATQ WORM!"
|
| X | Microsoft Update | wuamgrb.exe | "Added by the RBOT-AZE WORM!"
|
| X | Microsoft Update | WINDOC.EXE | "Added by the SDBOT.PF WORM!"
|
| X | Microsoft Update | phqghumea.exe | "Added by the SDBOT.AFO WORM!"
|
| X | Microsoft Update | system32.exe | "Added by the RBOT.IS WORM!"
|
| X | Microsoft Update | bling.exe | "Added by the RBOT-AVK WORM!"
|
| X | Microsoft Update | Sygate.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | update.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | WinDrv32.exe | "Added by the RBOT.EGW WORM!"
|
| X | Microsoft Update | devmks32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft update | winupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | msupdate.exe | "Added by the BOROBOT-I TROJAN!"
|
| X | Microsoft Update | mixer.exe | "Added by the RBOT-AIR WORM!"
|
| X | Microsoft Update | taskmgr32.exe | "Added by the RBOT-CV WORM!"
|
| X | Microsoft Update | drive.exe | "Added by the BIFROSE-PN WORM!"
|
| X | Microsoft Update | wangard.exe | "Added by the RBOT-LH WORM!"
|
| X | MICROSOFT UPDATE | WUAGTRD.EXE | "Added by the RBOT-CJ WORM!"
|
| X | Microsoft Update | spool.exe | "Added by the AGENT-GJC TROJAN!"
|
| X | Microsoft Update | bnmveqfts.exe | "Added by the BANLOAD.KWQ TROJAN!"
|
| X | Microsoft Update | dqbxhupdt | "Added by a variant of the SDBOT WORM! See here"
|
| X | Microsoft Update | enule.exe | "Added by the IRCBOT.DU BACKDOOR!"
|
| X | Microsoft Update | explorer.exe | "Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft Update | imchemaoa.exe | "Added by the BANLOAD.KWQ TROJAN!"
|
| X | Microsoft Update | livemessenger.com | "Added by the ADLOAD-LN TROJAN!"
|
| X | Microsoft Update | msnmsgl.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Update | nnwyaupdt | "Added by the RBOT.RHK BACKDOOR!"
|
| X | Microsoft Update | ntservice.exe | "Added by the AGENT-DIS TROJAN!"
|
| X | Microsoft Update | rundll32.dll | "Added by the CIADOOR.GN BACKDOOR!"
|
| X | Microsoft Update | wuamgrdx.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Update | wutr.exe | "Added by the SPYBOT.AAR WORM!"
|
| X | Microsoft Update | SetPoints.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Update | system.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Update | service.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Update | msgn.exe | "Added by the RBOT.RQ BACKDOOR!"
|
| X | Microsoft Update | wuamgrd16.exe | "Added by the RBOT-BQ WORM!"
|
| X | Microsoft Update | windows32.exe | "Added by the RBOT-BHQ WORM!"
|
| X | Microsoft Update | winsyst.exe | "Added by the RBOT-DL WORM!"
|
| X | Microsoft Update 23 | NtKernelSystem.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 23 | spoolvs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 32 | explore32.exe | "Added by the SPYBOT.CYM WORM!"
|
| X | Microsoft Update 32 | MSupdate32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Update 32 | wininit.exe | "Added by the RBOT-ANY WORM!"
|
| X | Microsoft Update 32 | wininit32.exe | "Added by the RBOT-AKJ WORM!"
|
| X | Microsoft Update 32 | [path to file] | "Added by the RBOT-AJJ WORM!"
|
| X | Microsoft Update 32 | mscnfg.exe | "Added by the RBOT-ALM WORM!"
|
| X | Microsoft Update 32 | servic.exe | "Added by the RBOT-AXN WORM!"
|
| X | Microsoft Update 32 | winitXP32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 32 | mssetup32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 32 | wiit.exe | "Added by the RBOT-AMS WORM!"
|
| X | Microsoft Update 32 | explorer.exe | "Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft Update 32 | network.exe | "Added by the RBOT-ARZ WORM!"
|
| X | Microsoft Update 32 | om4r.exe | "Added by the RBOT-AQP WORM!"
|
| X | Microsoft Update 32 | winin.exe | "Added by the RBOT-ARR WORM!"
|
| X | Microsoft Update 32 | wuinit.exe | "Added by the AGOBOT-UE WORM!"
|
| X | Microsoft Update 32 | neta.exe | "Added by the RBOT-AMI WORM!"
|
| X | Microsoft Update 32 | spoolvs.exe | "Added by the RBOT-BBQ WORM!"
|
| X | Microsoft Update 32 | rundll32.exe | "Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe |
| X | Microsoft Update 32 | taskMangr.exe | "Added by the RBOT.AIE BACKDOOR!"
|
| X | Microsoft Update 32 | winssx.exe | "Added by the RBOT-ARW WORM!"
|
| X | Microsoft Update 33 | init.exe | "Added by the RBOT-ATT WORM!"
|
| X | Microsoft Update 64 BIT | wininit32.exe | "Added by the RBOT-AHE WORM!"
|
| X | Microsoft Update 64 BIT | winman32.exe | "Added by the RBOT-AKI WORM!"
|
| X | Microsoft Update 64 BIT | schvost.exe | "Added by the RBOT.CAU WORM!"
|
| X | Microsoft Update 64 BIT | winl32xe.exe | "Added by the RBOT-AQO WORM!"
|
| X | Microsoft Update Clinic | svsipconfig.exe | "Added by the RBOT.BR WORM!"
|
| X | MICROSOFT UPDATE CONFIGURATION | WIN32SNC.EXE | "Added by the RBOT-AI WORM!"
|
| X | Microsoft Update Control | Ms64.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Debugger | wincfg32.exe | "Added by the SPYBOT.ZC WORM!"
|
| X | Microsoft Update Device | flolo.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Update Device Drivers | wuauclt.exe | "Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft Update DLL | rxxhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Drivers | explorers.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update Emulator | kern-mxe.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Emulator | wuaddsff.exe | "Added by the RBOT-GX WORM!"
|
| X | Microsoft Update Event | svnhost.exe | "Added by the AGOBOT-GW BACKDOOR!"
|
| X | Microsoft Update Loader | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Loaders 2005 | winusers.exe | "Added by the RBOT-AIQ WORM!"
|
| X | Microsoft Update Loaders 2006 | winusersystem32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Update Machine | expl0rer.exe | "Added by the SDBOT.OK WORM!"
|
| X | Microsoft Update Machine | rxhost.exe | "Added by the RBOT.FC WORM!"
|
| X | Microsoft Update Machine | servicz.exe | "Added by the RBOT-HU WORM!"
|
| X | Microsoft Update Machine | SP2.exe | "Added by the SPYBOT.FP WORM!"
|
| X | Microsoft Update Machine | winini.exe | "Added by the RBOT-KV WORM!"
|
| X | Microsoft Update Machine | xvshost.exe | "Added by the RBOT.QP WORM!"
|
| X | Microsoft Update Machine | memstat.exe | "Added by the RBOT-OM WORM!"
|
| X | Microsoft Update Machine | ntce.exe | "Added by the RBOT-FA WORM!"
|
| X | Microsoft Update Machine | system03.exe | "Added by the RBOT-NM WORM!"
|
| X | Microsoft Update Machine | wuawx.exe | "Added by the RBOT-CE WORM!"
|
| X | Microsoft Update Machine | zonealarm.exe | "Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
|
| X | Microsoft Update Machine | systemll.exe | "Added by the RBOT-JT WORM!"
|
| X | Microsoft Update Machine | winupdt.exe | "Added by the RBOT-FP WORM!"
|
| X | Microsoft Update Machine | svshost.exe | "Added by the RBOT.AK WORM!"
|
| X | Microsoft Update Machine | wuamgd.exe | "Added by the SDBOT.HQ WORM!"
|
| X | Microsoft Update Machine | wupdt32x.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update Machine | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | linux.exe | "Added by the RBOT-IM WORM!"
|
| X | Microsoft Update Machine | lmrss.exe | "Added by the RBOT-DY WORM!"
