| X | Starter | scvhosting.exe | "Added by the SDBOT.RU WORM!"
|
| X | starter | scvhostingg.exe | "Added by the FORBOT-FB WORM!"
|
| X | startkey | scvhost.exe | "Added by the BIFROSE-PM TROJAN!"
|
| U | Startup Manager Scanner | StartupMonitor.exe | "Startup-Mechanic Startup monitor - offers boot protection of your PC from harmful trojans |
| Y | Startup Scan | Sensor.EXE | "AntiVirus Quick Heal - scheduling agent"
|
| ? | StatusClient | StatusClient.exe | Part of Hewlett Packard network printer drivers
|
| ? | StatusClient 2.6 | StatusClient.exe | Part of Hewlett Packard network printer drivers
|
| X | strmsnmgrs | msnxmsgrsc.exe | "Added by the SDBOT.JDR WORM!"
|
| X | strmsnmsgrs | msnmsgrsc.exe | "Added by a variant of the RBOT WORM!"
|
| X | STV | winscrne.exe | "Added by a variant of the SDBOT WORM!"
|
| X | SunJavaSched | ccEvtMngr.exe | "Added by the SDBOT-YP WORM!"
|
| X | SunJavaSched Updater | avamx.exe | "Added by the RBOT-ABJ WORM!"
|
| N | SunJavaUpdateSched | jusched.exe | "Checks with Sun's Java updates site to see if newer Java versions are available. Either visit the Java download page or click on Start → Control Panel → Java → Update → Update Now"
|
| X | SunJavaUpdateSched | scvhost.exe | "Added by the SDBOT-AVX WORM!"
|
| X | SunJavaUpdateSched | javamx.exe | "Added by the SDBOT-WI WORM!"
|
| X | SunJavaUpdateSched10 | jushed.exe | "Added by the ACKANTTA.F WORM!"
|
| X | SunJavaUpdateSched132 | jschd.exe | "Added by the AUTORUN-AQY WORM!"
|
| X | SunJavaUpdateSched16 | jvshed.exe | "Added by the ACKANTTA.G WORM!"
|
| X | SunJavaUpdatSched | spoolsv.exe | "Added by the BANCBAN-NP TROJAN! Note - this is not the legitimate spoolsv.exe which is always located in %System%. This one is located in %ProgramFiles%\MSN Messenger"
|
| U | Support.com Scheduler and Command Dispatcher | tgcmd.exe | "Part of software from SupportSoft (aka Support.com) provided to manufacturers and ISPs that allows them to offer on-line support - to update drivers |
| U | SurfChoice | SCMan.exe | "SCMan is a utility that can control services on WinNT from the command line. This utility can create |
| N | suScheduler | UCLauncher.exe | "Scheduler for versions of ThinkVantage System Update (for software updates) found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks"
|
| X | SVCHOST | scvhost.exe | "Added by the MYTOB.E or MYTOB.G WORMS!"
|
| X | svchost | inetinfo.scr | "Added by the ODELUD WORM!"
|
| X | SVCHost Protocol32 | scvhost32.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | svchostdll.scr | svchostdll.scr | "Added by the BANCBAN-FM TROJAN!"
|
| X | Svchosts | SCVHOST.EXE | "Added by the AGOBOT-RQ BACKDOOR!"
|
| X | svchosts.scr | svchosts.scr | "Added by the BANCBAN-DQ TROJAN and variants!"
|
| X | svcshare | nvscv32.exe | "Added by the FUJACKS-Z WORM!"
|
| X | SwiftCleaner | SwiftCleanerScanner.exe | "SwiftCleaner rogue cleaning utility - not recommended |
| U | SybaseCentral43 | scjview.exe | "Related to SQL Anywhere from Sybase. A comprehensive package providing data management and data exchange technologies"
|
| X | Symantec Autoscan | [random filename] | "Added by the RBOT-AJO WORM!"
|
| X | SymantecFilterCheck | bsyys.scr | "Added by the BANLOAD.DZC TROJAN!"
|
| X | Syntax Script | systacq.exe | "Added by the SDBOT.AI WORM!"
|
| X | Syntax Script | saskatcw.exe | "Added by the SDBOT-TE WORM!"
|
| X | syscfg | syscfg32.exe | "Added by the KWBOT.S WORM!"
|
| X | syscfg34.exe | syscfg34.exe | "Added by the ELECTRON WORM!"
|
| X | Syscheck | win.hta | Browser hijacker
|
| X | syscheck | iexplorer.exe | Added by the AGENT.DM TROJAN! Note - this is not the legitimate Internet Explorer (iexplore.exe)
|
| U | SysCheck32 | sb32mon.exe | "Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
|
| X | SysCleaner | SysCleaner.exe | "SysCleaner rogue cleaning utility - not recommended |
| X | sysclx | ntldrt.exe | "Added by the JLOK-A WORM!"
