X | WebSUpdater | wupda.exe | "Added by the STARTPAGE.C TROJAN!"
|
U | WildTangent Web Driver updater | wcmdmgrl.exe | "Web Driver delivery system for WildTangent on-line games. Periodically checks for updates - can be disabled within the programs control panel. Note that WildTanget's privacy policy used to state that they also collect and share individuals information but this is no longer the case"
|
X | Win Process Updates | winupdates.exe | "Added by a variant of the SDBOT WORM!"
|
X | Win Secure Update | [random filename] | "Added by the RBOT-AGI WORM!"
|
X | win update | wupda32.exe | "Added by the SDBOT.J WORM!"
|
X | win update | wapdate.exe | "Added by a variant of the RBOT WORM!"
|
X | Win Update | SysUpdate.exe | "Added by the AGOBOT-TN WORM!"
|
X | Win Update | oleupdate.exe | "Added by the AGENT-UY TROJAN!"
|
X | Win Update | msnmger.exe | "Added by the RBOT-GDP WORM!"
|
X | win update | wupdate.exe | "Added by the RBOT-P BACKDOOR!"
|
X | Win Updater | WINUPDATER.EXE | "Added by the RBOT.IP WORM!"
|
X | Win32 Kernel Update | win32update.exe | "Added by the PROXY-BS TROJAN!"
|
X | Win32 Ms Auto Updater | AutomsUPD.exe | "Added by a variant of the RBOT WORM!"
|
X | win32 security updates downloader | tskmngr.exe | "Added by a variant of the SDBOT WORM! See here"
|
X | Win32 Update | svchosts.exe | "Added by a variant of the SDBOT WORM!"
|
X | Win32 Update | dl32.exe | Added by an unidentified WORM or TROJAN!
|
X | win32 update service | svchostt.exe | "Added by a variant of the SDBOT WORM!"
|
X | Win32 USB2 Driver | winupdate.exe | "Added by the AGOBOT.YE WORM!"
|
X | Win32 USB2 Driver | updatemgr.exe | "Added by a variant of the FORBOT WORM!"
|
X | win32update | win32update.exe | "Added by the GENOME.AQUV TROJAN!"
|
X | Win32Updater | KERNAL32.EXE | "Added by the SPYBOT-OK WORM!"
|
X | Winamp Update | yhn.exe | "Added by the SDBOT-ACR WORM!"
|
X | Windosupdate manager | runwin32.exe | "Added by the SDBOT.NNS BACKDOOR!"
|
X | window2 | ieupdate.exe | "Added by the FORBOT-BM WORM!"
|
X | WindowRegKey update | wins.exe | "Added by the SPYBOT.I WORM!"
|
X | Windows 32 Update | Windows-Update.exe | "Added by a variant of the RBOT WORM!"
|
X | windows auto update | msblast.exe | "Added by the BLASTER.B WORM!"
|
X | windows auto update | penis32.exe | "Added by the BLASTER (or MSBLAST.A) WORM!"
|
X | Windows Auto Update | winupdater.exe | "Added by the SDBOT.TF WORM!"
|
X | Windows auto update | bazzi.exe | "Added by the AHKER.E WORM!"
|
X | Windows auto update | LSASS.exe | "Added by the AHKER.G WORM! Note - this is not the legitimate lsass.exe process |
X | Windows Auto Updater | WINDOWSUPDATE.EXE | "Added by the SDBOT.PB WORM! Note the space at the beginning of the filename"
|
X | Windows Automatic Update | wuamgrder.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Automatic Updater | windrg.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Automatic Updates | dvldr.exe | "Added by the RBOT.MF WORM!"
|
X | Windows Automatical Updater | dcz.exe | "Added by the RBOT.CXS WORM!"
|
X | Windows AutomaticUpdater | runddls.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Configuration Utility | winxupdate.exe | "Added by the AGOBOT.LW WORM!"
|
X | Windows Core Kernel Update | win32bootcfg.exe | "Added by the RANCK-EL TROJAN!"
|
X | Windows Debugging Tools | updatecfg.exe | "Added by the RBOT-AXU WORM!"
|
X | Windows Defender Updater | wdu*.exe | "Added by a variant of the FakeAlert TROJAN! This infection displays fake Windows Defender alerts which link to spyware-kicker.com"
|
X | Windows driver update | dmsvc32.exe | "Added by the SDBOT-GP BACKDOOR!"
|
X | Windows driver update | Ipconfig32.exe | "Added by the SDBOT-JV WORM!"
|
X | Windows drivers update | windowsupdate.exe | "Added by the RBOT-ACE WORM!"
|
X | Windows Explorer Update Build 1142 | EXPLORER32.EXE | "Added by the KaZaA based KWBOT or KWBOT.Y WORMS!"
