| N | Logitech QuickCam | ManifestEngine.exe | "Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
|
| N | LogitechSoftwareUpdate | ManifestEngine.exe | "Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
|
| Y | Logoff | SCTUINotify.exe | "Part of Windows SteadyState |
| X | LotsOfGames | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | LotsOfJokes | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | LowRiskFileTypes | sysguard.exe | "Added by the FAKEAV-UY TROJAN!"
|
| X | LowVersionSupport | [filename] | "Added by the LASTRAS TROJAN!"
|
| X | LSA | wfdmgr.exe | "Added by the MYTOB.C WORM!"
|
| X | LSASS 32 | ISASS32.pif | "Added by the ASSIRAL-C WORM!"
|
| U | LSPFix | LSPmonitor.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | LtcyCfgApply | LtcyCfg.exe | "PCI Latency Tool - ""Utility to set PCI Latency and possibly prevent game stutter or improve FPS"" for older AGP/PCI graphics cards"
|
| X | ltwob | formatsys.exe | "Added by the SERFLOG.A WORM!"
|
| N | Lwinst Run Profiler | lwtest.exe | Logitech Wingman Profiler for the Logitech joysticks. Available via Start -> Programs
|
| Y | LXCFCATS | "rundll32 [path] LXCFtime.dll | _RunDLLEntry@16" |
| U | lxdfamon | lxdfamon.exe | Lexmark 6500 Series printer device monitor
|
| U | lxdfmon.exe | lxdfmon.exe | Lexmark 6500 Series printer device monitor
|
| X | M-soft Office | M-soft Office.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
|
| X | M1cr0s0ft S3rcurity | systemconfig.exe | "Added by the RBOT.BKB WORM!"
|
| X | M1cr0s0ft Upd4t4zS | update32.exe | "Added by the RBOT-MI WORM!"
|
| X | m32info | m32info.exe | "Added by the CRYPTER.A TROJAN!"
|
| X | Macfee Security Patch | Mpfsheild.exe | "Added by the RBOT-NP WORM!"
|
| X | Machine Update Soft | wusas.exe | Added by an unidfentified WORM!
|
| X | mackfy.exe | msms.exe | "Added by the SDBOT-DID WORM!"
|
| X | Macromedia 8 | Flash Player.exe | "Added by the JAMBU-A WORM!"
|
| X | Macromedia Flash Update | scvhost.exe | "Added by a variant of the RBOT WORM!"
|
| U | MACVNTFY | MACVNTFY.EXE | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | MAFWTaskbarApp | MAFWTray.exe | Drivers for the M-Audio Firewire Audiophile - Interface
|
| U | MagicFormation | MagicFormation.exe | "MagicFormation from Tokyo Downstairs - a docking program that allows you to group icons in a ring anywhere on the desktop using mouse gestures to access things like My Documents |
| U | MagicFormation.exe | MagicFormation.exe | "MagicFormation from Tokyo Downstairs - a docking program that allows you to group icons in a ring anywhere on the desktop using mouse gestures to access things like My Documents |
| U | Mailbox Verifier | mboxvrfy.exe | "Mailbox Verifier (MV) is free software that will notify you about new messages arrived to your mailbox. Only works with POP3 mailboxes (not web-mail based systems). You should be able to set your mail system to check all accounts at regular intervals anyway if you prefer (in Outlook for instance)"
|
| X | MainStart | svcmfte32.exe | "Added by the STINX-A TROJAN!"
|
| X | Major Microsoft Windows Driver Boot loader | bpool.exe | "Added by the MYTOB.AJ WORM!"
|
| X | Malware Defense | mdefense.exe | "Malware Defense rogue security software - not recommended |
| X | malwaredef | malwaredef.exe | "Malware Defender 2009 rogue security software - not recommended |
| X | MalwareProMFC | MalwarePro.exe | "MalwarePro rogue security software - not recommended |
| X | Managment Service | [random filename] | Added by the RBOT.BIS TROJAN!
|
| N | ManifestEngine | ManifestEngine.exe | "Automatic updater for versions of Logitech QuickCam webcam software. Check for updates via the System Tray icon - see the LogitechVideoTray entry"
|
| X | Mantis | [filename] | "Added by the MANTIBE VIRUS!"
|
| X | Mascro soft SDK updates2 | SDKrepair2.exe | "Added by the SDBOT.BXM WORM!"
|
| U | masqform.exe | masqform.exe | "PureEdge Viewer - provides automation framework to manage and deploy XML forms-based processes for e-business and e-government systems. PureEdge was taken over by IBM (see here) and the product became Workplace Forms"
|
| U | Matador | mlfbuddy.exe | "MailFrontier - anti-spam application"
|
| X | MatrixScreen | [filename] | "Added by the MATRIXSCREEN TROJAN!"
|
| X | mb2np | [random filename] | Added by the IRCBOT.TJ WORM!
|
| X | MbarInstall | [random filename] | "Mirar adware"
|
| X | McAfee | McAffeAv.exe | "Added by the NETSKY.AL WORM!"
|
| X | mcafee | Win32.dll.vbs | "Added by the CATCHER-B WORM!"
|
| X | Mcafee Anti Scan | NortonScn.exe | "Added by a variant of the RBOT WORM!"
|
| X | McAfee Antivirus | McAfeeAV.exe | "Added by a variant of the RBOT WORM!"
|
| X | McAfee Antivirus 32 | MCAFEEAV32.EXE | "Added by the SPYBOT-EH WORM!"
|
| X | Mcafee Antivirus Monitoring System326 | VSStatmn326.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Mcafee Antivirus Monitoring System32mn | VSStatmn32.exe | "Added by a variant of the RBOT WORM!"
|
| X | McAfee Antivirus Protection | mcafeeAV.exe | "Added by a variant of the RBOT WORM!"
|
| Y | McAfee Application Installer | mcappins.exe | Used by older versions of McAfee internet security related products to clean up installation files that are no longer required once the product is installed. This entry will normally only appear once the product has been installed before the system is rebooted
|
| X | Mcafee Auto Protect | mcafeshield.exe | "Added by the RBOT-UH WORM!"
|
| U | McAfee Backup | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Backup and Restore | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Data Backup | LogOnHook.exe | "Part of McAfee Data Backup (now Online Backup) - which ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection. The exact purpose of this entry is unknown at present but it unloads after startup"
|
| U | McAfee Data Backup | McAfeeDataBackup.exe | "McAfee Data Backup (now Online Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| Y | McAfee Desktop Firewall Tray | FireTray.exe | "McAfee Desktop Firewall"
|
| Y | McAfee Family Protection | mfp.exe | "McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content |
| Y | McAfee Firewall | CPD.EXE | Firewall bundled with McAfee VirusScan 6.*. Can also be listed as CPD_EXE
|
| U | McAfee Guardian | CMGrdian.exe | "McAfee Guardian shortcut menu on the System Tray (looks like a castle) given access to Internet Security |
| Y | McAfee Managed Desktop Agent | MYAGTSVC.EXE | "Part of the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Starts via a registry ""RunServices"" key on Windows 98/Me and as a service on Windows NT/2K/XP"
|
| U | McAfee Managed Services Tray | StartMyagtTry.exe | System tray notification for the now obsolete McAfee Managed VirusScan anti-virus and anti-spyware security tool for small businesses. Not required to be protected but you lose notifications
|
| U | McAfee Online Backup | MOBKstat.exe | "System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| U | McAfee Online Backup Status | MOBKstat.exe | "System Tray access to McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| X | McAfee Online virus Scanner | avp.exe | "Added by the RBOT-GCV WORM! Not to be confused with Kaspersky anti-virus and AOL's Active Virus Shield (by Kaspersky) - found in either a Kaspersky or AOL sub-directory"
|
| X | McAfee Online Virus Scanner | nzm.exe | "Added by the IRCBOT.XV WORM!"
|
| U | McAfee QuickClean Imonitor | Plguni.exe | "Part of McAfee's QuickClean - which removes internet clutter and unwanted programs. This entry monitor changes made to the registry so that they can be undone later using QuickClean - such as removing programs. QuickClean is now integrated into their Total Protection |
| Y | McAfee SecurityCenter | mcagent.exe | "McAfee SecurityCenter is the main support center for McAfee's range of internet security products such as Total Protection |
| Y | McAfee SecurityCenter | McUpdate.exe | Automatic virus definition and software updates/upgrades for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online
|
| X | mcafee Software Intrenet | mcafee.exe | "Added by the RBOT-ATR WORM! Note - this is not a valid McAfee program"
|
| U | McAfee SpamKiller | MskAgent.exe | "McAfee SpamKiller - rule-based and list-based spam filter. Available as a stand-alone product or included in older versions of Internet Security and Total Protection"
|
| Y | McAfee VirusScan | mcmnhdlr.exe | "Part of older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online. When Windows boots it checks whether a virus scan is necessary before you do anything with your PC. Typically |
| Y | McAfee VirusScan | mcvsshld.exe | "ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed |
| Y | McAfee VirusScan | oasclnt.exe | "On-access real-time scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files for malware as you access |
| X | Mcafee VirusScan Manager | mvcsvm.exe | "Added by the SILLYFDC.BBV TROJAN!"
|
| X | McAfee Windows Protection | mcafee32.exe | "Added by a variant of the SPYBOT WORM!"
|
| N | McAfee Winguage | ?? | "Part of McAfee Nuts & Bolts. ""WinGuage is a dynamic reporting tool that constantly monitors your use of Windows and your applications |
| U | McAfee.InstantUpdate.Monitor | RuLaunch.exe | "Instant Updater for McAfee's VirusScan |
| U | McAfeeDataBackup | McAfeeDataBackup.exe | "McAfee Online Backup (formerly Data Backup) - ""takes the hassle out of manually backing up all of your valuable digital files - from Microsoft Outlook email and contacts to treasured family photos"". Available as a stand-alone product or included in Internet Security and Total Protection"
|
| Y | McAfeeFireTray | Firetray.exe | "McAfee Desktop Firewall"
|
| X | MCAFEEIPS | setup.exe | "Added by the WHITEWELL TROJAN!"
|
| X | McAfeeScanPlus | McAfeeScanPlus.exe | "Added by the MEPCOD TROJAN! This trojan file does not belong to any McAfee Antivirus Software and is found in the Windows or Winnt folder"
|
| Y | McAfeeUpdaterUI | UpdaterUI.exe | McAfee common updater user interface
|
| Y | McAfeeUpdaterUI | UdaterUI.exe | Updater user interface for McAfee's VirusScan Enterprise corporate anti-virus and anti-spyware security tool
|
| Y | McAfeeVirusScanService | Avsynmgr.exe | "From McAfee VirusScan version 5.x. Runs VirusScan System Tray (Vsstat.exe) |
| Y | McAfeeWebscanX | WebScanX.exe | "From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs |
| X | Mcaffe Antivirus | Mcafeescn.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | MCAFFE FLD LOADER | MCAFFEFLD.EXE | "Added by the RBOT-PY WORM!"
|
| X | Mcaffee | mcsheild.exe | "Added by the RBOT-FDP WORM!"
|
| X | Mcrosoftr Update | Mcrosoftr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Mcsoft | gfeqzvq.exe | "Added by the SDBOT-NV WORM!"
|
| X | Media Player Update | xpsp1mfh.exe | "Added by a variant of the RBOT WORM!"
|
| X | Media Services | [filename].exe | "Added by the AGENT-BA BACKDOOR!"
|
| X | Media Software UPdater | sscs.exe | "Added by the RBOT-ABE WORM!"
|
| X | Media Transfer Protocals | msstc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| N | MediaFace Integration | Sethook.exe | "Fellowes Neato® cd label design software. ""Launch NEATO's MediaFACE II label making software directly from the productname toolbar"""
|
| U | Mediafour Mac Volume Notifications | MACVNTFY.EXE | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | Mediafour MacDrive | MacDrive.exe | "MacDrive 7 & MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Version 6 is not Vista compatible but doesn ""include support for striped Mac arrays created with ATTO ExpressStripe software."""
|
| U | Mediafour MacDrive | MDDiskProtect.exe | "Part of MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | Mediafour MacDrive | MDGetStarted.exe | "MacDrive 7 from Mediafour Corporation - ""enables anyone using Windows Vista |
| U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | "Mediafour Xplay - allows you to use an Apple iPod digital music player with a PC running Windows. If not used regularily start manually before connecting the iPod"
|
| U | Mediafour XPlay Tray Notification Icon | Xptryicn.exe | "Xplay 2 from Mediafour Corporation - ""expands what you can do with any iPod |
| U | MediafourGettingStartedWithMacDrive6 | MacDrive.exe | "MacDrive 6 CrossStripe Edition from Mediafour Corporation - ""a perfect way to share files between Mac OS and Windows."" Unlike the standard version of MacDrive 7 |
| U | MediaLifeService | MediaLifeService.exe | "Related to MediaPlay Cordless Mouse from Logitech"
|
| ? | MedionVFD | MdionLCM.exe | "Related to Medion Display Information. What does it do and is it required?"
|
| ? | meidntpa | vqgdpfrs.exe | "??"
|
| X | MemConfig | SetupIE.com | "Added by the TAPLAK WORM!"
|
| X | Memory Manager | memorymanager.pif | "Added by the DELF-JJ TROJAN!"
|
| X | Memory Service | freememory.exe | Added by the RBOT.GEN WORM!
|
| U | Memory+ | tfimemsr.exe | "Memory optimizer. MS MVPs (Most Valued Professional) recommend not using memory managers with Win98/SE/ME. See this article and make up your own mind"
|
| X | MenaceFighter | GDC.exe | "MenaceFighter rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| N | MessagerStarter Freeserve | StartMessager.exe | Freeserve Messenger
|
| X | Messenger6 | command.pif | "Added by the INZAE.B WORM!"
|
| X | messnger | [worm filename] | "Added by the DELODER WORM!"
|
| N | Metacafe | MetacafeAgent.exe | "Metacafe - video sharing on the web. Note - if you subscribe make sure you read the Privacy Policy"
|
| X | Mfc**.exe [* = random char] | Mfc**.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| X | Mfc**32.exe [* = random char] | Mfc**32.exe [* = random char] | "CoolWebSearch/HomeSearch adware - for examples |
| ? | mfgboot | ?? | "??"
|
| X | mfhsornwnduy | regsvr32.exe gisyflngpshcvuakv.dll | "Pro AntiSpyware 2009 rogue spyware remover - not recommended |
| X | mFilter | MNeck.exe | "Added by the CLICKER-AG TROJAN!"
|
| X | mfin32 | mfin32.exe | MyFreeInternetUpdate - adware downloader
|
| Y | mfp | mfp.exe | "McAfee Family Protection - which 'is easy-to-use and built to empower parents to say ""yes"" to their children's online interests while protecting them as they learn and explore' and ""protects children of all ages from exposure to inappropriate content |
| U | MFP PanelMgr | SSMMgr.exe | "Monitors ink levels |
| Y | MFP Server Agent | MFPAgent.exe | "Multi Function Printer (MFP) Server Agent for Belkin's Wirless G All-in-One Print Server and ZyXEL's NPS-520"
|
| U | MFP1815_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Dell Laser MFP 1815 multifunction printer
|
| X | Mfqneqfeb | vdddwq.exe | "Added by the RANDEX.AP WORM!"
|
| X | Mgsgi service | wkzfn.exe | "Added by the AGOBOT-AHL WORM!"
|
| X | Mi7sft sdce | b0yz.exe | "Added by the RBOT.CWG WORM!"
|
| X | Mi7sft sdce | MNSQ.exe | "Added by the RBOT.DMU WORM!"
|
| X | Mi7sft sdce | scorti.exe | "Added by the RBOT.ELC WORM!"
|
| X | Mickey Mouse Cereal | [random filename].exe | "Added by the RANKY.Q TROJAN!"
|
| X | Micosoft Data Core | runservice.exe | "Added by the IRCBOT.BK WORM!"
|
| X | Micosoft Data Core stuff | svshosts.exe | "Added by the RBOT.FZA WORM!"
|
| X | Micosoft Startup | syscall.exe | "Added by the SDBOT-JI WORM!"
|
| X | Micosoft Startup | systall.exe | "Added by the SDBOT-GM BACKDOOR!"
|
| X | Micr0s0ft Ms D0s | msdx.exe | "Added by the RBOT-AON WORM!"
|
| X | Micr0s0ft Upd4t4z | svchost32.exe | "Added by the RBOT.ALF WORM!"
|
| X | Micrcoft Exploerer | spoolsal.exe | "Added by the RBOT-AKK WORM!"
|
| X | Micrcoft Exploerer | svchose.exe | "Added by the RBOT-ASL WORM!"
|
| X | Micrcoft Updat | spoolsae.exe | "Added by the RBOT-AIB WORM!"
|
| X | Micrcoft Updat | spoolsaex.exe | "Added by the RBOT-AJM WORM!"
|
| X | Micrcoft Updat | Internet.exe | "Added by the RBOT-ANA WORM!"
|
| X | Micrcsoft Certificate Services | cflmon.exe | "Added by the RBOT-FWV WORM!"
|
| X | Micro Office | [path to trojan] | "Added by the BANCBAN-QC TROJAN!"
|
| X | Micro Process | appconf.exe | Added by an unidentified WORM or TROJAN!
|
| X | MicroedSoft Toolbar | Smoked.exe | "Added by the RBOT-ALN WORM!"
|
| X | Microfinder lptt01 | mcf.exe | "RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Microfinder ml097e | mcf.exe | "RapidBlaster variant (in a ""mcf"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | Microfot Update | winldx32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microft Exploerer | spoolsac.exe | "Added by the RBOT-AMD WORM!"
|
| X | Microft Update 32 | winssx.exe | "Added by the RBOT-AQS WORM!"
|
| X | MicroLoad | [random filename] | "Added by the DARBY WORM!"
|
| X | Micromedia Flash Update | wdfmrg.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Micromedia Flash Update | xptxt.exe | "Added by the RBOT-GAB WORM!"
|
| X | Microoft Timing | pupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | MICROSFT ANTIVIRUS UPDATE SUPPORT | [random 10-letter filename].EXE | "Added by the RBOT-AQA WORM!"
|
| X | MICROSFT ANTIVIRUS UPDATE SUPPORT | MSGUPDATED.EXE | "Added by the RBOT-APZ WORM!"
|
| X | Microsft Conf 32 | msaconf.exe | "Added by the RBOT.EYA WORM!"
|
| X | Microsft Confige 32 | msaconfigurez.exe | "Added by the RBOT.CLC WORM!"
|
| X | Microsft Corporation Version 2001.12.4414 | comrel.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | Microsft Corporation Version 2002.12.2414 | comserv.exe | "Added by a variant of the SLAPER TROJAN!"
|
| X | MICROSFT MX UPDATE SUPPORT | taskmngrs.exe | "Added by the RBOT-AUZ WORM!"
|
| X | MICROSFT MX UPDATE SUPPORT | winmx32.EXE | "Added by the IRCBOT-FD WORM!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | [random filename] | "Added by the RBOT-ASM or RBOT-AUW WORMS!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | MSN32.EXE | "Added by the RBOT-AWJ WORM!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | mtakthmyn.EXE | "Added by the RBOT-AUJ WORM!"
|
| X | MICROSFT RAMA UPDATE SUPPORT | MSGUPDAT32.EXE | "Added by the RBOT-BBB WORM!"
|
| X | Microsft Remote Procedure Daemon | msrpcd.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsft Security Monitor Process | cmh.exe | "Added by the EGGDROP.V WORM!"
|
| X | Microsft Security Monitor Process | mssmppp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsft Security Monitor Process | mssmpp.exe | "Added by the SDBOT-DJW WORM!"
|
| X | Microsft Updtes | sarvice.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsft Upgraed | [random filename].exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsft Windows Adapter 5.1.3013 | [random filename] | "Added by the SMALL.HIT TROJAN!"
|
| X | microsft windows updates | mwupdate32.exe | "Added by a variant of the TOXBOT/CODBOT WORM!"
|
| X | Microsof Value | nmatt.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsof Windows Host | svhost32.exe | "Added by the RBOT.ADY WORM!"
|
| X | Microsof Winlog Host | wilogon32.exe | "Added by the RBOT.XC WORM!"
|
| X | Microsofot x386 System Monitor | system32.exe | "Added by the WOOTBOT.M WORM!"
|
| X | microsoft | svchost.exe | "Added by the ASTEF or RESPAN WORMS! Note - this is not the legitimate svchost.exe process which should NOT appear in Msconfig/Startup!"
|
| X | microsoft | microsoft.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
|
| X | Microsoft | win32.exe | "Added by the DARKMOON TROJAN!"
|
| X | Microsoft | iexplore.exe | "Added by the QQROB-R TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Microsoft | svchost.exe | "Added by the ADUYO-A TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft | wuauclt.exe | "Added by the QQROB-AAQ TROJAN! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft | guard.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft | wcsntfy.exe | "Added by the AGOBOT-AHT WORM!"
|
| X | Microsoft | ssmss.exe | "Added by the RBOT-FZF WORM!"
|
| X | Microsoft | lsass.ppf | "Added by the RBOT-GAA WORM!"
|
| X | Microsoft | msvchost.exe | "Added by the RBOT-GAW WORM!"
|
| X | Microsoft | mixers.exe | "Added by the AGOBOT-AHU WORM!"
|
| X | Microsoft | msmsger.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft | MSUPDATE.exe | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft | radnom.exe | "Added by the RBOT-GHO WORM!"
|
| X | Microsoft | rtvcscan.exe | "Added by the RBOT-GGU WORM!"
|
| X | Microsoft | taskbar.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft | updater.exe | "Added by the RBOT-GHP WORM!"
|
| X | Microsoft | windl32.exe | "Added by the SDBOT-DCZ WORM!"
|
| X | Microsoft | aim.exe | "Added by the RBOT-GRY WORM! Note - this is not the popular AOL Instant Messenger utility"
|
| X | Microsoft | Explorerr.exe | "Added by the IRCBOT-WG TROJAN!"
|
| X | Microsoft | kasperskyLive32.exe | "Added by the RBOT-GRT WORM!"
|
| X | Microsoft | msngerf.exe | "Added by the RBOT-GLW WORM!"
|
| X | Microsoft | netsrv.exe | "Added by the RBOT-GOS WORM!"
|
| X | Microsoft | rundll.exe | "Added by the RBOT-GSJ WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
|
| X | Microsoft | WinSecUp.exe | "Added by the RBOT-GPL WORM!"
|
| X | Microsoft | wsim32.exe | "Added by the RBOT-GTL WORM!"
|
| X | Microsoft | wplayer.exe | "Added by the IRCBOT-ABP TROJAN!"
|
| X | Microsoft | mdms.exe | "Added by the AGENT-GHY TROJAN!"
|
| X | Microsoft | Explorer.exe | "Added by a variant of the RBOT WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft | install.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft | internetdat.exe | "Added by the RBOT.ETY BACKDOOR!"
|
| X | Microsoft | ntsvr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft | schost.exe | "Added by the RBOT.FEH BACKDOOR!"
|
| X | Microsoft | soundvol32.exe | "Added by the RBOT.CIJ BACKDOOR!"
|
| X | Microsoft | sqlservice.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft | svhost.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft | winampaa.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft | winline.exe | "Added by the AGENT.KT TROJAN!"
|
| X | Microsoft | system32.exe | "Added by the IRCBOT-ZZ WORM!"
|
| X | Microsoft | winsys32.exe | "Added by the RBOT-GSQ WORM!"