|
| X | syscm | Syscm.exe | "Vanish adware"
|
| X | SysCom | msnmsgr.exe | "Added by the BANK-AF TROJAN! Note - this is not the valid MSN Messenger (now Windows Live Messenger) utility which is located in either %ProgramFiles%MSN Messenger or %ProgramFiles%Windows LiveMessenger. This one is located in %Windir%\system"
|
| ? | SysComp | mssdnl.com | "Unknown but suspect as *.com are not usually run at start up and the name isn't recognized"
|
| X | syscon | syscon.exe | "Added by the APRILCONE.A WORM!"
|
| X | syscon lptt01 | syscon.exe | "RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | syscon ml097e | syscon.exe | "RapidBlaster variant (in a ""Syscon"" folder in Program Files). Recommended you use RapidBlaster Killer to uninstall - see here"
|
| X | sysconfig | iexplorer.exe | "Added by the CULT.C WORM! Note - this is not the legitimate Internet Explorer (iexplore.exe)"
|
| X | SysConfig | syscfg35.exe | "Added by the KAZMOR.C WORM!"
|
| X | SysConfig | wincfg32.exe | "Added by the SDBOT.ZD WORM!"
|
| U | Sysconfig | Stealth KeySpy.exe | "StealthKeySpy - keystroke logger/monitoring program - remove unless you installed it yourself!"
|
| X | sysconfig32 | sysconfig32.exe | "Added by the AGENT-MSP TROJAN!"
|
| X | Syscpy | Syscpy.exe | "Firewall-bypassing |
| X | SysCtl | sysctl.exe | "Added by the AOK TROJAN!"
|
| X | Sysctrls | procdll.exe | "Added by the WEEDBOTZ.14 TROJAN!"
|
| X | Sysctrls | winupdate.exe | Added by an unidentified WORM or TROJAN!
|
| X | Sysctrls | mscntrl.exe | "Added by the KOLABC.BB WORM!"
|
| X | Sysctrls | Sysctrls.exe | "Added by the AGENT.AWZ TROJAN!"
|
| X | Sysctrls | win32dll.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Sysctrls32 | sevchost.exe | "Added by the RBOT.ADF BACKDOOR!"
|
| X | SysCVMS.exe | SysCVMS.exe | "Added by the SMALL.CBA TROJAN!"
|
| X | SysScan | bvt.exe | "Added by the AUTOUPDER TROJAN!"
|
| U | System | sysctrl.exe | "Added by WinGuardian. Note - this commercial keylogger is no longer made or sold by Webroot but older copies may still be in existance |
| X | System | wsscntfy.exe | "Added by a variant of the SDBOT WORM!"
|
| X | system | ssclie.exe | "Added by the AGENT.LW BACKDOOR!"
|
| X | System Cache | SysCache.exe | "Added by an unidentified VIRUS |
| X | System CGI Manager | syscgmgr.exe | "Added by an unidentified WORM or TROJAN! See here"
|
| X | System Config Boot | syscgboot.exe | "Added by the AGENT.VWU TROJAN!"
|
| X | System Configuration | syscfg32.exe | "Added by the MYTOB.EA WORM!"
|
| X | System Core Memory | syscoremem.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | System CSRSS Patch | scrtkfg.exe | "Added by the RBOT-ADA WORM!"
|
| X | System Efficiency Monitor | mscedit32.exe | "Added by the SDBOT.P TROJAN!"
|
| X | System Efficiency Monitor | mscommand.exe | "Added by the KWBOT.P WORM!"
|
| X | System Host | scvhost.exe | "Added by a variant of the RBOT WORM!"
|
| U | System LifeGuard Scheduler | Slsched.exe | "System LifeGuard scheduler"
|
| X | System Loader | syscfg.exe | "Added by the AGOBOT-BS BACKDOOR!"
|
| X | System Management Service | smsc.exe | "Added by the RBOT-ANN WORM!"
|
| X | System MScvb | mscvb32.exe | "Added by the SOBIG.C WORM!"
|
| X | System Protector | lsascs.exe | "System Protector rogue security software - not recommended |
| X | System Scanner | system.exe | "Added by the AGOBOT-DI BACKDOOR!"
|
| X | System Security Checker | ssc.exe | "Added by the IRCBOT-WI TROJAN!"
|
| X | System Support | syscfg.exe | "Added by the RBOT-AGQ WORM!"
|
| X | System Tray | msccn32.exe | "Added by the SOBIG.B WORM! Warning - spreading via infected E-mail attachments with the sender address faked as support@microsoft.com! Note - this is not the legitimate systray.exe process"
|
| X | System Unix | syscfg32.exe | "Added by the RBOT-ZD WORM!"
|
| X | System Updates | winsci.exe | "Added by a variant of the RBOT WORM!"
|
| X | System-Service | EXPLORER.SCR | "Added by the BENJAMIN.A WORM! KaZaA file-sharing users beware!"
|
| X | SystemCheck | SysCheckBop32.exe | "WINBO adware"
|
| X | SystemChecker | Syschk.exe | "Added by the GALIL.F WORM!"