|
X | Windows Firewall Updater | updatees.exe | "Added by the RBOT-GBX WORM!"
|
X | Windows Firewall Updater | cronos.exe | "Added by the RBOT-GBY WORM!"
|
X | Windows Firewall Updater | ctfcom.exe | "Added by the RBOT-GCB WORM!"
|
X | Windows Firewall Updater | windowsupdate.exe | "Added by the SPYBOT.AVEO WORM!"
|
X | Windows Java Update | weatherBug32.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Loader | SysUpdate.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows Manager Update Inc | tgb.exe | "Added by the SDBOT-ACM WORM!"
|
X | Windows Media Player Update | [random filename] | "Added by the RBOT-ET WORM!"
|
X | Windows Media Updater | crease.exe | "Added by the RBOT-ATI WORM!"
|
X | Windows Micro Drivers | wupdates32.exe | "Added by the RBOT-AEH WORM!"
|
X | Windows Microsoft Update | wintask32.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows MS Update 32 | fhm.exe | "Added by the IRCBOT.GEN WORM!"
|
X | Windows MS Update 32 | sucker.exe | "Added by the FORBOT-GJ WORM!"
|
X | Windows MS Update 32 | jebote.exe | "Added by the FORBOT-GK WORM!"
|
X | Windows MSN Updates | wnd32.exe | "Added by the IRCBOT-ABA TROJAN!"
|
X | Windows NT Update Manager | WINL0G0N.exe | "Added by the AGOBOT-NU WORM! Note that those are zeroes in the filename and not capital ""o"""
|
X | Windows Online Updater | dllman.exe | "Added by the RBOT-TE WORM!"
|
X | Windows Process | win_update.exe | "Added by the LASTWORD WORM!"
|
X | Windows Registry Scan | timeupdate.exe | "Added by the SPYBOT.JE WORM!"
|
X | Windows Secure Update | winupser.exe | "Added by the RBOT-GCG WORM!"
|
X | Windows Secure Update | WinSecUp.exe | "Added by the RBOT-GCD WORM!"
|
X | Windows Secure Update | load.exe | "Added by the FORBOT-GU WORM!"
|
X | Windows Secure Update | WinSecure.exe | "Added by the RBOT-GDO WORM!"
|
X | Windows Security Update | security32.exe | "Affilred adware"
|
X | Windows Security Update | ndsass.exe | "Added by the RBOT.ESM BACKDOOR!"
|
X | Windows Service Pack Auto Update | winworks.exe | "Adware downloader - detected by eScan antivirus as the AGENT.BT TROJAN!"
|
X | Windows Service Pack Auto Update | figgaz.exe | "Detected by Kaspersky as the AGENT.BT TROJAN!"
|
X | Windows Service Pack Auto Update | ballin.exe | Added by an unidentified WORM or TROJAN!
|
X | Windows Service Pack Auto Update | del-me.exe | "Adware |
X | Windows Service Update | livecal.exe | "Added by the SDBOT-DEY WORM!"
|
X | Windows Service Update | crsss.exe | "Added by the SDBOT.CWX WORM!"
|
X | Windows Service Update | mswsgs.exe | "Added by the RBOT.FQB WORM!"
|
X | Windows Services | wupdate.exe | "Added by the GAOBOT.ZT WORM!"
|
X | Windows Services Update | svch0st.exe | "Added by a variant of the RBOT WORM! Note - the filename has the digit 0 rather then the uppercase ""o"""
|
X | Windows SP2 Update | Sp2update.exe | "Added by the WOOTBOT.BS WORM!"
|
X | Windows Svshost Service Update 32 | svcsshost32.exe | "Added by the FORBOT-GD WORM!"
|
X | WINDOWS SYSTEM | xpupdate.exe | "Added by the ZOTOB-G WORM!"
|
X | WINDOWS SYSTEM | wupdate.exe | "Added by the MYTOB-HT WORM!"
|
X | WINDOWS SYSTEM UPDATE | xDcc.exe | "Added by the MYOTB-EH WORM!"
|
X | Windows System Update Tools | upds.exe | "Added by the VANBOT.CX BACKDOOR!"
|
X | Windows Update | [filename] | "Added by the NORIO TROJAN! Acts as a hi-jacker redirecting to adult content sites"
|
X | Windows Update | iexplorere.exe | "Added by the GAOBOT.AP WORM!"
|
X | windows update | uddater.exe | "Added by the LEOX TROJAN!"
|
X | Windows Update | wudate.exe | "Added by the AGOBOT.ML WORM!"
|
X | Windows Update | wupdate.exe | "Wengs adware"
|
X | windows update | sychost.exe | "Added by the LEOX.B WORM!"