|
| X | Microsoft | winnn.exe | "Added by the RANDEX.GGP WORM!"
|
| X | Microsoft | symtea.exe | "Added by the SPYBOT.AMTE WORM!"
|
| X | Microsoft | MicrosoftCorporation.exe | "Added by the KILLFILES.AED TROJAN!"
|
| X | Microsoft | firefox.exe | "Added by the RBOT-GVJ TROJAN! Note - this is not the popular FireFox web browser and is located in %System%"
|
| X | Microsoft (C) HTML Application host | [random filename] | "Added by the RBOT-YB WORM!"
|
| X | Microsoft (R) Windows Configuration Backup Service | svchost.exe | "Added by the RANKY.X TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in either a ""config"" |
| X | Microsoft (R) Windows DLL Loader | rundll32.exe | "Added by the RANKY.W TROJAN! Note - this is not the legitimate rundll32.exe process |
| X | Microsoft (R) Windows Network Latency Controller | 1.tmp | "Added by a generic password stealer TROJAN - see here"
|
| X | Microsoft (R) Windows Network Latency Controller | nlc.exe | "Added by a generic password stealer TROJAN - see here"
|
| X | Microsoft (R) Windows Network Latency Controller | sp2vc.exe | "Added by a generic password stealer TROJAN - see here"
|
| X | Microsoft (R) Windows Network Security Management Service | nsms.exe | "Added by the RANKY.LC TROJAN!"
|
| X | Microsoft (R) Windows Protected Content Restoration Service | services.exe | "Added by the AGENT.AGV BACKDOOR! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\etc"
|
| X | Microsoft (R) Windows Protocol Deployment Manager | [random].tmp | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft (R) Windows TCP/IP Socket Driver | [path to trojan] | "Added by the PROXY-DD TROJAN!"
|
| X | Microsoft (R) Windows TCP/IP Socket Layer | services.exe | "Added by the RBOT.ARM WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\winsock"
|
| X | Microsoft (R) Windows Update Service | wuauclt.exe | "Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft (R) Windows Vista/NT Runtime Compatibility Service | nrcs.exe | "Added by the RANKY.X TROJAN!"
|
| X | Microsoft .NET Confingurator | msnconf.exe | "Added by an unidentified VIRUS |
| X | Microsoft 16Bit Update | wuapdate16.exe | "Added by the RBOT.CZ WORM!"
|
| X | Microsoft 64 Bit Runtime Updater | wupdt64.exe | "Added by a variant of the RBOT WORM!"
|
| U | Microsoft ActiveSync | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| X | Microsoft ActiveX Debugger NT | [path to trojan] | "Added by the BANCOS-DO TROJAN!"
|
| X | Microsoft Admin Protocal | MSADNIN.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft ADservice | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Agent | mdss32.exe | "Added by the KEYLOG-AG TROJAN!"
|
| X | Microsoft Agent | svch0st.exe | "Added by the VB-DRO WORM!"
|
| X | Microsoft ALG32 Protocol | alg32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft ALGXP Protocol | alg32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft all | mmall.exe | Wopla.ac malware variant
|
| N | Microsoft Announcement Listener | Annclist.exe | MS WebTV for Windows. Used to display TV on your PC via a compatible video card with in-built tuner (such as ATI All-In-Wonder). If you don't use it - uninstall it
|
| X | Microsoft Ansti Update | msie.exe | "Added by the RBOT-LE WORM!"
|
| X | Microsoft Anti Virus Controller | msavc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Anti Virus Controller | msavc32.exe | "Added by the SDBOT.EPW BACKDOOR!"
|
| X | Microsoft Anti-Spy | [random filename] | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft AntiSpyware | Bazzi.exe | "Added by the AHKER.J WORM!"
|
| X | Microsoft AntiSpyware | KT06.pif | "Added by the IRCBOT.GEN WORM!"
|
| X | Microsoft AOL Instant Messenger | MSAOL32.exe | "Added by the RBOT-AAI WORM!"
|
| X | Microsoft AOL32 Protocol | aol32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Application Center | mappc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Application Manager | msapl32.exe | "Added by the BROPIA-AE TROJAN!"
|
| X | Microsoft AUT Update | MSlti32.exe | "Added by the RBOT-X WORM!"
|
| X | Microsoft AUT Update | MSlti16.exe | "Added by the RBOT.EB WORM!"
|
| X | Microsoft Authority Service | lsass.exe | "Added by the KALEL-D WORM! Note - this is not the legitimate lsass.exe process |
| X | Microsoft auto update | winupdate.exe | "Added by the BMBOT TROJAN!"
|
| X | Microsoft Auto Update | WINHLP16.EXE | "Added by the RBOT.GY WORM!"
|
| X | Microsoft auto update | wuauclt.exe | "Added by the CULT-B TROJAN! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft Automatic Update Serivce | msautou.exe | "Added by the RBOT-AOB WORM!"
|
| X | Microsoft Automatic Updater | Explorer.exe | "Added by the RBOT-SG WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft AutoUpdater | svhost.exe | "Added by the RBOT.QG WORM!"
|
| X | Microsoft Bool Value | MV2.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft boot system cfg32 | actboost.exe | "Added by the BROPIA.R WORM!"
|
| U | Microsoft Broadband Networking | MSBNTray.exe | Microsoft Broadband Networking Tray Application
|
| X | Microsoft Browser Services | Brwsr32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Browser Services | Brwsr64.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Buffer App | msbuffer.exe | "Added by the SLINBOT.NQ BACKDOOR!"
|
| X | Microsoft Cab Manager | exec.exe | "Affilred adware"
|
| X | Microsoft Cab Manager | cab.exe | "Added by the DELF-JJ TROJAN!"
|
| X | Microsoft Calculator | calc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft checker | MsPMSPTv.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Client | mshost.exe | "Added by the RBOT-AND WORM!"
|
| X | Microsoft Client | msclient.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Client Pc | spoolsrv.exe | "Added by the RBOT-AQM WORM!"
|
| X | Microsoft Client/Server Runtime Server Subsystem | csrs.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Client/Server Runtime Server Subsystem | csrssa.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Com Port Manager | svdhost.exe | "Added by the SDBOT-NI WORM!"
|
| X | Microsoft Command C | sshost.exe | "Added by the RBOT-CMK WORM!"
|
| X | Microsoft Command C | winhost32.exe | "Added by the SDBOT-BBA WORM!"
|
| X | Microsoft Command Line | wincmd.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Conf Ldr | sysconf.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | Microsoft ConfgKeys | wurmgrd32.exe | "Added by the RBOT-ARX WORM!"
|
| X | Microsoft Config | msconf.exe | "Added by the RBOT.PV WORM!"
|
| X | Microsoft Config | MSCONF.EXE | "Added by the RBOT-LG WORM!"
|
| X | Microsoft Config 32 | msconfigx32.exe | Reported as the MSCONFIGX32 TROJAN! Possible Rbot variant
|
| X | Microsoft Config 32bit | mscnfg32.exe | "Added by the RBOT-Z WORM!"
|
| X | Microsoft Config File | config.exe | Added by the KILLFILES.GR TROJAN! This is malware that will attempt to delete all system dlls!
|
| X | Microsoft Config Loader | msconfig32.exe | "Added by the AGOBOT.XX WORM!"
|
| X | Microsoft Config Loader | msrun32.exe | "Added by the AGOBOT-DY WORM!"
|
| X | Microsoft Config Loader | msconf32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Configoration Service | msconfigs.exe | "Added by the RBOT-ETT WORM!"
|
| X | Microsoft Configs 32 | msgconfigrs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Configuewe | msconfiguwe.exe | "Added by the SDBOT-BPK WORM!"
|
| X | Microsoft Configuration | msconfig32.exe | "Added by the SDBOT.MQ WORM!"
|
| X | Microsoft Configuration 35 | microsot1.exe | "Added by an unidentified TROJAN!"
|
| X | Microsoft Configuration Wizard | taskmrg.exe | "Added by the SDBOT-MX TROJAN!"
|
| X | Microsoft Configure 32 | msgconfigre.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Connection Manager Monitor | cmmon.pif | "Added by the RBOT-AKV WORM!"
|
| X | Microsoft Control Center | crtl.exe | "Added by the RBOT-VX WORM!"
|
| X | Microsoft Core Support | MSxUP32.exe | "Added by the RBOT-ANR WORM!"
|
| X | Microsoft Core Support | [random filename] | "Added by a variant of the RBOT TROJAN!"
|
| X | Microsoft Corp | svchost.exe | "Added by the PUSHBOT.QD WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Corp SQL Certificates | sqlcer.exe | "Added by the ZYBOT-C WORM!"
|
| X | Microsoft Corp SSL Certificates | windowz.exe | "Added by the RBOT-GCZ WORM!"
|
| X | Microsoft Corp TLS Certificates | msauth.exe | "Added by the RBOT-GAC WORM!"
|
| X | Microsoft Corp Updates | wupdates.exe | "Added by the RBOT-AUU WORM!"
|
| X | Microsoft Corp. Host Services | svchosl.exe | "Added by the RBOT-FMZ WORM!"
|
| X | Microsoft Corporaticn SQL Handler | sqlhandler.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Corporation | [random filename] | "Added by various VIRUSES |
| X | Microsoft Corporation | jview.exe | "Added by the RBOT-AOD WORM!"
|
| X | Microsoft Corporation Svchost Service | mssvc.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Microsoft Corporation Svchost Service | mswsc.exe | Added by the AGENT.MAB TROJAN!
|
| X | Microsoft Corporation SYM monitor | mssym.exe | "Added by the RBOT-GDB WORM!"
|
| X | Microsoft CP Web Manager | webcp.exe | "Added by the IRCBOT.HP TROJAN!"
|
| X | Microsoft CPU Over Heat Manager | CPU.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft CPXP Protocol | cpxp.exe | "Added by the RBOT.ATP WORM!"
|
| X | Microsoft Critical Services | svhhost.exe | "Added by the AGOBOT-AJA WORM!"
|
| X | Microsoft Crs Fix Serv | wincrs.exe | "Added by the SDBOT.BWF WORM!"
|
| X | Microsoft CRT Monitor Manager | crtmon.exe | "Added by the ROBOTON.A WORM!"
|
| X | Microsoft CSRSS Service | nsmscrs.exe | "Added by the RBOT-BPT WORM!"
|
| X | Microsoft CSRSS32 Protocol | csrss32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft CSRSS386 Protocol | csrss386.exe | "Added by a variant of the SPYBOT WORM!"
|
| U | Microsoft CTF Loader | ctfmon.exe | "Supports multiple languages and alternative method inputs in Windows and MS Office. The language bar is displayed alongside the System Tray if more than one keyboard layout is enabled (for switching input languages) or |
| X | Microsoft Cvrt | mscvrt32.exe | "Added by an unidentified VIRUS |
| X | Microsoft Data Helper | cihost.exe | "Malware |
| X | Microsoft Data Machine | csdata32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Database Handler | mssql32.exe | "Added by the RANDEX.AX WORM!"
|
| X | Microsoft Datalog Application | msdata.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft DDE Control | wupades.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft DDEs Control | Erun.pif | "Added by the RBOT-AMU WORM!"
|
| X | Microsoft Debug Manager Console | mdm32.exe | "Added by the AGOBOT-AQ WORM!"
|
| X | Microsoft Debug Service | dbgbgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Decryption Technology | Msfenoe.exe | "Added by the SPYBOT-DG WORM!"
|
| U | Microsoft Default Manager | DefMgr.exe | "Part of MSN Toolbar from version 4.* onwards (renamed ""Bing Bar"" from version 5.* onwards) which includes the Bing search engine. Via Start → All Programs → Microsoft Default Manager you can elect to keep Bing as the default search engine and set it to notify you of any changes to your browsers default settings. Not required if you choose not to use Bing"
|
| X | Microsoft Desktop Manager | msdesk32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Dev | iexplorer32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Development Debugger | msdev.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Development Services | msdevelop.exe | "Added by the RBOT-FWS WORM!"
|
| X | Microsoft Device Manager | msdevmgr32.exe | "Added by the LATEDA.B TROJAN!"
|
| X | Microsoft Device Manager | mscmtl32.exe | "Added by the AGENT.BMQ BACKDOOR!"
|
| X | Microsoft Device Manager | svcswin.exe | "Added by the IRCBOT-YH TROJAN!"
|
| X | Microsoft Diagnostic | [random filename] | "Added by the ACEBOT TROJAN!"
|
| X | Microsoft Diagnostic | msdiag32.exe | "Added by the RBOT-UC WORM!"
|
| X | Microsoft Digital Clock | msclock.exe | "Added by the NACKBOT-D WORM!"
|
| X | Microsoft Digital Cryptors | mdigits.exe | "Added by the SDBOT.LM WORM!"
|
| X | Microsoft DirectX | Spoolserv.exe | "Added by the DINFOR WORM!"
|
| X | Microsoft DirectX | rasmngr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft DirectX | PDSched.exe | "Added by the SDBOT.CN WORM!"
|
| X | Microsoft DirectX | wuamgrd.exe | "Added by the SDBOT.MY WORM!"
|
| X | Microsoft DirectX | time123.exe | "Added by the SDBOT.MD WORM!"
|
| X | Microsoft Directx | directxat.exe | "Added by the SDBOT-BXF WORM! Note - disables autostart for the SharedAccess service and deactivates the Microsoft Internet Connection Firewall (ICF)"
|
| X | Microsoft DirectX | wupdate.exe | "Added by the RBOT-L WORM!"
|
| X | Microsoft Directx click | directxclick.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Directx clicks | directxclickers.exe | "Added by the RBOT-GHT WORM!"
|
| X | Microsoft Directx push | directxpushup.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Directxsp | directxbt.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft Directxspnew | directxnew.exe | "Added by a variant of the RBOT-GHT WORM!"
|
| X | Microsoft DirktorWin | [random filename] | "Added by the SPYBOT.GEN3 TROJAN!"
|
| X | Microsoft Disk Scanner | scansdisk.exe | "Added by the WOOTBOT.DT WORM!"
|
| X | Microsoft DLL | fumeta.exe | "Added by the RBOT-AUG WORM!"
|
| X | Microsoft Dll | runapidll.exe | "Added by the RBOT-GRG WORM!"
|
| X | Microsoft DLL Authentification | dllsecure.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Extensions | SystemDll.exe | "Added by the RBOT-ADV WORM!"
|
| X | Microsoft dll Host Service | wkssr.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft DLL Host Service | dllmemhost.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Host Service | svcdllhst.exe | "Added by the AGENT.EAK TROJAN!"
|
| X | Microsoft dll Host Service | svchost.exe | "Added by the RBOT.BMS BACKDOOR! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft DLL Library | winlib32.exe | "Added by the ATNAS.A WORM!"
|
| X | Microsoft Dll Management | windll.exe | "Added by the RBOT-MT WORM!"
|
| X | Microsoft Dll Manager | microsoft32dll.exe | "Added by the SHEUR.LH TROJAN!"
|
| X | Microsoft DLL Manager | dllmgr.exe | "Added by the SDBOT-KJ WORM!"
|
| X | Microsoft DLL Monitor | dllmon32.exe | "Added by the AGENT.WP WORM!"
|
| X | Microsoft DLL Monitor | dllmon64.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Monitor | dllmonitor.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Dll Printer Manager | dllpt.exe | "Added by the SDBOT.BIH WORM!"
|
| X | Microsoft DLL Service | servicedll.exe | "Added by the IRCBOT.OX BACKDOOR!"
|
| X | Microsoft DLL Service | svcdll.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft DLL Source | dllsrc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft DLL Verifier | file.exe | "Added by the RBOT-AED WORM!"
|
| X | Microsoft DLL Verifier | chkfile.exe | "Added by the RBOT-AOC WORM!"
|
| X | Microsoft DLL Verifier | csrssv.exe | "Added by the RBOT-ATK WORM!"
|
| X | Microsoft DLL Verifier | mscon.exe | "Added by the SDBOT.EAH WORM!"
|
| X | Microsoft DLL Verifier | winavguard.exe | Added by the SDBOT.AAD WORM!
|
| X | Microsoft DLL Verifier | wns.exe | "Added by the SPYBOT-LA WORM!"
|
| X | Microsoft DLLSet32 | dllset32.exe | "Added by the RBOT.OZ WORM!"
|
| X | Microsoft DNS Host Resolution | hostres.exe | "Added by the AGOBOT-MK BACKDOOR!"
|
| X | Microsoft DNS Query | msdns.exe | "Added by the AGENT-BS TROJAN!"
|
| X | Microsoft DNSx | mdnex.exe | "Added by the DELBOT-AI WORM!"
|
| X | Microsoft Document | krisp.exe | "Added by the SDBOT-RQ WORM!"
|
| X | Microsoft Domain Controller | mstc.exe | "Added by the NUGACHE.A WORM!"
|
| X | Microsoft Driver | faet.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Driver Control | windrv.exe | "Added by the SDBOT.FW WORM!"
|
| X | Microsoft Driver Manager | mswindrv.exe | "Added by the FORBOT-EZ WORM!"
|
| X | Microsoft Driver Setup | msddrv42.exe | "Added by the PALEVO WORM!"
|
| X | Microsoft Driver Setup | Jwrb.exe | "Added by the AUTORUN-AOB WORM!"
|
| X | Microsoft Driver Setup | dllhost.exe | "Added by the AUTORUN-AOZ WORM!"
|
| X | Microsoft Driver Setup | sysmngsr322.exe | "Added by the BUZUS-AS TROJAN!"
|
| X | Microsoft Driver Setup | w7services.exe | "Added by the AUTORUN-ARJ WORM!"
|
| X | Microsoft Driver Setup | mslsrv32.exe | "Added by the SDBOT-DPF TROJAN!"
|
| X | Microsoft Driver Setup | ccdrive32.exe | "Added by the AGENT-LYL TROJAN!"
|
| X | Microsoft Driver Setup | cidrive32.exe | "Added by the AGENT-NES TROJAN!"
|
| X | Microsoft driver update | Mshome.exe | Added by the SDBOT.BL WORM!
|
| X | Microsoft Drivers | WSconf.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft ErgoPack | wserb32.exe | "Added by the RBOT-RI WORM!"
|
| X | Microsoft EV32 Service | MSev32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Event Engine | EvtEngn.exe | "Added by the RBOT-XV WORM!"
|
| X | Microsoft Excel | msexcel.exe | "Added by the RBOT-TQ WORM!"
|
| X | Microsoft Excele | msmsgs.exe | "Added by the AGENT.AJQG TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
|
| X | Microsoft Excell | wuamngr32.exe | "Added by the RBOT-QH WORM!"
|
| X | Microsoft Executing | microsoft.exe | "Added by the AGOBOT.UV WORM!"
|
| X | Microsoft Explorer | svapache.exe | "Added by the RBOT-VR WORM!"
|
| X | Microsoft Explorer | explorer.scr | "Added by the RBOT-ADH WORM!"
|
| X | Microsoft Explorer | explorer.pif | "Added by the SDBOT-ACX WORM!"
|
| X | Microsoft Explorer | explorer.exe | "Added by the POEBOT-LY WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft Explorer Service | msexplore.exe | "Added by the IRCBOT.AYB BACKDOOR!"
|
| X | Microsoft explorer Update | internal.exe | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft Explorer(64) | explorer64.exe | "Added by the SPYBOT-R WORM!"
|
| X | Microsoft Explorer2 | system.exe | "Added by the IRCBOT.BS TROJAN!"
|
| X | Microsoft Explorer2 | nome.exe | "Added by the RANDEX.AA WORM!"
|
| X | Microsoft Explorer2 | bitchbot.exe | "Added by the SDBOT.EV WORM!"
|
| X | Microsoft EXPLOREXP Protocol | explorexp.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Features | ms32cfg.exe | "Added by the RBOT.HO WORM!"
|
| X | Microsoft Features | msie.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft File Demand Manager | wmgrdf.exe | "Added by a variant of the RBOT WORM!"
|
| N | Microsoft Find Fast | Findfast.exe | From older versions of MS Office - searches disk drives for Office file types and creates an index to make opening them easier. When indexing is in progress it can use lots of CPU time and memory - especially on slower/older machines
|
| X | Microsoft Firewall | firewallsp2.exe | "Added by the RBOT-MC WORM!"
|
| Y | MICROSOFT FIREWALL CLIENT | ISATRAY.EXE | "MS Internet Security and Acceleration Server - see here"
|
| X | Microsoft FixUp | pevblbvr.exe | "Added by the RBOT.DWK WORM!"
|
| X | Microsoft FixUp | wnpzjpuw.exe | "Added by a variant of the SDBOT WORM!"
|
| X | microsoft frontpage | twain.exe | "Added by the AGENT.AQO TROJAN!"
|
| X | Microsoft Games | gamemanager.exe | "Added by the SPYBOT.AHQ WORM!"
|
| X | Microsoft Generic Update Manager | wupdate.exe | "Added by the RBOT-AWC TROJAN!"
|
| X | Microsoft Genetic Procress | svchost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Genuine Logon | msnmsg.exe | "Added by the IRCBOT-XH WORM!"
|
| X | Microsoft Genuine Logon | svchost.exe | "Added by the SDBOT.EXT WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | MicroSoft Getway Dire | [random filename] | "Added by the IRCBRUTE.AM WORM!"
|
| X | MicroSoft Getway mqbol | [12 random letters].exe | "Added by the RBOT.GBA WORM!"
|
| X | Microsoft Gina V Encryption | MSGINAV.EXE | "Added by an unidentified VIRUS |
| N | Microsoft Greetings Reminder | MHPRMINF.EXE | You really want to be reminded about somebody's birthday at the expense of resources?
|
| N | Microsoft Greetings Reminders | MHPRMIND.EXE | Microsoft Home Publishing greetings reminder
|
| N | Microsoft Greetings Workshop Reminder | Gwremind.exe | You really want to be reminded about somebody's birthday at the expense of resources?
|
| X | Microsoft HDCP for NT | msdhcp.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft HDCP for NT and Win9x | msdhcprs.exe | "Added by a variant of the PEERBOT WORM!"
|
| X | Microsoft Help | svh0st.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Help | svchosl.exe | "Added by the AGENT-GPX TROJAN!"
|
| X | Microsoft Help Support | mshelp32.exe | "Addded by the KELVIR-BF WORM!"
|
| X | Microsoft Help SVC | msnmngr.exe | "Added by the SDBOT-PQ WORM!"
|
| X | Microsoft Help System | mshelp32.exe | "CoolWebSearch parasite variant"
|
| X | Microsoft Helpdesk Side | mshelpdsk.exe | "Added by the SPYBOT.ANJJ WORM!"
|
| X | Microsoft Host Protocol | svhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Hosting Service | WINHOSTING.EXE | "Added by the RBOT.AEV WORM!"
|
| X | Microsoft Hosts Service | Isass.exe | "Added by a variant of the RBOT WORM!"
|
| X | microsoft hotmail monitor | mshotmon.exe | "Added by the MYTOB-FL WORM!"
|
| X | Microsoft hren1 | mmhren1.exe | Added by a variant of the AGENT.IWW TROJAN!
|
| X | Microsoft Hyptertext Helper | mshtha.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft IDCN | mshe1p.exe | Added by an unidentified TROJAN!
|
| X | Microsoft IE | Iexplore.exe | "Added by the FORBOT-AG WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Microsoft IE Execute shell | IEExec.exe | "Added by the ALADINZ.N TROJAN!"