|
| X | SystemCleanerPRO | sysclpro.exe | "SystemCleanerPro rogue security software - not recommended |
| X | SystemOPsv | scrtvc32.exe | "Added by a variant of the SPYBOT WORM!"
|
| X | Systems | scchost.exe | "Added by the DAEMOZ.A TROJAN!"
|
| X | Systems | sescmgr.exe | "Added by the DWNLDR-GAH TROJAN!"
|
| X | systemscroot | systembin.exe | "Added by a variant of the RBOT WORM!"
|
| X | SystemWindows | scvhost.exe | "Added by the SILLYFDC-CG WORM!"
|
| X | sysygm32 | syscxd32.exe | "Added by the IRCBOT-PC TROJAN!"
|
| X | Task Scheduler Engine | schedsvc32.exe | "Added by the RBOT-ASJ WORM!"
|
| X | Taskschd | TRAYWND.EXE | "Added by the LITMUS.002 TROJAN!"
|
| U | TaskScheduler | TaskSch.exe | "ProSeries accounting software related"
|
| X | Terminal Services | mstscc.exe | "Added by the SDBOT-CZW WORM!"
|
| U | TEscKey | TEscKey.exe | Toshiba Escape Key handler. Enables you to program and use the <FN><Esc> key combination to perform a specific function
|
| ? | Tesco Insert Detect | InsDetect.exe | "Part of Tesco Picture Suite. Detects a digital camera is plugged into a USB port or when a memory card with photos is inserted?"
|
| N | Tesco.net | "rundll32 [path] RyDial.dll | QuickStart" |
| N | The Assistant | eSched.exe | "Related to WinTotal from a la mode inc. FormFiller for appraisers"
|
| X | Time Zone Synchronization | wscript zshell.js | "Added by the NETDEX-A TROJAN!"
|
| N | TkBell.Exe | realsched.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| N | TkBellExe | realsched.exe | "Application Scheduler installed along with RealOne Player. Once installed |
| N | TOSCDSPD | toscdspd.exe | "Related to Toshiba laptop CD/DVD drivers. This is a non-essential process. Disabling or enabling this is down to user preference"
|
| X | TotalSecure2009 | scan.exe | "Total Secure 2009 rogue security software - not recommended |
| U | TotRecSched | TotRecSched.exe | "Scheduler for Total Recorder - allows automatic recording of a show at a given time for later playback or you can use the scheduler as an alarm"
|
| U | TPKBDLED | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
|
| U | Tpscrex | Tpscrex.exe | "Lenovo (IBM) ThinkPad hotkey related"
|
| U | TpScrLk | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
|
| U | TpScrLk.exe | TpScrLk.exe | IBM Thinkpad utility for displaying the Scroll Lock status on the System Tray - for Thinkpad's that don't have a Scroll Lock LED
|
| N | Transcode360 | Transcode360Tray.exe | "Designed for WinXP Media Center Edition 2005 and the Xbox 360 |
| Y | TrendMicro OfficeScan NT | TMLISTEN.EXE | Virus scanner
|
| U | TrojanScanner | Trjscan.exe | "Trojan Remover from Simply Super Software. Scans for an removes trojan viruses where anti-virus software may have not detected or removed"
|
| X | TS | tsc.exe | "Total Security rogue security software - not recommended |
| U | TSClientMSIUninstaller | tscuinst.vbs | "Related to Terminal Services Client Remote Desktop Connection Software from Microsoft"
|
| X | ttool | scvc.exe | "Added by the BCKDR-OWM BACKDOOR!"
|
| U | TV Scheduler | TVSCHL.EXE | "ProLink PlayTVpro TV tuner software scheduler"
|
| U | TvrSchedule | Schedule.exe | "Scheduler for Mercury Ez View TV Tuner Card"
|
| U | TVT Scheduler Proxy | scheduler_proxy.exe | "Found on IBM/Lenovo ThinkCentre/ThinkStation desktops and Thinkpad notebooks. Included with versions of ThinkVantage System Update (for software updates) |
| U | Tweak UI 1.33 deutsch | "RUNDLL32.EXE TWEAKUI.CPL | TweakMeUp" |
| N | TwkSCardSrv | SCardS32.Exe | Used with Towitoko SmartCard Readers for card recognition
|
| X | UERScw | UERScw.exe | "Part of the ErrorSafe rogue system error and cleaning utility - not recommended"
|
| X | ugescw | ugescw.exe | "Part of the ErrClean rogue system error and cleaning utility and other members of this family. See here for more examples"
|
| U | UniSc | Unisc.exe | McAfee UnInstaller
|
| X | upascw | upascw.exe | "PersonalAntiSpy rogue spyware remover - not recommended |
| X | Update Checker | scvhost.exe | "Added by the AGENT-DSF TROJAN!"
|
| X | Update Install | Schost.exe | "Added by the GAOBOT.AO WORM!"
