| X | svchost | inetinfo.scr | "Added by the ODELUD WORM!"
|
| X | svchost Netware Manager | svchost.exe | "Added by the EXVID.A WORM! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | SwimSuitNetwork | SwimSuitNetwork.exe | Advertising spyware
|
| Y | Symantec NetBackup Desktop Agent | DLOClientu.exe | "Part of Symantec's NetBackup backup software"
|
| U | Symantec NetDriver Monitor | SNDMon.exe | "Part of Symantec's LiveUpate (eg |
| U | Symantec NetDriver Warning | SNDWarn.exe | Part of Symantec Live Update - displays the warning when you need to update the firewall database
|
| X | Symmetrical Network | symmec.exe | "Added by the DELBOT-N WORM!"
|
| X | Sysnet | snuninst.exe | Unidentified adware
|
| X | sysnet | sysnet.exe | "CasClient adware - also detected as the CMAPP TROJAN!"
|
| X | System | inetinfo.exe | "Added by the PARDROP-A TROJAN!"
|
| X | system | sysnet.exe | "Added by the VETOR-J WORM!"
|
| X | System Net | sys32.exe | "Added by the FORBOT-FX WORM!"
|
| X | System Net Database | sysnd.exe | "Added by the RBOT-AAW WORM!"
|
| X | System Networking | sysnet.exe | "Added by the RBOT.API WORM!"
|
| X | System Restore | svcnet.exe | "Added by the TIBICK WORM!"
|
| X | System Update2 | wininet.exe | "Added by the AUTOTROJ-C TROJAN!"
|
| X | system32 | NeT-BoT.exe | "Added by the AGOBOT-LJ WORM!"
|
| X | System64 | inet.exe | "Added by the DENGLE-A TROJAN!"
|
| X | SystemMap32 | Netisp32.vbs | "Added by the REDIST.C WORM!"
|
| X | SystemNetwork | NETSERV.EXE | Added by the NETCONTROL VIRUS!
|
| X | SystemNetwork | sysnet.exe | "Added by a variant of the RBOT WORM!"
|
| X | Tcp Application Manager | netsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | TCP Internet Services | TCPSVC32.EXE | "Added by the SPYBOT.X TROJAN!"
|
| X | Telnet | Telnet.exe | "Added by the VOUMIT-A WORM! Note - this is not the legitimate telnet.exe application which is always located in %System% and should not normally figure in Msconfig/Startup! This file is located in a ""mirc32"" folder"
|
| X | Telnet24 | [random filename] | "Added by the RBOT-ARD WORM!"
|
| N | Tesco.net | "rundll32 [path] RyDial.dll | QuickStart" |
| X | The Ethernet | ethernet.exe | "Added by a variant of the SDBOT WORM!"
|
| X | The Ethernet | intranet.exe | "Added by a variant of the SDBOT WORM!"
|
| X | The Intranet | intranet.exe | "Added by a variant of the SDBOT WORM!"
|
| X | TkNetDriver Monitor | lexbce.exe | "Added by the SDBOT-ADF WORM!"
|
| X | TmNetDriver Monitor | exbce.exe | "Added by the SDBOT-ABR WORM!"
|
| X | Topic lnternet | lnternet32.exe | "Added by the RBOT-GLZ WORM!"
|
| U | True Internet Color Icon | internetcolor.exe | "Part of 3Deep® from E-Color (now superseded by 3DxWizzard™) - ""With True Internet Color PCs can display the best color possible over the web. Enabled web sites will know how connected monitors display color and will send them color corrected images"""
|
| X | TurboNet | [path to trojan] | "Added by the RENOS-EA TROJAN!"
|
| N | USRobotics 802.11g Wireless Network Utility | USRWLANG.exe | "USRobotics Wireless Network Utility - used to configure security settings for connecting to WEP encrypted Access Point through the USR Wireless adapter. You must uncheck ""Use Windows to configure my wireless settings"" for the program to work properly. Has Site Survey capabilities |
| X | VCMnet11 | VCMnet11.exe | "Windows AFA Internet Enhancement - a browser hijacker |
| X | Video Process | netsvcs.exe | "Added by the AGOBOT.LH WORM!"
|
| X | vmnetdhcp | vmnetdhcp.exe | "Added by the DWNLDR-GTC TROJAN!"
|
| X | vtmesys | netcxcfm.exe | "Added by a variant of the RBOT-GNA WORM!"
|
| X | vtmesys | netlprto.exe | "Added by the RBOT-GNA WORM!"