|
| X | MicroSoft IE Sasser | ISASS.EXE | "Added by the SDBOT.MX WORM!"
|
| X | Microsoft IIS | syshost.exe | "Added by the FRANCETTE WORM!"
|
| X | Microsoft IIS | [filename] | "Added by the FRANCETTE-S WORM!"
|
| U | Microsoft IME 2002 | IMJPMIG.EXE | "Microsoft's Input Method Editor for the Japanese language which is used to both display and enable the input of characters in e-mails |
| X | Microsoft Inc. | iexplorer.exe | "Added by the LOVGATE.E WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Microsoft Inc. | iexplorer.exe... | "Added by the LOVGATE.AO WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Microsoft Incroporate | mfs.exe | "Added by the RBOT-ANF WORM!"
|
| X | Microsoft Inet Xp.. | teekids.exe | "Added by the BLASTER.C WORM!"
|
| X | Microsoft Information | securenet.exe | "Added by the SDBOT.AJM WORM!"
|
| X | Microsoft Information Check | microsoft.exe | "Added by the IRCBOT.AUH TROJAN!"
|
| X | Microsoft Initialization Service | initsvc.exe | "Added by the IRCBOT.AXK BACKDOOR!"
|
| X | Microsoft Initialization Services | initserv.exe | "Added by the IRCBOT-ABO TROJAN!"
|
| X | Microsoft Install Shield Services | rundll64 | "Added by the RBOT-FSH WORM!"
|
| X | Microsoft Installshield | nundll32.exe | "Added by the AGOBOT-AHZ WORM!"
|
| X | Microsoft Instant Messenger | msngmsngr32.exe | "Added by the SPYBOTER.GEN TROJAN!"
|
| X | Microsoft Int Service | MsIntSrv.exe | "Added by a variant of the RBOT WORM!"
|
| U | Microsoft IntelliPoint | ipoint.exe | "Microsoft IntelliPoint utility (from version 5.5) - required to support the programmable buttons and additional features on Microsoft's range of mice |
| U | Microsoft IntelliPoint | point32.exe | "Microsoft IntelliPoint utility (up to version 5.4) - required to support the programmable buttons and additional features on Microsoft's range of mice |
| U | Microsoft Intellitype Pro | speedkey.exe | Additional keyboard shortcuts on MS programmable keyboard
|
| U | Microsoft IntelliType Pro | itype.exe | "Microsoft IntelliType Pro utility (from version 5.5) - required to support the multimedia keys |
| U | Microsoft IntelliType Pro | type32.exe | "Microsoft IntelliType Pro utility (up to version 5.4) - required to support the multimedia keys |
| X | Microsoft Internal AntiVirus Systems | dIlhost.exe | "Added by the RBOT-AEV WORM!"
|
| X | Microsoft Internel Corporat | netvhost.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Internel Corporat | smbvhost.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Internet | expl0rer.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Internet | windows32.exe | "Added by the SDBOT-F WORM!"
|
| X | Microsoft Internet | wincfg16.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Internet Acceleration Utility | iau.exe | "EasySearch adware"
|
| X | Microsoft Internet Acceleration Utility | [path to file] | "Added by the AGENT-CX TROJAN!"
|
| X | Microsoft Internet Acceleration Utility | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Microsoft Internet Antivirus Protection | antivirus.exe | "Detected by Kaspersky as the IRCBOT.BSK TROJAN!"
|
| X | Microsoft Internet Dumping Protocol | inetdump.exe | "Added by the IRCBOT.BLL BACKDOOR!"
|
| X | Microsoft Internet Exp | iiexplorer.exe | "Added by the RBOT-KX WORM!"
|
| X | Microsoft Internet Explorer | iexplore.exe | "Added by the POEBOT-J WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%"
|
| X | Microsoft Internet Explorer | iexplorer.exe | "Added by the SDBOT-XN WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Microsoft Internet Explorer | crsys32.exe | "Added by the RBOT.UZ WORM!"
|
| X | Microsoft Internet Explorer | movies.exe | "Added by the BANCOS-DZ TROJAN!"
|
| X | Microsoft Internet Explorer | svzhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Internet Explorer | mccagent.exe | "Added by the DLOADER-UD TROJAN!"
|
| X | Microsoft Internet Explorer | sysini.exe | "Added by the DELF-LN TROJAN!"
|
| X | Microsoft Internet Explorer | svchost.exe | "Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
|
| X | Microsoft Internet Explorer | lEXPLORE.EXE | "Added by the RBOT-AMM WORM! Note - the executable is spelt with a lower case ""L"" rather than an lower or upper case ""i"" which is the case with Internet Explorer"
|
| X | Microsoft Internet Explorer | svchosts.exe | "Added by the BANCBAN-U TROJAN!"
|
| X | Microsoft Internet Explorer | [path to trojan] | "Added by the BANCBAN-AS TROJAN!"
|
| X | Microsoft Internet Explorer | msngrt.exe | "Added by the SDBOT-GU BACKDOOR!"
|
| X | Microsoft Internet Explorer | _svchost.exe | "Added by the TINY.LX TROJAN!"
|
| X | Microsoft Internet Explorer Manager | ie.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Internet Explorer Update | ieupdate.exe | "Added by the SHEUR.MH TROJAN!"
|
| X | Microsoft Internet Firewall | firewall.exe | "Added by the IRCBOT.MD BACKDOOR! Located in %System%"
|
| X | Microsoft Internet Firewall Manager | GMT16.exe | "Added by the RANDEX.AT WORM!"
|
| X | Microsoft Internet Firewall Update | updater.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Internet Services | Smss32.exe | "Added by the RBOT.MS WORM!"
|
| X | Microsoft Internet Syncing | inetsync.exe | "Added by the IRCBOT.BLL BACKDOOR!"
|
| X | Microsoft Intrenet Explorer | goaw.pif | "Added by the RBOT-API WORM!"
|
| X | Microsoft Intrenet Explorer | Soundsyst.exe | "Added by the RBOT-AQU WORM!"
|
| X | Microsoft Intrenet Explorer | cnsg.pif | "Added by the RBOT-ARO WORM!"
|
| X | Microsoft Intrenet Explorer | wcumrg.exe | "Added by the SDBOT-AFD WORM!"
|
| X | Microsoft IPC | system.exe | "Added by the NULLBOT TROJAN!"
|
| X | Microsoft IPC | svshost.exe | "Added by an unidentified VIRUS |
| X | Microsoft IT Update | win64.exe | "Added by the RBOT.GA WORM!"
|
| X | Microsoft IT Update | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft IT Update | IEserv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft IT Update | msupdate.exe | "Added by the RBOT-FE WORM!"
|
| X | Microsoft IT Update | winn43.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft IT Update | svchsst.exe | "Added by the RBOT-DH WORM!"
|
| X | Microsoft IT Update | win43.exe | "Added by the RBOT-SA WORM!"
|
| X | Microsoft IT Update | windows.exe | "Added by the RBOT-JM WORM!"
|
| X | Microsoft IT Update | winsyst32.exe | "Added by the RBOT-FC WORM!"
|
| X | Microsoft IT Update | Rhost32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Java Virtual Machine | MsConfiG.exe | "Added by the FORBOT-DV WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
|
| X | Microsoft Java Virtual Machine | msjvm.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Java Virtual Machine | javavm.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Java Virtual Machine | msjavarxp.exe | "Added by the FORBOT-DL WORM!"
|
| X | Microsoft Java Virtual Machine | winscr32.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Microsoft Java Windows Update | [filename] | "Added by the RBOT-DZ WORM!"
|
| X | Microsoft JavaVM | msjarun.exe | "Added by the RBOT-JW WORM!"
|
| X | Microsoft Kernel | Windows_kernel32.exe | "Added by the NETSKY.AE WORM!"
|
| X | Microsoft Keyboard Enhance 2.0. | iasrecst.exe | "Added by the BCKDR-QIL BACKDOOR!"
|
| X | Microsoft Keyboard Enhance V2.0 | iasrecst.exe | "Detected by F-Prot as the DOWNLOADER2.AILI TROJAN!"
|
| X | Microsoft Kinetik Svc | msftksvc.exe | "Added by the AGENT.AGDO TROJAN!"
|
| X | Microsoft LAN32 Protocol | lanXp.exe | "Added by the RBOT-SS WORM!"
|
| X | MicroSoft Legal Service | Srb0ty.exe | "Added by the SPYBOT.HW WORM!"
|
| X | MicroSoft Legal Syst3m32 | Syst3m32.exe | "Added by the RBOT.UYL WORM!"
|
| X | Microsoft Lmhosting Service | lmhosts.exe | "Added by the RBOT-RC WORM!"
|
| X | Microsoft Locals 332 | [random filename] | "Added by the RBOT-KU WORM!"
|
| X | Microsoft Locals466 | xagwxzy.exe | "Added by the SPYBOT.EL WORM!"
|
| U | Microsoft Location Finder | LocationFinder.exe | "Microsoft Location Finder ""is a client-side application that turns a regular WiFi enabled laptop |
| X | Microsoft Login | winlogin.exe | "Added by the RBOT-AJP WORM!"
|
| X | Microsoft Logins | winlogins.exe | "Added by the SPYBOT.BCZ WORM!"
|
| X | Microsoft Logon User Interface | logonnui.exe | "Added by the RBOT-BCC WORM!"
|
| X | Microsoft LSA layer | MSLSA32.exe | "Added by the RBOT-AKZ WORM!"
|
| X | Microsoft Lsass Center | Isass.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Lsass Center | telecomes.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Lsass Manager | lsass.exe | "Added by a variant of the SDBOT WORM! Note - this is not the legitimate lsass.exe process |
| X | Microsoft Lsass Service | wintcp32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft LSASS386 Protocol | scvhost32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft LV | [path to file] | "Added by the BDOOR-BDL BACKDOOR!"
|
| X | Microsoft Machine | winjava.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft machine | blah.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft machine | scvhost.exe | "Added by the RBOT.AEU TROJAN!"
|
| X | Microsoft Machine | updata.exe | "Added by the RBOT-DJ WORM!"
|
| X | Microsoft Machine | temp.exe | "Added by the RBOT-FSQ WORM!"
|
| X | Microsoft Machine | winxp43.exe | "Added by the RBOT-IA WORM!"
|
| X | Microsoft machine | arcpack.scr.exe | "Added by the RBOT.ADF BACKDOOR!"
|
| X | Microsoft Machine Script | iexplorersis.exe | "Added by the RBOT-CMH WORM!"
|
| X | Microsoft MachineUpdatese | tempes.exe | "Added by the RBOT.EWN BACKDOOR!"
|
| X | Microsoft Macro Protection SubSsy | msacroprots386.exe | "Added by the RBOT-KE WORM!"
|
| X | Microsoft Macro Protection Subsystems | msmacroprotxz.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Macro Protection Subsystems | Msmacroprot32.exe | "Added by the RBOT.KN WORM!"
|
| X | Microsoft Manage Services | sychost.exe | "Added by the SLENFBOT.AD WORM!"
|
| X | Microsoft Manage Services | schost.exe | "Added by the SLENFBOT.B WORM!"
|
| X | Microsoft Management | lmas.exe | "Added by the FORBOT-CZ WORM!"
|
| X | Microsoft Management Console | lssas.exe | "EasySearch adware"
|
| X | Microsoft Management Console | [path to trojan] | "Added by the SMUTSRCH-A TROJAN!"
|
| X | Microsoft Management Console | lssas1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| X | Microsoft Manager | msmanager.exe | "Added by the MYTOB.LF WORM!"
|
| X | Microsoft Map PC | mappc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Mapped PC | mappedpc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft media | winmplayers.exe | "Added by a variant of the SPYBOT WORM!"
|
| U | Microsoft Media Center Tray Applet | ehTray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| X | Microsoft Media Manager | medman.exe | "Added by the RBOT.EUZ WORM!"
|
| X | Microsoft Media player 9 | msmedia32.exe | "Added by the RBOT-ADO WORM!"
|
| X | Microsoft media services | Iassd.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft media services | winmplayer.exe | "Added by the RBOT.ZO WORM!"
|
| X | Microsoft MediaScope | winmes.exe | "Added by the RBOT-XU WORM!"
|
| X | Microsoft Memory Dumping Protocol | memdump.exe | "Added by the IRCBOT.BJK BACKDOOR!"
|
| X | Microsoft Memory Flow Cycle | flowcycle.exe | "Added by the IRCBOT.WAD BACKDOOR!"
|
| X | Microsoft Memory Flow Cycle | flowcycles.exe | "Added by the WAREZOV.AAK WORM!"
|
| X | Microsoft Message Machine | msmesg32.exe | "Added by the SPYBOT.BI WORM!"
|
| X | Microsoft Messenger Management Controls | msmgmctl.exe | "Added by the RBOT-APA WORM!"
|
| X | Microsoft messenger sd | msngersd.exe | Added by an unidentified TROJAN!
|
| X | Microsoft Messenger Service | msmsg32.exe | "Added by the RBOT.BOK WORM!"
|
| X | Microsoft Messenger XP | MSMSN32.exe | "Added by the RBOT-ZP WORM!"
|
| X | Microsoft MicroP Protocol | wdgmr32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Ming Service | ming.exe | "Added by the RBOT-AWS WORM!"
|
| X | Microsoft Movie Maker | Mmaker.exe | "Added by the IRCBOT.C TROJAN! Note that this is not a valid Microsoft program"
|
| X | Microsoft MSGPLUS32 Protocol | msgplus32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft MSN 7 Services | msnmsg.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft MSN 7 Services | msnmsger.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft MSN Messenger | msnmnsgr.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Msn Messenger | msmsgs.exe | "Added by the BUZUS.AYX TROJAN! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
|
| X | Microsoft MSN Services | msnsm.exe | "Added by the RBOT.ARV BACKDOOR!"
|
| X | Microsoft MSNGR32 Protocol | msngr32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft msnseru | msnseru.exe | "Added by the RBOT-APB WORM!"
|
| X | Microsoft MsnST | msnst32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft MSUPDATE | SpoolSvc.exe | "Added by the SXTB-A TROJAN!"
|
| X | Microsoft Neser Experience | nese.exe | "Added by the RBOT-YH WORM!"
|
| X | Microsoft Netview | gesfm32.exe | "Added by the RANDEX.C WORM!"
|
| X | Microsoft Netview | mssvc32.exe | "Added by an unidentified VIRUS |
| X | Microsoft Netview Component v5.1 | msnv32.exe | "Added by the RANDEX.F WORM!"
|
| X | Microsoft Network | msnet.exe | "Added by the MOCKBOT.A WORM!"
|
| X | Microsoft Network | Networksystem.exe | "Added by the SDBOT-AAI WORM!"
|
| X | Microsoft Network Daemon for Win32 | Netd32.exe | "Added by the SDBOT.R TROJAN!"
|
| X | Microsoft Network Host | svc0host.exe | "Added by the SDBOT-AEN WORM!"
|
| X | Microsoft Network Neighbourhood | networknbh.exe | "Added by the RBOT.DMN WORM!"
|
| X | Microsoft Network Services Controller | mmsvc32.exe | "Added by the NANPY-A WORM!"
|
| X | Microsoft Networking Agent For SP2 | msnac32.exe | "Added by the SPYBOT.PEN WORM!"
|
| X | Microsoft Nod32 Service | nood32.exe | "Added by the RBOT.EJP WORM!"
|
| X | Microsoft Norotn Anti Virus | mnhpot.exe | "Added by the RBOT-GRO WORM!"
|
| X | Microsoft Norton Antivirus | norton.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft NotePad | notepad.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft NT Drivers | ntdrv.exe | Added by the SDBOT.AJN TROJAN!
|
| X | Microsoft NT Update | winexec32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Nvidia Video | nvidia.exe | "Added by a variant of the SDBOT WORM!"
|
| N | Microsoft Office | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| N | Microsoft Office | Msoffice.exe | Feature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
|
| X | Microsoft Office | MSMSGR.exe | "Added by the GAOBOT.BB WORM!"
|
| N | Microsoft Office | Osa9.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft Office | lserv.exe | "Added by the SDBOT.MH WORM!"
|
| X | Microsoft Office | Microsoft Office.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
|
| X | Microsoft Office | msoicons.exe | "Added by the RBOT-ZI WORM! - NOTE - do no confuse with the legitimate Msoicons.exe file described here. The latter wil not be listed among your startups!"
|
| X | Microsoft Office | Nxcao.exe | "Added by the RBOT-ZE WORM!"
|
| X | Microsoft Office | nxcxtpr.exe | "Added by the RBOT-YG WORM!"
|
| X | Microsoft Office | svxhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Office | msoffice32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Office | msoff.exe | "Added by the RAKER-C TROJAN!"
|
| X | Microsoft Office | microsoft.exe | "Added by the BANKER-VF TROJAN!"
|
| X | Microsoft Office | msvcp.exe | "Added by the AGENT-XK TROJAN!"
|
| X | Microsoft Office | msmsgr.exe | "Added by the GAOBOT.BB WORM!"
|
| X | Microsoft Office | mdm.exe | "Added by the IBOT-A TROJAN! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| U | Microsoft Office 2010 | BCSSync.exe | "Part of SharePoint Server 2010 which is part of the Microsoft Office 2010 suite. ""Business Connectivity Services (BCS) uses a cache to store a copy of the external data required by the BCS solutions deployed on the Office client. A process called BCSSync.EXE runs on the client and provides automatic cache refresh and data synchronization of the entity instances."" For more information - see here"
|
| N | Microsoft Office Fast Cache | Fastboot.exe | "Part of MS Office 95 (v7.0). According to this it improves the performance. Most likely a predecessor of MS Find Fast and can be disabled"
|
| U | Microsoft Office Groove | GROOVE.EXE | "System Tray access to and alerts for MS Office Groove - a stand-alone product or included with the Enterprise/Ultimate versions of MS Office 2007. ""A collaboration software program that helps teams work together dynamically and effectively |
| X | Microsoft Office Monitor | alg2k.exe | "Added by the SDBOT-CZO WORM!"
|
| X | Microsoft Office Monitor | aql32.exe | "Added by the RBOT-GCY TROJAN!"
|
| N | Microsoft Office OneNote | ONENOTEM.EXE | "System Tray access to MS Office OneNote 2003 & 2007 - an electronic notebook that allows you to create free-form notes |
| N | Microsoft Office OneNote 2003 Quick Launch | ONENOTEM.EXE | "System Tray access to MS Office OneNote 2003 - an electronic notebook that allows you to create free-form notes |
| X | Microsoft Office quick launch | OSA.exe | "Added by the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
|
| X | Microsoft Office Quick Launcher | iau1.exe | "Added by the DLOADR-AWD TROJAN!"
|
| N | Microsoft Office Shortcut Bar | Msoffice.exe | Feature included with older versions of MS Office giving you access to common Office functions and optional shortcuts to Office (and other) programs. Some people prefer it but a better way is to create desktop shortcuts if you want access these features and programs quickly. Also available via Start → All Programs
|
| X | Microsoft Office Start | winupdates.exe | "Added by the GAOBOT.BC WORM!"
|
| N | Microsoft Office Startup | osa.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| N | Microsoft Office Startup | Osa9.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft Office Studio | scvhvst.exe | "Added by the RANDEX.CST WORM!"
|
| X | Microsoft OfficeXP | officeXP.exe | "Added by the KILLAV.MA WORM!"
|
| X | Microsoft Oftice | msmsgs.exe | "Added by the IRCBOT.ALT WORM! Note - this particular msmsgs.exe file is located in %System% and should not be mistaken for the MSN Messenger file of the same name which is located in %Program Files%\Messenger"
|
| X | MicroSoft OneCare | FreeS3x.exe | "Added by the SDBOT-DJT WORM!"
|
| X | Microsoft Opeions | IEXwe.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Outlook Express Protocol | svchst.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Patch Update | bootini.exe | "Added by the RBOT-FMN WORM!"
|
| X | Microsoft PC Health Remote Assistance File Open & Save controls | sfrcdlg32.exe | "Added by the RBOT-AVY WORM!"
|
| X | Microsoft PCHealth32 | [path to file] | "Added by the NICE-A TROJAN!"
|
| X | Microsoft PCHealth32 | NDDENB.exe | "Added by the PWSYAHOO-A TROJAN!"
|
| X | Microsoft PCI Manager | mspci.exe | "Added by the RBOT.BBG WORM!"
|
| N | Microsoft People Near Me | p2phost.exe | "Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
|
| X | Microsoft Personal Firewalls | bakw.exe | "Added by the RBOT-KS WORM!"
|
| X | Microsoft Problem Doctor | windr128.exe | "Added by the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Problem Doctor | windr32.exe | "Added by a variant of the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Problem Doctor | windr64.exe | "Added by a variant of the SMALLTRO.EF TROJAN!"
|
| X | Microsoft Proc Driver32 | msprc.exe | "Added by a variant of the WOOTBOT WORM!"
|
| X | Microsoft Procedure Call | MSPCALL.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Process Manager | process32.exe | "Added by the CHECKOUT WORM!"
|
| X | Microsoft Profile Manager | profile.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft PSTCP32 Data | pstcp32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft QMGR | msnqmgr.exe | "Added by the IRCBOT-S TROJAN!"
|
| X | Microsoft quick launch | OSA.exe | "Added by a variant of the VBOT.A BACKDOOR! Note that OSA.exe was used in older versions of Office to launch common components to help speed up the launch but it is no longer normally used - see here. This file is located in a valid MS Office 2003 (aka Office 11) directory - %Program Files%\Microsoft Office\OFFICE11 - and may overwrite a valid file"
|
| X | Microsoft RDLL | sysconf32.exe | "Added by a variant of the SDBOT TROJAN!"
|
| X | Microsoft Redirect | [path to file] | "Added by the BANKER-FW TROJAN!"
|
| X | Microsoft Redirect | systen.exe | "Added by the BANCOS-FO TROJAN!"
|
| X | Microsoft Regestry Edit Manager | regedit.exe | "Added by the SHEUR.HC TROJAN! Note - this is not the valid Windows registry editor which resides in %Windir% and will not normally figure in Msconfig/Startup! This version resides in %System%"
|
| X | Microsoft Regestry Manager | regedit32.exe | "Added by a variant of the IRCBOT.ARD WORM!"
|
| X | Microsoft Regestry Manager | registry32.exe | "Added by the IRCBOT.ARD WORM!"
|
| X | Microsoft Registro | svchostt.exe | "Added by the BANCOS-DH TROJAN!"
|
| X | Microsoft Registry | csrse.exe | "Added by the RBOT-PC WORM!"
|
| X | MicroSoft Remote Secure Service | MSRSS.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Restore | scrgrd.exe | "Added by the SPYBOT.BR WORM!"
|
| X | Microsoft Router Manager | linksys.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Router Manager | router.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Rundll | windos.exe | "Added by the SDBOT-WF WORM!"
|
| X | Microsoft Runtime | CfgDll32.exe | "Added by the RANDEX.BD WORM!"
|
| X | Microsoft Safe Mode Manager | safemode.exe | "Added by the IRCBOT.HM BACKDOOR!"
|
| X | Microsoft Scanreg | microsoftscanreg.exe | "Added by the FRANRIV.A WORM!"
|
| X | Microsoft SCVHOST32 Protocol | scvhost32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft sddcE Contol | taskmnegr.exe | "Added by the RBOT-AUM WORM!"
|
| X | Microsoft sddcE Contol | taskmn.exe | "Added by the RBOT-BJZ WORM!"