|
| X | updatesched | [random filename] | "ZenoSearch adware"
|
| X | ushli | sscbltqu.exe | Obtained from an MP3 search list site. Also generates random processes on reboot
|
| X | Ussi | wnscpit.exe | "PurityScan adware"
|
| X | vcmicrec | msccsed.exe | "Added by the MAILBOT-CE TROJAN!"
|
| X | VelocidadSimple | scrmain.exe | VelocidadSimple rogue optimization utility - not recommended
|
| X | Video Process | sysconf.exe | "Added by the GAOBOT.GEN!POLY or GAOBOT.UM or GAOBOT.ADX WORMS!"
|
| X | Video Processor | msconfsys88.exe | "Added by the AGOBOT-QG WORM!"
|
| X | Virscanner | smss.exe | "Added by the DWNLDR-GWE TROJAN! Note - this is not the legitimate smss.exe process which is always located in %System% and should not normally figure in Msconfig/Startup! This one is located in %Windir%"
|
| U | Virtual Access Scheduler | VASCHD32.EXE | The scheduler for mail and usenet tool
|
| X | Virtual CD v6 | grplscd.exe | "Added by the RBOT-AXV WORM!"
|
| X | Virus Scan | virscana.exe | "Added by an unidentified VIRUS |
| X | VirusCheckII | AVIRCHK.EXE | "Added by the DASMIN TROJAN!"
|
| X | VirusRescue | VirusRescue.exe | "VirusRescue rogue security software - not recommended"
|
| Y | VirusScan Online | mcvsshld.exe | "ActiveShield - background scanner for older versions of McAfee VirusScan and the now obsolete McAfee VirusScan Online which scans files in the background as and when they are accessed |
| ? | VirusScanMSC | VsStat.exe | "Part of McAfee VirusScan. System Tray application as with previous versions (were also VsStat.exe) |
| X | VirusScanner | mnsys.exe | "Added by the SDBOT-AFQ WORM!"
|
| X | VirusSchlacht | pgs.exe | "VirusSchlacht |
| X | Virus_Scanner | Virus_Cleaner.exe | "Added by the PANOL WORM!"
|
| N | Vistascan | vistascan.exe | "Included in VistaScan are VistaAccess and VistaShuttle. VistaAccess gives you quick and easy access to scanning functions right from your desktop. For Windows users |
| N | VoipDiscount | VoipDiscount.exe | "VoipDiscount - free internet telephony utility using the VoIP (Voice over Internet Protocol). Call online friends for free and regular phones either for free (limited use) or low rates. One of a number provided by Betamax - the others generally have different rate plans. Similar to the more popular Skype"
|
| X | Vprocess | scvtw32.exe | "Added by the AGOBOT-FR BACKDOOR!"
|
| Y | VrBootScan | VRBScan.exe | "Boot scan feature of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal |
| Y | VrSchedule | Vrres.exe | "Part of the HAURI ViRobot series of internet security products. HAURI's ViRobot engine is included in those used by VirusTotal |
| X | vscan | joke.vbs | "Added by the ROOKIE-A TROJAN!"
|
| X | vscanner | spooll32.exe | "Added by the OPTIXPRO.10 TROJAN!"
|
| X | vschost | vschosts.exe | "Added by the VIPSY-A TROJAN!"
|
| X | vschost | vschost.exe | "Added by the AGENT.QK BACKDOOR!"
|
| X | W32.Scran | Scran.exe | "Added by the NARCS WORM!"
|
| X | w32alanis | mope.scr | "Added by the SINALA WORM!"
|
| X | W32Load | [random filename].scr | "Added by the CASPID WORM!"
|
| X | W32Tc | WTC32.scr | "Added by the VOTE.D or VOTE.K WORMS!"
|
| U | Watson Subscriber for SENS Network Notifications | dwtrig20.exe | "Used to launch Microsoft Error Reporting (DW20.exe) - if |
| U | WCESCOMM | WCESCOMM.EXE | "Connection manager for Microsoft ActiveSync - mobile device synchronization software for Windows XP (and earlier) |
| N | Weatherscope | Weatherscope.exe | "WeatherScope - ""displays your current local temperature in the system tray of your computer (near the clock) whenever you are online!"" Not recommended as it bundles GAIN adware. You can get the adware free version for a whopping $30. Please note that Claria Corporation no longer support GAIN-Supported software - see here"
|
| N | Webposition Gold 2 | wpsche~1.exe | "Scheduler for Web Position Gold - utility to help optimize the position of web-sites in search engines"
|
| U | WebScan | DEFSCANGUI.EXE | "eAcceleration Stop-Sign security software related. Previously not recommended |
| U | webscan | stopsignav.exe | "eAcceleration Stop-Sign security software related. Previously not recommended |
| Y | WebScanX | WebScanX.exe | "From McAfee VirusScan up to version 4.x. Provides functionality for VShield Download Scan and Internet Filter modules. Enables internet scanning. Guards against malicious ActiveX programs |
| X | wescmv | [random filename] | "Added by a variant of the SLAPER TROJAN!"