|
X | Windows Update | Wuamgrd.exe | "Added by a variant of the SPYBOT WORM!"
|
X | Windows Update | inetinf.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
X | Windows Update | WindowsUpdate.exe | "Added by the BAYROB-A TROJAN!"
|
X | Windows Update | host32.exe | "Added by the RBOT-GU WORM!"
|
X | windows update | wuraclt.exe | "Added by the RBOT-PO WORM!"
|
X | windows update | Wuanclt.exe | "Added by the RBOT.XZ WORM!"
|
X | Windows Update | svchosts.exe | "Added by the FRUCTA TROJAN!"
|
X | Windows Update | ebay.exe | "Added by the GAOBOT.BUU WORM!"
|
X | Windows Update | windows.exe | "Added by the RBOT-RB WORM!"
|
X | windows update | wuaurlt.exe | "Added by the RBOT.ADG WORM!"
|
X | Windows Update | Update.exe | "Added by the DELF-FN TROJAN!"
|
X | Windows Update | winmguard.exe | "Added by the RBOT-EM WORM!"
|
X | Windows Update | wuampd.exe | "Added by the RBOT.UM WORM!"
|
X | windows update | wuarclt.exe | "Added by the RBOT-OF WORM!"
|
X | Windows Update | winupdate.exe | "Added by the SDBOT-WS WORM!"
|
X | Windows Update | msnwinsb.exe | "Added by the RBOT-AAH WORM!"
|
X | Windows Update | scvhost.exe | "Added by the SDBOT-XT WORM!"
|
X | windows update | Microsoft.exe | "Added by the LMIR.A TROJAN!"
|
X | Windows Update | mplupdate.exe | "Added by the MOEGA WORM!"
|
X | windows update | msnsever.exe | "Added by the RBOT-AHN WORM!"
|
X | Windows Update | taskmr.exe | "Added by the MYTOB-GZ WORM!"
|
X | Windows Update | update32.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update | wininfo.exe | "Added by the MYTOB.GA WORM!"
|
X | Windows Update | winlogin.exe | "Added by the BANKER-DV TROJAN!"
|
X | Windows Update | msnupdates.exe | "Added by the RBOT-ALK WORM! Note - this file has nothing to do with Windows updates or MSN"
|
X | Windows Update | qtask.exe | "Added by the RBOT-AKU WORM! Note - do not confuse with the Quicken file of the same name as described here"
|
X | windows update | real.exe | "Added by the LEGMIR-AU WORM!"
|
X | Windows Update | windowsx.exe | "Added by the BANCD-A TROJAN!"
|
X | Windows update | wudupdate.exe | "ISTBar adware related"
|
X | Windows Update | wupdmgr.exe | "Added by the BANCBAN-FC TROJAN and variants!"
|
X | Windows Update | csrss.exe | "Added by the BANKER-HM TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | Windows Update | msnsupdate.exe | "Added by the RBOT-AXS WORM!"
|
X | Windows Update | XPLoogNT.exe | "Added by the BANCD-B TROJAN!"
|
X | Windows Update | install.exe | "Added by the BANKER-IB TROJAN!"
|
X | Windows Update | msi.exe | "Added by the BANKER-XB TROJAN!"
|
X | Windows Update | Sqltob.exe | "Added by the DASHER.A WORM!"
|
X | windows update | logonuit.exe | "Added by the LEGMIR-AO TROJAN!"
|
X | Windows Update | avkir.exe | "Added by the RBOT-GJP WORM!"
|
X | Windows Update | easypwnt.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows Update | MSDEVS30.exe | Added by the SPYBOT.AHC WORM!
|
X | Windows Update | SecretStub.exe | "Added by the SRAMLER.C WORM!"
|
X | Windows Update | Winload.exe | "Added by the DEDMIR-A WORM!"
|
X | Windows Update | taskngr.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Windows Update | usnsvc.exe | "Added by the KOBOT-C WORM!"
|
X | Windows Update | win32update.exe | "Added by the SDBOT.FTK WORM!"
|
X | Windows Update | livesrvs.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update | McAfee.exe | "Added by a variant of the IRCBOT BACKDOOR! See here. Note - this is not a valid McAfee program"
|
X | Windows Update | McAfee3.exe | "Added by an unidentified WORM or TROJAN! See here"
|
X | Windows Update | msconfig32.exe | "Added by a variant of the SPYBOT WORM! See here"
|
X | Windows Update | msnsa32.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
X | Windows Update | scrigz.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
X | Windows Update | winsc.exe | "Added by the BUZUS.RYI TROJAN!"
|
X | Windows Update | wuauclt32.exe | "Added by the SDBOT.DHY WORM!"
|
X | Windows Update | dllhostup.exe | "Added by the BANCBAN-NB TROJAN!"