|
| X | Microsoft Update Machine | windowsu.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | wininigo.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | winmgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | Winmsixp32.exe | "Added by the RBOT.DN WORM!"
|
| X | Microsoft Update Machine | Winregs32.exe | "Added by the RBOT.DN WORM!"
|
| X | Microsoft Update Machine | winxpini.exe | "Added by the RBOT-OB WORM!"
|
| X | Microsoft Update Machine | wuamgrd.exe | "Added by the RBOT-HE WORM!"
|
| X | Microsoft Update Machine | wuagrd.exe | "Added by the RBOT-GF WORM!"
|
| X | Microsoft Update Machine | LANWAKE.EXE | "Added by the RBOT-QZ WORM!"
|
| X | Microsoft Update Machine | scvhost.exe | "Added by the RBOT-GS WORM!"
|
| X | Microsoft Update Machine | winhost.exe | "Added by the RBOT-GK WORM!"
|
| X | Microsoft Update Machine | winss.exe | "Added by the RBOT.JU WORM!"
|
| X | Microsoft Update Machine | WUAMGRDXS.EXE | "Added by the RBOT-GL WORM!"
|
| X | Microsoft Update Machine | crss32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | lsasse.exe | "Added by the RBOT-DI WORM!"
|
| X | Microsoft Update Machine | qwerty.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | rxxhost.exe | "Added by the RBOT.EP WORM!"
|
| X | Microsoft Update Machine | servicez.exe | "Added by the SPYBOT.BI WORM!"
|
| X | Microsoft Update Machine | spoolserv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | Systemnt.exe | "Added by the RBOT.DA WORM!"
|
| X | Microsoft Update Machine | systemse.exe | "Added by the RBOT-BD WORM!"
|
| X | Microsoft Update Machine | taskmngrs.exe | "Added by the RBOT-CR WORM!"
|
| X | Microsoft Update Machine | windowsup.exe | "Added by the RBOT-FV WORM!"
|
| X | Microsoft Update Machine | wuamgard.exe | "Added by the SPYBOT.CS WORM!"
|
| X | Microsoft Update Machine | wupdate32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | system.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | TMEMSER.EXE | "Added by the RBOT-NQ WORM!"
|
| X | Microsoft Update Machine | winnie.exe | "Added by the RBOT-ACD WORM!"
|
| X | Microsoft Update Machine | winortho.exe | "Added by the RBOT-NW WORM!"
|
| X | Microsoft Update Machine | wins32.exe | "Added by the RBOT.EZ WORM!"
|
| X | Microsoft Update Machine | serviz.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | TASKMAN4.EXE | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | wftestb.exe | "Added by the RBOT-AFZ WORM!"
|
| X | Microsoft Update Machine | Win32.exe | "Added by the SDBOT.UV WORM!"
|
| X | Microsoft Update Machine | windns.exe | "Added by the RBOT.EF WORM!"
|
| X | Microsoft Update Machine | MSOICONS.EXE | "Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
|
| X | Microsoft Update Machine | WINSVC32.EXE | "Added by the RBOT.CU WORM!"
|
| X | Microsoft Update Machine | ntsystem.exe | "Added by the RBOT.GF WORM!"
|
| X | Microsoft Update Machine | winupdte.exe | "Added by the RBOT-GKL WORM!"
|
| X | Microsoft Update Machine | jkfrnz.exe | "Added by the RBOT-GOZ WORM!"
|
| X | Microsoft Update Machine | wlimyc.exe | "Added by the RBOT-GQN WORM!"
|
| X | Microsoft Update Machine | xagwxzy.exe | "Added by the RBOT.S WORM!"
|
| X | Microsoft Update Machine | jkydxg.exe | "Added by the RBOT.AEA BACKDOOR!"
|
| X | Microsoft Update Machine | opmmve.exe | "Added by the KOLABC.DES WORM!"
|
| X | Microsoft Update Machine | paxrxo.exe | "Added by the PUSHBOT.A WORM!"
|
| X | Microsoft Update Machine | psmszw.exe | "Added by the KOLABC.CC WORM!"
|
| X | Microsoft Update Machine | syadpo.exe | "Added by the CIADOOR.GN BACKDOOR!"
|
| X | Microsoft Update Machine | systemi.exe | "Added by the BUZUS.JKU TROJAN!"
|
| X | Microsoft Update Machine | thvfyq.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | ubthec.exe | "Added by the AGENT.AWZ TROJAN!"
|
| X | Microsoft Update Machine | winmngr.exe | "Added by the RBOT.GKQ BACKDOOR!"
|
| X | Microsoft Update Machine | gbhglj.exe | "Added by the IRCBOT-ZJ TROJAN!"
|
| X | Microsoft Update Machine | wuamgdr.exe | "Added by the RBOT-IO BACKDOOR!"
|
| X | Microsoft Update Manager | WINRLS.EXE | "Added by the RBOT-AF WORM!"
|
| X | Microsoft Update Manager | svshost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Manager | scvhost.exe | "Added by the AGOBOT.AXJ WORM!"
|
| X | Microsoft Update Manager | scvideo.exe | "Added by the SDBOT-CVP TROJAN!"
|
| X | Microsoft Update Mechene | Updatez.exe | "Added by the RBOT-GI WORM!"
|
| X | Microsoft Update Module | rundll24.exe | "Added by the RBOT-PS WORM!"
|
| X | Microsoft Update Process | wmipcvse.exe | "Added by the AGOBOT-JF TROJAN!"
|
| X | Microsoft Update Security Patch | mssecurityupdatepatch.exe | Added by the AGENT.EF TROJAN!
|
| X | Microsoft Update Server | mssrv.exe | "Added by an unidentified VIRUS |
| X | Microsoft Update Service | csrss32.exe | "Added by the AGOBOT-HC WORM!"
|
| X | Microsoft Update Service | mswin32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft update service | systemm.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update SERVICE | phqghum.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Service | msupdate.pif | "Added by the RBOT-AQB WORM!"
|
| X | Microsoft Update Service | wmiprvre.exe | "Added by the AGOBOT-NN WORM!"
|
| X | Microsoft Update Services | wcsnfty.exe | "Added by the RBOT-AGK WORM!"
|
| X | Microsoft Update Services | wsnfty.exe | "Added by the RBOT-AFU WORM!"
|
| X | Microsoft Update Time | wuam.exe | "Added by the RBOT-M WORM!"
|
| X | Microsoft Update USB2 | wuammgrd32.exe | "Added by the RBOT-ADT WORM!"
|
| X | Microsoft Update v2.6 | lxxex.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Win32a | winupdate32a.exe | "Added by the RBOT-LO WORM!"
|
| X | Microsoft Update Win32x | winupdate32x.exe | "Added by the RBOT-AJN WORM!"
|
| X | Microsoft Update32 | wuamgrd32.exe | "Added by the RBOT-PU WORM!"
|
| X | Microsoft Updater | winsys32.exe | "Added by the RBOT.RL WORM!"
|
| X | Microsoft Updater | msconsole.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Updater | svhost.exe | "Added by the AGENT.CDF TROJAN!"
|
| X | Microsoft Updater | vbcjlg.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Updater | wuamgrds.exe | "Added by the RBOT.A WORM!"
|
| X | Microsoft Updater | winupdate.exe | "Added by the AGENT-KIR TROJAN!"
|
| X | Microsoft Updater Resources | WinFixd32.exe | "Added by the SPYBOT.CA WORM!"
|
| X | Microsoft Updater v2 | [path to worm] | "Added by the AUTORUN-BCI WORM!"
|
| X | Microsoft UPDATER32 | lsass.exe | "Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
|
| X | Microsoft UPDATER32 | LSASS32.EXE | "Added by the RANDEX.AR WORM!"
|
| X | Microsoft Updaters | tskmgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updaters | sysconfigs.exe | "Added by the RBOT-DF TROJAN!"
|
| X | Microsoft Updaters Pros | WINDLL32XP.EXE | Added by the SPYBOTTER.GEN VIRUS!