|
| U | Whitney2_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4725 Series photocopier
|
| U | WHITNEY2_XRX_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox Phaser 3200MFP multifunction laser printer
|
| U | WhitneyXerox_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Xerox WorkCentre PE220 Series multifunction laser printer
|
| U | WHITNEY_S2P | Scan2pc.exe | Scan to PC application for the scanning function of the Samsung SCX-4x21 Series multifunction printers
|
| X | wiascr | wiascr.exe | "Added by the AGENT.AM TROJAN! Note - example names include ""XviD"" |
| X | Widnows Xp Web scan | xpscan.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Win startup | mscfg32.exe | "Added by the SPYBOT-AE WORM!"
|
| X | win-xp | nvsc32.exe | "Added by the BROPIA.N WORM!"
|
| X | win32 | Shakira_1997_Part_1_.Mpeg_.scr | "Added by the MYLIFE.N WORM!"
|
| X | Win32 Cnfg32 | msconfgh.exe | "Added by the MYTOB.NB WORM!"
|
| X | Win32 Secure | msconfigsvc.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Win32 USB2 Driver | smsc.exe | "Added by the SDBOT.FO WORM!"
|
| X | Win32 USB2 Driver | syscfg32.exe | "Added by the FORBOT-R WORM!"
|
| X | Win32G | Scandisk.com | "Added by the ESTRELLA TROJAN!"
|
| X | Winamp Agent | cvscc.exe | "Added by the AGOBOT-GK WORM!"
|
| X | WinAntiSpyware 2006 Scanner | was6.exe | "WinAntiSpyware 2006 rogue spyware remover - not recommended |
| U | WinBackup Scheduler | Wbsched.exe | "LIUtilities WinBackup scheduler - backup software"
|
| X | wincfg | syscnfg.exe | "Added by an unidentified VIRUS |
| X | WinDLL (scvhost32.dll) | "rundll32.exe scvhost32.dll | start" |
| X | Windows 32 Rescue | win32resc.exe | "Added by the FORBOT-EU WORM!"
|
| X | Windows Anti Virus Control Center | avrscan.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows Anti Virus Control Center | winavscan.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows cfg | ascv.exe | "Added by the AGOBOT-SZ BACKDOOR!"
|
| X | Windows Conf | windowsconf.exe | "Added by a variant of the IRCBOT TROJAN! See here"
|
| X | Windows Configuration Loader | asclt.exe | "Added by the SDBOT-OA WORM!"
|
| X | Windows Data Server | autodisc.exe | "Added by the SPYBOT-CB WORM!"
|
| X | Windows Dcom2 Fix | mscom32.exe | "Added by the RBOT-QT WORM!"
|
| Y | Windows Defender | MSASCui.exe | "Main user interface for Microsoft's Windows Defender on XP/Vista - which ""helps protect your computer against pop-ups |
| X | Windows DLL Loader | SYSCFG16.EXE | "Added by the DOMWIS-N WORM!"
|
| X | Windows Driver Foundation | MTVSCMXT.EXE | "Added by a variant of the RBOT WORM!"
|
| X | Windows Essensials | mvnesc.exe | "Added by a variant of the IRCBOT TROJAN!"
|
| X | Windows Firewalll | scvhost.exe | "Added by the RBOT-EK WORM!"
|
| X | Windows Framework | scvh0st.exe | "Malware installed by different rogue security software including SpyKillerPro and the XP AntiVirus series"
|
| X | Windows Helper | wsctnfy.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Host Service | scvhosts.exe | "Added by the SPYBOT.NLI WORM!"
|
| X | Windows HTML file reader | Sysconf32.exe | "Added by the NOOMY.A WORM!"
|
| X | Windows Image Acquisition (WIASC) | WIAcs.exe | "Added by the RIZO.A TROJAN!"
|
| X | Windows Image Acquisition (WIASSC) | WIAcss.exe | "Added by the RIZO.A TROJAN!"
|
| X | Windows JavaScript Daemon | Winjsd.exe | "Added by the WOOTBOT.AF WORM!"
|
| X | Windows Loader Service | civsc.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Messenger 4.14 | landisc.exe | "Added by the SDBOT-KR WORM!"
|
| X | Windows MSConfig Startup Logger | winlog.exe | "Added by the RBOT.BCU WORM!"
|
| X | Windows Network Service | Msconf32.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows NT Logon Application | winlogon.scr | "Added by the RBOT-ALP WORM!"
|
| X | Windows Performance Monitor | wmscupd.exe | "Added by the IRCBOT_GEN WORM!"
|
| X | Windows Pool Manager | poolsc.exe | "Added by the OBOT.CH WORM!"
|
| ? | Windows Print Spooler | SCVHOSTS.EXE | "Suspicious due to the similarity to the valid ""svchost.exe"" file"
|
| X | Windows Registry Scan | regscan32.exe | "Added by the RBOT.KE WORM!"
|
| X | Windows Registry Scan | timeupdate.exe | "Added by the SPYBOT.JE WORM!"