|
X | Windows Update | explored.exe | "Added by the GAOBOT.MF WORM!"
|
X | Windows Update | smsscr.exe | "Added by the BANKER-DK TROJAN!"
|
X | Windows Update | sysdrv.exe | "Added by the AGENT-IYE TROJAN!"
|
X | Windows Update | winupupdate1.exe | "Added by the RBOT-UV WORM!"
|
X | Windows Update | klass.exe | "Added by the BIFROSE-ZH TROJAN!"
|
X | Windows Update | winlogonEvt.exe | "Added by the VB-DXM TROJAN!"
|
X | Windows update | explore.exe | "Added by the GAOBOT.AL WORM!"
|
X | Windows Update | fdos.exe | "Added by the RBOT-COG WORM!"
|
X | Windows Update | leak32x.exe | "Added by the AGENT.ALY BACKDOOR!"
|
X | Windows update | msb32.exe | "Added by the GAOBOT.CG WORM!"
|
X | Windows update | svdhost.exe | "Added by the GAOBOT.CG WORM!"
|
X | Windows Update | tskmngr.exe | "Added by the AGENT.ALY BACKDOOR!"
|
X | Windows Update | windb32.exe | "Added by the AGENT.ALY BACKDOOR!"
|
X | Windows update 2005 | [random filename] | "Added by the RBOT.ARP WORM!"
|
X | Windows Update 32 | winlogons.exe | "Added by the FORBOT-FI WORM!"
|
X | Windows Update 32 | rempss.exe | "Added by the FORBOT-FW WORM!"
|
X | Windows Update 32 | slsys.exe | "Added by the FORBOT-FT WORM!"
|
X | Windows update 32bit | winupd32.exe | "Added by the SDBOT.BE WORM!"
|
X | Windows Update 63 | shupd64.exe | "Added by the FORBOT-GA WORM!"
|
X | Windows Update 64 | nbupd64.exe | "Added by a variant of the FORBOT WORM!"
|
X | Windows Update 64 | WinV.exe | "Added by the FORBOT-FP WORM!"
|
X | Windows Update Auto Update | wuaumgr.exe | "Added by a variant of the SPYBOT WORM!"
|
X | Windows Update Automatic Updates | [path to backdoor] | "Added by the VBBOT.AM BACKDOOR!"
|
X | Windows Update Automation | winuptdate.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update AutoUpdate Client | waucult.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update AutoUpdate Client | wuauclt.exe | "Added by the LAZAR.B TROJAN! Note - this is not the legitimate wuauclt.exe process |
X | Windows Update AutoUpdate Client Product | wuauct.exe | "Added by the AGOBOT.ACL WORM!"
|
X | Windows Update Center | svthx.exe | "Added by the STUBBOT.A WORM!"
|
X | Windows Update Center | W32RSA.exe | Added by an unidentified WORM or TROJAN!
|
X | Windows Update Check | syslodr.exe | "Added by the SMALL.LU TROJAN!"
|
X | Windows Update Checker | [random filename] | Adware downloader trojan
|
X | Windows Update Checker | msupdte32.exe | "Added by the SDBOT-AEF WORM!"
|
X | Windows Update Checker | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows Update Checker | deinst_qfe002.exe | Added by a variant of the Win32.Small TROJAN!
|
X | Windows Update Client | wuclient.exe | "Added by the SMALL-RN TROJAN!"
|
X | Windows Update Client Service | windrvl32.exe | "Added by the AGOBOT-MM TROJAN!"
|
X | Windows update config | svhost.exe | "Added by the SDBOT-PF WORM!"
|
X | windows update configurator | svghost.exe | "Added by a variant of the SPYBOT WORM!"
|
X | windows update configurator | explore.exe | "Added by the SDBOT.RY BACKDOOR!"
|
X | Windows Update Controller | mwoffice.exe | "Added by the BATTRY-A TROJAN!"
|
X | Windows Update Draven | draven.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows Update Drive | updrvs.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows Update Files | dnetc.exe | "Added by an unidentified VIRUS |
X | Windows Update Firewall System | ctfmoom.exe | "Added by the RBOT-GAN WORM!"
|
X | Windows Update Firewall System | winmsfw.exe | "Added by the RBOT-EEO WORM!"
|
X | Windows Update Firewall System | ctfmom.exe | "Added by the SPYBOT.ANDM WORM!"
|
X | Windows Update GUI Executable x32x | wupdategux32.exe | "Added by the RBOT.CXY WORM!"
|
X | Windows Update Host | winupsvc.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows Update IPv6 Layer | WIN32IPV6.EXE | "Added by the RBOT.DUD WORM!"
|
X | Windows update loader | xpupdate.exe | "Malware installed by different rogue security software including SpyKillerPro. Also detected as the BRAVE-A TROJAN!"