|
| X | Microsoft Updates | systemc32.exe | "Added by the RBOT-GR WORM!"
|
| X | Microsoft Updates | wkssvr.exe | "Added by the RBOT.R WORM!"
|
| X | Microsoft Updates | wkssvrs.exe | "Added by the RBOT-EB WORM!"
|
| X | Microsoft Updates | wuamgrd.exe | "Added by the RBOT-CO WORM!"
|
| X | Microsoft Updates | wtemp32.exe | "Added by the RBOT-AHQ WORM!"
|
| X | Microsoft Updates | svehost.exe | "Added by the RBOT-GRW WORM!"
|
| X | Microsoft Updates | svshost.exe | "Added by the AGOBOT-AIW WORM!"
|
| X | Microsoft Updates | svdhost.exe | "Added by the RBOT-GVH WORM!"
|
| X | Microsoft Updates | service.exe | "Added by the POISON.HPT BACKDOOR!"
|
| X | Microsoft Updates | [worm filename] | "Added by the AGOBOT-AIZ WORM!"
|
| X | Microsoft Updates | wgcptsud.exe | "Added by the RBOT-GTF WORM!"
|
| X | Microsoft Updates | winit.exe | "Added by the SDBOT-CSB WORM!"
|
| X | Microsoft Updates 2 USB | wgafixer.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updates 5 USB | sp3fixer.exe | "Added by the RBOT-ADS WORM!"
|
| X | Microsoft UpdateS Machine | wgrd.exe | "Added by the RBOT-FI WORM!"
|
| X | Microsoft Updates Resources | WinFixIDs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updating | navguard.exe | "Added by the RBOT.HW WORM!"
|
| X | Microsoft Updating | syswr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updating | wuamguards.exe | "Added by the RBOT-BY WORM!"
|
| X | Microsoft Updating Client | websvc.exe | "Added by the RBOT.AQ WORM!"
|
| X | Microsoft Updating Machine | sysc0de.exe | "Added by the RBOT.RB WORM!"
|
| X | Microsoft Updatting | miroupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updote | [random filename] | "Added by the RBOT-ARC WORM!"
|
| X | Microsoft UpMachine | doezs.exe | "Added by the RBOT.BCT WORM!"
|
| X | Microsoft upnp Update | msie.exe | "Added by the RBOT-LQ WORM!"
|
| X | Microsoft uptime Service | sysuptime.exe | "Added by the RBOT-ACG WORM!"
|
| X | Microsoft uptime Service | sycuptime.exe | "Added by the RBOT-AHY WORM!"
|
| X | Microsoft UpToDate Driver (32-bits) | [random filename].exe | "Added by the SPYBOT.LXJ WORM!"
|
| X | Microsoft Urlmon | urlmon.exe | "Added by the AGENT-GOO TROJAN!"
|
| X | Microsoft USA Plug | usaplug.exe | "Added by the RBOT-DVC WORM!"
|
| X | Microsoft USB Windows2 Driver | usbautotuner.exe | "Added by the SILLYFDC.BCL WORM!"
|
| X | Microsoft USB2 Driver | crmss.exe | "Added by the RBOT-VK WORM!"
|
| X | Microsoft usnsvc Service | usnsvc.exe | "Added by a variant of the KOBOT-C WORM!"
|
| N | Microsoft Utility Startup | OSA9.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft Values | igfkishc.exe | "Added by the RBOT-GLO WORM!"
|
| X | Microsoft Vertupdate | MSvert32.exe | "Added by the MYTOB-CY WORM!"
|
| X | Microsoft Video Capture Controls | MSsrvs32.exe | "Added by the SDBOT-AAK WORM!"
|
| X | Microsoft Virtual Service Manager | vservice32.exe | "Added by the MSNWORM.T WORM!"
|
| X | Microsoft Virual Machine | sms.exe | "Added by the RBOT-SP WORM!"
|
| X | Microsoft Vista Upgrade Validation Service | cfmon.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Visual Application | vpcrtf.exe | "Added by the IRCBOT-XJ TROJAN!"
|
| X | Microsoft Visual Debuger | mdm.exe | "Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| X | Microsoft Visual SourceSafe | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| X | Microsoft Visual SourceSafe | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| X | MicroSoft Visual SP | igxdfdfds.com | "Added by the SDBOT.GAV WORM!"
|
| X | MicroSoft Visual SP2 | igfxsrvc32.exe | "Added by the SDBOT.GAV WORM!"
|
| X | Microsoft Visual Studio | plscdksxg.exe | "Added by the RBOT-AWV WORM!"
|
| X | Microsoft Visual Studio VSA | varpc32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft web update | webmsn.exe | "Added by the RBOT-EMQ WORM!"
|
| X | Microsoft Win Update | WinUP.exe | "Added by the RBOT-BPR WORM!"
|
| X | Microsoft WIN32 Security | MSsec32.exe | "Added by the RBOT-DOQ TROJAN!"
|
| X | MicroSoft Wind0ws Updater | winsupdater.exe | "Added by a variant of the RBOT WORM!"
|
| X | MicroSoft Window Updater | winsupdater.exe | "Added by the RBOT-ZZ WORM!"
|
| X | Microsoft Windows | atup | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows 128bit Subsystem | system12.exe | "Added by the RANCK-CZ TROJAN!"
|
| X | Microsoft Windows 2000 | Winupdsdgm.exe | "Added by the GAOBOT.AO WORM!"
|
| X | Microsoft Windows 32 Update | win32update.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Windows Autowxckn | autowxckn.exe | "Added by the RBOT.DYZ BACKDOOR!"
|
| X | Microsoft Windows Communicator for NT/XP | wincomm.exe | "Added by the RBOT.ATH WORM!"
|
| X | Microsoft Windows DLL Services Configuration | newdll.exe | "Added by the SDBOT-ZR WORM!"
|
| X | Microsoft Windows DLL Services Configuration | newdll2.exe | "Added by the SDBOT-ABD WORM!"
|
| X | Microsoft Windows DLL Services Configuration | poker.exe | "Added by the SDBOT-ZY WORM!"
|
| X | Microsoft Windows DLL Services Configuration | poker3.exe | "Added by the SDBOT-AAH WORM!"
|
| X | Microsoft Windows DLL Services Configuration | proxy.exe | "Added by the SDBOT-ZL WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windir32.exe | "Added by the SDBOT.BHF WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windir32a.exe | "Added by a variant of the SDBOT.BHF WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windll32.exe | "Added by the SDBOT.BHD WORM!"
|
| X | Microsoft Windows DLL Services Configuration | winDSL.exe | "Added by the SDBOT-ZG WORM!"
|
| X | Microsoft Windows DLL Services Configuration | dllmanager32.exe | "Added by the SDBOT-BTU WORM!"
|
| X | Microsoft Windows Express | Microsoft Update | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Windows Game Updater | msgame32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows GUI | Windowz.exe | "Added by the RANDEX.AEV WORM!"
|
| X | Microsoft Windows GUI | msmonk32.exe | "Added by the SDBOT-PE WORM!"
|
| U | Microsoft Windows Media Player Network Sharing Service Configuration Application | WMPNSCFG.exe | "Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music |
| X | Microsoft Windows Secure | windocs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Secure | windocs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Secure Server | rpcxWindows.exe | "Added by the RBOT-LL WORM!"
|
| X | Microsoft Windows Secure Update | rpcxwinupdt.exe | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft Windows Securety | wurguar.exe | "Added by the RBOT-KY WORM!"
|
| X | Microsoft Windows Security | spvsper.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Security | wscndrives.exe | "Added by the RBOT-AJK WORM!"
|
| X | Microsoft Windows Services Edt | dllrun32.exe | "Added by the RBOT-GAF WORM!"
|
| X | Microsoft Windows Session Manager Subsystem | smss.exe | "Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Windows Sound | svghost.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Windows Sound | svshost.exe | "Added by the RBOT.RNE BACKDOOR!"
|
| X | Microsoft Windows Sound | svuhost.exe | "Added by the KOLAB.XC WORM!"