|
| X | Windows Registry Scan | svcdll.exe | "Added by the RBOT-TP WORM!"
|
| X | Windows Registry Scan | regscan23.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Registry Scan | regscan.exe | "Added by the RBOT-HA WORM!"
|
| X | Windows Registry Scan | winmedia.exe | "Added by the SPYBOT.GK WORM!"
|
| X | Windows Rescue System | winsto.exe | "Added by the SUURCH.CG TROJAN!"
|
| X | Windows SA | omniscient.exe | "BLAZEFIND adware"
|
| X | Windows Scheduler | wmscheduler.exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Scheduler! | scheduler.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Screensaver | Service.exe | "Added by the KELVIR.P WORM!"
|
| X | WINDOWS SCREENSAVER | ssaver.scr | "Added by the SDBOT-YZ WORM!"
|
| X | Windows Secure Connection | winsc.exe | "Added by the SDBOT.BTN WORM!"
|
| X | Windows Security | winscure.exe | "Added by the RBOT-BAF WORM!"
|
| X | Windows Security Center Notification App | wscnfty.exe | "Added by a variant of the RBOT WORM!"
|
| X | Windows Servcesc | [9 random letters].exe | "Added by a variant of the SDBOT WORM! See here"
|
| X | Windows Server Client Verification Service | wscvs.exe | "Added by the AGENT.AWC TROJAN!"
|
| X | Windows Service Agent | wmscc.exe | "Added by the RBOT-GQP WORM!"
|
| X | Windows Service Host | scvhost.exe | "Added by the SDBOT.N TROJAN!"
|
| X | Windows Service Host | schost.exe | "Added by the GAOBOT.AO WORM!"
|
| X | Windows Services | scmsg.exe | "Added by a variant of the SDBOT WORM!"
|
| X | Windows Services | scvhoste.exe | "Added by the SPYBOT.OBZ WORM!"
|
| X | Windows Services | smsc.exe | "Added by a variant of the SDBOT WORM!"
|
| X | windows shellext.32 | mschost.exe | "Added by the BLASTER.K WORM!"
|
| X | Windows SQL management 1.33 | scvhost.exe | "Added by the SPYBOT-OB WORM!"
|
| Y | Windows SteadyState - Session Timer Notify (UI) | SCTUINotify.exe | "Part of Windows SteadyState |
| X | WINDOWS SYSTEM | smsc.exe | "Added by the MYTOB-BR WORM!"
|
| X | Windows System Configuration | SYSCFG16.EXE | "Added by the WISDOOR-K TROJAN!"
|
| X | Windows System Configuration | Passcfg16.exe | "Added by the DOMWIS-E TROJAN!"
|
| X | Windows System Manager | sysconf.exe | "Added by the MYTOB.AL WORM!"
|
| X | Windows System Manager | smsc.exe | "Added by a variant of the RBOT WORM!"
|
| X | WINDOWS SYSTEM mscdvvs | mscdvvs.exe | "Added by the MYTOB.MD WORM!"
|
| X | WINDOWS SYSTEM SCALPE | scalpe91.exe | "Added by the MYTOB-HI WORM!"
|
| X | Windows System-Control Drivers | syscontrl.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows Task Scheduler | asijdie.exe | Added by an unidentified WORM or TROJAN!
|
| X | Windows Time Service Diagnostic Tool | winscrvs.exe | "Added by the RBOT.FTV BACKDOOR!"
|
| X | Windows UDP Control Center | ehSched.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows UDP Control Center | scvhost.exe | "Added by the PUSHBOT.EH WORM!"
|
| X | Windows UDP Control Center | winuscn32.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows UDP Control Center | wksvcsc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | Windows UDP Control Services | wksvcsc.exe | "Added by the ANTIAV-C TROJAN!"
|
| X | Windows Update | scvhost.exe | "Added by the SDBOT-XT WORM!"
|
| X | Windows Update | msconfig32.exe | "Added by a variant of the SPYBOT WORM! See here"
|
| X | Windows Update | scrigz.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | Windows Update | winsc.exe | "Added by the BUZUS.RYI TROJAN!"
|
| X | Windows Update | smsscr.exe | "Added by the BANKER-DK TROJAN!"
|
| X | Windows Update Process | wmiprvsc.exe | "Added by the SDBOT-CB WORM!"
|
| X | Windows Update Service | regscv.exe | "Added by the AGOBOT-AM BACKDOOR!"
|
| X | Windows Virus Scanner | winvsvc.exe | "Added by a variant of the IRCBOT BACKDOOR! See here"
|
| X | WindowsCRC | wscrc.exe | "Added by the SDBOT-VU WORM!"
|
| X | WindowsCriticalUpdate | windows_critical_update.exe | "Added by the ASTEF or RESPAN WORMS!"
|
| X | Winds Sersc Agts | rzrzncrtz.exe | "Added by the RBOT-GTV WORM!"