|
| X | W3KNetwork | "rundll32.exe w3knet.dll | dllinitrun" |
| U | Warnet | warnet.exe | Warnet - system cleanup software
|
| U | Watson Subscriber for SENS Network Notifications | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| X | Win Net Wks32 | netwks32.exe | "Added by the RBOT.AA WORM!"
|
| X | win32 internet server | winserver.exe | "Added by the DERMON-D TROJAN!"
|
| X | Win32 Network Driver | crss.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Win32.Trojan.Downloader | netstat2.exe | "Added by the PAINTER TROJAN!"
|
| X | Windeows NetStart Service2 | tesakrmger.exe | "Added by the RBOT-AMY WORM!"
|
| X | windll | windotnetsrv.exe | "Added by the AUTORUN-ANO WORM!"
|
| U | Windows & Internet Cleaner Pro | WICleaner.exe | "Windows & Internet Cleaner Pro - ""Powerful and easy to use internet surfing privacy protection & PC security software"""
|
| X | Windows .Net Manager | localsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | netsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | spoolsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | svcadmin.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | svcman.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | svcrun.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | tcpsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows .Net Manager | websvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows connection manager | Internet.exe | "Added by the RBOT-APN WORM! Note - file is found in the Windows or Winnt folder. Make sure you check the link on this one |
| X | Windows Internet Browser Services | internet.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Internet Browser Services | internet128.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Internet Browser Services | internet32.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Internet Browser Services | internet64.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Internet Explorer 6 | firefox.exe | "Added by the SPYBOT.ANA WORM! Note - this is not the Mozilla Firefox web browser which is always located in %ProgramFiles%\Mozilla Firefox. This file is found in %System%"
|
| X | Windows Internet Manager | svchost.exe | "Added by the IRCBOT-AAC TROJAN! Note - this is not the legitimate svchost.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| X | Windows Internet Protocol | winproc32.exe | "CoolWebSearch Winproc32 parasite variant - also detected as the STARTPA-BF TROJAN!"
|
| X | Windows Internet Protocol | deinst_qfe001.exe | Added by a variant of the Win32.Small TROJAN!
|
| X | Windows Internet Service | wininet.exe | "Added by the RBOT-AUX WORM!"
|
| X | Windows Local Services | netsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows Net Cfg | service.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows NetDDe | wrmana32.exe | "Added by the MYTOB.IM WORM!"
|
| X | Windows Nets | WinNET.exe | "Added by the RBOT-MO WORM!"
|
| X | Windows NetStart Service | winsN2S.exe | "Added by the RBOT-ZX WORM!"
|
| X | Windows NetStart Service2 | winsN2S.exe | "Added by the RBOT-ABN WORM!"
|
| X | Windows NetStart Service2 | winsN2SD.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Netsystem Layer | Netsystem.exe | "Added by the RBOT.BEI WORM!"
|
| X | Windows Network Controller | Mqguard.exe | "Added by the FORBOT-CL WORM!"
|
| X | Windows Network Controller | WinxPupd.exe | "Added by the FORBOT-DK WORM!"
|
| X | Windows Network Controller | winmms32.exe | "Added by the FORBOT-ED WORM!"
|
| X | Windows Network Controller | wingmt.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Network Controller | Win9x.exe | "Added by the WOOTBOT.I WORM!"
|
| X | Windows Network Controller | winmms32.exe.exe | "Added by the FORBOT-ED WORM!"
|
| X | Windows Network Firewall | firewall.exe | "Added by the POEBOT-J WORM! Located in %System%"
|
| X | Windows Network Logon | npesvc.exe | "Added by the AGENT.ERZ TROJAN!"
|
| X | Windows Network Service | winvc32.exe | "Added by the RBOT.RY WORM!"
|
| X | Windows Network Service | Msconf32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Network Service | Realteks.exe | "Added by the RBOT-GTG WORM!"
|
| X | Windows Network Services | winnetwork.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Network Services | winnetwork128.exe | "Added by the SLENFBOT.J WORM!"
|
| X | Windows Network Services | winnetwork32.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Network Services | winnetwork64.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Network Session | nspsvc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Networking | winsys32.exe | "Added by the GAOBOT.FL WORM!"