|
| X | Microsoft Windows Sound Drivers | sounddrivers.exe | "Added by the SLENFBOT.ABU WORM!"
|
| X | Microsoft Windows Updata | scvhost.exe | "Added by the RBOT.CEM BACKDOOR!"
|
| X | Microsoft Windows Updata | windows.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Updata | [5 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update | rundlls.exe | "Added by the HABRACK WORM!"
|
| X | Microsoft Windows Update | msoffice2.exe | "Added by the RBOT-GB WORM!"
|
| X | Microsoft Windows Update | spools.exe | "Added by the SDBOT.TD WORM!"
|
| X | Microsoft Windows Update | svchos.exe | "Added by the SDBOT.AC WORM!"
|
| X | Microsoft Windows Update | svcshost.exe | "Added by the FORBOT-CF WORM!"
|
| X | Microsoft Windows Update | svmhost.exe | "Added by the FORBOT-CH WORM!"
|
| X | Microsoft Windows Update | svshost.exe | "Added by the WOOTBOT.CJ WORM!"
|
| X | Microsoft Windows Update | msnmessenger.exe | "Added by the SDBOT.AJ WORM!"
|
| X | Microsoft Windows Update | msnwun.exe | "Added by the SDBOT-RM WORM!"
|
| X | Microsoft Windows Update | scvvhost.exe | "Added by the FORBOT-DH WORM!"
|
| X | Microsoft Windows Update | swwhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update | MSNMSGR.EXE | "Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| X | Microsoft Windows Update | svzhost.exe | "Added by the FORBOT-EV WORM!"
|
| X | Microsoft Windows Update | sccvhost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Update | scrhost.exe | "Added by the RBOT-AOW WORM!"
|
| X | Microsoft Windows Update | mnswinsx.exe | "Added by the RBOT-AWH WORM!"
|
| X | MICROSOFT Windows update | pdate.exe | "Added by the RBOT.BZT WORM!"
|
| X | Microsoft Windows Update | srshost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Update | rhost32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Windows Update | windowsupdate.exe | "Added by the AGOBOT.ON WORM!"
|
| X | Microsoft Windows Update | servcs.exe | "Added by the SDBOT.AL BACKDOOR!"
|
| X | Microsoft Windows Update | syssinfos.exe | "Added by the RBOT-FWR WORM!"
|
| X | Microsoft Windows Update Application | wuap.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update Client | csrss.exe | "Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
|
| X | Microsoft Windows Update Client | services.exe | "Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Windows Update Logon | win-logon.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update Service | wupdmgr32.exe | "Added by the DOS.AUTOCAT TROJAN!"
|
| X | Microsoft Windows Update Service | msnmsg.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Windows Update x86 | [various filenames] | "Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe |
| X | Microsoft Windows Update XP64 | ********.exe [* = random char] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update XP64 | updatexp64.exe | "Added by the SDBOT-AIM WORM!"
|
| X | Microsoft Windows Update XP64 | Lcuninst.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Update XP64 | mzhxlixm.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Updater | winupdgm.exe | "Added by the GAOBOT.BI WORM!"
|
| X | Microsoft Windows Updater | WINIUPDATES.EXE | "Added by the RBOT-KK WORM!"
|
| X | Microsoft Windows Updater | WINUPDATE.EXE | "Added by the RBOT-LI WORM!"
|
| X | Microsoft Windows Updater | TMNTSrv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Updater | win32upd.exe | "Added by the RBOT-EC WORM!"
|
| X | Microsoft Windows Updater | msnupdateit.exe | "Added by the AGOBOT-RL WORM!"
|
| X | Microsoft Windows Updater | windates.exe | "Added by the SDBOT.TE WORM!"
|
| X | Microsoft Windows Updater | spoolvs.exe | "Added by the RBOT.ACQ WORM!"
|
| X | Microsoft Windows Updater | suvhost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Updater | winfix.exe | "Added by the RBOT-CM WORM!"
|
| X | Microsoft Windows updaterD | log32zx.exe | "Added by the MYDOOM.W WORM!"
|
| X | Microsoft Windows Updates | explorer32.exe | "Added by the SDBOT.VQ WORM!"
|
| X | Microsoft Windows Updates | wsap32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Updating System | msresource.exe | "Added by the RBOT-EAM WORM!"
|
| X | Microsoft Windows Visual V2.0 | msiutil.exe | "Added by the DELF.JPH TROJAN!"
|
| X | Microsoft Windows XP Configuration Loader | m32svco.exe | "Added by the SDBOT.WORM!.48548 WORM!"
|
| X | Microsoft Winedows startup | WinKey.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Microsoft Winedows Updateing | NinKey.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Winsock Service | msusvc.exe | "Added by the RBOT-ANS WORM!"
|
| X | Microsoft WinSound | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft winsupdater | WINSUPDATER.EXE | "Added by the SPYBOTER.FB BACKDOOR!"
|
| X | Microsoft WinUpdate | mntcgf032.exe | "Added by the RBOT-PF WORM!"
|
| X | Microsoft WinUpdate | svh0st.exe | "Added by the SPYBOT.DL WORM!"
|
| X | Microsoft WinUpdate | syslx32.exe | "Added by an unidentified VIRUS |
| X | Microsoft WinUpdate | syswin32.exe | "Added by the RBOT-HO WORM!"
|
| X | Microsoft WinUpdate | spfix.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft WinUpdate | Winamp61.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft WinUpdate | Winupd32.exe | "Added by the RBOT.MQ WORM!"
|
| X | Microsoft WinUpdate | WinNTinit32.exe | "Added by the RBOT.VS WORM!"
|
| X | Microsoft WinUpdate | msupdte.exe | "Added by an unidentified TROJAN! See examples here & here"
|
| X | Microsoft WinUpdates | serm32.exe | "Added by the RBOT.GE WORM!"
|
| X | Microsoft Word Profissional | Java Plug In close.exe | "Added by the BANKER-EL TROJAN!"
|
| N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works
|
| X | Microsoft Wxdate | Syswu32.exe | "Added by the SPYBOT.HZ WORM!"
|
| X | Microsoft X Update | wuamkoppnp.exe | "Added by the RBOT-ANI WORM!"
|
| X | Microsoft's System Module | Sysmodule.exe | "Added by the BDOOR-FJ BACKDOOR!"
|
| X | Microsoft--Updates | sxvhost.exe | "Added by the RBOT-FH WORM!"
|
| X | Microsoft-Update | wngard.exe | "Added by the RBOT-JV WORM!"
|
| X | Microsoft-Updates | svxhost.exe | "Added by the RBOT-CT WORM!"
|
| X | MicrosoftCorp | securebind.exe | "Added by the INJECT TROJAN!"
|
| X | MicrosoftCorp | update.exe | "Added by the AUTORUN-ASG WORM!"
|
| X | MicrosoftCorp | wupdate.exe | "Added by the AGENT-LAY TROJAN!"
|
| X | Microsoftf DDEs ContDLL | rune.pif | "Added by the RBOT-AGF WORM!"
|
| X | Microsoftf DDEs ContrDL | runm.pif | "Added by the RBOT-AFQ WORM!"
|
| X | microsoftm eegs cuntrol | loor.pif | "Added by a variant of the RBOT WORM!"
|
| X | MicrosoftMultimediaTask | Mmtask.exe | Adware downloader - not the valid MusicMatch Jukebox which shares the same filename
|
| X | MicrosoftNAPC | securebind.exe | "Added by the INJECT TROJAN!"
|
| X | MicrosoftNAPC | update.exe | "Added by the AUTORUN-ASG WORM!"
|
| X | MicrosoftNAPC | wupdate.exe | "Added by the AGENT-LAY TROJAN!"
|
| X | MicroSoftRun | MSCOMM.dll | "Added by the AGENT-DJG TROJAN!"
|
| X | Microsofts Security Manager | ****.exe [**** = random char] | "Added by the RBOT-WH TROJAN!"
|
| X | Microsofts Updates | lsasss.exe | "Added by the RBOT-AEX WORM!"