|
| X | Microsoft sdk temp | sdktemp.exe | "Added by the RBOT-ANP WORM!"
|
| X | Microsoft SDKP3 | mswinsdq.exe | "Added by the RBOT-ARY WORM!"
|
| X | Microsoft Secure | Messenger.NET Service | "Added by the FORBOT-AM WORM!"
|
| X | Microsoft Secure Messenger.NET Service | securitychk.exe | "Added by the SDBOT.VT WORM!"
|
| X | Microsoft Security | winService.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft security adviser | mssadv.exe | "Microsoft Security Adviser rogue security software - not recommended"
|
| X | Microsoft Security Center | savservices.exe | "Added by the RBOT-ANU WORM!"
|
| X | Microsoft Security Center | wcsntfy.exe | "Added by the SDBOT.BYD WORM!"
|
| X | Microsoft Security Controlers | fxsecues.exe | "Added by a variant of the SDBOT WORM!"
|
| Y | Microsoft Security Essentials | msseces.exe | "System Tray access to a notifications from Microsoft Security Essentials which ""provides real-time protection for your home PC that guards against viruses |
| X | Microsoft Security GManagers | [random filename] | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Security Hot Fix Update | mshotfix.exe | "Affilred adware"
|
| X | Microsoft Security Management | winnt.exe | "Added by the RBOT-MQ WORM!"
|
| X | Microsoft Security Management | winserv.exe | "Added by the RBOT-MJ WORM!"
|
| X | Microsoft Security Management | winamp.exe | "Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player which resides in a ""Winamp"" subdirectory of the Program Files directory"
|
| X | Microsoft Security Management | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Security Management | bling.exe | "Added by the RBOT.XL WORM!"
|
| X | Microsoft Security Management | sp2fix.exe | "Added by the RBOT.UB WORM!"
|
| X | Microsoft Security Manager | winamp.exe | "Added by the RBOT.TU WORM! Note - this is NOT the popular Winamp media player which is located in %ProgramFiles%\Winamp. This one is located in %System%"
|
| X | Microsoft Security Monitor Process | mssmp.exe | "Added by the RBOT-FUB WORM!"
|
| X | Microsoft Security Monitor Process | mnsmp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | msmp.exe | "Added by the RBOT.GKQ WORM!"
|
| X | Microsoft Security Monitor Process | mssm32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Security Monitor Process | lsas.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | msword.exe | "Added by the VIRUT.P VIRUS!"
|
| X | Microsoft Security Monitor Process | service.exe | "Added by the DELF.BERW BACKDOOR!"
|
| X | Microsoft Security Monitor Process | svcchost.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | windowsupdate.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | [random filename] | "Added by variants of the RBOT WORM! See here"
|
| X | Microsoft Security Monitor Process | com.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | exel.exe | "Added by the SDBOT.AFX BACKDOOR!"
|
| X | Microsoft Security Monitor Process | firewall.exe | "Added by a variant of the IRCBOT BACKDOOR! Located in %System%"
|
| X | Microsoft Security Monitor Process | flash.exe | "Added by the EGGDROP.EE BACKDOOR!"
|
| X | Microsoft Security Monitor Process | hel.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Microsoft Security Monitor Process | HelpMe.exe | "Added by the VB.BJO TROJAN!"
|
| X | Microsoft Security Monitor Process | kar.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Security Monitor Process | lindicracker.exe | "Added by the BIFROSE.GR BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mail.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mmp.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mssm32.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Security Monitor Process | mssmpi32.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Security Monitor Process | nitty.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Microsoft Security Monitor Process | ofice.exe | "Added by the VIRUT.N VIRUS!"
|
| X | Microsoft Security Monitor Process | point.exe | "Added by the IRCBOT.AVP BACKDOOR!"
|
| X | Microsoft Security Monitor Process | princ.exe | "Added by the HUPIGON.WTL TROJAN!"
|
| X | Microsoft Security Monitor Process | web.exe | "Added by the EGGDROP.V BACKDOOR!"
|
| X | Microsoft Security Monitor Process | winsys32.exe | "Added by the VIRUT.N VIRUS!"
|
| X | Microsoft Security Monitor Process | winsyss32.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Microsoft Security Monitor Process | word.exe | "Added by the EGGDROP.DC BACKDOOR!"
|
| X | Microsoft Security Panager | [filename] | "Added by the RBOT-ANL WORM!"
|
| X | Microsoft Security Panagers | [random filename] | "Added by the RBOT-AIG WORM!"
|
| X | Microsoft Security Panagers | zzoboony.exe | "Added by the RBOT-AOI WORM!"
|
| X | Microsoft Security Pansasagers | dgkztsqgn.exe | "Added by the RBOT-BBJ WORM!"
|
| X | Microsoft Security Process | wininit.exe | "Added by the RBOT-FKM WORM!"
|
| X | Microsoft Security System | mssecsys.exe | "Added by the IRCBOT-WJ TROJAN!"
|
| X | Microsoft Security Update | security32.exe | "Added by the DELF-JJ TROJAN!"
|
| X | Microsoft Server | rserv.exe | "Added by the AGOBOT.AVS WORM!"
|
| X | Microsoft Server Applacations | msnmsg.exe | "Added by the AGOBOT.BBM WORM!"
|
| X | Microsoft Server Applacations | wuauct1.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Server Applacations | lsasss.exe | "Added by the RBOT-AQQ WORM!"
|
| X | Microsoft Server Applacations | Q8See.exe | "Added by the SPYBOT.GEN3 TROJAN!"
|
| X | Microsoft Server Applacations | cli.exe | "Added by the RBOT-GAQ WORM!"
|
| X | Microsoft Server Application | Sound.exe | "Added by the RBOT-NE WORM!"
|
| X | microsoft server base | lass.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Server Process | svhst32.exe | "Added by the BCKDR-QHR BACKDOOR!"
|
| X | Microsoft Service | microhost.exe | "Added by the RBOT-LC WORM!"
|
| X | Microsoft Service | winsvc.exe | "Added by the SPYBOT-DB WORM!"
|
| X | Microsoft Service | rundll.exe | "Added by the POPO-A WORM! Note - this is NOT the Win9x/Me system file of the same name as described here"
|
| X | Microsoft Service | service.exe | "Added by the IRCBOT-XX BACKDOOR!"
|
| X | Microsoft Service | winspl.exe | "Spyman spyware"
|
| X | Microsoft service | cssrs.exe | "Added by the STARTP-DC TROJAN!"
|
| X | Microsoft Service 32 | mssvc32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Service 32 | sysddm32.exe | "Added by the SDBOT.AKC WORM!"
|
| X | Microsoft Service Access Manager | Access.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Service Boot | sboot.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Service Controller | services.exe | "Added by the KALEL-D WORM! Note - this is not the legitimate services.exe process |
| X | Microsoft Service Disk Cycle | disksave.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Service Drivers | System.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Service Drivers | VSADNIM.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Service Execution Manager | execute.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Microsoft Service firewall Manager | firewall.exe | "Added by a variant of the SDBOT BACKDOOR! Located in %System%"
|
| X | Microsoft Service Host Manager | 32svchost.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Service Host Process | svchost.exe | "Added by the KRYNOS.B WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Help"
|
| X | Microsoft Service Information | msnservices.exe | "Added by the RBOT.ID WORM!"
|
| X | Microsoft Service Login Manager | winlogin.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Service Manager | service32.exe | "Added by the IRCBOT.WDW BACKDOOR!"
|
| X | Microsoft Service Manager | winsvc.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Service Pack | WindowsSP.exe | "Added by the RBOT-RF WORM!"
|
| X | Microsoft Service Pack2.1 | svchost2.exe | "Added by the RBOT.ASN BACKDOOR!"
|
| X | Microsoft Service Tools | MStools1.exe | "Added by the RBOT-BHT WORM!"
|
| X | Microsoft Services | lsserv.exe | "Added by an unidentified VIRUS |
| X | Microsoft Services | lssrv.exe | "Added by the RBOT.CW WORM!"
|
| X | Microsoft Services | services.exe | "Added by the ALETS TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Services | lsrv.exe | "Added by the RBOT-BK WORM!"
|
| X | Microsoft Services | svshost.exe | "Added by the ALETS.B TROJAN!"
|
| X | Microsoft Services | bsc32.exe | "Added by the BDOOR-AW BACKDOOR!"
|
| X | Microsoft Services | Smss32.exe | "Added by the RBOT-AD WORM!"
|
| X | Microsoft Services | svssshost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Services | module.exe | "Added by the LAVITS WORM!"
|
| X | Microsoft Services | msmpserv.exe | "Added by the IRCBOT.BKA BACKDOOR!"
|
| X | Microsoft Services Unitd | MSU32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Servicez Manager | servicemgrz.exe | "Added by the RBOT-ASN WORM!"
|
| X | Microsoft Session Manager Subsystem | smss.exe | "Added by the KALEL-D WORM! Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!"
|
| X | Microsoft Setup Initializazion | localhost.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| N | Microsoft Sidewinder Game Controller Software | SWTRAY.EXE | MS SideWinder game controller system tray icon. Available via Start -> Programs
|
| X | Microsoft Sinsup | odjiwjf.exe | "Added by the RBOT-DN WORM!"
|
| X | Microsoft Software | sysinfo33.exe | "Added by the RBOT.LS WORM!"
|
| X | microsoft software | ****.exe [* = random char] | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft software | cdaccess.exe | "Added by the RBOT.ABK WORM!"
|
| X | Microsoft Software Update | nmon.exe | "Added by the RBOT.HZ WORM!"
|
| X | Microsoft Sound Driver | sound32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Sound Technology | winsound.exe | "Added by the RBOT-AGG WORM!"
|
| N | Microsoft Sound Volume Tool | mssvol.exe | This is a Blue version of the yellow speaker icon on the system tray and is used to edit advanced Sound Features that the MS DSS80 Speakers add. Should be accessible via Start -> Settings -> Control Panel
|
| X | Microsoft Sounds | soundman.exe | "Added by the RBOT-GCI WORM!"
|
| X | Microsoft SpA Service | msapps.exe | "Added by the RBOT-VI WORM!"
|
| X | Microsoft SpA Service | win32.exe | "Added by the RBOT.ATS WORM!"
|
| X | Microsoft SpA Service | Winupd32.exe | "Added by the RBOT.LT WORM!"
|
| X | Microsoft SpAr Service | winsbsd32.exe | "Added by the RBOT-RN WORM!"
|
| X | Microsoft Special offer | infoebay.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Spool ** Service | spool**.exe | "Added by a variant of the IRCBOT TROJAN - where ** represents a 2 digit number"
|
| X | Microsoft Spool Server for Win32 | spoolsrv.exe | "Added by the RANDEX.H WORM!"
|
| X | Microsoft Spool Svc | spoolsvc32.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Spooler Services | Spoolsv.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | MicroSoft ssadsadas3s1 | eXtream.exe | "Added by the SPYBOT.ZK TROJAN!"
|
| X | MicroSoft ssadssjdhasjadas3s1 | kdjfsdklfjsl.exe | "Added by the SDBOT.AEX WORM!"
|
| X | MicroSoft ssas3s1 | SADASDA.exe | "Added by the RBOT.URF WORM!"
|
| X | Microsoft SSISVRI32 Protocol | ssisvri.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Standard Executions Library | win32lib.exe | "Added by the RBOT-AUK WORM!"
|
| X | Microsoft standard protector | winsocks5.exe | Added by the SMALL.CF TROJAN!
|
| X | Microsoft standard protector | [path to trojan] | "Added by the STOX-C TROJAN!"
|
| X | Microsoft startup | wmpIayer.exe | Added by the IRCBOT.ACI TROJAN!
|
| X | Microsoft Startup Manager | sysservice.exe | "Added by the AVALANEC TROJAN!"
|
| N | Microsoft Sticky Notes | stikynot.exe | "Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
|
| X | Microsoft Stuff you know | winslogin.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Sum32 | sum32.exe | "Added by the RBOT-YW WORM!"
|
| X | Microsoft Support | sys32ms.exe | "Added by the RBOT-AHI WORM!"
|
| X | microsoft support | svchostt.exe | "Added by the AGOBOT.AWN WORM!"
|
| X | Microsoft SVC | mssvc.exe | "Added by the BIFROSE-UQ TROJAN!"
|
| X | Microsoft Svchost local services | winoem.exe | "Added by the RBOT-FPE WORM!"
|
| X | Microsoft Svchost local services | nzm23.exe | "Added by the RBOT-GMC WORM!"
|
| X | Microsoft Svchost local services | msnserver.exe | "Added by the RBOT-GPM WORM!"
|
| X | Microsoft Syn Manager | Manager.exe | "Added by the SDBOT.BEF WORM!"
|
| X | Microsoft Synchronization Manager | asgard.exe | "Added by the SDBOT-AEA WORM!"
|
| X | Microsoft Synchronization Manager | bot.exe | "Added by the SDBOT.IH WORM!"
|
| X | Microsoft Synchronization Manager | netscape.exe | "Added by the RANDEX.AE WORM!"
|
| X | Microsoft Synchronization Manager | slhost.exe | "Added by the SDBOT.YH WORM!"
|
| X | Microsoft Synchronization Manager | svhost.exe | "Added by the SDBOT-PY WORM!"
|
| X | Microsoft Synchronization Manager | WinLoginnn.exe | "Added by the SPYBOT.FO WORM!"
|
| X | Microsoft Synchronization Manager | winupdate.exe | "Added by the SDBOT.ER WORM!"
|
| X | Microsoft Synchronization Manager | xXx.exe | "Added by the SDBOT-KZ WORM!"
|
| X | Microsoft Synchronization Manager | ___synmgr.exe | "Added by the MASLAN.A or MASLAN.C WORMS!"
|
| X | Microsoft Synchronization Manager | al.exe | "Added by the OPTXPRO.132 TROJAN!"
|
| X | Microsoft Synchronization Manager | win.exe | "Added by the SDBOT.AK WORM!"
|
| X | Microsoft Synchronization Manager | java.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Synchronization Manager | svchosts.exe | "Added by the SDBOT-LM WORM!"
|
| X | Microsoft Synchronization Manager | winlogon32.exe | "Added by the SDBOT.AEU WORM!"
|
| X | Microsoft Synchronization Manager | svxhost.exe | "Added by the SDBOT-ZU WORM!"
|
| X | Microsoft Synchronization Manager | wincfg32.exe | "Added by the SDBOT.DO WORM!"
|
| X | Microsoft Synchronization Manager | screen.exe | "Added by the SDBOT-ACO WORM!"
|
| X | Microsoft Synchronization Manager | devldr32.exe | "Added by a variant of the RBOT WORM! Note - do not confuse with the legitimate Creative Labs devldr32.exe file"
|
| X | Microsoft Synchronization Manager | explorer.exe | "Added by the SDBOT-AEA WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft Synchronization Manager | firewire.exe | "Added by the SDBOT-AFC WORM!"
|
| X | Microsoft Synchronization Manager | wmedia.exe | "Added by the SDBOT.BFC WORM!"
|
| X | Microsoft Synchronization Manager | win932.exe | "Added by the SDBOT.AH WORM!"
|
| X | Microsoft Synchronization Manager | mircup.exe | "Added by the SDBOT.BQD WORM!"
|
| U | Microsoft Synchronization Manager | mobsync.exe | "Microsoft Synchronization Manager for 2K/XP - used to update network copies of materials that were edited offline |
| X | Microsoft Synchronization Manager | alien.exe | "Added by the SDBOT-MV BACKDOOR!"
|
| X | Microsoft Synchronization Manager | microsoft.exe | "Added by the SDBOT-OM WORM!"
|
| X | Microsoft Synchronization Manager 2 | svhostc.exe | "Added by the SLINBOT.ST WORM!"
|
| X | MicroSoft sys32 | sysmsgr32.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | MicroSoft sys3s1 | h4ckn3t.exe | "Added by the RBOT.QTY WORM!"
|
| X | Microsoft System | msupdtm.exe | "Added by the SPYBOT.PKC WORM!"
|
| X | Microsoft System | mssys32.exe | "Added by the PETTICK.A WORM!"
|
| X | Microsoft System | sys.exe | "Added by the RBOT.AKI WORM!"
|
| X | Microsoft System | winamp1.exe | "Added by the SDBOT-UF WORM!"
|
| X | Microsoft System Administration | system.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft System Backup | [random filename] | "Added by the RBOT-AGM WORM!"
|
| X | Microsoft System Checkup | Cool.exe | "Added by the DONK.B WORM!"
|
| X | Microsoft System Checkup | Wnetlib.exe | "Added by the DONK.C WORM!"
|
| X | Microsoft System Checkup | dbnetlib.exe | "Added by the DONK.L WORM!"
|
| X | Microsoft System Checkup | Keymgr.exe | "Added by the DONK.M WORM!"
|
| X | Microsoft System Checkup | inetman.exe | "Added by the DONK.O WORM!"
|
| X | Microsoft System Checkup | ntsysmgr.exe | "Added by the DONK.S WORM!"
|
| X | Microsoft System Checkup | ntsysman.exe | "Added by the SDBOT-QW WORM!"
|
| X | Microsoft System Checkup | libsysmgr.exe | "Added by the SDBOT-CAF WORM!"
|
| X | Microsoft System Checkup | sysmgr.exe | "Added by the SDBOT-OO TROJAN!"
|
| X | Microsoft System Checkup | netapi32.exe | "Added by the DONK-E WORM!"
|
| X | Microsoft System Checkup | wnetmgr.exe | "Added by the DONK.Q WORM!"
|
| X | Microsoft System Checkup | libsys32.exe | "Added by the SDBOT-ACK WORM!"
|
| X | Microsoft System Checkup | netlogin32.exe | "Added by the SDBOT-GN BACKDOOR!"
|
| N | Microsoft System Configuration Utility | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
|
| X | Microsoft System Debug | services32.exe | "Added by the RBOT.AKH WORM!"
|
| X | Microsoft System DLL Services Configuration | windir32.exe | "Added by the SDBOT-ACY TROJAN!"
|
| X | Microsoft System File | svchots.exe | "Added by the RBOT.BYU WORM!"
|
| X | Microsoft System Firewall 2006.2 | msmsgr.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft System Firewall 2006.2 | msnmsgr.exe | "Added by a variant of the SDBOT WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| X | Microsoft System Firewall 2006.2 | reg32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft System Init | mtmnr0.exe | "Added by the SDBOT.BR TROJAN!"
|
| X | Microsoft System Monitor | monsys.exe | "Added by the IRCBOT-YV TROJAN!"
|
| X | Microsoft System Monitor | system.exe | "Added by the IRCBOT.AUT BACKDOOR!"
|
| X | Microsoft System NT | svhost.exe | "Added by the SDBOT.COU WORM!"
|
| X | Microsoft System Restore Configuration | CBRSS.EXE | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft System Saver | [path to worm] | "Added by the RBOT.BSK WORM!"
|
| X | Microsoft System Security Agent | MSTSA.EXE | "Added by the RBOT.CCM WORM!"
|
| X | Microsoft System Service | dnservice.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft System Service | taskmgr1.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft System Service | winIogon2.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft System Service Device | mssdh.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft System Services | msnmgsr.exe | "Added by the KELVIR.K WORM!"
|
| X | Microsoft System Services | msmsgr.exe | "Added by the RBOT-ZH WORM!"
|
| X | Microsoft System Update | sysupdate.exe | "Added by the SDBOT.DG WORM!"
|
| X | Microsoft system Value | sys57.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft System32 Update | cmsrg.exe | "Added by the RBOT-GN WORM!"
|
| X | Microsoft Task Manager Daemon | spoolsrv.exe | "Added by the SDBOT.FLL WORM!"
|
| X | Microsoft Task Messenger Config | taskmgsr.exe | "Added by the SDBOT-JK WORM!"
|
| X | Microsoft task tray monitor | ctray.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Task32 Protocol | taskmgr32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Taskmanager Updater | keyboard.exe | "Added by the RBOT-ALU WORM!"
|
| X | Microsoft TCP Protocol | wintcp32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft TCP Service | scvhost.exe | "Added by the AGOBOT-L WORM!"
|
| X | Microsoft TCP/IP Connection Monitor | svchost32.exe | "Added by the RBOT.KS WORM!"
|
| X | Microsoft Telecom Center | tellecom.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Telecoma Center | tellcoma.exe | "Added by the RBOT-AWX WORM!"
|
| X | Microsoft Telecoms Center | telcoms.exe | "Added by the IRCBOT.GEN WORM!"
|
| X | Microsoft Telecoms Center | xpfilesys.exe | Added by the RBOT.BCJ TROJAN!
|
| X | Microsoft Telecoms Center | winupn.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Telecoms Center | svcchost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Time Manager | dveldr.exe | "Added by the RBOT-HQ WORM!"
|
| X | MicroSoft Toolbar | key.exe | "Added by the RBOT-AEW WORM!"
|
| X | Microsoft Transfer File Server | mtfs.exe | "Added by the RBOT.AFE WORM!"
|
| X | Microsoft Tray | [random filename] | "Added by the DELF.BZ TROJAN!"
|
| X | Microsoft TTL Verifier | msttl.exe | "Added by the RBOT-GAP WORM!"
|
| X | Microsoft U | wuamkopxp.exe | "Added by the RBOT-AHC WORM!"
|
| X | Microsoft UMA Update | MSuma32.exe | "Added by the RBOT.FS WORM!"
|
| X | MICROSOFT UNPACCKER SYSTEM | unpak32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MICROSOFT UNPACK SYSTEM | winrarx.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updat3 | mswkst32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | Microsoft.exe | "Added by the GAOBOT.AFJ WORM!"
|
| X | Microsoft Update | mssmgrd.exe | "Added by the SDBOT.JT WORM!"
|
| X | Microsoft Update | mvsc.exe | "Added by the SPYBOT.DAZ WORM!"
|
| X | Microsoft Update | ascdl.exe | "Added by the GAOBOT.SY WORM!"
|
| X | Microsoft Update | Isac.exe | "Added by the RBOT-AU WORM!"
|
| X | Microsoft Update | automgr32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | mediap.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | Microsoftx.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | msconfg.exe | "Added by the RBOT.H WORM!"
|
| X | Microsoft Update | Mslti32.exe | "Added by the RBOT-LX WORM!"
|
| X | Microsoft Update | muamgrd.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Update | navmgrd.exe | "Added by the SDBOT.DP TROJAN!"
|
| X | Microsoft Update | Smss32.exe | "Added by the RBOT-CB WORM!"
|
| X | Microsoft Update | sys32cfg.exe | "Added by the RBOT.DR WORM!"
|
| X | Microsoft Update | VPC32.EXE | "Added by the AGOBOT.XM WORM!"
|
| X | Microsoft Update | winsys32.exe | "Added by the RBOT.BD WORM!"
|
| X | Microsoft Update | wuamgrd.exe | "Added by the RBOT-LK WORM!"
|
| X | Microsoft Update | wuammgr32.exe | "Added by the RBOT-AW WORM!"
|
| X | Microsoft Update | wudmate.exe | "Added by the RBOT.AP WORM!"
|
| X | Microsoft Update | msawindows.exe | "Added by the GAOBOT.AFJ WORM!"
|
| X | Microsoft Update | msiwin84.exe | "Added by the GAOBOT.AFJ WORM!"
|
| X | Microsoft Update | wuamgrd32.exe | "Added by the RBOT.ZB WORM!"
|
| X | Microsoft Update | NAV.exe | "Added by the RBOT-IV WORM!"