|
| X | Windows Networking Monitor | mdm.exe | "Added by a variant of the IRCBOT BACKDOOR! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| X | Windows Networking Monitorin | xmdmx.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Networking Monitoring | mdm.exe | "Added by the IRCBOT.AKZ WORM! Note - this is not the legitimate Machine Debug Manager (mdm.exe) process which is located in %ProgramFiles%\Common Files\Microsoft Shared\VS7Debug (98/Me/XP/Vista) or C:\WINDOWS\SYSTEM (Me only)"
|
| X | Windows Networks | netcog.exe | "Added by the MYTOB.FH WORM!"
|
| X | Windows Offical Netvvorks | mywriter32.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Service Manager | netsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows Services | NetworkDriver32.exe | "Added by the RBOT-ACR WORM!"
|
| X | Windows Services | NetworkDrivers.exe | "Added by the SDBOT-YO WORM!"
|
| X | Windows System Configuration | WinNeth.exe | "Added by the RETHE-A WORM!"
|
| X | Windows System Configuration | nether.exe | "Added by the OPANKI-AB WORM!"
|
| X | Windows Telnet Server | wintel.exe | "Added by the AGOBOT-MW WORM!"
|
| X | Windows Update | inetinf.exe | "Added by a variant of the AGOBOT/GAOBOT WORM!"
|
| X | Windows Update Files | dnetc.exe | "Added by an unidentified VIRUS |
| X | Windows Web Services | netsvc.exe | "Added by the DLOADER-NY TROJAN!"
|
| X | Windows32 Net Database | msnd32.exe | "Added by the RBOT-AAL WORM!"
|
| X | WindowsRegKey%update | ethernet32m.exe | "Added by the RBOT-EN WORM!"
|
| X | WinINet | services.exe | "Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus and note the space at the beginning of the ""Startup Item"" field"
|
| X | wininet | wininet.exe | "Added by the STUBBOT-C WORM!"
|
| X | wininet.dll | regperf.exe | "Added by the ZLOB TROJAN and variants!"
|
| X | wininet32 | wininet32.exe | "Added by the RAZNEW-A TROJAN!"
|
| X | wininetd | wininetd.exe | "Added by the WINET TROJAN!"
|
| X | winnet | winnet.exe | "CommonName Toolbar spyware. To uninstall see here"
|
| X | WinNetDDE | [random characters].exe | "Added by the NETDEPIX.B TROJAN!"
|
| Y | WinPoet | WinPPPoverEthernet.exe | "WinPoET is the industry's first Windows-based PPP over Ethernet client. Developed by iVasion |
| X | Wins Service Driver | winet.exe | "Added by the RBOT-APV WORM!"
|
| X | WinSig | NetXP.exe | "Added by the BANKER-FN TROJAN!"
|
| X | winsock2 | netsvr.exe | "Added by the AGOBOT.LY WORM!"
|
| ? | WOOKIT | GestMaj.exe GestionnaireInternet.exe | "Wanadoo broadband ISP (now rebranded as Orange) related. What does it do and is it required?"
|
| U | X10 Device Network Service | x10nets.exe | Belongs to X10 video streaming device(s)
|
| X | xload32 | netdd.exe | "Added by the NETSPY TROJAN!"
|
| X | xloadnet | xloadnet.exe | Added by the VB.NCK TROJAN!
|
| U | Xnet2 | xnet2.exe | "Green Dam Youth Escort content control software. Internet filtering software that the Chinese government requires to be installed on all new computers sold in China after July 1 |
| X | Xp | p2pnetworking.exe | "Added by the SDBOT.XA WORM!"
|
| U | xPlanetControl | xPlanetControl.exe | "Tool that displays a globe with current day/night zones and clouds on users desktop."
|
| X | Xpnet | NetXp.exe | "Added by the BANCBAN-AT TROJAN!"
|
| X | Yahoo! | ethernet.exe | "Added by the PROSTI.AA BACKDOOR!"
|
| N | zdnet | kontiki.exe | "Kontiki Delivery Manager - Windows-based client software that enables secure delivery of content to users' desktops"
|
| X | Zenet | "rundll32 CNBabe.dll | DllStartup" |
| X | [random name] | netdde.exe | "PurityScan adware. Do not confuse with the legitimate Network DDE - DDE Communication (netdde.exe) process which is always located in %System% and should not figure in Msconfig/Startup!"
|
| X | [various names] | MsNetHelper.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | _WinINet | services.exe | "Added by the SOBER.R WORM! Note - this is not the legitimate services.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%\ConnectionStatus"
|
| X | {29123221-3AF8-488c-85DE-6B3EC59E8074} | netmedia.exe | "NetMedia adware"
|
| X | {52-28-8E-E8-ZN} | thinksnet.exe | "Zeno Think-Adz adware"
|