|
| X | Microsofts Updatez | cmsssr.exe | "Added by an unidentified VIRUS |
| X | Microsofts Updatez | exploirez.exe | "Added by a variant of the RBOT WORM!"
|
| X | MicrosoftServiceManager | msupdat.exe | "Added by the YAHA.AA WORM!"
|
| X | MicrosoftSourceSafe | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| X | MicrosoftSourceSafe | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | MicrosoftUpdate | syshelper.exe | "Added by the WOOTBOT.AC WORM!"
|
| X | MicrosoftUpdate | WinUp32.exe | "Added by an unidentified VIRUS |
| X | MicrosoftUpdate | MicrosoftUpdate.exe | "Added by the BANKER-EHC TROJAN!"
|
| X | MicrosoftUpdate | windll.exe | "Added by the RBOT-IH WORM!"
|
| X | MicrosoftUpdate | RBuilder.exe | "Added by the DLOADR-BMV TROJAN!"
|
| X | MicrosoftUpdate | svhest.exe | "Added by the RBOT-ES WORM!"
|
| X | MicrosoftUpdate | downnew.exe | "Added by the TANTO-D TROJAN!"
|
| X | MicrosoftUpdates | [path to trojan] | "Added by the DELF-LO TROJAN!"
|
| X | MicrosoftUpdates | syshelped.exe | "Added by the FORBOT-AZ WORM!"
|
| X | MicrosoftValue | syscnfg.exe | "Added by an unidentified VIRUS |
| X | Microsoftvirus | sysoverload.exe | "Added by the FORBOT-AL WORM!"
|
| X | MicrosoftWindows | [various filenames] | "MagicSearch - a CoolWebSearch parasite variant"
|
| X | Microsoftz turn Control | aexl.exe | "Added by the SDBOT.BCO WORM!"
|
| X | Microsoftz turn Control | read.pif | "Added by the RBOT-AFS WORM!"
|
| X | Microsoft« ActiveX Debugger NT | setdebugnt.exe | "Added by the BANCOS-CZ TROJAN!"
|
| N | Microsoft® Windows® Operating System | "RunDLL32.exe ehuihlp.dll | BootMediaCenter" |
| N | Microsoft® Windows® Operating System | "rundll32.exe oobefldr.dll | ShowWelcomeCenter" |
| X | Microsot NT Support | [random filename].exe | "Added by the RBOT-CTI WORM!"
|
| X | Microsotufed Update 32 | windinit.exe | "Added by the RBOT-CTJ WORM!"
|
| X | Microszoft Update Mach1nezs | svchst.exe | "Added by the RBOT-ED WORM!"
|
| X | Micrsft Updese | xagwxz.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Micrsoft CFG 32 | lrbzus32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Micrsoft DerSystem | uqieelpb.exe | "Added by the RBOT-GRI WORM!"
|
| X | Micsoft-Published-Software | explrer.exe | "Added by the RBOT-GFL WORM!"
|
| X | Micsorosft Security Center | wcnsfty.exe | "Added by the RBOT-AHU WORM!"
|
| ? | MigrationVendorSetupCaller | "rundll32.exe migrate.dll | CallVendorSetupDlls" |
| U | Mindful | Mindful.exe | "Mindful from Felitec inc. ""Event reminder software with date and time tools in a simple to use system tray application"""
|
| X | MINIBUG | MINIBUG.EXE | "Displays ads inside Weatherbug - see here"
|
| N | MiniEYE-MiniREAD Launch | ARLaunch.exe | "eyeQ - improve your reading speed"
|
| X | miniport | usb2chk.exe | "Added by the LAZAR-A TROJAN!"
|
| X | Miosf Update | wimsqaad.exe | "Added by the SDBOT.AG TROJAN!"
|
| X | Mircosoft Update | wuampkd.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Mircrosoft Windows Config DLL | rundllc32b.exe | "Added by the RBOT-ZY WORM!"
|
| X | MistikotitaTuIpologisti | GDC.exe | "MistikotitaTuIpologisti Greek rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| U | ML1HelperStartUp | ML1HEL~1.EXE | "ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| U | ML1HelperStartUp | ML1Helper.exe | "ScreenScenes ""Midnight Lake"" screensaver. The freeware version comes with GAIN branded ads (pop-ups and others). ScreenScenes do however offer you the option of doing away with the ads by purchasing the screensaver for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| ? | MM Install | setup.exe | "Possibly Money Manager from Moneysoft?"
|
| X | MMicrosoft Security Management | inetforn.exe | "Added by the RBOT.AFZ WORM!"
|
| ? | MMRun | mmrun.exe | "??"
|
| X | MMSystem | "rundll32.exe mmsystem.dll | RunDll32" |
| ? | mmusrstp | procrun.exe | "??"
|
| X | mmxrun | msosa.exe | Added by an unidentified TROJAN or WORM!
|
| X | mmxrun | mswinindex.exe | "TwoSeven spyware"
|
| ? | mnu | igomnu.exe | "Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?"
|
| N | Mobile Connectivity Suite | Application Launcher.exe | "System Tray access to the HTC Sync mobile phone management utility for models including the Hero |
| U | Mobile Phone Suite | MobilePhoneSuite.exe | Logitech Mobile Phone Suite
|
| N | MOD | muamgr.exe | "Using MicroAngelo On Display |
| X | Modem Driverz Updates | mdmdrv.exe | "Added by a variant of the SDBOT WORM!"
|
| N | ModemUtility | mdmsetpe.exe | System Tray configuration icon for Aztech modems
|
| X | Modifiet Amateur HTPB | wuaclt.exe | "Added by the IRCBOT.AYS WORM!"
|
| X | ModularConfig | syscnfg.exe | "Added by an unidentified VIRUS |
| X | Module Call initialize | "RUNDLL32.EXE reg.dll | ondll_reg" |
| X | Modulo 00FE0F01 Host Internet | syschost.exe | "Added by the DELF-KW TROJAN!"
|
| X | MonContenuassistant | GDC.exe | "MonContenuassistant French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | MoneyStartUp | Money Startup.exe | Microsoft Money
|
| N | MoneyStartUp10.0 | Activation.exe | Part of MS Money 2002. Available via Start -> Programs
|
| X | MONPluginSrIvcs | n3monap23.exe | "Added by a variant of the RBOT WORM!"
|
| N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel
|
| X | MoreContent | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MoreResults | MoreResults.exe | "MoreResults adware"
|
| N | Morpheus | morpheus.exe | "MusicCity Networks' Morpheus - another peer-to-peer client based on Kazaa. Notable in that this one doesn't seem to install the adware that clog the Kazaa download. They claim they are adware free |
| X | MotherBoard Sounds | Sounds.exe | "Added by the RBOT-AAP WORM!"
|
| X | motoin | mm15201518.Stub.exe | "Delfin Promulgate adware variant"
|
| U | Motorola Desktop Suite | DesktopSuite.exe | "Related to Motorola Desktop Suite - PC software managing Motorola mobiles such as the A1000"
|
| U | Motorola Desktop Suite mRouter Config | mRouterConfig.exe | "Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth |
| U | Mount Safe & Sound | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
|
| U | mount.exe | mount.exe | "Part of ""GiPo@FileUtilities - GiPo@Mount ""Provides advanced substitutional and mounting services. It allows to attach a local drive to an empty folder on an NTFS volume (only for Windows 2000/XP) and to substitute a local folder for a drive letter"""
|
| X | mouse | mouse.exe | "Added by the RBOT-AHJ WORM!"
|
| U | Mouse 32A | Mouse32A.exe | Mouse utility. If you disable this entry you will not be able to use any of the non-standard functions of the mouse
|
| N | Mouse Suite 98 Daemon | pelmiced.exe | Mouse driver. Appears to cause a behaviour where the desktop suddenly flips back up when playing DirectX associated games
|
| U | Mouse Suite 98 Daemon | ICO.EXE | "Found on some Sony Vaio |
| X | mousebut | mousebut.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | Mousecntl | mousecntl.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| N | MouseCount | MC.exe | "MouseCount by Kittyfeet Software. "Utility for counting how many times us computer junkies click our mouse in a given session/day/week/month/year." Not required"
|
| X | mousedrive.exe | instantmsgrs.exe | "Added by the FORBOT-ER WORM!"