|
| X | Microsoft Update | systemi32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Update | xpupdate.exe | "Added by the RBOT-QE WORM!"
|
| X | Microsoft Update | webm.exe | "Added by the SDBOT.WK WORM!"
|
| X | Microsoft Update | wuagrd.exe | "Added by the RBOT-FK WORM!"
|
| X | Microsoft Update | aaupdt.exe | "Added by the RBOT-RQ WORM!"
|
| X | Microsoft Update | lsac.exe | "Added by the GAOBOT.XW WORM!"
|
| X | Microsoft Update | Mupdate.exe | "Added by the RBOT-AG WORM!"
|
| X | Microsoft Update | prowind32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Update | snlogsvc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | svhost.exe | "Added by the RBOT-PI WORM!"
|
| X | Microsoft Update | wauguard.exe | "Added by the RBOT.AEE WORM!"
|
| X | Microsoft Update | winscv.exe | "Added by the RBOT-BH WORM!"
|
| X | Microsoft Update | winsys.exe | "Added by the RBOT-GV WORM!"
|
| X | Microsoft Update | wserv32.exe | "Added by the RBOT.AF WORM!"
|
| X | Microsoft Update | wtm32.exe | "Added by the RBOT-AQ WORM!"
|
| X | Microsoft Update | wumgrd.exe | "Added by the SDBOT-KY WORM!"
|
| X | Microsoft Update | wuampd.exe | "Added by the RBOT-UT WORM!"
|
| X | Microsoft Update | msupdate32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Update | Botnet.exe | "Added by the RBOT.AFL WORM!"
|
| X | Microsoft Update | sghost.exe | "Added by the SDBOT.AKV WORM!"
|
| X | Microsoft Update | update_w.exe | "Added by the RBOT-EW WORM!"
|
| X | Microsoft Update | windows24.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | wingrd32.exe | "Added by the RBOT-DW WORM!"
|
| X | Microsoft Update | wssvr.exe | "Added by the RBOT-OD WORM!"
|
| X | Microsoft Update | wuamagr32.exe | "Added by the SPYBOT.CG WORM!"
|
| X | Microsoft Update | WinUpdate32.exe | "Added by the RBOT-TI WORM!"
|
| X | Microsoft Update | wkfix.exe | "Added by the RBOT-ABZ WORM!"
|
| X | Microsoft Update | Kkk.exe | "Added by the RBOT-AHL WORM!"
|
| X | Microsoft Update | mcupdate.exe | "Added by the RBOT.XT WORM! Note - this file is located in %System% and should not be confused with the McAfee antivirus executable as described here"
|
| X | Microsoft Update | Micr0s0ft.exe | "Added by the AGOBOT.AAR WORM!"
|
| X | Microsoft Update | Msnmsngr.exe | "Added by the RBOT.BQS WORM!"
|
| X | Microsoft Update | msupdate32.exe | "Added by the SPYBOT.LZ WORM!"
|
| X | Microsoft Update | scvhost.exe | "Added by the RBOT-AEM WORM!"
|
| X | Microsoft Update | svghost.exe | "Added by the RBOT.BUJ WORM!"
|
| X | Microsoft Update | sys.exe | "Added by the RBOT-AJ WORM!"
|
| X | Microsoft Update | up2dat5.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | winamp.exe | "Added by a variant of the RBOT WORM! Note - this is NOT the popular Winamp media player"
|
| X | Microsoft Update | win-mang.exe | "Added by the RBOT-AFK WORM!"
|
| X | Microsoft Update | winupdater.exe | "Added by the RBOT.BIN WORM!"
|
| X | Microsoft Update | wuamk0032.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | wuamk032.exe | "Added by the RBOT-AHD WORM!"
|
| X | Microsoft Update | wuamk0p32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | wuamkop.exe | "Added by the RBOT-AFI WORM!"
|
| X | Microsoft Update | wuamkop32.exe | "Added by the RBOT.BGU WORM!"
|
| X | Microsoft Update | wuampkd.exe | "Added by the SDBOT.BBX WORM!"
|
| X | Microsoft Update | svzhost.exe | "Added by the RBOT.OX WORM!"
|
| X | Microsoft Update | win32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | wininit.exe | "Added by the RBOT-AKR WORM!"
|
| X | Microsoft Update | wuamgrd3.exe | "Added by the RBOT-AMC WORM!"
|
| X | Microsoft Update | Wudates.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | ms.exe | "Added by the SDBOT.CC WORM!"
|
| X | Microsoft Update | wuagmsd.exe | "Added by the RBOT-AX WORM!"
|
| X | Microsoft Update | cmss.exe | "Added by the RBOT-ATQ WORM!"
|
| X | Microsoft Update | wuamgrb.exe | "Added by the RBOT-AZE WORM!"
|
| X | Microsoft Update | WINDOC.EXE | "Added by the SDBOT.PF WORM!"
|
| X | Microsoft Update | phqghumea.exe | "Added by the SDBOT.AFO WORM!"
|
| X | Microsoft Update | system32.exe | "Added by the RBOT.IS WORM!"
|
| X | Microsoft Update | bling.exe | "Added by the RBOT-AVK WORM!"
|
| X | Microsoft Update | Sygate.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | update.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update | WinDrv32.exe | "Added by the RBOT.EGW WORM!"
|
| X | Microsoft Update | devmks32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft update | winupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update | msupdate.exe | "Added by the BOROBOT-I TROJAN!"
|
| X | Microsoft Update | mixer.exe | "Added by the RBOT-AIR WORM!"
|
| X | Microsoft Update | taskmgr32.exe | "Added by the RBOT-CV WORM!"
|
| X | Microsoft Update | drive.exe | "Added by the BIFROSE-PN WORM!"
|
| X | Microsoft Update | wangard.exe | "Added by the RBOT-LH WORM!"
|
| X | MICROSOFT UPDATE | WUAGTRD.EXE | "Added by the RBOT-CJ WORM!"
|
| X | Microsoft Update | spool.exe | "Added by the AGENT-GJC TROJAN!"
|
| X | Microsoft Update | bnmveqfts.exe | "Added by the BANLOAD.KWQ TROJAN!"
|
| X | Microsoft Update | dqbxhupdt | "Added by a variant of the SDBOT WORM! See here"
|
| X | Microsoft Update | enule.exe | "Added by the IRCBOT.DU BACKDOOR!"
|
| X | Microsoft Update | explorer.exe | "Added by the RBOT.AEU BACKDOOR! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft Update | imchemaoa.exe | "Added by the BANLOAD.KWQ TROJAN!"
|
| X | Microsoft Update | livemessenger.com | "Added by the ADLOAD-LN TROJAN!"
|
| X | Microsoft Update | msnmsgl.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Update | nnwyaupdt | "Added by the RBOT.RHK BACKDOOR!"
|
| X | Microsoft Update | ntservice.exe | "Added by the AGENT-DIS TROJAN!"
|
| X | Microsoft Update | rundll32.dll | "Added by the CIADOOR.GN BACKDOOR!"
|
| X | Microsoft Update | wuamgrdx.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Update | wutr.exe | "Added by the SPYBOT.AAR WORM!"
|
| X | Microsoft Update | SetPoints.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Update | system.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Update | service.exe | "Added by a variant of the RBOT WORM! See here"
|
| X | Microsoft Update | msgn.exe | "Added by the RBOT.RQ BACKDOOR!"
|
| X | Microsoft Update | wuamgrd16.exe | "Added by the RBOT-BQ WORM!"
|
| X | Microsoft Update | windows32.exe | "Added by the RBOT-BHQ WORM!"
|
| X | Microsoft Update | winsyst.exe | "Added by the RBOT-DL WORM!"
|
| X | Microsoft Update 23 | NtKernelSystem.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 23 | spoolvs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 32 | explore32.exe | "Added by the SPYBOT.CYM WORM!"
|
| X | Microsoft Update 32 | MSupdate32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Update 32 | wininit.exe | "Added by the RBOT-ANY WORM!"
|
| X | Microsoft Update 32 | wininit32.exe | "Added by the RBOT-AKJ WORM!"
|
| X | Microsoft Update 32 | [path to file] | "Added by the RBOT-AJJ WORM!"
|
| X | Microsoft Update 32 | mscnfg.exe | "Added by the RBOT-ALM WORM!"
|
| X | Microsoft Update 32 | servic.exe | "Added by the RBOT-AXN WORM!"
|
| X | Microsoft Update 32 | winitXP32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 32 | mssetup32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update 32 | wiit.exe | "Added by the RBOT-AMS WORM!"
|
| X | Microsoft Update 32 | explorer.exe | "Added by the RBOT-ARF WORM! Note - the legitimate Windows Explorer (same filename) is located in %Windir% and would not normally appear in Msconfig/Startup unless you added it manually! This one is located in %System%"
|
| X | Microsoft Update 32 | network.exe | "Added by the RBOT-ARZ WORM!"
|
| X | Microsoft Update 32 | om4r.exe | "Added by the RBOT-AQP WORM!"
|
| X | Microsoft Update 32 | winin.exe | "Added by the RBOT-ARR WORM!"
|
| X | Microsoft Update 32 | wuinit.exe | "Added by the AGOBOT-UE WORM!"
|
| X | Microsoft Update 32 | neta.exe | "Added by the RBOT-AMI WORM!"
|
| X | Microsoft Update 32 | spoolvs.exe | "Added by the RBOT-BBQ WORM!"
|
| X | Microsoft Update 32 | rundll32.exe | "Added by the RBOT.AIE BACKDOOR! Note that this BACKDOOR modifies the file rundll32.exe |
| X | Microsoft Update 32 | taskMangr.exe | "Added by the RBOT.AIE BACKDOOR!"
|
| X | Microsoft Update 32 | winssx.exe | "Added by the RBOT-ARW WORM!"
|
| X | Microsoft Update 33 | init.exe | "Added by the RBOT-ATT WORM!"
|
| X | Microsoft Update 64 BIT | wininit32.exe | "Added by the RBOT-AHE WORM!"
|
| X | Microsoft Update 64 BIT | winman32.exe | "Added by the RBOT-AKI WORM!"
|
| X | Microsoft Update 64 BIT | schvost.exe | "Added by the RBOT.CAU WORM!"
|
| X | Microsoft Update 64 BIT | winl32xe.exe | "Added by the RBOT-AQO WORM!"
|
| X | Microsoft Update Clinic | svsipconfig.exe | "Added by the RBOT.BR WORM!"
|
| X | MICROSOFT UPDATE CONFIGURATION | WIN32SNC.EXE | "Added by the RBOT-AI WORM!"
|
| X | Microsoft Update Control | Ms64.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Debugger | wincfg32.exe | "Added by the SPYBOT.ZC WORM!"
|
| X | Microsoft Update Device | flolo.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Update Device Drivers | wuauclt.exe | "Added by a variant of the SDBOT WORM! Note - this is not the legitimate wuauclt.exe process |
| X | Microsoft Update DLL | rxxhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Drivers | explorers.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update Emulator | kern-mxe.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Emulator | wuaddsff.exe | "Added by the RBOT-GX WORM!"
|
| X | Microsoft Update Event | svnhost.exe | "Added by the AGOBOT-GW BACKDOOR!"
|
| X | Microsoft Update Loader | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Loaders 2005 | winusers.exe | "Added by the RBOT-AIQ WORM!"
|
| X | Microsoft Update Loaders 2006 | winusersystem32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Update Machine | expl0rer.exe | "Added by the SDBOT.OK WORM!"
|
| X | Microsoft Update Machine | rxhost.exe | "Added by the RBOT.FC WORM!"
|
| X | Microsoft Update Machine | servicz.exe | "Added by the RBOT-HU WORM!"
|
| X | Microsoft Update Machine | SP2.exe | "Added by the SPYBOT.FP WORM!"
|
| X | Microsoft Update Machine | winini.exe | "Added by the RBOT-KV WORM!"
|
| X | Microsoft Update Machine | xvshost.exe | "Added by the RBOT.QP WORM!"
|
| X | Microsoft Update Machine | memstat.exe | "Added by the RBOT-OM WORM!"
|
| X | Microsoft Update Machine | ntce.exe | "Added by the RBOT-FA WORM!"
|
| X | Microsoft Update Machine | system03.exe | "Added by the RBOT-NM WORM!"
|
| X | Microsoft Update Machine | wuawx.exe | "Added by the RBOT-CE WORM!"
|
| X | Microsoft Update Machine | zonealarm.exe | "Added by the RBOT-BZ WORM! Note - this is not the valid Zone Labs firewall program!"
|
| X | Microsoft Update Machine | systemll.exe | "Added by the RBOT-JT WORM!"
|
| X | Microsoft Update Machine | winupdt.exe | "Added by the RBOT-FP WORM!"
|
| X | Microsoft Update Machine | svshost.exe | "Added by the RBOT.AK WORM!"
|
| X | Microsoft Update Machine | wuamgd.exe | "Added by the SDBOT.HQ WORM!"
|
| X | Microsoft Update Machine | wupdt32x.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update Machine | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | linux.exe | "Added by the RBOT-IM WORM!"
|
| X | Microsoft Update Machine | lmrss.exe | "Added by the RBOT-DY WORM!"
|
| X | Microsoft Update Machine | windowsu.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | wininigo.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | winmgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | Winmsixp32.exe | "Added by the RBOT.DN WORM!"
|
| X | Microsoft Update Machine | Winregs32.exe | "Added by the RBOT.DN WORM!"
|
| X | Microsoft Update Machine | winxpini.exe | "Added by the RBOT-OB WORM!"
|
| X | Microsoft Update Machine | wuamgrd.exe | "Added by the RBOT-HE WORM!"
|
| X | Microsoft Update Machine | wuagrd.exe | "Added by the RBOT-GF WORM!"
|
| X | Microsoft Update Machine | LANWAKE.EXE | "Added by the RBOT-QZ WORM!"
|
| X | Microsoft Update Machine | scvhost.exe | "Added by the RBOT-GS WORM!"
|
| X | Microsoft Update Machine | winhost.exe | "Added by the RBOT-GK WORM!"
|
| X | Microsoft Update Machine | winss.exe | "Added by the RBOT.JU WORM!"
|
| X | Microsoft Update Machine | WUAMGRDXS.EXE | "Added by the RBOT-GL WORM!"
|
| X | Microsoft Update Machine | crss32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | lsasse.exe | "Added by the RBOT-DI WORM!"
|
| X | Microsoft Update Machine | qwerty.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | rxxhost.exe | "Added by the RBOT.EP WORM!"
|
| X | Microsoft Update Machine | servicez.exe | "Added by the SPYBOT.BI WORM!"
|
| X | Microsoft Update Machine | spoolserv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | Systemnt.exe | "Added by the RBOT.DA WORM!"
|
| X | Microsoft Update Machine | systemse.exe | "Added by the RBOT-BD WORM!"
|
| X | Microsoft Update Machine | taskmngrs.exe | "Added by the RBOT-CR WORM!"
|
| X | Microsoft Update Machine | windowsup.exe | "Added by the RBOT-FV WORM!"
|
| X | Microsoft Update Machine | wuamgard.exe | "Added by the SPYBOT.CS WORM!"
|
| X | Microsoft Update Machine | wupdate32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | system.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | TMEMSER.EXE | "Added by the RBOT-NQ WORM!"
|
| X | Microsoft Update Machine | winnie.exe | "Added by the RBOT-ACD WORM!"
|
| X | Microsoft Update Machine | winortho.exe | "Added by the RBOT-NW WORM!"
|
| X | Microsoft Update Machine | wins32.exe | "Added by the RBOT.EZ WORM!"
|
| X | Microsoft Update Machine | serviz.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | TASKMAN4.EXE | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | wftestb.exe | "Added by the RBOT-AFZ WORM!"
|
| X | Microsoft Update Machine | Win32.exe | "Added by the SDBOT.UV WORM!"
|
| X | Microsoft Update Machine | windns.exe | "Added by the RBOT.EF WORM!"
|
| X | Microsoft Update Machine | MSOICONS.EXE | "Added by the RBOT.AWS WORM! Note - do no confuse with the legitimate Msoicons.exe file described here. The latter should not normally figure in Msconfig/Startup!"
|
| X | Microsoft Update Machine | WINSVC32.EXE | "Added by the RBOT.CU WORM!"
|
| X | Microsoft Update Machine | ntsystem.exe | "Added by the RBOT.GF WORM!"
|
| X | Microsoft Update Machine | winupdte.exe | "Added by the RBOT-GKL WORM!"
|
| X | Microsoft Update Machine | jkfrnz.exe | "Added by the RBOT-GOZ WORM!"
|
| X | Microsoft Update Machine | wlimyc.exe | "Added by the RBOT-GQN WORM!"
|
| X | Microsoft Update Machine | xagwxzy.exe | "Added by the RBOT.S WORM!"
|
| X | Microsoft Update Machine | jkydxg.exe | "Added by the RBOT.AEA BACKDOOR!"
|
| X | Microsoft Update Machine | opmmve.exe | "Added by the KOLABC.DES WORM!"
|
| X | Microsoft Update Machine | paxrxo.exe | "Added by the PUSHBOT.A WORM!"
|
| X | Microsoft Update Machine | psmszw.exe | "Added by the KOLABC.CC WORM!"
|
| X | Microsoft Update Machine | syadpo.exe | "Added by the CIADOOR.GN BACKDOOR!"
|
| X | Microsoft Update Machine | systemi.exe | "Added by the BUZUS.JKU TROJAN!"
|
| X | Microsoft Update Machine | thvfyq.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Machine | ubthec.exe | "Added by the AGENT.AWZ TROJAN!"
|
| X | Microsoft Update Machine | winmngr.exe | "Added by the RBOT.GKQ BACKDOOR!"
|
| X | Microsoft Update Machine | gbhglj.exe | "Added by the IRCBOT-ZJ TROJAN!"
|
| X | Microsoft Update Machine | wuamgdr.exe | "Added by the RBOT-IO BACKDOOR!"
|
| X | Microsoft Update Manager | WINRLS.EXE | "Added by the RBOT-AF WORM!"
|
| X | Microsoft Update Manager | svshost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Manager | scvhost.exe | "Added by the AGOBOT.AXJ WORM!"
|
| X | Microsoft Update Manager | scvideo.exe | "Added by the SDBOT-CVP TROJAN!"
|
| X | Microsoft Update Mechene | Updatez.exe | "Added by the RBOT-GI WORM!"
|
| X | Microsoft Update Module | rundll24.exe | "Added by the RBOT-PS WORM!"
|
| X | Microsoft Update Process | wmipcvse.exe | "Added by the AGOBOT-JF TROJAN!"
|
| X | Microsoft Update Security Patch | mssecurityupdatepatch.exe | Added by the AGENT.EF TROJAN!
|
| X | Microsoft Update Server | mssrv.exe | "Added by an unidentified VIRUS |
| X | Microsoft Update Service | csrss32.exe | "Added by the AGOBOT-HC WORM!"
|
| X | Microsoft Update Service | mswin32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft update service | systemm.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Update SERVICE | phqghum.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Service | msupdate.pif | "Added by the RBOT-AQB WORM!"
|
| X | Microsoft Update Service | wmiprvre.exe | "Added by the AGOBOT-NN WORM!"
|
| X | Microsoft Update Services | wcsnfty.exe | "Added by the RBOT-AGK WORM!"
|
| X | Microsoft Update Services | wsnfty.exe | "Added by the RBOT-AFU WORM!"
|
| X | Microsoft Update Time | wuam.exe | "Added by the RBOT-M WORM!"
|
| X | Microsoft Update USB2 | wuammgrd32.exe | "Added by the RBOT-ADT WORM!"
|
| X | Microsoft Update v2.6 | lxxex.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Update Win32a | winupdate32a.exe | "Added by the RBOT-LO WORM!"
|
| X | Microsoft Update Win32x | winupdate32x.exe | "Added by the RBOT-AJN WORM!"
|
| X | Microsoft Update32 | wuamgrd32.exe | "Added by the RBOT-PU WORM!"
|
| X | Microsoft Updater | winsys32.exe | "Added by the RBOT.RL WORM!"
|
| X | Microsoft Updater | msconsole.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Updater | svhost.exe | "Added by the AGENT.CDF TROJAN!"
|
| X | Microsoft Updater | vbcjlg.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Updater | wuamgrds.exe | "Added by the RBOT.A WORM!"
|
| X | Microsoft Updater | winupdate.exe | "Added by the AGENT-KIR TROJAN!"
|
| X | Microsoft Updater Resources | WinFixd32.exe | "Added by the SPYBOT.CA WORM!"
|
| X | Microsoft Updater v2 | [path to worm] | "Added by the AUTORUN-BCI WORM!"
|
| X | Microsoft UPDATER32 | lsass.exe | "Added by the RANDEX.AR WORM! Note - this is not the legitimate Lsass.exe system file should normally NOT figure in Msconfig/Startup!"
|
| X | Microsoft UPDATER32 | LSASS32.EXE | "Added by the RANDEX.AR WORM!"
|
| X | Microsoft Updaters | tskmgr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updaters | sysconfigs.exe | "Added by the RBOT-DF TROJAN!"
|
| X | Microsoft Updaters Pros | WINDLL32XP.EXE | Added by the SPYBOTTER.GEN VIRUS!
|
| X | Microsoft Updates | systemc32.exe | "Added by the RBOT-GR WORM!"
|
| X | Microsoft Updates | wkssvr.exe | "Added by the RBOT.R WORM!"
|
| X | Microsoft Updates | wkssvrs.exe | "Added by the RBOT-EB WORM!"
|
| X | Microsoft Updates | wuamgrd.exe | "Added by the RBOT-CO WORM!"
|
| X | Microsoft Updates | wtemp32.exe | "Added by the RBOT-AHQ WORM!"
|
| X | Microsoft Updates | svehost.exe | "Added by the RBOT-GRW WORM!"
|
| X | Microsoft Updates | svshost.exe | "Added by the AGOBOT-AIW WORM!"
|
| X | Microsoft Updates | svdhost.exe | "Added by the RBOT-GVH WORM!"
|
| X | Microsoft Updates | service.exe | "Added by the POISON.HPT BACKDOOR!"
|
| X | Microsoft Updates | [worm filename] | "Added by the AGOBOT-AIZ WORM!"
|
| X | Microsoft Updates | wgcptsud.exe | "Added by the RBOT-GTF WORM!"
|
| X | Microsoft Updates | winit.exe | "Added by the SDBOT-CSB WORM!"
|
| X | Microsoft Updates 2 USB | wgafixer.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updates 5 USB | sp3fixer.exe | "Added by the RBOT-ADS WORM!"
|
| X | Microsoft UpdateS Machine | wgrd.exe | "Added by the RBOT-FI WORM!"
|
| X | Microsoft Updates Resources | WinFixIDs.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updating | navguard.exe | "Added by the RBOT.HW WORM!"
|
| X | Microsoft Updating | syswr.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updating | wuamguards.exe | "Added by the RBOT-BY WORM!"
|
| X | Microsoft Updating Client | websvc.exe | "Added by the RBOT.AQ WORM!"
|
| X | Microsoft Updating Machine | sysc0de.exe | "Added by the RBOT.RB WORM!"
|
| X | Microsoft Updatting | miroupdate.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Updote | [random filename] | "Added by the RBOT-ARC WORM!"
|
| X | Microsoft UpMachine | doezs.exe | "Added by the RBOT.BCT WORM!"
|
| X | Microsoft upnp Update | msie.exe | "Added by the RBOT-LQ WORM!"
|
| X | Microsoft uptime Service | sysuptime.exe | "Added by the RBOT-ACG WORM!"