|
X | Windows Update Manager | wupdmngr.exe | "Added by the RANDEX.BTB WORM!"
|
X | Windows Update Manager | Winlog0n.exe | "Added by the AGENT-BO TROJAN!"
|
X | Windows Update Manager | wupdate.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update Manager | bootwiz.exe | Added by the MYBOT WORM!
|
X | Windows Update Manager | WindowsUpdateManager.exe | "Added by a variant of the IRCBOT TROJAN!"
|
X | Windows Update Manager for NT | wupdmgr32.exe | "Added by the SDBOT.AH WORM!"
|
X | windows update microsoft | updatem.exe | "Added by the RBOT-CHE WORM!"
|
X | Windows Update Monitoring Service | winupdt.exe | "Added by the RBOT-PL WORM!"
|
X | Windows Update Process | wmiprvsc.exe | "Added by the SDBOT-CB WORM!"
|
X | Windows Update Service | csrs.exe | "Added by the AGOBOT-NI WORM!"
|
X | Windows Update Service | smcg.exe | "Added by the SDBOT.QY WORM!"
|
X | Windows Update Service | SP00ISS.exe | "Added by the SDBOT-ZH WORM!"
|
X | Windows Update Service | update32.pif | "Added by the RBOT-ALC WORM!"
|
X | Windows Update Service | trest.exe | Identified by BitDefender as a variant of the PEED TROJAN!
|
X | Windows Update Service | wmiprvse32.exe | "Added by the AGOBOT.NI WORM!"
|
X | Windows Update Service | regscv.exe | "Added by the AGOBOT-AM BACKDOOR!"
|
X | Windows Update Service | msupdate32.exe | "Added by the DLOADR-CRJ TROJAN!"
|
X | Windows Update Service 2004/2005 | systemupdate.exe | "Added by the RBOT-JE WORM!"
|
X | Windows Update services | wins32svcs.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update Services | winupdate32.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Update Software | system.exe | "TOFGER.BX spyware"
|
X | Windows Update SP3 | Windat.EXE | "Added by the RBOT-GTS WORM!"
|
X | Windows Update Svc | rundll32.exe xpupdate.dll | "ContraVirus rogue security software - not recommended |
X | Windows Update System | mswins.exe | "Added by the IRCBOT.DN WORM!"
|
X | Windows Update System Shell | svhostcs32.exe | "Added by the RBOT-AAZ WORM!"
|
X | Windows Update V6 | [random filename] | "Added by the RBOT-KT WORM!"
|
X | Windows Update.exe | N/A | Homepage hijacker
|
X | Windows Updated | spoolsae.exe | "Added by the RBOT-APM WORM!"
|
X | Windows Updated | updatr.exe | "Added by the RBOT-AYB WORM!"
|
X | Windows Updater | wupdmgr32.exe | "Added by a variant of the DOS.AUTOCAT TROJAN!"
|
X | Windows Updater | iexplorerrs.exe | "Added by the RBOT-TN WORM!"
|
X | Windows Updater | svigost.exe | "Added by the RBOT-VS WORM!"
|
X | Windows Updater | wupdate.exe | "Added by the WOOTBOT.AJ WORM!"
|
X | Windows Updater | sdsys.exe | "Added by the FORBOT-JG WORM!"
|
X | Windows Updater Online | winupdatexx.exe | "Added by a variant of the RBOT WORM!"
|
X | Windows Updater Servc | xpuupdate.exe | "ContraVirus rogue security software - not recommended |
X | Windows Updater Service Manager | winupdatr.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
X | Windows Updater Services | msnupdate.exe | "Added by a variant of the RBOT WORM!"
|
X | windows updaters | winupdats.exe | "Added by the SPYBOT-IS WORM!"
|
X | Windows Updates | lsassx.exe | "Added by a variant of the SDBOT WORM!"
|
X | Windows Updates | winupd32.exe | "Added by the MYTOB.CE WORM!"
|
X | Windows Updates | w32dns.exe | "Added by the SDBOT-BFW WORM!"
|
X | Windows Updates Agent | winupdate.exe | "Added by the SPYBOT.HW WORM!"
|
X | Windows USB Monitor | servupdate.exe | "Added by the IRCBRUTE.AQ TROJAN!"
|
X | Windows XP Automatic Update | wXPupdate.exe | "Added by the RBOT-AFC WORM!"
|
X | WindowsACEbar | acebarupdate.exe | "BarACE adware"
|
X | WindowsCriticalUpdate | windows_critical_update.exe | "Added by the ASTEF or RESPAN WORMS!"
|
X | Windows�Updates | Update.exe | "Added by the RBOT.TRA BACKDOOR!"