|
| X | MouseDrv | [path to worm] | "Added by the ZOLOAD-B WORM!"
|
| X | MouseDrv | update.exe | "Added by the ZOTOB.N WORM!"
|
| U | mouseElf | MC.exe | "Genius NetScroll mouse driver - required if you use non-standard Windows driver features"
|
| U | mouseElf | mouseElf.exe | System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
|
| U | MouseImp | MImpHost.exe | "MouseImp Pro - "A reliable assistant that turns your mouse into a simple |
| X | mousepad | mousepad.exe | "Added by the CLICKER TROJAN!"
|
| U | MouseWare | Logi_MwX.exe | "Logitech Mouseware driver. Needed to support some additional functionality of Logitech mice/trackballs such as ""SmartMove"". If you disable it and find you don't need it leave it disabled"
|
| U | Mousinfo | mousinfo.exe | MS mouse information tool - for troubleshooting mouse problems
|
| X | MoussaEvil | [path to file] | "Added by the MUSANUB-A WORM!"
|
| N | Movielink Manager Uninstall | msvcmm32.exe | "Auto-update for Movielink - internet movie rental System Tray access"
|
| N | Mozilla Quick Launch | Netscp6.exe | Netscape 6 and Mozilla browsers
|
| N | Mozilla Quick Launch | Mozilla.exe | Netscape 6 and Mozilla browsers
|
| N | mozilla_cleanup | xpicleanup.exe | "Firefox Mozilla cleans up after installation. It is invoked on a restart after installation |
| U | Mozy Status | mozystat.exe | "Mozy - free backup at a secure |
| X | MP3Collection | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3download | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3files | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3freeDownload | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3freeDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3nice | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3Themes | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3ToTheMax | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| U | MplSetup | MplSetup.exe | Used by Ricoh network printers to enable network printing from the client
|
| U | MP_STATUS_MONITOR | monitr32.exe | Cannon Multi-Pass status monitor - your choice
|
| X | mqbkup | mqbkup.exe | "Added by the OPASERV.K WORM!"
|
| U | mRouterConfig | mRouterConfig.exe | "Configuration for Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth |
| U | MRU-Blaster Scheduler | scheduler.exe | "Scheduler for MRU-Blaster - ""a program made to do one large task - detect and clean MRU (most recently used) lists on your computer"""
|
| N | MRU-Blaster Silent Clean | mrublaster.exe | "MRU-Blaster - performs silent cleaning of MRU lists at boot"
|
| U | MRUBlaster | indexcleaner.exe | "MRU-Blaster related - runs once in order to delete the index.dat file in the Temporary Internet Files and/or Cookies folder"
|
| X | MS Auto-IPSec Protection | MSASP32.exe | "Added by the RBOT-AER WORM!"
|
| X | MS Autoloader 32 | MSAuto32.exe | "Added by the SPYBOT.BD WORM!"
|
| X | Ms Builders | Wupated.exe | "Added by the AGOBOT-SS WORM!"
|
| X | Ms configsu | msconfigsu.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MS Configuration | MSFramer.exe | "Added by the RANDEX.OL WORM!"
|
| X | Ms Configuration | microsoftsa32.exe | "Added by the KELVIR.X WORM!"
|
| X | MS Configuration Utility | msconfig32.exe | "Added by the WOOTBOT.DY WORM!"
|
| X | MS DirectX Sound Drivers | msdrvdx.exe | "Added by the RBOT.BCX WORM!"
|
| X | MS DVD DirectX Sound Drivers | msdrvdx.exe | "Added by the SDBOT-XJ WORM!"
|
| X | MS Internet Executor 32 | MSIXEC32.exe | "Added by the RBOT-AEQ WORM!"
|
| X | Ms Java Update For Windows NT/XP | msijavaupdt32.exe | "Added by the RANDEX.AF WORM!"
|
| X | MS Java virtual machine | javavm.exe | "Added by the RBOT.ABG WORM!"
|
| X | MS lsass Startup | lsass135.exe | "Added by the RBOT.WM WORM!"
|
| X | MS PLUS INC | wpad.exe | "Added by the MYTOB-AN WORM!"
|
| X | MS Remote Procedure Call | msrpc32.exe | "Added by the RBOT-QL WORM!"
|
| X | MS Security | systm.pif | "Added by the RBOT-AQN WORM!"
|
| X | MS Security Authority Service | lsass.exe | "Added by the KALEL-B WORM! Note - this is not the legitimate lsass.exe process |
| X | MS Security Hotfix | service5.exe | "Added by the GAOBOT.AG WORM!"
|
| X | MS Security Update 993 | msident.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MS Sound Config 16bit | sndcfg16.exe | "Added by the SDBOT.MB TROJAN!"
|
| X | Ms Sound Drivers | msdrv.exe | "Added by the SDBOT-WR WORM!"
|
| X | MS Sys Security | mswin.pif | "Added by the RBOT-APJ WORM!"
|
| X | MS System Call Function | msscf32.exe | "Added by the RBOT-GBZ WORM!"
|
| X | MS System Security | mswin32.pif | "Added by the RBOT-AOX WORM!"
|
| X | MS UniX | navupdate64.exe | "Added by the RBOT.CRZ BACKDOOR!"
|
| X | MS Unix Binary | win32ttb.exe | "Added by the SPYBOT.OQ WORM!"
|
| X | MS Unix Binary | msmq2inst.exe | "Added by the RBOT-YF WORM!"
|
| X | MS Unix Binary | msnupdate.exe | "Added by the RBOT-AAM WORM!"
|
| X | MS Unix Binary | outlookexpressupdate.exe | "Added by the RBOT-YU WORM!"
|
| X | MS Unix Binary | Win32Update.exe | "Added by the RBOT-BAS WORM!"
|
| X | MS Unix Binary | Norton2005Update.exe | "Added by a variant of the RBOT WORM!"
|
| X | MS Unix Binary | trmupdate.exe | "Added by the RBOT-ACC WORM!"
|
| X | MS Unix Binary | WinGuard.exe | "Added by the RBOT-ACL WORM!"
|
| X | MS Unix Binary | msnq3insller.exe | "Added by the RBOT.GXH BACKDOOR!"
|
| X | MS Update | syshost.exe | "Added by the EVAMAN-F WORM!"
|
| X | Ms Update WinServices NT/XP | winservnt32.exe | "Added by the VANEBOT-G WORM!"
|
| X | MS UPDATER | update.exe | "Added by the RBOT-VC WORM!"
|
| X | MS Updates | mscache.exe | Spyware web downloader
|
| X | MS Updates | syshosts.exe | "Added by the MYDOOM.Y WORM!"
|
| X | MS Updates | aupd.exe | Spyware web downloader
|
| X | MS Updating Utility | msupdater.exe | "Added by the RBOT-XR WORM!"
|
| X | MS USB 2.0 Windows Support | msusb32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Ms Valud Loader | Svhots.exe | "Added by the AGOBOT-SP WORM!"
|
| X | ms window update | ******.exe [* = random character] | "Added by a variant of the RBOT WORM!"
|
| X | MS Windows Executor Process | MSEXECP32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MS Windows Security Updater | updater.pif | "Added by the RBOT-AKY WORM!"
|
| X | MS Windows Update | scguard.exe | "Added by the RBOT-YZ WORM!"
|
| X | MS-DOS Security Service | ms-dos.pif | "Added by the RBOT-AMR WORM!"
|
| X | MS-RunKey | arr.exe | MS-Connect dialler/hijacker
|
| Y | MSASCui | MSASCui.exe | "Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups |
| X | MsAudio | explorer.exe | "Added by the LEGMIR-BY TROJAN! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | MsAudio | "MsVM_STI.EXE RunDll32 cmicnfg.cpl | CMICtrlWnd" |
| X | MSbackups | backups.exe | "Added by the BANLOAD-TL TROJAN!"