|
| X | Microsoft uptime Service | sycuptime.exe | "Added by the RBOT-AHY WORM!"
|
| X | Microsoft UpToDate Driver (32-bits) | [random filename].exe | "Added by the SPYBOT.LXJ WORM!"
|
| X | Microsoft Urlmon | urlmon.exe | "Added by the AGENT-GOO TROJAN!"
|
| X | Microsoft USA Plug | usaplug.exe | "Added by the RBOT-DVC WORM!"
|
| X | Microsoft USB Windows2 Driver | usbautotuner.exe | "Added by the SILLYFDC.BCL WORM!"
|
| X | Microsoft USB2 Driver | crmss.exe | "Added by the RBOT-VK WORM!"
|
| X | Microsoft usnsvc Service | usnsvc.exe | "Added by a variant of the KOBOT-C WORM!"
|
| N | Microsoft Utility Startup | OSA9.exe | On older versions of MS Office this launches common Office components to help speed up the launch of Office programs. On slower machines it can be a resource hog and some users claim there's no difference with or without it - but it usually isn't required. This must be left enabled if you use the Microsoft Office Shortcut Bar (MSOFFICE.EXE) and have set it to load at startup. Available via Start → All Programs
|
| X | Microsoft Values | igfkishc.exe | "Added by the RBOT-GLO WORM!"
|
| X | Microsoft Vertupdate | MSvert32.exe | "Added by the MYTOB-CY WORM!"
|
| X | Microsoft Video Capture Controls | MSsrvs32.exe | "Added by the SDBOT-AAK WORM!"
|
| X | Microsoft Video Controls | tskmsgr.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Video Driver | videodrv.exe | "Added by the SDBOT-AGP WORM!"
|
| X | Microsoft Viewer Monitor Manager | viewmon.exe | "Added by the XPAK.A TROJAN!"
|
| X | Microsoft Virtual Service Manager | vservice32.exe | "Added by the MSNWORM.T WORM!"
|
| X | Microsoft Virual Machine | sms.exe | "Added by the RBOT-SP WORM!"
|
| X | Microsoft Vista Upgrade Validation Service | cfmon.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Visual Application | vpcrtf.exe | "Added by the IRCBOT-XJ TROJAN!"
|
| X | Microsoft Visual Debuger | mdm.exe | "Added by the SDBOT-DOO WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| X | Microsoft Visual SourceSafe | services.exe | "Added by the NEVEG.B or NEVEG.C WORMS! Note - this is not the legitimate services.exe process |
| X | Microsoft Visual SourceSafe | winlogon.exe | "Added by the NEVEG.A WORM! Note - this is not the legitimate winlogon.exe process |
| X | MicroSoft Visual SP | igxdfdfds.com | "Added by the SDBOT.GAV WORM!"
|
| X | MicroSoft Visual SP2 | igfxsrvc32.exe | "Added by the SDBOT.GAV WORM!"
|
| X | Microsoft Visual Studio | plscdksxg.exe | "Added by the RBOT-AWV WORM!"
|
| X | Microsoft Visual Studio VSA | varpc32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Web CP Manager | webcp32.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Web Device | wdevice.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft web update | webmsn.exe | "Added by the RBOT-EMQ WORM!"
|
| U | Microsoft Webserver | svctrl.exe | Personal web server program which enables you to create and host a web server from your computer. Not required for most people
|
| X | Microsoft Win Corp TLS Verification | mswintls.exe | "Added by the RBOT-GCT WORM!"
|
| X | Microsoft Win Update | WinUP.exe | "Added by the RBOT-BPR WORM!"
|
| X | Microsoft WIN32 DOS | MSdos32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft WIN32 Security | MSsec32.exe | "Added by the RBOT-DOQ TROJAN!"
|
| X | MicroSoft Wind0ws Updater | winsupdater.exe | "Added by a variant of the RBOT WORM!"
|
| X | MicroSoft Window Updater | winsupdater.exe | "Added by the RBOT-ZZ WORM!"
|
| X | Microsoft Windows | mstask0.exe | "Added by the SDBOT.FQ WORM!"
|
| X | Microsoft Windows | atup | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows | Microsoft Windows.hta | HTA file which creates an executable on the hard drive which subsequently proceeds to download files from a malware site!
|
| X | Microsoft Windows | explorar.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows | [path to file] | "Added by the BDOOR-LI BACKDOOR!"
|
| X | Microsoft Windows | bootini.exe | "Added by the VANEBOT-K WORM!"
|
| X | Microsoft Windows | Kernel.exe | "Added by the EDIBARA-A VIRUS!"
|
| X | Microsoft Windows | Kernel.vbs | "Added by the EDIBARA-A VIRUS!"
|
| X | Microsoft Windows | pwjbvphi.exe | "Added by the RBOT-GQK WORM!"
|
| X | Microsoft Windows | windets.com | "Added by the FLOOD-EQ TROJAN!"
|
| X | Microsoft Windows (D) | iexplore.exe | Identified as a variant of the TrojanSpy.Agent malware
|
| X | Microsoft Windows 128bit Subsystem | system12.exe | "Added by the RANCK-CZ TROJAN!"
|
| X | Microsoft Windows 16Bit | mswinn16.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Windows 2000 | Winupdsdgm.exe | "Added by the GAOBOT.AO WORM!"
|
| X | Microsoft Windows 32 Update | win32update.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Windows 32Bit | mswinn32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows 64 Bit | mswin32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Adapter 5.1.3214 | [worm filename].exe | "Added by the STRAT.GEN-3 WORM!"
|
| X | Microsoft Windows Autowxckn | autowxckn.exe | "Added by the RBOT.DYZ BACKDOOR!"
|
| X | Microsoft Windows Client Firewall | msclt.exe | "Added by the VANEBOT-F WORM!"
|
| X | Microsoft Windows Communicator for NT/XP | wincomm.exe | "Added by the RBOT.ATH WORM!"
|
| X | Microsoft Windows Config 32 | win32conf.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Control | mswctl32.exe | "Added by the RBOT.JP WORM!"
|
| X | Microsoft Windows CSRSS | csrss.exe | "Added by the KALEL-A WORM! Note - this worm replaces the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup!"
|
| N | Microsoft Windows Desktop Search System Tray | WindowsSearch.exe | System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version (3.0.1) also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation and this is the Windows Defender entry
|
| N | Microsoft Windows Desktop Search Tool Tray Admin | WindowsSearch.exe | "System Tray access to Windows Desktop Search for XP from Microsoft - which adds additional search options including a search box on the Taskbar. For this version (2.6.*) |
| X | Microsoft Windows DHCP | ___r.exe | "Added by the MASLAN.A or MASLAN.C WORMS!"
|
| X | Microsoft Windows DLL 32-BIT | msncheck32.exe | "Added by the SDBOT-XX WORM!"
|
| X | Microsoft Windows DLL Services | mwindll.exe | "Added by the SDBOT-VX WORM!"
|
| X | Microsoft Windows DLL Services Configuration | newdll.exe | "Added by the SDBOT-ZR WORM!"
|
| X | Microsoft Windows DLL Services Configuration | newdll2.exe | "Added by the SDBOT-ABD WORM!"
|
| X | Microsoft Windows DLL Services Configuration | poker.exe | "Added by the SDBOT-ZY WORM!"
|
| X | Microsoft Windows DLL Services Configuration | poker3.exe | "Added by the SDBOT-AAH WORM!"
|
| X | Microsoft Windows DLL Services Configuration | proxy.exe | "Added by the SDBOT-ZL WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windir32.exe | "Added by the SDBOT.BHF WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windir32a.exe | "Added by a variant of the SDBOT.BHF WORM!"
|
| X | Microsoft Windows DLL Services Configuration | windll32.exe | "Added by the SDBOT.BHD WORM!"
|
| X | Microsoft Windows DLL Services Configuration | winDSL.exe | "Added by the SDBOT-ZG WORM!"
|
| X | Microsoft Windows DLL Services Configuration | dllmanager32.exe | "Added by the SDBOT-BTU WORM!"
|
| X | Microsoft Windows DLLHandler | bitpaint.exe | "Added by the SDBOT.AHG WORM!"
|
| X | Microsoft Windows Drivers | windrv.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows DVR | windvr.exe | "Added by the RBOT-AXD WORM!"
|
| X | Microsoft Windows Expl0rer | expl0rer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Windows Explorer | iexplorer.exe | "Added by a variant of the RBOT WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | Microsoft Windows Explorer | explorewin.exe | "Added by the IRCBOT.WORM.212480.H WORM!"
|
| X | Microsoft Windows Express | Microsoft Update | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Windows Express | websploit.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Windows Express | windowslogonb.exe | "Added by the SDBOT.ABOO WORM!"
|
| X | Microsoft Windows Files Loader | cgy32win.exe | "Added by the RBOT-AXR WORM!"
|
| X | Microsoft Windows Game Updater | msgame32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows GUI | Windowz.exe | "Added by the RANDEX.AEV WORM!"
|
| X | Microsoft Windows GUI | msmonk32.exe | "Added by the SDBOT-PE WORM!"
|
| X | Microsoft Windows Kernel Services | winkrnl386.exe | "Added by the ZEBROXY TROJAN!"
|
| X | Microsoft Windows Keyboard service | keyboard.exe | "Added by the RBOT-CRF WORM!"
|
| X | Microsoft Windows Loader | wloader.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Windows Logon Process | winlogon.exe | "Added by the PROXYSER-R TROJAN! Note - this is not the legitimate winlogon.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Windows Media Player | mediaplayer.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Media Player | wimp.exe | "Added by the RBOT-FN WORM!"
|
| U | Microsoft Windows Media Player Network Sharing Service Configuration Application | WMPNSCFG.exe | "Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music |
| X | Microsoft Windows Registry Service | wregistry.exe | "Added by the AGOBOT.AKG WORM!"
|
| N | Microsoft Windows Search System Tray | WindowsSearch.exe | "System Tray access to Windows Search 4.0 for XP from Microsoft - which adds additional search options including a search box on the Taskbar. This version also includes the Windows Search (WSearch) service which indexes files and e-mails items so you can quickly find words and phrases. Disabling this entry does not affect the normal operation"
|
| X | Microsoft Windows Secure | windocs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Secure | windocs.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Secure Server | rpcxWindows.exe | "Added by the RBOT-LL WORM!"
|
| X | Microsoft Windows Secure Update | rpcxwinupdt.exe | Added by an unidentified WORM or TROJAN!
|
| X | Microsoft Windows Securety | wurguar.exe | "Added by the RBOT-KY WORM!"
|
| X | Microsoft Windows Security | spvsper.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Security | wscndrives.exe | "Added by the RBOT-AJK WORM!"
|
| X | Microsoft Windows Service | winsys.exe | "Added by the RBOT-ADP WORM!"
|
| X | Microsoft Windows Service Pack | winspkn.exe | "Added by the RBOT-AYD WORM!"
|
| X | Microsoft Windows Services | msw32.exe | "Added by the RBOT-FWQ WORM!"
|
| X | Microsoft Windows Services | Sersices.exe | "Added by the SDBOT-NO WORM!"
|
| X | Microsoft Windows Services Edt | ssvvcchhoosst.exe | "Added by the RBOT-FYF TROJAN!"
|
| X | Microsoft Windows Services Edt | dllrun32.exe | "Added by the RBOT-GAF WORM!"
|
| X | Microsoft Windows Session Manager Subsystem | smss.exe | "Added by the PROXYSER-R TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| U | Microsoft Windows Sidebar | Sidebar.exe | "Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
|
| X | Microsoft Windows Socketx32 Services | winsockx32.exe | "Added by the RBOT-FWT WORM!"
|
| X | Microsoft Windows Sound | svghost.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Windows Sound | svshost.exe | "Added by the RBOT.RNE BACKDOOR!"
|
| X | Microsoft Windows Sound | svuhost.exe | "Added by the KOLAB.XC WORM!"
|
| X | Microsoft Windows Sound Drivers | sounddrivers.exe | "Added by the SLENFBOT.ABU WORM!"
|
| X | Microsoft Windows Storage Machine Service | winms.exe | "Added by the RBOT-AHK WORM!"
|
| X | Microsoft Windows SVCHOST | SVCHOST.exe | "Added by the VB.KV WORM! Note - this is not the legitimate svchost.exe process which should not normally figure in Msconfig/Startup!"
|
| X | Microsoft Windows System | srwhost.exe | "Added by the RBOT-AWU WORM!"
|
| X | Microsoft Windows System | syshost.exe | "Added by the RBOT-ASW WORM!"
|
| X | Microsoft Windows System | System.exe | "Added by the VB.KV WORM!"
|
| X | Microsoft Windows System Kernel | kernel32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Windows System Service Manager | winsvc.exe | "Added by the SPYBOT.LR WORM!"
|
| X | Microsoft Windows Task Management | mstasks.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Task Manger | Mstosk.exe | "Added by the SDBOT-WW WORM!"
|
| X | Microsoft Windows Tasks Management | taskmng.exe | "Added by the RBOT-FXK WORM!"
|
| X | Microsoft Windows Updata | scvhost.exe | "Added by the RBOT.CEM BACKDOOR!"
|
| X | Microsoft Windows Updata | windows.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Updata | [5 random letters].exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update | rundlls.exe | "Added by the HABRACK WORM!"
|
| X | Microsoft Windows Update | msoffice2.exe | "Added by the RBOT-GB WORM!"
|
| X | Microsoft Windows Update | spools.exe | "Added by the SDBOT.TD WORM!"
|
| X | Microsoft Windows Update | svchos.exe | "Added by the SDBOT.AC WORM!"
|
| X | Microsoft Windows Update | svcshost.exe | "Added by the FORBOT-CF WORM!"
|
| X | Microsoft Windows Update | svmhost.exe | "Added by the FORBOT-CH WORM!"
|
| X | Microsoft Windows Update | svshost.exe | "Added by the WOOTBOT.CJ WORM!"
|
| X | Microsoft Windows Update | msnmessenger.exe | "Added by the SDBOT.AJ WORM!"
|
| X | Microsoft Windows Update | msnwun.exe | "Added by the SDBOT-RM WORM!"
|
| X | Microsoft Windows Update | scvvhost.exe | "Added by the FORBOT-DH WORM!"
|
| X | Microsoft Windows Update | swwhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update | MSNMSGR.EXE | "Added by the SDBOT-WM WORM! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%\MSN Messenger or %ProgramFiles%\Windows Live\Messenger. This one is located in %System%"
|
| X | Microsoft Windows Update | svzhost.exe | "Added by the FORBOT-EV WORM!"
|
| X | Microsoft Windows Update | sccvhost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Update | scrhost.exe | "Added by the RBOT-AOW WORM!"
|
| X | Microsoft Windows Update | mnswinsx.exe | "Added by the RBOT-AWH WORM!"
|
| X | MICROSOFT Windows update | pdate.exe | "Added by the RBOT.BZT WORM!"
|
| X | Microsoft Windows Update | srshost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Update | rhost32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Microsoft Windows Update | windowsupdate.exe | "Added by the AGOBOT.ON WORM!"
|
| X | Microsoft Windows Update | servcs.exe | "Added by the SDBOT.AL BACKDOOR!"
|
| X | Microsoft Windows Update | syssinfos.exe | "Added by the RBOT-FWR WORM!"
|
| X | Microsoft Windows Update Application | wuap.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update Client | csrss.exe | "Added by the KEBEDE-G WORM! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\Systems32"
|
| X | Microsoft Windows Update Client | services.exe | "Added by the AUTORUN.DVE WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Microsoft Windows Update Logon | win-logon.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update Service | wupdmgr32.exe | "Added by the DOS.AUTOCAT TROJAN!"
|
| X | Microsoft Windows Update Service | msnmsg.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Microsoft Windows Update x86 | [various filenames] | "Added by a variant of the RBOT WORM! Filenames seen include (but are not limited to firefox.exe |
| X | Microsoft Windows Update XP64 | ********.exe [* = random char] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Update XP64 | updatexp64.exe | "Added by the SDBOT-AIM WORM!"
|
| X | Microsoft Windows Update XP64 | Lcuninst.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Update XP64 | mzhxlixm.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Updater | winupdgm.exe | "Added by the GAOBOT.BI WORM!"
|
| X | Microsoft Windows Updater | WINIUPDATES.EXE | "Added by the RBOT-KK WORM!"
|
| X | Microsoft Windows Updater | WINUPDATE.EXE | "Added by the RBOT-LI WORM!"
|
| X | Microsoft Windows Updater | TMNTSrv.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft Windows Updater | win32upd.exe | "Added by the RBOT-EC WORM!"
|
| X | Microsoft Windows Updater | msnupdateit.exe | "Added by the AGOBOT-RL WORM!"
|
| X | Microsoft Windows Updater | windates.exe | "Added by the SDBOT.TE WORM!"
|
| X | Microsoft Windows Updater | spoolvs.exe | "Added by the RBOT.ACQ WORM!"
|
| X | Microsoft Windows Updater | suvhost.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Updater | winfix.exe | "Added by the RBOT-CM WORM!"
|
| X | Microsoft Windows updaterD | log32zx.exe | "Added by the MYDOOM.W WORM!"
|
| X | Microsoft Windows Updates | explorer32.exe | "Added by the SDBOT.VQ WORM!"
|
| X | Microsoft Windows Updates | wsap32.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft Windows Updating System | msresource.exe | "Added by the RBOT-EAM WORM!"
|
| X | Microsoft Windows Visual V2.0 | msiutil.exe | "Added by the DELF.JPH TROJAN!"
|
| X | Microsoft Windows W32 Services | mssw32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Windows WinSaSS Management | winsass.exe | "Added by the RBOT-APW WORM!"
|
| X | Microsoft Windows WKS Service | gt.exe | "Added by the SDBOT.IR BACKDOOR!"
|
| X | Microsoft Windows WKS Service | mstask0.exe | "Added by the SDBOT.FV WORM!"
|
| X | Microsoft Windows Workstation | devcode.exe | "Added by the RBOT-AWL WORM!"
|
| X | Microsoft Windows XP Configuration Loader | m32svco.exe | "Added by the SDBOT.WORM!.48548 WORM!"
|
| X | Microsoft Windows XP/2K Explorer | winexplorer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Microsoft Winedows startup | WinKey.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Microsoft Winedows Updateing | NinKey.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Microsoft Winedows WinServ | iPodFix.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft WINGS32 Protocol | WinSGR32.exe | "Added by the RBOT-APU WORM!"
|
| X | Microsoft WinRaR | winrar.exe | "Added by the RBOT-AEC WORM!"
|
| X | Microsoft Winsock | mswinsck.exe | "Added by the RBOT-ANK WORM!"
|
| X | Microsoft Winsock Service | msusvc.exe | "Added by the RBOT-ANS WORM!"
|
| X | Microsoft Winsock Wrapper | ws2_32s.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Microsoft Winsock32 System | winsock32.exe | "Added by the SPYBOT.AKKC WORM!"
|
| X | Microsoft WinSound | [random filename] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft winsupdater | WINSUPDATER.EXE | "Added by the SPYBOTER.FB BACKDOOR!"
|
| X | Microsoft WinUpdate | mntcgf032.exe | "Added by the RBOT-PF WORM!"
|
| X | Microsoft WinUpdate | svh0st.exe | "Added by the SPYBOT.DL WORM!"
|
| X | Microsoft WinUpdate | syslx32.exe | "Added by an unidentified VIRUS |
| X | Microsoft WinUpdate | syswin32.exe | "Added by the RBOT-HO WORM!"
|
| X | Microsoft WinUpdate | spfix.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft WinUpdate | Winamp61.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft WinUpdate | Winupd32.exe | "Added by the RBOT.MQ WORM!"
|
| X | Microsoft WinUpdate | WinNTinit32.exe | "Added by the RBOT.VS WORM!"
|
| X | Microsoft WinUpdate | msupdte.exe | "Added by an unidentified TROJAN! See examples here & here"
|
| X | Microsoft WinUpdates | serm32.exe | "Added by the RBOT.GE WORM!"
|
| X | Microsoft WM | mswm32.exe | "Added by the BCKDR-AM BACKDOOR!"
|
| X | Microsoft Word | BootSector.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Microsoft Word Profissional | csrss.exe | "Added by the BANCBAN-DB TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""s1613"" subfolder"
|
| X | Microsoft Word Profissional | Java Plug In close.exe | "Added by the BANKER-EL TROJAN!"
|
| X | Microsoft Word Profissional | csrss.exe | "Added by the BANKER-DJ TROJAN! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""protect"" subfolder"
|
| X | Microsoft Word Profissional | csrss.exe | "Added by the BANKER-DP TROJAN! ! Note - this is not the legitimate csrss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""JavaVM"" subfolder"
|
| N | Microsoft Works Calendar Reminders | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
|
| N | Microsoft Works Portfolio | WksSb.exe | The Works Portfolio tool lets you collect and organize text and pictures from the Web or your favorite program. The Works Portfolio provides a location where you can store items you want to later put into a document or other file. Can be prevented from starting from a setting within Portfolio
|
| N | Microsoft Works Update Detection | wkdetect.exe | Checks for updates to MS Works
|
| X | Microsoft World Service | winworld.exe | Added by an unidentified IRC worm with backdoor capability!
|
| X | Microsoft WPCEmail | [path to trojan] | "Added by the SNIFFER-N TROJAN!"
|
| X | Microsoft WWW | [path to trojan] | "Added by the AGENT-DRI TROJAN!"
|
| X | Microsoft Wxdate | Syswu32.exe | "Added by the SPYBOT.HZ WORM!"
|
| X | Microsoft X Update | wuamkoppnp.exe | "Added by the RBOT-ANI WORM!"
|
| X | microsoft xdaemon 2.0 | xdaemon.exe | "Added by the DELF.D TROJAN!"
|
| X | Microsoft XML Service | msxmlx.exe | "Added by the RBOT.KS WORM!"
|
| X | Microsoft Xp Systems loader | winsystem32xp.exe | "Added by the KELVIR.W WORM!"
|
| X | Microsoft Xp Systems loaders | win32xpsys.exe | "Added by the SPYBOT.NYT WORM!"
|
| X | Microsoft XPSP Protocol | xp386.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft xpsp2 | Networksystem.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Microsoft xpsp2 | xpsp2.exe | "Added by the SDBOT-YQ WORM!"
|
| X | Microsoft's System Module | Sysmodule.exe | "Added by the BDOOR-FJ BACKDOOR!"
|
| X | Microsoft(R) System Manager | sysmgr.exe | "Added by the AGENT.QTR TROJAN!"
|
| X | Microsoft--Updates | sxvhost.exe | "Added by the RBOT-FH WORM!"
|
| X | Microsoft-software | ****.exe [* = random char] | "Added by a variant of the RBOT WORM!"
|
| X | Microsoft-Update | wngard.exe | "Added by the RBOT-JV WORM!"
|
| X | Microsoft-Updates | svxhost.exe | "Added by the RBOT-CT WORM!"
|
| X | Microsoft.exe | [random].exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | microsoft.exe | microsoft.exe | "Added by the GOLDUN-GB TROJAN!"
|
| X | Microsoft32 | win32sys.exe | Added by an unidentified WORM or TROJAN!
|
| X | microsoft420 | microsoft420.exe | "Added by the MENACE.B WORM!"
|
| X | Microsoft64 | antiv.exe | "Added by the SOBER WORM!"