|
| N | WinDVR SchSvr | SchSvr.exe | "WinScheduler is installed with WinDVD Remote Control for WinDVD from Intervideo. If you want to schedule recordings from your TV tuner card |
| U | WinFast Schedule | Wfwiz.exe | Leadtek WinFast TV tuner scheduler and remote control driver - required if you use the latter
|
| U | WinFastDTV | DTVSchdl.exe | "Scheduler for WinFast DTV digital TV cards from Leadtek Research Inc"
|
| X | WinHelp | realsched.exe | "Added by the LOVGATE-F WORM! Note - this is not the legitimate RealPlayer (realsched.exe) application of the same name. This one is located in %System%"
|
| X | Winhlp32 | Wscript.exe Msexec32.vbs | "Added by the GANT.B WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""Msexec32.vbs"" file is found in %System%"
|
| X | WINLOGON | wscript.exe WINLOGON.vbs | "Added by the YSPAN.F WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WINLOGON.vbs"" file is found in %System%"
|
| X | Winlogon | scssrr.exe | "Added by the AGENT-LXB TROJAN!"
|
| ? | WinManager | schost.exe | "??"
|
| X | Winmgr.exe | scvhost.exe | "Added by the AGOBOT.AFG WORM!"
|
| X | winrun | msconfig.exe | "Added by the WINUR WORM! Note - this is not the legitimate msconfig.exe which should only appear in Msconfig/Startup if you leave the warning box unchecked after changing an Msconfig entry and rebooting. This one is located in c:\winrun"
|
| X | WinScMngr | winsmc.exe | "Added by the SDBOT-BPZ WORM!"
|
| X | Winsock Driver | nvscv32.exe | "Added by the AGOBOT-FD WORM!"
|
| X | Winsock Driver | scvhost.exe | "Added by the RBOT.AEU BACKDOOR!"
|
| X | Winsock2 driver | wincfg.scr | "Added by the SPYBOT-E TROJAN!"
|
| X | Winsock2.dll | WINLODR.SCR | "Added by an unidentified VIRUS |
| X | Winsock32driver | win32server.scr | "Added by the HACARMY TROJAN!"
|
| X | WinStart | Wscript.exe WinStart.vbs | "Added by the CIAN.C WORM! Note that wscript.exe is a legitimate Microsoft file used to launch script files and shouldn't be deleted. The ""WinStart.vbs"" file is located in %System%"
|
| X | winsys | syschost.exe | Added by an unidentified TROJAN!
|
| U | WinSysCheck | sb32mon.exe | "Part of the SpyBuddy keystroke logger/monitoring program - see here. Remove unless you installed it yourself!"
|
| X | WINTASK DLL | jusched32.exe | "Added by the MYTOB.AI WORM!"
|
| N | WinTOTAL Scheduler | guru.exe | WinTOTAL Real estate appraisal software related
|
| X | winupdate | jusched.exe | "Added by the DWNLDR-FUX TROJAN! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %Windir%"
|
| U | Wireless Connection Manager | wirelesscm.exe | "Wireless adapter configuration utility for D-Link's range"
|
| X | Wlan Driver | avscan.exe | "Added by the WOOTBOT.DH WORM!"
|
| X | WMI Standard Event Consumer - Scripting | scrcons32.exe | "Added by the RBOT-GRD WORM!"
|
| X | WMI Standard Event Consumer - Scripting | scrcs.exe | "Added by a variant of the RBOT-GRD WORM!"
|
| X | wmon | jusched.exe | "Added by the AGOBOT-OW WORM! Note that this is not the legitimate Sun Microsystems file (of the same name) which is usually located in %Program Files%\Java\version number\bin. This one is located in %System%"
|
| U | WMPNSCFG | WMPNSCFG.exe | "Network sharing tool for Windows Media Player 11 for XP & Vista. When using WMP 11 on home network you can choose to share your favorite music |
| X | WNSC | wnsin**.exe [* = random char] | "PurityScan adware"
|
| X | Wnsck2 driver | wlogf.exe | "Added by the SPYBOT-AF WORM!"
|
| X | WNSI | wnscp**.exe [* = random char] | "PurityScan adware"
|
| X | WOOZ | autodisc.exe | "Added by the AGENT-CPS TROJAN!"
|
| U | Workstation Scheduler | wm95.exe | "Desktop Management Scheduler. Part of Novell's Netware Client. Schedueles NDS events. If events have been schedueled |
| X | WPSVC Services | wpnsc.exe | "Added by a variant of the IRCBOT BACKDOOR!"
|
| X | wsc | mstdl.exe | "MaCatte Antivirus 2009 rogue security software - not recommended |
| U | WScheduler | WScheduler.exe | "Windows Scheduler - "schedule unattended running of applications |
| X | wscmgr | wscmgr.exe | "Added by the AUTORUN-AA WORM!"
|
| X | wscnfty | wscnfty.exe | "Added by a variant of the RBOT WORM!"
|
| X | wscntfys | wsscntfy.exe | "Added by the SDBOT-TN WORM!"