|
| X | mscheck | rundll32.exe wincheck071008.dll mymain | "Added by the AGENT.ADXI TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""wincheck071008.dll"" file is located in %System%"
|
| X | MSChoExE | suge.exe | "Added by a variant of the RBOT WORM!"
|
| X | Mscolour | mscolour.exe | "Added by the GEMA TROJAN!"
|
| X | MSConfig Manager | msupdate.exe | "CoolWebSearch parasite variant"
|
| X | msconfig service | MSupdate32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH downloader TROJAN!
|
| X | MSConfigs | RUNDLL64.dll.vbs | "Added by the WEKODE-B WORM!"
|
| X | msconfigurator | ctfsdk.exe | "Added by the DELF-ALS TROJAN!"
|
| ? | MSCRMStartup | Microsoft.Crm.Application.Hoster.exe | "Related to Microsoft Dynamics CRM integrated solutions for Financial |
| X | MSDOS Security Service | msdos.pif | "Added by the RBOT-AMP WORM!"
|
| X | MSDrive | rundll32.exe drvkoc.dll | "Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
|
| X | MSDrive | rundll32.exe drvmod.dll | "Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
|
| X | MSDrive | rundll32.exe drvsoh.dll | "Added by a variant of the OP DIALER! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""drvmod.dll"" file is found in %System%"
|
| X | Msemu32 | Msemu32.exe | Unidentified spyware/adware/hijacker
|
| X | msennger | ournik.com | "Added by the IRCFLOOD.AL BACKDOOR!"
|
| X | MSFTP Service Config | r3grun.exe | "Added by a variant of the SDBOT WORM!"
|
| X | msgina | wuauclt2.exe | "Added by the IYUS-H TROJAN!"
|
| X | MSI Configuration | msiconf.exe | "Added by the AGENT.AKSZ TROJAN!"
|
| X | msliveupdate | msliveupdate.exe | "Added by the AGOBOT.ALT WORM!"
|
| X | msmautoprotect | msmssgs.exe | "Added by the BIFROSE-AJ TROJAN!"
|
| X | MSMessnger | msnupd.exe | "Added by the RBOT-ADY WORM!"
|
| X | MSN | iTuneshelp.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Msn | "rundll32.exe ilss32.dll | network" |
| X | MSN 9.0 Plus | [random letters].exe | "Added by the RBOT-ALY WORM!"
|
| X | MSN Auto-Updater | msnaupdater.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN Auto-Updater | msnupdates.exe | "Added by the AUTORUN.WORM.GEN WORM!"
|
| X | MSN Communication Manager | msncommgr.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | MSN Configuration | msnconfig.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Msn Configuration Loader | msngms.exe | "Added by the KELVIR.T WORM!"
|
| X | MSN Configuration Loader | msmsncfg.exe | "Added by the AGOBOT-KX BACKDOOR!"
|
| X | MSN Debug Mgr | msndebugs.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | MSN File Configuration | msnfilecfg.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN File Sharing | msnusr.exe | "Added by the SLENFBOT.AM WORM!"
|
| X | MSN File Sharing! | msnuser.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN Funny Images | imsngsr.exe | "Added by the AGOBOT-TT WORM!"
|
| X | MSN Manager | usnmsn.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Msn Message Acount Helper 7.7 | msnmessage7.7.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN Message Background loader | [path to worm] | "Added by the RBOT-AIE WORM!"
|
| X | MSN Messenger 32 | msniu.exe | "Added by the RBOT-AWB WORM!"
|
| X | MSN Messenger 323 | msniu3.exe | "Added by the RBOT-AXB WORM!"
|
| X | MSN Messenger Service Startup | msnservice.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Msn Messenger Update | msnupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Msn Messenger update | msnservice.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN Messenger User Controls | msmsgr.exe | "Added by the KELVIR.HI WORM!"
|
| X | MSN Messengger | MsRun32.exe | "Added by the IMAUT.CO WORM!"
|
| X | Msn Plus Updater | msnplus.exe | "Added by the RBOT-MU WORM!"
|
| X | MSN Popup Blocker | msnpopblck.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| N | MSN Quick View | Msndc.exe | Quick way to connect to MSN internet service
|
| X | MSN Router | msnrouter.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN Security Agent | msnsecure.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN Service Updates | winproc.exe | "Added by the KELVIR-BB WORM!"
|
| X | MSN Service Utilities | nkn.exe | "Added by the KELVIR-BC WORM!"
|
| X | MSN Setup | MSN.msn | "Added by the JAMBU WORM!"
|
| X | Msn Startup | msnstartup.exe | "Added by the ARBOT.AA WORM!"
|
| X | MSN Update | mscon.exe | "Added by the RBOT-QA WORM!"
|
| X | MSN Update | msn32.exe | "Added by the RBOT.AHN WORM!"
|
| X | MSN Update | DLLCON.EXE | "Added by the RBOT-EA WORM!"
|
| X | MSN Update Cfg | msnupdbt.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | MSN Update Client | msnupdater.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN Update Client | msnupdcli.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Msn Update Manager (Sp2) | MSMSGS.EXE | "Added by the AGOBOT-NL WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
|
| X | Msn Update Service | userx.exe | "Added by the MYTOB.JF WORM!"
|
| X | MSN Update Service | msnupdsv.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Msn Update SUPPORT | [random filename] | "Added by the RBOT-BPS WORM!"
|
| X | MSN Updater | msnms.exe | "Added by the FORBOT-CG WORM!"
|
| X | Msn Updater | msnplugins.exe | "Added by the RBOT-HS WORM!"
|
| X | Msn Updater | windatemanager.exe | "Added by the SDBOT.TS WORM!"
|
| X | MSN UPDATERS | virtualmemory.exe | "Added by the RBOT-JK WORM!"
|
| X | MSN Updating | msnupdate.exe | "Added by the QHOST.AEI TROJAN!"
|
| X | msn upddate | mesenger.exe | "Added by the RBOT-AVZ WORM!"
|
| X | MSN User | mymsnusr.exe | "Added by the IRCBOT.AVD BACKDOOR!"
|
| X | MSN User Server | msnserver.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN User Server! | msnservices.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN User Service | msnsvc.exe | "Added by the SLENFBOT.NS WORM!"
|
| X | MSN User Service! | msnserv.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN User Services | msnuserv.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN User Svc | msnusnsvc.exe | "Added by the IRCBOT.AVV BACKDOOR!"
|
| N | MSN Webcam Recorder | ml20gui.exe | """MSN Webcam Recorder is a tool that allows you to record video streamed to and from your computer by MSN Messenger's Webcam Feature"""
|
| X | MSN6.1 Auto-Updater | v6msn.exe | "Added by the AUTORUN-MM WORM!"
|
| X | MSN8m Startup | msn8m.exe | "Added by a variant of the RBOT WORM!"
|
| N | msnappau | msnappau.exe | "Updater for the MSN toolbar that can be downloaded onto IE. Calls home every day or so to ""update"" the toolbar"
|
| X | MSNPluginSrIvcs | n3vasap23.exe | "Added by a variant of the RBOT WORM!"
|
| X | MSNPluginSrvcs | p6.exe | "Added by the SDBOT.AKJ or RBOT-VJ WORMS!"
|
| X | MSNPluginSrvcs | sagate.exe | "Added by the SDBOT.AKJ WORM!"
|
| X | MSNPlus | msnplus.exe | "Added by the BANKER-DAN TROJAN!"
|
| X | MSNS PLUS XP2 | msdupd.exe | "Added by the RBOT-BCE WORM!"
|
| X | msnupdt | kolie.exe | "Added by a variant of the RBOT WORM!"
|
| X | msoft-updater23 | mssysstems.exe | "Added by the RBOT-ATU WORM!"
|
| X | msoft-updater23 | slssystem.exe | "Added by the RBOT-ASR WORM!"
|
| X | msoupdater | msoupdater.exe | "Added by the DLOADER.GBD TROJAN!"
|
| X | MSPluginSrvc | p3.exe | "Added by the RBOT-WV WORM!"