|
| Y | MicrosoftAntiSpywareCleaner | gcASCleaner.exe | "Microsoft Antipsyware - now superseded by Microsoft's Windows Defender"
|
| X | MicrosoftCorp | flashsplayer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MicrosoftCorp | javaw.exe | "Added by the BUZUS.BULO TROJAN!"
|
| X | MicrosoftCorp | msnrmgs.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MicrosoftCorp | regtray.exe | "Added by the POISON.AHNW BACKDOOR!"
|
| X | MicrosoftCorp | securebind.exe | "Added by the INJECT TROJAN!"
|
| X | MicrosoftCorp | sysdiag64.exe | "Added by a the AUTOINF-AB WORM!"
|
| X | MicrosoftCorp | traymgr.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MicrosoftCorp | update.exe | "Added by the AUTORUN-ASG WORM!"
|
| X | MicrosoftCorp | wupdate.exe | "Added by the AGENT-LAY TROJAN!"
|
| X | MicrosoftDriverService32 | drsys32.exe | "Added by the IRCBOT.AKX BACKDOOR!"
|
| X | Microsoftf DDEs ContDLL | rune.pif | "Added by the RBOT-AGF WORM!"
|
| X | Microsoftf DDEs ContrDL | runm.pif | "Added by the RBOT-AFQ WORM!"
|
| X | Microsoftf DDEs Control | lxes.exe | "Added by the RBOT.BOF WORM!"
|
| X | Microsoftf DDEs Control | wees.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoftf DDEs Control | soff.pif | "Added by the RBOT-AKH WORM!"
|
| X | Microsoftf DDEs Control | why-.exe | "Added by the RBOT-AMV WORM!"
|
| X | Microsoftf DDEs Control | msnn.exe | "Added by the RBOT-AXT WORM!"
|
| X | Microsoftf DDEs Control | FEnR.exe | "Added by the RBOT-AIM WORM!"
|
| X | Microsoftf DDEs Control | w33s.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoftf DDEs Control | waes.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsoftkeysd | systemproc.exe | "Added by the FORBOT-BI WORM!"
|
| X | Microsoftkeysd | systemwin32s.exe | "Added by the WOOTBOT.CO WORM!"
|
| X | Microsoftkeysds | lass32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MicrosoftKs | Drivers.bat | "Added by the SHUTDOWN-F TROJAN!"
|
| X | microsoftm eegs cuntrol | loor.pif | "Added by a variant of the RBOT WORM!"
|
| X | MicrosoftMessenger | msnserv.exe | "Added by the DARKER.M WORM!"
|
| X | Microsoftmsn32.exe | microsoftmsn32.exe | "Added by the CERTIF-C TROJAN!"
|
| X | MicrosoftMultimediaTask | Mmtask.exe | Adware downloader - not the valid MusicMatch Jukebox which shares the same filename
|
| X | MicrosoftNAPC | flashsplayer.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MicrosoftNAPC | javaw.exe | "Added by the BUZUS.BULO TROJAN!"
|
| X | MicrosoftNAPC | msnrmgs.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MicrosoftNAPC | regtray.exe | "Added by the POISON.AHNW BACKDOOR!"
|
| X | MicrosoftNAPC | securebind.exe | "Added by the INJECT TROJAN!"
|
| X | MicrosoftNAPC | sysdiag64.exe | "Added by a the AUTOINF-AB WORM!"
|
| X | MicrosoftNAPC | traymgr.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MicrosoftNAPC | update.exe | "Added by the AUTORUN-ASG WORM!"
|
| X | MicrosoftNAPC | wupdate.exe | "Added by the AGENT-LAY TROJAN!"
|
| X | MicrosoftNetwork Daemon for Win32 | NETD32.EXE | "Added by the RANDEX.F WORM!"
|
| X | MicrosoftOEM | smvss.exe | "Added by the DEDLER-G TROJAN!"
|
| X | MicrosoftPersonalFirewall | spoolsrv.exe | "Added by the WOOTBOT.DO BACKDOOR!"
|
| X | MicrosoftROMDriverService | cdrss.exe | "Added by the IRCBOT.BLF BACKDOOR!"
|
| X | MicroSoftRun | MSCOMM.dll | "Added by the AGENT-DJG TROJAN!"
|
| X | Microsofts Help Services | msnmngr.exe | "Added by the SDBOT-PJ WORM!"
|
| X | Microsofts media | winmplayd.exe | Added by an undidentified WORM or TROJAN!
|
| X | Microsofts media | wingtp.exe | "Added by the RBOT-VO WORM!"
|
| X | Microsofts MediaScope | winmep.exe | "Added by the RBOT-WB WORM!"
|
| X | Microsofts MediaScope | winmedplay.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsofts Security Manager | ****.exe [**** = random char] | "Added by the RBOT-WH TROJAN!"
|
| X | Microsofts Service | lcsrv16.exe | "Added by a variant of the RBOT WORM!"
|
| X | Microsofts Updates | lsasss.exe | "Added by the RBOT-AEX WORM!"
|
| X | Microsofts Updatez | cmsssr.exe | "Added by an unidentified VIRUS |
| X | Microsofts Updatez | exploirez.exe | "Added by a variant of the RBOT WORM!"
|
| X | MicrosoftServiceManager | mstask32.exe | "Added by the YAHA.P WORM!"
|
| X | MicrosoftServiceManager | Wintsk32.exe | "Added by the YAHA.U WORM!"
|
| X | MicrosoftServiceManager | EXPLORERE.EXE | "Added by the YAHA.AB WORM!"
|
| X | MicrosoftServiceManager | msupdat.exe | "Added by the YAHA.AA WORM!"
|
| X | MicrosoftShell | Shellcomm.exe | "Added by the BANCBAN-QG TROJAN!"
|
| X | MicrosoftSourceSafe | csrss.exe | "Added by the WEBUS TROJAN! Note - this is not the legitimate csrss.exe process which should not normally figure in Msconfig/Startup!"
|
| X | MicrosoftSourceSafe | lsass.exe | "Added by the WEBUS.B TROJAN! Note - this is not the legitimate lsass.exe process which should not normally figure in Msconfig/Startup!"
|
| X | MicrosoftSys | SPOOLSYS.exe | "Added by the TARNO.N TROJAN!"
|
| X | MicrosoftUpdate | syshelper.exe | "Added by the WOOTBOT.AC WORM!"
|
| X | MicrosoftUpdate | WinUp32.exe | "Added by an unidentified VIRUS |
| X | MicrosoftUpdate | MicrosoftUpdate.exe | "Added by the BANKER-EHC TROJAN!"
|
| X | MicrosoftUpdate | windll.exe | "Added by the RBOT-IH WORM!"
|
| X | MicrosoftUpdate | RBuilder.exe | "Added by the DLOADR-BMV TROJAN!"
|
| X | MicrosoftUpdate | svhest.exe | "Added by the RBOT-ES WORM!"
|
| X | MicrosoftUpdate | downnew.exe | "Added by the TANTO-D TROJAN!"
|
| X | MicrosoftUpdates | [path to trojan] | "Added by the DELF-LO TROJAN!"
|
| X | MicrosoftUpdates | syshelped.exe | "Added by the FORBOT-AZ WORM!"
|
| X | MicrosoftValue | syscnfg.exe | "Added by an unidentified VIRUS |
| X | Microsoftvirus | sysoverload.exe | "Added by the FORBOT-AL WORM!"
|
| X | MicrosoftWindows | [various filenames] | "MagicSearch - a CoolWebSearch parasite variant"
|
| X | MicrosoftWindows | a@26m.exe | "Added by the KILLPAR-B TROJAN!"
|
| X | MicrosoftXP Service Pack 2 | servicepack2.exe | "Added by the RBOT.EMC WORM!"
|
| X | Microsoftz turn Control | aexl.exe | "Added by the SDBOT.BCO WORM!"
|
| X | Microsoftz turn Control | read.pif | "Added by the RBOT-AFS WORM!"
|
| X | Microsoft© | iexplore.exe | "Added by the IRCBOT-ACO TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe) which is always located in %ProgramFiles%\Internet Explorer and should not normally figure in Msconfig/Startup! This one is located in %System%\dllcache"
|
| X | Microsoft© PID Lex | PIDLex.exe | "Added by the NIOVADOOR TROJAN!"
|
| X | Microsoft© System Mapper | SysMap.exe | "Added by the MAPSY TROJAN!"
|
| X | Microsoft« ActiveX Debugger NT | setdebugnt.exe | "Added by the BANCOS-CZ TROJAN!"
|
| U | Microsoft® Windows Mobile® Device Center | wmdc.exe | "Windows Mobile Device Center - mobile device management/synchronization software for Windows7/Vista |
| U | Microsoft® Windows® Operating System | Sidebar.exe | "Windows Sidebar is a pane on the side of the Microsoft Windows Vista desktop where you can keep your gadgets organized and always available. In Windows 7 this feature is known as Desktop Gadgets and each gadget can be placed anywhere on the desktop. If the file isn't located in %ProgramFiles%\Windows Sidebar or you're using other versions of Windows it could be part of the Searchcentrix hijacker"
|
| N | Microsoft® Windows® Operating System | "RunDLL32.exe ehuihlp.dll | BootMediaCenter" |
| N | Microsoft® Windows® Operating System | p2phost.exe | "Signs a user into the People Near Me feature at login in Windows 7 and Vista. People Near Me enables you to use certain peer-to-peer (P2P) programs on a network - that ""identifies people nearby who are using computers and allows those people to send you invitations for programs such as Windows Meeting Space. They can only invite you to participate in programs that are installed on your computer."" Available via Start → Control Panel"
|
| U | Microsoft® Windows® Operating System | ehTray.exe | "Media Center Tray Applet - part of Windows Media Center on XP MCE |
| N | Microsoft® Windows® Operating System | "rundll32.exe oobefldr.dll | ShowWelcomeCenter" |
| N | Microsoft® Windows® Operating System | stikynot.exe | "Microsoft Sticky Notes - virtual sticky notes tool from Windows Vista. This implementation of the popular yellow ""Post-It"" tool is part of the Tablet PC features and allows you to enter either handwriting (via a pen or mouse) or record a voice note. AVailable via Start → All Programs"
|
| U | Microsoft® Windows® Operating System | WMPNSCFG.exe | "Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music |
| N | Microsoft® Works 7.0 | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
|
| N | Microsoft® Works 8 | wkcalrem.exe | If you schedule an event at any time in Microsoft Works Calendar and set a reminder then a shortcut will be added to Start → All Programs → Startup so this reminder service loads every time Windows starts
|
| X | Microsot NT Support | [random filename].exe | "Added by the RBOT-CTI WORM!"
|
| X | Microsotufed Update 32 | windinit.exe | "Added by the RBOT-CTJ WORM!"
|
| X | Microszoft Update Mach1nezs | svchst.exe | "Added by the RBOT-ED WORM!"
|
| U | Microtek Scanner Finder | ScannerFinder.exe | Monitors whether a scanner is present. Provided with Microtek scanners
|
| X | Microzoft_Ofiz | KdzEregli.exe | "Added by the AMUS.A WORM!"
|
| X | Micrsft Updese | xagwxz.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Micrsoft CFG 32 | lrbzus32.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Micrsoft DerSystem | uqieelpb.exe | "Added by the RBOT-GRI WORM!"
|
| X | Micrsoft Driver | windrive.exe | "Added by the SDBOT.AF TROJAN!"
|
| X | Micrsoft Driver | msdriver.exe | "Added by the SDBOT-XD WORM!"
|
| X | Micrsoft Driver | windrive32.exe | "Added by the SLINBOT.TT BACKDOOR!"
|
| X | Micrsoft Internet Explorer | IEXPL0RE.EXE | "Added by the RBOT-AQV WORM! Note the number ""0"" in the filename"
|
| X | Micsoft-Published-Software | explrer.exe | "Added by the RBOT-GFL WORM!"
|
| X | Micsorosft Security Center | wcnsfty.exe | "Added by the RBOT-AHU WORM!"
|
| N | MightyFAX Controller | MFNTCTL.EXE | "Mighty FAX from RKS Software - "installs a printer driver so that you can fax directly from Windows software""
|
| U | Mindful | Mindful.exe | "Mindful from Felitec inc. ""Event reminder software with date and time tools in a simple to use system tray application"""
|
| N | MINIFERT.EXE | MINIFERT.EXE | Part of Backweb
|
| X | minimo | [path to file] | "Added by the MOSUCK-X TROJAN!"
|
| X | Mioft Wiws Seice ent | [worm filename].exe | "Added by the RBOT-GIJ WORM!"
|
| X | Miosf Update | wimsqaad.exe | "Added by the SDBOT.AG TROJAN!"
|
| X | Mirate Sp 2 Information | miratesp2.exe | "Added by the RBOT.QH WORM!"
|
| X | Mircosoft DNS Service | svchost.exe | "Added by the IRCBOT-AK TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in a ""drivers"" subfolder"
|
| X | Mircosoft Sockets SP2 | mssck.exe | "Added by the MYTOB.ET WORM!"
|
| X | Mircosoft Update | wuampkd.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Mircosoft Windows Developer Enviroment | devenv.exe | Added by an unidentified WORM or TROJAN!
|
| X | Mircosoft Windows Developer Enviroment | devenv.exe | "Added by the RBOT.AUJ BACKDOOR!"
|
| X | Mircrosoft Svchost32 | svchost32.exe | "Added by the RBOT-AZW WORM!"
|
| X | Mircrosoft Technic Help | EditKey.exe | "Added by the KOLABC.AS WORM!"
|
| X | Mircrosoft Technic Help | RegKey.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Mircrosoft Windows Config DLL | rundllc32b.exe | "Added by the RBOT-ZY WORM!"
|
| U | MirrorFolderShell | mrfshl.exe | "MirrorFolder backup software"
|
| X | Mirsoft sdcE | taskmegr.exe | "Added by the RBOT-AWY WORM!"
|
| X | Miscrosoft Windows Explorer | IEEXPLORER.exe | Reported as the SDBOT.YX WORM!
|
| X | Mlcr0s0ftf DDEs C0ntr0i | WAed.pif | "Added by the RBOT-BJW WORM!"
|
| X | MlCROSOFT FEnR | MlCROSOFT.EXE | "Added by the GAOBOT.CII WORM! Note that both the name and command have a lower case ""L"""
|
| U | MMERefresh | MMERefresh.exe | "Part of Digidesgin Protools. Refreshes your midi ports on the 002(R) (the 002R is a hardware audio/midi converter connected to your computer via firewire). Must be running in order to use the MIDI functionality of the Digi002R"
|
| X | MMicrosoft Security Management | inetforn.exe | "Added by the RBOT.AFZ WORM!"
|
| X | mmsddlx | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| U | Mobipocket Reader Notifications | readernotify.exe | "Part of Mobipocket Reader - ""Store all your eBooks |
| X | Modeminf | Modeminf.exe | "Added by a variant of the CRYPTER.C TROJAN!"
|
| X | Modifiet Amateur HTPB | wuaclt.exe | "Added by the IRCBOT.AYS WORM!"
|
| X | ModularConfig | syscnfg.exe | "Added by an unidentified VIRUS |
| X | Modulo 00FE0F01 Host Internet | syschost.exe | "Added by the DELF-KW TROJAN!"
|
| X | MonAppli | [random filename] | "Added by the DELF.IF TROJAN! The most common filenames are isys32.exe & msnmsg.exe"
|
| X | Monitor Test | [random filename] | "Added by the SDBOT-NC WORM!"
|
| N | Monstersoundtray | Freectrl.exe | Diamond Multimedia sound card control panel
|
| X | Motherboard Config | Ati2xxx.exe | "Added by the RBOT-AIK WORM!"
|
| N | Motive SmartBridge | BTHelpNotifier.exe | "System tray icon for help from BT Broadband |
| U | Motorola Desktop Suite mRouter Config | mRouterConfig.exe | "Configuration for Motorola's version of Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth |
| U | Mount Safe & Sound | Fbmount.exe | From McAfee VirusScan version 5.x. Creates back-up sets of critical files in a separate area of a hard drive. If you make regular back-ups it's not needed and can be painful during system start
|
| U | mouseElf | MC.exe | "Genius NetScroll mouse driver - required if you use non-standard Windows driver features"
|
| U | mouseElf | mouseElf.exe | System Tray access to the mouse control panel for Genius Netscroll mice. Required if you use non-standard Windows driver features
|
| U | Mousinfo | mousinfo.exe | MS mouse information tool - for troubleshooting mouse problems
|
| X | MoussaEvil | [path to file] | "Added by the MUSANUB-A WORM!"
|
| X | Mozila Firefox | firebox.exe | "Added by the RBOT-AIP WORM!"
|
| X | Mozilla Firebird v0.8 Internet Browser | netstats.exe | "Added by the IRCBOT.MC TROJAN!"
|
| X | Mozilla Firefox | F1REF0X.EXE | "Added by the SDBOT-UP BACKDOOR! Note that the filename has the numbers ""1"" and ""0"" in place of upper case ""i"" and ""o"" respectively"
|
| X | Mozilla Firefox | firefox.exe | "Added by the AUTOTUN.POM WORM! Note - this is not the popular FireFox web browser and is located in %System%"
|
| X | MP3files | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3freeDownload | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| X | MP3freeDownloads | "rundll32.exe MSA64CHK.dll | DllMostrar" |
| Y | MPFExe | mpf.exe | McAfee Personal Firewall
|
| Y | MPFExe | MpfTray.exe | McAfee Personal Firewall
|
| Y | MPFTray | MpfTray.exe | McAfee Personal Firewall
|
| U | MPSExe | mscifapp.exe | McAfee.com Privacy Service - "combines personal identifiable information (PII) protection with online advertisement blocking and content filtering"
|
| U | mRouterConfig | mRouterConfig.exe | "Configuration for Intuwave's m-Router - ""that enables easy connectivity between mobile devices and PCs across Bluetooth |
| X | Mr_CoolFace_Game | Emma.exe | "Added by the ROMARIO-A WORM!"
|
| X | MS Config | msdconfig.exe | "Added by the RBOT-CZH WORM!"
|
| X | MS Config Loader | svchos1.exe | "Added by the AGOBOT.R WORM!"
|
| X | MS Config Loader | MSWin32bck.exe | "Added by the GAOBOT.AA WORM!"
|
| X | MS Config Loader | svcrhost.exe | "Added by a variant of the RBOT WORM!"
|
| X | MS Config Service | Msloader32.exe | "Added by the RBOT-KJ WORM!"
|
| X | MS Config Stream | msasm.exe | "Added by the AGOBOT-BA WORM!"
|
| X | MS Config v12 | mscfg12.exe | "Added by the AGOBOT.YP WORM!"
|
| X | MS Config v13 | lrbz32.exe | "Added by the GAOBOT.AOL WORM!"
|
| X | MS Config v13 | mscfg13.exe | "Added by the AGOBOT.YQ WORM!"
|
| X | Ms configsu | msconfigsu.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MS Configuration | MSFramer.exe | "Added by the RANDEX.OL WORM!"
|
| X | Ms Configuration | microsoftsa32.exe | "Added by the KELVIR.X WORM!"
|
| X | MS Configuration Utility | msconfig32.exe | "Added by the WOOTBOT.DY WORM!"
|
| X | MS Decryption Software | active.exe | "MediaTickets adware variant"
|
| X | MS FIREWALL | msfrewall.exe | "Added by the SDBOT-PU WORM!"
|
| X | MS FIREWALL | msfirewall.exe | "Added by the SDBOT-QH WORM!"
|
| X | MS Java Applets for Windows NT & XP | javaapplet.exe | "Added by the RBOT.BHG WORM!"
|
| X | Ms Java for Windows NT | MS32.exe | "Added by the VANEBOT-H WORM!"
|
| X | Ms Java for Windows NT | msi32java.exe | "Added by the VANEBOT-I WORM!"
|
| X | Ms Java for Windows NT | msjava.exe | "Added by the VANEBOT-E WORM!"
|
| X | Ms Java for Windows NT | msi32info.exe | "Added by the RBOT.AFX WORM!"
|
| X | MS Java for Windows XP & NT | javanet.exe | "Added by the VANEBOT-A WORM!"
|
| X | Ms Java Update For Windows NT/XP | msijavaupdt32.exe | "Added by the RANDEX.AF WORM!"
|
| X | MS Microsoft Socket Deamon | MSSCKD32.exe | "Added by a variant of the RBOT WORM!"
|
| X | MS Office | Office10.exe | "Added by the VB.DT TROJAN!"
|
| X | MS Security | systm.pif | "Added by the RBOT-AQN WORM!"
|
| X | MS Security Hotfix | service5.exe | "Added by the GAOBOT.AG WORM!"
|
| X | Ms sock for Windows NT | winser.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MS Sound Config 16bit | sndcfg16.exe | "Added by the SDBOT.MB TROJAN!"
|
| X | MS Sys Security | mswin.pif | "Added by the RBOT-APJ WORM!"
|
| X | MS System Call Function | msscf32.exe | "Added by the RBOT-GBZ WORM!"
|
| X | Ms System Config | Mscfg.exe | "Added by the SDBOT-CCR WORM!"
|
| X | Ms System Config | pcedit.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MS System Security | mswin32.pif | "Added by the RBOT-AOX WORM!"
|
| X | MS Task Manager 32 | [trojan filename] .exe | "Added by the RANKY.NF TROJAN!"
|
| X | MS Windows Security Updater | updater.pif | "Added by the RBOT-AKY WORM!"
|
| X | MS WINS Binary | ign32.pif | "Added by the RBOT-ASB WORM!"
|
| X | MS-DOS Boot Service | Boot32.pif | "Added by the RBOT-AMF WORM!"
|
| X | MS-DOS Security Service | ms-dos.pif | "Added by the RBOT-AMR WORM!"
|
| X | MS-DOS Service | MS-DOS.pif | "Added by the RBOT-AII WORM!"
|
| X | MS-DOS Windows Service | MS-DOS.PIF | "Added by the RBOT-AJW WORM!"
|
| X | MS-HTML | [random filename] | "Added by the LATINUS.15 TROJAN!"
|
| X | MS-patch | msconfig32.exe | "Added by the RBOT-AUF WORM!"
|
| X | MS32DLL | ffqca.exe | "Added by the SDBOT-YD WORM!"
|
| X | MsAudio | "MsVM_STI.EXE RunDll32 cmicnfg.cpl | CMICtrlWnd" |
| X | mschkdf.exe | mschkdf.exe | "Added by a variant of the SDBOT WORM!"
|
| ? | msci | mcinfo.exe | "McAfee Internet Security related. What does it do and is it required?"
|
| X | Msconf32 | Msconf32.exe | "Added by the AGOBOT-NR WORM!"
|
| X | MSCONFG32.EXE | MSCONFG32.EXE | "Added by the OPTIX.04.C TROJAN!"
|
| N | MSConfig | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. Located in %System% (98/Me/Vista) or %Windir%\PCHealth\HelpCtr\Binaries (XP)
|
| X | MSConfig | MSCONFIG32.EXE | "Added by the SPYBOT.B WORM!"
|
| X | msconfig | msconfig.exe | "CoolWebSearch MSConfig parasite variant. Note - this overwrites the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
|
| X | msconfig | msconfig.exe | "Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
|
| X | msconfig | wins.exe | "Added by the RBOT.PF WORM!"
|
| X | MSConfig | MSCONFIG35.EXE | "Added by a variant of the SPYBOT WORM!"
|
| X | msconfig | scvhost.exe | "Added by the AGENT-DSF TROJAN!"
|
| X | msconfig | winlog.exe | "Added by the IRCBOT-TJ TROJAN!"