|
| X | WSConfiguration | spoolsc.exe | "Added by the AGOBOT-HY WORM!"
|
| X | wscript.exe | vabian.vbs | "Added by the VABI VIRUS!"
|
| X | wscsvc.exe | wscsvc.exe | "Added by a password stealing BANKER TROJAN!"
|
| X | wscsvc32.exe | wscsvc32.exe | "Antivirus rogue security software - not recommended |
| X | wsctf.exe | wsctf.exe | "Added by the JAMPORK.E WORM!"
|
| X | Wsdata service | WSconf.exe | "Added by the SDBOT.ZU WORM!"
|
| X | WSSVC | smsc.exe | "Added by the AUTORUN-AGA WORM!"
|
| U | WTIndicator | SchedInd.exe | "WinTask - software that automates a variety of routine tasks quickly and simply"
|
| X | WTSC | wapisvcc.exe | "PurityScan adware"
|
| U | X4ALLNL | wdfsctl.exe | "XS4All Webdisk - web space management utility for the Dutch ISP"
|
| U | XemiComputers Scheduler | Scheduler.exe | "Smooth Program Scheduler from XemiComputers ""will start any program you want at a scheduled time"""
|
| U | XeroxScannerDaemon | XrxFTPLt.exe | "Xerox Scanner Daemon - driver for Xerox Scanner model fu621d"
|
| ? | XeroxScanUtility | xrxzipui.exe | "Associated with a Xerox multifunction and/or scanner. What does it do and is it required?"
|
| U | XSC SIP Client | X-Lite.exe | """CounterPath's X-Lite 3.0 is the market's leading free SIP based softphone available for download"". For VOIP and broadband users"
|
| U | XTNDConnect PC - ScheduleSync | SCHEDU~1.EXE | "ScheduleSync specific translator for XTNDConnect PC - ""award-winning desktop-sync application that enables you to easily synchronize your contacts |
| X | Yahoo Messengger | SCVHOST.exe | "Added by the SOHANA-V WORM!"
|
| X | Yahoo Messengger | SCVHSOT.exe | "Added by the HAKAG-A WORM!"
|
| X | Yahoo Messengger | SCVVHSOT.exe | "Added by the SILLYFDC-AE WORM!"
|
| X | Yahoo Messengger | SSCVIHOST.exe | "Added by the SOHANA-W WORM!"
|
| X | Yahoo Messengger | SSCVIIHOST.exe | "Added by the SOHANA-Y WORM!"
|
| X | Yahoo Messengger | scvhosts.exe | "Added by the SOHANNA-AH WORM!"
|
| X | Yahoo Messengger | scvshosts.exe | "Added by the TRAX-A WORM!"
|
| U | You've Got Pictures Screensaver | ygpsstra.exe | AOL You've Got Pictures Screensaver
|
| X | zsmscc | rundll32.exe zsmscc071001.dll mymain | "Added by the GENETIK.KQ TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""zsmscc071001.dll"" file is found in %System%"
|
| X | zsmscc | rundll32.exe mycc071208.dll mymain | "Added by the AGENT.FZK TROJAN! Note that rundll32.exe is a legitimate Microsoft file used to launch DLL file types and shouldn't be deleted. The ""mycc071208.dll"" file is found in %System%"
|
| U | ZSScheduler | zsscheduler.dll | "ZeroSpyware from FBM Software"
|
| X | [12 random characters] | autodisc.exe | "IeDriver adware variant"
|
| X | [32 random hex numbers] | tsc.exe | "Total Security rogue security software - not recommended |
| X | [filename] | svchost.scr | "Added by the BANKER-CC TROJAN!"
|
| X | [original filename] | svchost.scr | "Added by the BANCBAN-CX TROJAN!"
|
| X | [original filename] | xphost.scr | "Added by the BANCBAN-HM TROJAN!"
|
| X | [random characters] | rsbmsc.exe | "Detected by AntiVir antivirus as the BDS/Agent.adt TROJAN!"
|
| X | [random name] | scanregw.exe | "PurityScan adware. Note - do not confuse this with the legitimate Windows process scanregw.exe which is always found in the Windows folder on Win9x/ME machines"
|
| X | [random] | lsass.scr | "Added by the BANCBAN-CW TROJAN!"
|
| X | [random] | svchost.scr | "Added by the BANCBAN-CY TROJAN!"
|
| X | [various names] | ActionScr.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | NsCplTray.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | NSYSCPLSTR.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | scanSYS.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | StatusCheck.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| X | [various names] | sysconf16.exe | "Wareout - malware masquerading as a spyware and dialer remover"
|
| Y | _AntiSpyware | MssCli.exe | "Part of McAfee AntiSpyware"
|
| X | _ntrRescueService | _ntrrs.exe | "Added by the DLOADER-JV TROJAN!"
|
| U | {1290A33C-85F5-4164-A1BE-7DD299D4986A} | PBKScheduler.exe | "Scheduler for CyberLink PowerBackup - archiving/backup utility"
|