|
X | WindowsKeyUpdate | master.exe | "Added by the JOSAM WORM!"
|
X | WindowsReg% update | [random filename].exe | "Added by the RBOT-HH WORM!"
|
X | WindowsRegKey Autoupdate | [random filename] | "Added by a variant of the RBOT WORM!"
|
X | WindowsRegKey update | winupdate.exe | "Added by the RBOT-QJ WORM!"
|
X | WindowsRegKey update | windns.exe | "Added by the RBOT.IE WORM!"
|
X | WindowsRegKey update | winupdatexx.exe | "Added by the RBOT.LW WORM!"
|
X | WindowsRegKey update | [random filename] | "Added by the RBOT.QT WORM!"
|
X | WindowsRegKey update | svchoosts.exe | "Added by the RBOT.ADB WORM!"
|
X | WindowsRegKey update | svchostc.exe | "Added by the RBOT.IF WORM!"
|
X | WindowsRegKey update | wdnupdate.exe | "Added by the SDBOT.QX WORM!"
|
X | WindowsRegKey update | Windowsup.exe | "Added by the SDBOT.PU WORM!"
|
X | WindowsRegKey update | WINUPDATES.EXE | "Added by the RBOT-MM WORM!"
|
X | WindowsRegKey update | rkbuouoxfl.exe | "Added by the RBOT-OO WORM!"
|
X | WindowsRegKey update | winsys.exe | "Added by the RBOT-JY WORM!"
|
X | WindowsRegKey update | winupdat32.exe | "Added by the RBOT-AGW WORM!"
|
X | WindowsRegKey update XP | windexv1.exe | "Added by the RBOT-ABM WORM!"
|
X | WindowsRegKey%$ update | msi332.exe | "Added by the RBOT-IX WORM!"
|
X | WindowsRegKey%update | ethernet32m.exe | "Added by the RBOT-EN WORM!"
|
X | WindowsRegKeys update | winsysi.exe | "Added by the SDBOT.WE WORM!"
|
X | WindowsUpdate | windows_update.exe | "Added by the LOFNI WORM!"
|
X | WindowsUpdate | svchost.exe | "Added by the ASTEF or RESPAN WORMS or AGENT-V TROJAN! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
|
X | windowsupdate | RPC[RANDOM CHARACTERS].exe | "Added by the IRCBOT.B TROJAN!"
|
X | WindowsUpdate | USRINIT.EXE | "Added by the MADDIS.B WORM!"
|
X | windowsupdate | winupdate.exe | "Added by the WARPI WORM!"
|
X | WindowsUpdate | svchost.exe | "Added by the BDOOR-IK BACKDOOR! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
|
X | WindowsUpdate | winnnint.exe | Added by an unidentified WORM or TROJAN!
|
X | WindowsUpdate | [path to file] | "Added by the DUPA-B TROJAN!"
|
X | WindowsUpdate | svchostw.exe | "Added by the COBFINN_B TROJAN!"
|
X | WindowsUpdate | Nzil.exe | "Added by the CULLER-C WORM!"
|
X | WindowsUpdate | Strad.exe | "Added by the CULLER-D WORM!"
|
X | Windowsupdate | Windowsupdate.exe | "Added by the BANKER.ARK TROJAN!"
|
X | Windowsupdate | wupdmgr98.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
X | WinDOwsUPdate | smss.exe | "Added by the AUTORUN.DIB WORM! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ~A~m~B~u~R~a~D~u~L~� subfolder"
|
X | windowsupdate | autoupdate.exe | "Added by the IRCBOT-P BACKDOOR!"
|
X | WindowsUpdate | svdhost.exe | "Added by the AGOBOT-BP WORM!"
|
X | WindowsUpdate | twain.exe | "Added by the AGENT.BEA TROJAN!"
|
X | WindowsUpdate renew | iexplore.exe | "Added by the AGENT.QG TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
X | WindowsUpdate Service | wuautlc.exe | "Added by the RBOT-NR WORM!"
|
X | Windowsupdate Service | csrss.exe | "Added by the BABA-B WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in the root folder (ie |
X | WindowsUpdatecrss | crss.exe | "Added by a variant of the AGENT-HZ TROJAN!"
|
X | WindowsUpdateDirect | dupadirect.exe | "Added by the DUPA-C TROJAN!"
|
X | WindowsUpdatelsasss | lsasss.exe | "Added by a variant of the AGENT-HZ TROJAN!"
|
X | WindowsUpdatem1 | [path to file] | "Added by the AGENT-AAJ TROJAN!"
|
X | WindowsUpdatem2 | svchost.exe | "Added by an unidentified WORM or TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
X | WindowsUpdateManager | wupdmng.exe | "Added by the IRCBOT.OE BACKDOOR!"
