| Type |
Caption |
Section |
File name |
Description |
 |
System Restore Data |
|
[path] repcale.exe [path] beird.exe |
Added by the RANDON.AN WORM! Read more |
 |
boarddata |
|
[path] repcale.exe [path] palsp.exe |
Added by a variant of the RANDON.AN WORM! Read more |
 |
element furth |
|
[path] repcale.exe [path] palsp.exe |
Read more |
 |
installs sp2 |
|
[path] repcale.exe [path] palsp.exe |
Added by a variant of the RANDON.AN WORM! Read more |
 |
PrinterSpool |
|
[path] RESTORE.EXE [path] SPOOL.EXE |
Added by the ALADINZ.K TROJAN! Read more |
 |
Protection |
|
[path] runtask.exe [path] protection.exe |
Added by a variant of the AGENT.3.AU TROJAN! |
 |
svchost |
|
[path] SETUP.EXE |
Added by the SETCLO WORM! Read more |
 |
MEDIA32 |
|
[pathname of the executable] |
Added by the Troj/PurScan-Z trojan. Read more |
 |
Root_Machine |
|
[pathname of the Trojan executable] |
Added by the Troj/Bancban-DP password-stealing trojan for customers of Brazilian banks. Read more |
 |
spoolax |
|
[pathname of the Trojan executable] |
Added by the Troj/Perda-D Trojan. Read more |
 |
stdlib |
|
[pathname of the Trojan executable] |
Added by the Troj/Perda-E password-stealing Trojan. Read more |
 |
Windows Standard Securty |
|
[random 3 letter filename] |
Added by the W32/Rbot-ALF worm. Read more |
 |
KavSvc |
|
[random 6 char filename] |
Qoologic downloader trojan variant using random file names (examples: nzkklz.exe) |
 |
Startup Configuration |
|
[random 6 letter filename] |
Added by the W32/Rbot-ARV worm. This infection will connect to a remote IRC server and wait for commands to be executed on the infected computer. Read more |
 |
SysTray.Excn |
|
[random 8 character dll) |
Added by the Troj/Cozdoor-C Trojan.br /br /Uses CLSID: b{1722ECFF-4356-4f5b-B534-E67294FE75E9}/b. Read more |
 |
SysTray.Exsh |
|
[random 8 character dll] |
Added by the Troj/Cozdoor-D bacdoor Trojan.br /br /Uses CLSID: b{1768ECFC-4F5C-4f5b-B134-D67294FC78E9}/b. Read more |
 |
Legacy |
|
[RANDOM CHARACTERS] |
Added by the Backdoor.Eparssa backdoor Trojan. Read more |
 |
WinNetDDE |
|
[random characters].exe |
_blankNETDEPIX.B TROJAN! |
 |
Internet Agent |
|
[random CLSID] |
Added by the Read more |
 |
*ms setup |
|
[random file name] |
Virtumondo adware, also known as the VUNDO TROJAN! Read more |
 |
agent browser |
|
[random file name] |
Added by the PPdoor.M-bdr backdoor TROJAN! |