|
| X | MSPLUS | msplus32.exe | "Added by the MYTOB-AM or MYTOB-CL WORMS!"
|
| X | MSPP System Update 64 | wiaadmgr.exe | "Detected by Kaspersky as the RANKY.GEN TROJAN!"
|
| U | mspwr | pupstman.exe | """Transparent icon background"" feature of Ashampoo'sPowerUp XP (WinNT/2K/XP) and PowerUp Deluxe (Win98/Me)"
|
| U | mspwr | pupxpman.exe | "Related to Ashampoo's PowerUp XP"
|
| U | mspwr | pwrupst.exe | "Ashampoo's PowerUp XP is a ""tool for fine-tuning your Windows NT4 |
| U | mspwr | PuXpMan2.exe | "System Tray access to the Ashampoo® PowerUp XP Platinum 2 tweaking utility from Ashampoo GmbH & Co. KG - which includes (amongst others) one-click tuning |
| X | msrundll | msrund1l32.exe | "Added by the BINGHE TROJAN!"
|
| X | msrunocx32 | msrunocx32.exe | "Added by the SKUS WORM!"
|
| X | mssaru | mssaru.exe | "Added by the AGENT.AM TROJAN! Note - example names include ""XviD"" |
| X | mssdbsrv | msupdtck.exe | Added by a variant of a password stealing TROJAN!
|
| X | MsServer | msfun80.exe | "Added by the VB-CYG WORM!"
|
| X | MSServer | "Rundll32.exe [random].dll | #1" |
| X | mssonfig | winupdate.exe | "Added by a variant of the SDBOT WORM!"
|
| X | mssoul | msmscc2.exe | "Added by the DAPIZL.A banker WORM! (A ""banker worm"" is designed to pillage banking information and send it back to the perpetrators!)"
|
| X | mssoul | msmscc.exe | "Added by the BANCOS.HKT TROJAN!"
|
| X | MSStartOptimizer | WINUPD.EXE | "Added by the DASMIN-E TROJAN!"
|
| X | mssurfer lptt01 | mssurfer.exe | "RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | mssurfer ml097e | mssurfer.exe | "RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | MSTask | run dll.exe | "Yuupsearch adware"
|
| X | MSTray | rundll.exe | "Added by the BAMER-B TROJAN! Note - this is NOT the Win9x/Me system file of the same name as described here"
|
| X | msupd | msupd.exe | "Added by the IEACCESS DIALER!"
|
| X | MSUpdate | wupd.exe | "Added by the ALADINZ.M TROJAN!"
|
| X | MSUpdate | svchosthlp.exe | "Added by the BLASTER.T WORM!"
|
| X | msupdate | msupdate.exe | "Added by the RBOT-MZ WORM!"
|
| X | MSUpdate | criticalUpdate.exe | "Affilred adware"
|
| X | msupdate | update.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Msupdate | expIorer.exe | "Added by the TACTSLAY.A TROJAN!"
|
| X | Msupdate | outIook.exe | "Added by the TACTSLAY.A TROJAN!"
|
| X | Msupdate | svchosts.exe | "Added by a variant of the TACTSLAY TROJAN!"
|
| X | Msupdate | svcrhost.exe | "Added by the TACTSLAY.A TROJAN!"
|
| X | Msupdate | svcshost.exe | "Added by the TACTSLAY.A TROJAN!"
|
| X | MSupdate.exe | N/A | "CoolWebSearch parasite variant - resets home page to an adult content site"
|
| X | MSUpdateDevKit | axfd.exe | "Added by the SDBOT-ZD WORM!"
|
| X | msupdater | msupdater.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | MsUpdater System | udpsys32.exe | "Added by the RBOT.AAA WORM!"
|
| X | MSupdater.exe | N/A | "CoolWebSearch parasite variant. Installs the Winshow.dll browser plugin"
|
| X | msupdater25 | lsasser.exe | "Added by the RBOT-ATS WORM!"
|
| X | msupdates | msupdt.exe | "Added by the RBOT-JO WORM!"
|
| X | MSUpdSrv | msupdsrv.exe | "Browser hijacker |
| X | msupdtwiz | msupdtwiz.exe | "Added by the STRATION.DD WORM!"
|
| X | msurl | msurl32.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | msuser32.exe | msuser32.exe | "Added by the ANDROV TROJAN!"
|
| X | msvecurity | msvecurity.exe | "Added by the DORF-BO WORM!"
|
| X | MSVersion | INTERNETFEATURES.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | msvupdater | msvupdater.exe | "Added by a variant of the Storm/Nuwar/Zhelatin WORM! See here for an example"
|
| X | MSWindowsUpdate | Systern.exe | "Added by the RBOT-AFD WORM!"
|
| X | MSWindowsUpdate | mswinup.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MSWinupd | winupd.exe | "Added by the DLOADER-YE or DLOADR-AAA or DLOADER-ZF TROJANS - and others"
|
| X | MSWinupdate | winupdate.exe | "Added by the DLOADR-AAW TROJAN!"
|
| X | mswspl | plugin1.exe | "Added by the SMALL.IQ TROJAN!"
|
| X | MSWUpdate | [path to worm] | "Added by the SILLYFD-V WORM! The most common filename is lsass.exe but it not the legitimate lsass.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| X | MSxmlHpr | "RUNDLL32.EXE [path] msxm192z.dll | w" |
| X | Msy Startups | msyh32.exe | "Added by the AGOBOT-QC WORM!"
|
| X | Msy1 Startups | msyj32.exe | "Added by the AGOBOT-QQ WORM!"
|
| X | MS_SETUP.EXE | MS_SETUP.EXE | "Added by the CHARGE TROJAN!"
|
| X | MS_Update Check | wdfmgr.exe | "Added by the AGOBOT-TB WORM!"
|
| X | MS_update_0704_KB74073.exe | MS_update_0704_KB74073.exe | "Added by a variant of the UPDATEKB TROJAN!"
|
| ? | MtdAcqu | MtdAcqu.exe | "Metadata monitor part of Creative MediaSource™ player/organizer - which ""enables you to manage your entire digital music collection on both your computer and your Creative portable music player effortlessly."" Collects information on the songs. Is it required?"
|
| U | MUAL | mual.exe | Millesky video mail updater and launcher
|
| N | muamgr | muamgr.exe | "Using MicroAngelo On Display |
| X | muBlinder | muBlinder.exe | Program that bypasses Microsoft Update's Genuine Windows Validation
|
| ? | Mufix | mufix.exe | "Part of INFOConnect |
| X | mule_st_key | flec006.exe | "Added by the BAGLE.AV TROJAN!"
|
| U | Multi-function keyboard | GWHotkey.exe | "Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail |
| U | MultiCAM Initializer | MCamBoot.exe | "The MultiCAM Initializer is part of the MultiCAM software package provided by Vista Imaging in order to run up to 10 USB ViCAM or 3Com Home Connect PC Digital cameras on a single computer. Clears itself from memory once initialized but can also be safely disabled"
|
| X | Multimedia | windebug.exe | "Added by the VB-ERB WORM!"
|
| X | Multimedia Codecs | mcc.exe | "Added by the DLOADER-MB TROJAN!"
|
| X | Multimedia extensions | mservice.exe | "EasySearch adware"
|
| X | Multimedia extensions | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Multimedia extensions | mservice1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| U | Multimedia KBD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys
|
| U | MULTIMEDIA KEYBOARD | MMKeybd.exe | Multimedia keyboard manager. Required if you use the additional keys
|
| X | MULTIMEDIA KEYBOARD88 | smss.exe | "Added by the SILLYFDC WORM! Note - this is not the legitimate smss.exe process which should not normally figure in Msconfig/Startup!"
|
| X | multiran | multiran.exe | "Added by the COSIAM-E TROJAN!"
|
| U | MultiRes | MultiRes.exe | "MultiRes - system tray utility allowing quick access to changing desktop resolutions and has the ability to lock the screen refresh rate in WinNT/2K/XP"
|
| N | mumservice | mumservice.exe | "Software updater for Motorola products"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252