|
X | WindowsUpdateNT | svwhost.exe | "Added by the SHELLOT-B TROJAN!"
|
X | WindowsUpdateR | regserv.exe | "Added by the COBFINN_B TROJAN!"
|
X | WindowsUpdatesvchostss | svchostss.exe | "Added by the AGENT-HZ TROJAN!"
|
X | WindowsUpdatev4 | w32gins.exe | "Added by an unidentified WORM or TROJAN! Located in the Root folder (C:\) |
X | WindowsUpdatewinsec | winsec.exe | "Added by a variant of the AGENT-HZ TROJAN!"
|
X | WindowsXP Update | windowsxpupdate.exe | "Added by the RBOT-PB WORM!"
|
X | Windows_Updates | svthost.exe | "Added by a variant of the SPYBOT WORM!"
|
X | Windowz Update V2.0 | Explorer.exe | "Added by the YODO WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
X | Windowz Update V2.0 | updater.exe | "Added by the YODO-C WORM!"
|
X | Windoxs Update Center | W32RfSA.exe | "Added by a variant of the SDBOT WORM!"
|
X | WindUpdates | [path to trojan] | "Added by the AGENT.BF TROJAN!"
|
X | WindUpdates | WinUpdt.exe | Windupdates adware variant
|
X | WinLibUpdate | libupdate.exe | "Added by the BIONET series of TROJANS such as BIONET.31 or BIONET.310"
|
X | WinLibUpdate32 | libupdate32.exe | Added by the BIONET.405 TROJAN!
|
X | winlocatorupdate | updatewinlocator.exe | Locator adult content toolbar related
|
X | winnt DNS ident | winupdate32.exe | "Added by a variant of the RBOT WORM!"
|
X | Winprocer32 Update | winprocer32.exe | "Added by the RBOT.GW WORM!"
|
X | winprocessor Update | winprocessor.exe | "Added by the RBOT.IO WORM!"
|
X | Wins Update 32 | services32.exe | "Added by the FORBOT-FN WORM!"
|
X | WinSetBrowse | BasicUpdate.dll.vbs | "Added by the BISCUIT.A WORM!"
|
X | WinShowUpdate | copy [path] winshow.new [path] winshow.dll | "Winshow parasiate related - from the ""RunOnce"" keys it replaces ""winshow.dll"" with a new version"
|
X | Winsock driver | winnt update.exe | "Added by the SPYBOT-DM TROJAN!"
|
X | Winsock driver | winupdate32.exe | "Added by the SPYBOT-JZ TROJAN!"
|
X | Winsock2 driver | winupdate.exe | "Added by the SPYBOT-BX WORM!"
|
X | Winsock32driver | sp2XPupdate.exe | "Added by the HACKARMY.S TROJAN!"
|
X | Winsock32driver | winXPupdate.exe | "Added by the HACKARMY.9728 TROJAN!"
|
X | winsupdater | winsupdater.exe | "Added by the ALCRA-F WORM!"
|
X | winsupdatesysmngr64 | winsys64mnger.exe | "Added by the RBOT-BAG WORM!"
|
X | WINTASK DLL32 | updatewin | "Added by the MYTOB.NI WORM!"
|
X | WintelUpdate | [path to trojan] | "Added by the SMALL-EKW TROJAN!"
|
X | WinTimer | msupdate.cmd | "Hijacker - detected by Kaspersky as the STARTPAGE.TJ TROJAN!"
|
X | WinUpdate | RBSKQQBO.EXE | "Added by the VBSWG2B.A WORM!"
|
X | WinUpdate | wmbem.exe | "Added by the REVCUSS.B TROJAN!"
|
X | WinUpdate | updsys.exe | "Added by a variant of the RBOT WORM!"
|
X | winupdate | winupdate.exe | "Added by the ALCAN.B WORM!"
|
X | WinUpdate | svhost.exe | "Added by a variant of the SDBOT WORM!"
|
X | WinUpdate | svchots.exe | "Added by the SMALL.GXJ TROJAN!"
|
X | winupdate | jusched.exe | "Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
|
X | Winupdate | lsas.exe | "Added by the COSPET.JR TROJAN!"
|
X | Winupdate Engine | wupeng.exe | "MalwareCrush rogue security software - not recommended |
X | WinUpdate Loader | msnnm.exe | "Added by the REVCUSS.C TROJAN!"
|
X | Winupdate Service | winxp.exe | "Added by the SPYBOT.IR WORM!"
|
X | winupdate.exe | winupdate.exe | "Added by the RADO TROJAN!"
|
X | winupdate.reg | winupdate.exe | "Added by the SPYBOT.EAS WORM!"
|
X | winupdate2846 | vbsystem35.exe msvbrun.exe | "Added by a variant of the MUTIN-C TROJAN!"