|
| X | Msconfig | icpldrvx.exe | "Added by the BANLOAD.BFT TROJAN!"
|
| X | msconfig | msconfig.com | "Added by the IRCBOT-SM WORM!"
|
| X | msconfig | msconfig.bat | "Added by the PAHATIA.B WORM!"
|
| X | MSConfig | lssas.exe | "Added by the AUTORUN.CEY WORM!"
|
| X | MSConfig | xwpwqf.exe | "Added by the AGENT-NEW TROJAN!"
|
| X | Msconfig lptt01 | msconfig.exe | "RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
|
| X | MSConfig Manager | msupdate.exe | "CoolWebSearch parasite variant"
|
| X | Msconfig ml097e | msconfig.exe | "RapidBlaster variant (in a ""msconfig"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here. Note - this is not the valid Windows Msconfig which has the same executable name"
|
| X | msconfig service | MSupdate32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | msconfig. | msconf.exe | "Added by the BUZUS-AY WORM!"
|
| X | msconfig.exe | proxy.exe | Added by a variant of the AGENT.AH downloader TROJAN!
|
| X | msconfig.exe | uline.exe | Added by a variant of the AGENT.AH downloader TROJAN!
|
| X | msconfig38 | mssvcc.exe | "Added by the RBOT-BJV WORM!"
|
| X | MSConfig45 | MSConfig45.exe | "Added by the SDBOT.OJ TROJAN!"
|
| X | MSConfigr | jdbgmrg.exe | "Added by the DASMIN.C TROJAN! Note - this is not the valid JDBGMGR.EXE file - see here"
|
| N | MSConfigReminder | msconfig.exe | Entry that appears when you uncheck an item in the MSConfig Startup group and will disappear if on the next reboot you select the option to not be reminded that you are running in Selective Startup mode. This particular entry is specific only to 98/Me and is located in %System%
|
| X | MsConfigs | MsConfigs.exe | "Added by the ALCAN.A WORM!"
|
| X | MSConfigs | RUNDLL64.dll.vbs | "Added by the WEKODE-B WORM!"
|
| X | msconfigurator | ctfsdk.exe | "Added by the DELF-ALS TROJAN!"
|
| X | MSCORE | syscnfg.exe | "Added by an unidentified VIRUS |
| ? | MSCRMStartup | Microsoft.Crm.Application.Hoster.exe | "Related to Microsoft Dynamics CRM integrated solutions for Financial |
| X | msctfg32 | msctfg32.exe | "Added by the RBOT-TJ WORM!"
|
| X | msdefender | msdefender.exe | "Identified as a variant of the PAKES.CMD TROJAN! See here for an example"
|
| X | msdefender.exe | msdefender.exe | "Added by the PAKES.ZL TROJAN!"
|
| X | msdev | msconfig.exe | "Added by the AGOBOT.AAU WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting"
|
| X | MSDLL | syscnfg.exe | "Added by an unidentified VIRUS |
| X | MSDN for Windows NT | msdn.exe | "Added by a variant of the RBOT WORM!"
|
| X | MSDN for Windows NT & WinXP | msdnxp.exe | "Added by the IRCBOT-PE WORM!"
|
| X | MSDN for Windows with NT's | msdn-nt.exe | "Added by the RBOT-EWD WORM!"
|
| X | MSDOS Security Service | msdos.pif | "Added by the RBOT-AMP WORM!"
|
| X | MSDOS Service | MSDOS.PIF | "Added by the RBOT-AIY WORM!"
|
| X | MSDOS Windows Service | MSDOS.PIF | "Added by the RBOT-AKF WORM!"
|
| X | Msdos32 | Msdos32.pif | "Added by the RECORY WORM!"
|
| X | MSDRV | NetFilter.exe | "Added by the INTERRUPDATE TROJAN!"
|
| X | Msfind | Msfind.exe | "CoolWebSearch parasite variant"
|
| X | MSFind32 | msfind32.exe | "Added by the CAYAM WORM!"
|
| X | msfindosa.exe | msfindosa.exe | "Added by the DOWNLOADER-BS TROJAN!"
|
| X | MSFTP Service Config | r3grun.exe | "Added by a variant of the SDBOT WORM!"
|
| X | msfw.exe | msfw.exe | "Microsoft Security Adviser rogue security software - not recommended"
|
| X | MSFWAVTSM | FTPDev.exe | "Added by the RBOT-ACF WORM!"
|
| X | Msg Fixage | msgfixed.exe | "Added by the SDBOT.ZD WORM!"
|
| X | MsgApi | [path to file] | "Added by the DEDLER-D TROJAN! The most common filenames seen are ""csmss.exe"" and ""csmrs.exe"" |
| X | Msgsvc32 | [worm filename] | "Added by the NAUTICAL-A WORM!"
|
| X | MSI Configuration | msiconf.exe | "Added by the AGENT.AKSZ TROJAN!"
|
| X | msiconf.exe | msiconf.exe | Added by a variant of the FAKEALERT TROJAN!
|
| X | MSInfo | msinfo.exe | "Added by the ALADINZ.M TROJAN!"
|
| X | MSInfo | AVBgle.exe | "Added by the NETSKY.O WORM!"
|
| X | msjdqs | fddwqt.exe | "Added by the SDBOT-PO WORM!"
|
| X | MSKCES32 | [random filename] | "Added by the CLONER TROJAN!"
|
| X | MSLARISSA | MSLARISSA.pif | "Added by the ASSIRAL.B WORM!"
|
| X | MSLog | MicrosoftLog.exe | "Added by a variant of the SDBOT WORM!"
|
| X | msmc | msgdmf.exe | "ClientMan parasite variant"
|
| X | MSMcAfeee | Avsynmgr32e.exe | "Added by the FRAMAR TROJAN!"
|
| X | MSMcAfeeh | Avsynmgr32h.exe | "Added by the FRANGO TROJAN!"
|
| X | MSMcAfeeS | Avsynmgr32S.exe | "Added by the VOLAC or VOLAC.DR TROJANS!"
|
| X | MSMSGNER | zzgf.exe | "Added by the PWS-CCB TROJAN!"
|
| X | MSMSGNER | fgozmox.exe | "Added by the AGENT-EBJ BACKDOOR!"
|
| X | MSN | ctfmoons.exe | "Added by the SPYBOT.HI WORM!"
|
| X | MSN | Fixdriver.exe | "Added by the SILLYFDC.BBY WORM!"
|
| X | MSN Administration For Windows | msnadp32.exe | "Added by the BROPIA.W WORM!"
|
| X | Msn Boot | msnbootcfg.exe | "Added by the IRCBOT.BFU BACKDOOR!"
|
| X | MSN CNF Manager | msncnfmgr.exe | "Added by the VUNDO TROJAN!"
|
| X | Msn Config | msngf.exe | "Added by the RBOT-QG WORM!"
|
| X | MSN Configuration | msnconfig.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Msn Configuration Loader | msngms.exe | "Added by the KELVIR.T WORM!"
|
| X | MSN Configuration Loader | msmsncfg.exe | "Added by the AGOBOT-KX BACKDOOR!"
|
| X | MSN File & Folder Sharing App | msnfileshare.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | MSN File Configuration | msnfilecfg.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN File Sharing | msnusr.exe | "Added by the SLENFBOT.AM WORM!"
|
| X | MSN File Sharing Wizard | msnsharewiz.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | MSN File Sharing! | msnuser.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | MSN Funny Images | imsngsr.exe | "Added by the AGOBOT-TT WORM!"
|
| X | Msn Messenger | nkbf.exe | "Added by the RBOT-GMQ WORM!"
|
| X | MSN Messenger BETA 7 | bbsdf.exe | "Added by the RANKY.AA TROJAN! Note - this is not a valid MSN Messenger variant"
|
| X | MSN Software | msnsoftware.exe | "Added by the IRCBOT.AWD BACKDOOR!"
|
| X | MSN Update Cfg | msnupdbt.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | Msn Update SUPPORT | [random filename] | "Added by the RBOT-BPS WORM!"
|
| ? | MsnFixer | msnfixjs.js | "Located in the HPbinmsnfix directory of a HP PC"
|
| X | MSNMSGRE | swef.bat | IRC backdoor TROJAN or WORM!
|
| X | msnmsgy | [path to file] | "Added by the BANKER-EQ TROJAN!"
|
| X | msnnt | winampf.exe | Added by the SMALL.DTS TROJAN!
|
| X | Msoffice | msoffice.hta | Hijacker - redirecting to Searchdot.net
|
| X | MSOffice | services.exe | "Added by the DLOADER-EU TROJAN! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in an ""MSOffice"" subfolder"
|
| X | msoffice | msoffice.exe | "Added by the LIKASIMAL WORM!"
|
| X | MSOffice32 | msjcf.exe | "Added by the RAKER-A TROJAN!"
|
| X | MSOfficeCfg | msocfg.exe | Premium rate adult content dialer
|
| X | MSOfficeCfg | navchk.exe | Premium rate adult content dialer
|
| X | MSOfficeCfg | qservice.exe | Premium rate adult content dialer
|
| X | MSOfficeCfg | shman.exe | Premium rate adult content dialer
|
| X | MSOfficeCfg | ssvr.exe | Premium rate adult content dialer
|
| X | msoffwz | msoffwz.EXE | "Added by the BANCBAN-HQ TROJAN!"
|
| X | msoft-updater23 | mssysstems.exe | "Added by the RBOT-ATU WORM!"
|
| X | msoft-updater23 | slssystem.exe | "Added by the RBOT-ASR WORM!"
|
| X | MSPQFile | MSA****.TMP [* = random char] | Homepage hijacker
|
| X | MsServer | msfun80.exe | "Added by the VB-CYG WORM!"
|
| X | MsServer | msfir80.exe | "Added by the VB-CYJ TROJAN!"
|
| X | MSService_v1.0 | vfp02.exe | "NewWeb adware"
|
| X | mssfos | sfool.exe | "Added by the RANDEX.EUS WORM!"
|
| X | MSSGisg | [path to file] | "Added by the RANKY.N TROJAN!"
|
| X | mssonfig | winupdate.exe | "Added by a variant of the SDBOT WORM!"
|
| X | MSSQL for Windows NT & XP | mssqlsnt.exe | "Added by a variant of the SDBOT WORM!"
|
| X | mssurfer lptt01 | mssurfer.exe | "RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | mssurfer ml097e | mssurfer.exe | "RapidBlaster variant (in a ""surfer"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | MSUpdateDevKit | axfd.exe | "Added by the SDBOT-ZD WORM!"
|
| X | MsVBdll | MsVBdll.pif | "Added by the AIMDES.A WORM!"
|
| X | MSVBVM60 | MSVBVBM60.pif | "Added by the SCOLD-B WORM!"
|
| X | MSVersion | INTERNETFEATURES.exe | "Added by the POPMON.A TROJAN! - also known as PopMonster adware"
|
| X | Mswincfg | Mswincfg32.exe | "Added by the CYBRSPY.D TROJAN!"
|
| X | mswspl | [random filename] | "Added by the SMALL.IQ TROJAN!"
|
| X | Msys32 | morfitwebentrance.exe | "Morfit ADjectPager - ""uses home page rental technology for generating revenues"". Homepage hi-jacker that re-defines your IE or Netscape start page as http://www.web-entrance.com/. Any installed application including this must be un-installed before you can reset your homepage"
|
| X | ms_anti_spyware | mwfirewall.exe | "Added by the GAMQOWI TROJAN!"
|
| X | ms_anti_spywarebxp | mwfirebpx.exe | "Added by the SURILA-D TROJAN!"
|
| X | ms_anti_spywarebxp | mwfibpx.exe | "Added by the SURILA-J TROJAN!"
|
| X | MS_Update Check | wdfmgr.exe | "Added by the AGOBOT-TB WORM!"
|
| ? | Mufix | mufix.exe | "Part of INFOConnect |
| X | mule_st_key | flec006.exe | "Added by the BAGLE.AV TROJAN!"
|
| U | Multi-function keyboard | GWHotkey.exe | "Software that sets up the Gateway AnyKey keyboard shortcuts (a series of buttons that allow one-click access to e-mail |
| X | Mustafx | mustafx.exe | Added by a variant of the VIRANTIX.B TROJAN!
|
| X | My Supervisor | MSup1bf7.exe | "My Supervisor rogue system suite - not recommended |
| X | Myapp | [filename] | "Added by the FATEE.B WORM!"
|
| X | MyFastAccess | myfastupdate.exe | My-Fast-Access toolbar updater
|
| X | MyLife | CmdServ.exe | "Added by the HOLAR.A WORM!"
|
| X | mysoft | winexplor.exe | "Browser hijacker |
| N | MySoftware NewsFlash | Newsflsh.exe | "Runs in your task bar and receives alerts and release information on MySoftware products from Avenquest"
|
| U | N2PTray | Net2fone.exe | "An Internet telephony application. Needed only if you have an account at Net2Phone |
| X | NAV Auto Protect | msfwe1.exe | "Added by a variant of the RBOT WORM!"
|
| X | NAV Auto Protect | mcafee32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | NAV Auto Update | [random filename] | "Added by the SPYBOT-E WORM!"
|
| N | NAV CfgWiz | cfgwiz.exe | "Introduced with Norton Anti-Virus 2002 |
| N | NAV Configuration Wizard | cfgwiz.exe | "Introduced with Norton Anti-Virus 2002 |
| U | NAV DefAlert | DefAlert.exe | Norton Anti-Virus Definitions Alert. Warns you if virus definitions are out of date. Leave enabled unless you manually update virus definitions on a regular basis
|
| X | NavScan | [filename] | "Added by the OBSORB TROJAN!"
|
| Y | NECMFK | necmfk.exe | NEC wireless keyboard driver
|
| ? | neqprvfy.exe | neqprvfy.exe | "Appears to be related to the downloading of some application - possibly verifying updates?"
|
| X | NeroFil | NeroFil.EXE | "Added by the RBOT.EAM TROJAN!"
|
| X | NeroFileCheck | msjavam32.exe | "Added by the AGOBOT.AKM WORM!"
|
| U | NeroFilterCheck | NeroCheck.exe | Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
|
| U | NeroHomeFirstStart | NMFirstStart.exe | "Associated with Nero Scout |
| X | netconfig | netconfig.exe | "Added by the NETWARE TROJAN!"
|
| X | NETFP32.EXE | NETFP32.EXE | Added by the AGENT.CD TROJAN!
|
| ? | netfxupdate | netfxupdate.exe | "Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
|
| ? | NetFxUpdate_v1.0.3705 | netfxupdate.exe | "Would appear to be a valid Microsoft .NET file (see here) but other sources suggest it could be a trojan"
|
| X | nethost.exe | [path to file] | "Added by the PERDA-J TROJAN!"
|
| U | NetOnHold | FTNOHMgr.EXE | """FaxTalk NetOnHold 1.5 works with the Modem-On-Hold capabilities found in V.92 modems to provide the ability to place an Internet connection ""on hold"" and receive incoming calls or place outgoing calls"""
|
| U | NetScreen-Remote | SafeCfg.exe | "NetScreen Remote VPN client software"
|
| X | NetSurfageAssure | GDC.exe | "NetSurfageAssure French rogue privacy tool - not recommended. A member of the PCPrivacyTool family"
|
| Y | NettGain2000 Verifier | NettGain2000 Verifier.exe | Part of the Starband satellite client that attempts to optimize your satellite connection to increase speed
|
| X | NETVISIONAdulti | [random filename] | "Trafficadvance dialer"
|
| X | network device driver | msfirewall.exe | "Added by the DELF-LB TROJAN!"
|
| X | Networks Configurator | NetConfs.exe | "Added by the RBOT-OX WORM!"
|
| N | NetZIPFolders | nzfprop.exe | "
| U | NFM Service | NPDOR9x.exe | "Appears in startup if you have chosen to participate in on survey by NPD Online Research. Required for the survey to work correctly. Otherwise not required"
|
| X | Nfo | nfomon.exe | "Delfin Media Viewer adware related"
|
| N | nForce Tray Options | sstray.exe | nVidia nForce Taskbar Utility - quick access to the nForce2 "Sound Storm" control panel and related utilitys
|
| X | NI.ERS_9999_N91S3108 | [path to file] | "Installer for the ErrorSafe rogue system error and cleaning utility - see here"
|
| X | NI.GA6PU_0001_N108E1308 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
| X | NI.GA6PU_0001_N120C2910 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
| X | NI.GA6P_0001_N105E2704 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N108E1606 | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
| X | NI.GA6P_0001_N111C1707 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N115C0110 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N115E0110 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N122C0611 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N122C2210 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N122C2802 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_0001_N122E0611 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.GA6P_2001_N108E1606 | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
| X | NI.GDCDE_0001_N122C1912 | [path to file] | "Installer for the FestplattenReiniger German rogue privacy tool - see here"
|
| X | NI.GDC_0001_N111C1909 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.GDC_0001_N122C1912 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.GES_0001_N122C2610 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
| X | NI.UAVIFR_0001_N105M2404 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
| X | NI.UERSM_0001_N68M1602 | [path to file] | "Installer for the ErrorSafe rogue system error and cleaning utility - see here"
|
| X | NI.UGA6P | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
| X | NI.UGA6PH_0001_N122M2910 | [path to file] | "Installer for the AntiVirusAskeladd rogue security software - see here"
|
| X | NI.UGA6PK_0001_N122M1302 | [path to file] | "Installer for the VirusForsvar Danish rogue security software - see here"
|
| X | NI.UGA6PL_0001_N108M2808 | [path to file] | "Installer for the VirusSchlacht Swedish rogue security software - see here"
|
| X | NI.UGA6PL_0001_N120M1302 | [path to file] | "Installer for the VirusSchlacht Swedish rogue security software - see here"
|
| X | NI.UGA6PM_0001_N108M2108 | [path to file] | "Installer for the AntivirusScherm Dutch rogue security software - see here"
|
| X | NI.UGA6PM_0001_N122M1202 | [path to file] | "Installer for the AntivirusScherm Dutch rogue security software - see here"
|
| X | NI.UGA6PM_0001_N122M3010 | [path to file] | "Installer for the AntivirusScherm Dutch rogue security software - see here"
|
| X | NI.UGA6PT_0001_N108M2208 | [path to file] | "Installer for the VirusDifesa Italian rogue security software - see here"
|
| X | NI.UGA6PT_0001_N122M1202 | [path to file] | "Installer for the VirusDifesa Italian rogue security software - see here"
|
| X | NI.UGA6PT_0001_N122M2910 | [path to file] | "Installer for the VirusDifesa Italian rogue security software - see here"
|
| X | NI.UGA6PU_0001_N108M1308 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
| X | NI.UGA6PU_0001_N120M1202 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
| X | NI.UGA6PU_0001_N120M2910 | [path to file] | "Installer for the VirusSchlacht German rogue security software - see here"
|
| X | NI.UGA6PV_0001_N108M0207 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
| X | NI.UGA6PV_0001_N122M1202 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
| X | NI.UGA6PV_0001_N122M2910 | [path to file] | "Installer for the VirusGarde French rogue security software - see here"
|
| X | NI.UGA6P_0001_N105M2704 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N111M1707 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N115M0110 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N119M1510 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N120M1710 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N122M0611 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N122M2210 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0001_N122M2802 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_0007_N125M2002 | [path to file] | "Installer for the BestsellerAntivirus rogue security software - see here"
|
| X | NI.UGA6P_1001_N122M0402 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_1002_N122M1402 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_4001_N122M2111 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_4444_N122M2811 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_5001_N122M1902 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGA6P_5555_N122M0312 | [path to file] | "Installer for the AVSystemCare rogue security software - see here"
|
| X | NI.UGDC1_0001_N119M0911 | [path to file] | "Installer for the FilterProgram rogue privacy tool - see here"
|
| X | NI.UGDCCZ_0001_N122M0307 | [path to file] | "Installer for the SuspenzorPC Czech rogue privacy tool - see here"
|
| X | NI.UGDCCZ_0001_N122M0511 | [path to file] | "Installer for the SuspenzorPC Czech rogue privacy tool - see here"
|
| X | NI.UGDCCZ_0001_N122M1712 | [path to file] | "Installer for the SuspenzorPC Czech rogue privacy tool - see here"
|
| X | NI.UGDCDE_0001_N111M3007 | [path to file] | "Installer for the FestplattenReiniger German rogue privacy tool - see here"
|
| X | NI.UGDCDE_0001_N122M1912 | [path to file] | "Installer for the FestplattenReiniger German rogue privacy tool - see here"
|
| X | NI.UGDCGR_0001_N122M0307 | [path to file] | "Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
|
| X | NI.UGDCGR_0001_N122M1812 | [path to file] | "Installer for the FestplattenReiniger Greek rogue privacy tool - see here"
|
| X | NI.UGDCNL_0001_N111M3007 | [path to file] | "Installer for the NoCompromaat Dutch rogue privacy tool - see here"
|
| X | NI.UGDCNL_0001_N122M1912 | [path to file] | "Installer for the NoCompromaat Dutch rogue privacy tool - see here"
|
| X | NI.UGDCNL_0001_N122M3011 | [path to file] | "Installer for the NoCompromaat Dutch rogue privacy tool - see here"
|
| X | NI.UGDCPL_0001_N108M0207 | [path to file] | "Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
|
| X | NI.UGDCPL_0001_N122M2012 | [path to file] | "Installer for the OczyszczaczKomputerza Polish rogue privacy tool - see here"
|
| X | NI.UGDCRU_0001_N111M0208 | [path to file] | "Installer for the SanitarDiska Romanian rogue privacy tool - see here"
|
| X | NI.UGDCRU_0001_N122M2012 | [path to file] | "Installer for the SanitarDiska Romanian rogue privacy tool - see here"
|
| X | NI.UGDCTH_0001_N122M1712 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
| X | NI.UGDCTR_0001_N108M0407 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N108M0407 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N111M1909 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N122M0502 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N122M1912 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N122M2603 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N122M2610 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N122M2802 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0001_N122M2811 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGDC_0002_N108M1007 | [path to file] | "Installer for the PC Drive Tool rogue privacy tool - see here"
|
| X | NI.UGDC_0003_N108M2407 | [path to file] | "Installer for the PCPrivacyTool rogue privacy tool - see here"
|
| X | NI.UGESF_0001_N122M0201 | [path to file] | "Installer for the HataDuzelticisi Turkish rogue system error and cleaning utility - see here"
|
| X | NI.UGESL_0001_N105M0405 | [path to file] | "Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
|
| X | NI.UGESL_0001_N122M0303 | [path to file] | "Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
|
| X | NI.UGESL_0001_N122M2911 | [path to file] | "Installer for the SystemOrdnare Swedish rogue system error and cleaning utility - see here"
|
| X | NI.UGESM_0001_N122M0303 | [path to file] | "Installer for the DokterFix Dutch rogue system error and cleaning utility - see here"
|
| X | NI.UGESV_0001_N108M2006 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
| X | NI.UGESV_0001_N122M0303 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
| X | NI.UGESV_0001_N122M2811 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
| X | NI.UGESV_0001_N122M3010 | [path to file] | "Installer for the SysDepannage French rogue system error and cleaning utility - see here"
|
| X | NI.UGES_0001_N122M0502 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
| X | NI.UGES_0001_N122M2111 | [path to file] | "Installer for the ErrClean rogue system error and cleaning utility - see here"
|
Fatal error: Maximum execution time of 30 seconds exceeded in /home/iamnotag/domains/iamnotageek.com/public_html/startup/search.php on line 252
|