|
X | winupdate86.exe | winupdate86.exe | "Added by the FAKEAV-AHQ TROJAN!"
|
X | WinUpdateAdministrator | CSRSS.EXE | "Added by the PUNYA-A WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in C:\Application Data\WINDOWS"
|
X | WinUpdateB | breatle.exe | "Added by the BRATLE.AWORM!"
|
X | winupdateconn | [path to file] | "Added by the COMBRA-A WORM!"
|
X | winupdateconn_ | Explorer.EXE | "Added by the COMBRA-B WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
X | Winupdatee | winsvcc.exe | "Added by the AGENT.AN TROJAN!"
|
X | winupdatefiv_ | [path to file] | "Added by the COMBRA.C WORM!"
|
U | WinUpdateProtection | csrss.exe | "EmployeeWatch is a commercial surveillance software program designed to monitor user activity on a computer. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a subfolder of C:\windowsupdate\ufp"
|
X | WinUpdater | update.exe | "Added by the STARTPAGE.C TROJAN!"
|
X | winupdates | winupdates.exe | "Added by the ALCRA-B WORM!"
|
X | winupdate_ | [path to file] | "Added by the COMDOR.A WORM!"
|
X | WinxDiagUpdate | WinxDiagUpdate | "Added by the RBOT.BWQ BACKDOOR!"
|
X | Winxp update | Cappp.exe | "Added by the RBOT.DKO WORM!"
|
X | WinXp Updater | winxp32.exe | "Added by the RBOT-HG WORM!"
|
X | WinXpUpdate32 | WinXpUpdate32.exe | "Added by the AGENT.YWL WORM!"
|
X | WinZip Update | WinZip.exe | "Added by a variant of the RBOT WORM! Note - this is not part of the popular WinZip file compression utility"
|
X | WMP Auto Update | WINMEDUP.EXE | "Added by the RBOT.CF WORM!"
|
X | wmupdate | wmupdate.exe | "Added by the AGENT-GGJ TROJAN!"
|
X | wnxpupdate | spvspool.exe | "Added by the DABORA.B WORM!"
|
X | wnxupdate | updatexp.exe | "Added by the COMBRA-G WORM!"
|
X | won update | WAPDATE.EXE | "Added by the RBOT.N WORM!"
|
X | wupdate | wisvccz.exe | "Added by the ORSE-B TROJAN!"
|
X | wupdate | wi32.exe | "Detected by Panda as Trustbid spyware"
|
X | WUpdate | 1037v.exe | "Added by the CLAGGER-AR TROJAN!"
|
X | Wupdate driver | [various filenames] | "Added by a variant of the SPYBOT WORM!"
|
X | Wupdate driver | wupdadte.exe | "Added by the SPYBOT-CQ WORM!"
|
X | WUpdates | WUpdates.exe | "Added by the SWEPDAT TROJAN!"
|
X | Wxp4 | Norton Update.exe | "Added by the ERKEZ.D WORM!"
|
X | xDRam rar procx | xwinupdaterarx.exe | "Added by the RILER-W TROJAN!"
|
X | xp32win | xpupdater02.exe | "Added by the MOSUCK-A TROJAN!"
|
X | xpiupdate | xpiupdate.exe | "Added by the RBOT-AAB WORM!"
|
X | xpsp2install | xpsp2Update.exe | "Added by the AGENT-DPK BACKDOOR!"
|
X | xpsp2Update | xpsp2Update.exe | "Added by the AGENT-DPK BACKDOOR!"
|
X | xpupdate | updates.exe | "Added by the BROPIA.L WORM!"
|
X | XTServiceUpdate | XTServiceUpdate.exe | hahame.net adware downloader
|
X | Yahoo Update | Yahoo!.exe | "Added by the YAHOO! TROJAN!"
|
X | Yahoo Update | Yahoo.exe | "Added by the RBOT.AH BACKDOOR!"
|
X | Yahoo Updater | Messenger.exe | "Added by the FORBOT-FE WORM!"
|
X | YhooUpdates | ymsmsgs.exe | "Added by the SMALL_K TROJAN!"
|
X | zervpack2 | update2.exe | "Added by the SDBOT.WD WORM!"
|
X | Zi5 | AntiVirus Update.exe | "Added by the ERKEZ.G WORM!"
|
U | ZoneUpdate | csrss.exe | "WinSpy surveillance software. Uninstall this software unless you put it there yourself. Note - this is not the same file as the csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""ComRoot"" subfolder"
|
X | Zupdate | Zupdate.exe | "Associated with B3d Projector foistware - see here"
|
X | {C0FB7D08-056E-1033-0501-03020730002c} | Update.exe | "Added by the AGENT-EOG TROJAN!"
|